Method and apparatus for handling security key in wireless communication system

The method ensures secure and reliable communication by deriving and transmitting security keys through F1 application protocol messages, addressing security challenges during L1/L2 triggered mobility and Conditional Handover in wireless communication systems.

WO2026034971A1PCT designated stage Publication Date: 2026-02-12SAMSUNG ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/011691
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-05
Filing Date
2025-08-05
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Existing wireless communication systems face challenges in ensuring the security of data communication between user equipment (UE) and base stations during mobility scenarios such as L1/L2 Triggered Mobility (LTM) and Conditional Handover (CHO), particularly in dual-connectivity scenarios, which can lead to service interruptions and reliability issues.

Method used

A method involving a central unit of a base station that derives security keys based on next hop parameters and counters, and transmits this information via F1 application protocol messages to ensure secure communication during L1/L2 triggered mobility, using explicit or implicit methods to maintain key consistency between the UE and base stations.

Benefits of technology

Enhances security and reliability of signaling and user data communication during mobility scenarios, reducing service interruptions and maintaining consistent security keys across different base stations, thereby supporting seamless handovers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025011691_12022026_PF_FP_ABST
    Figure KR2025011691_12022026_PF_FP_ABST
Patent Text Reader

Abstract

The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. The present disclosure provides a node and a user equipment in a wireless communication system and methods performed by the same. A method performed by a central unit of a first base station in a wireless communication system, including: receiving, from an access and mobility management function (AMF), a next hop (NH) parameter and a first next hop chaining counter (NCC) value; deriving at least one first security key related to at least one candidate base station based on the NH parameter and the first NCC value; and transmitting, to a distributed unit of the first base station, security related information for supporting a user equipment (UE) during L1 / L2 triggered mobility (LTM) via an F1 application protocol (F1AP) message, wherein the security related information includes the first NCC value.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD AND APPARATUS FOR HANDLING SECURITY KEY IN WIRELESS COMMUNICATION SYSTEM

[0001] The present disclosure relates to a field of wireless communication technologies, and in particular, to a node and a user equipment in a wireless communication system and methods performed by the same.

[0002] 5G mobile communication technologies define broad frequency bands such that high transmission rates and new services are possible, and can be implemented not only in "Sub 6GHz" bands such as 3.5GHz, but also in "Above 6GHz" bands referred to as mmWave including 28GHz and 39GHz. In addition, it has been considered to implement 6G mobile communication technologies (referred to as Beyond 5G systems) in terahertz bands (for example, 95GHz to 3THz bands) in order to accomplish transmission rates fifty times faster than 5G mobile communication technologies and ultra-low latencies one-tenth of 5G mobile communication technologies.

[0003] At the beginning of the development of 5G mobile communication technologies, in order to support services and to satisfy performance requirements in connection with enhanced Mobile BroadBand (eMBB), Ultra Reliable Low Latency Communications (URLLC), and massive Machine-Type Communications (mMTC), there has been ongoing standardization regarding beamforming and massive MIMO for mitigating radio-wave path loss and increasing radio-wave transmission distances in mmWave, supporting numerologies (for example, operating multiple subcarrier spacings) for efficiently utilizing mmWave resources and dynamic operation of slot formats, initial access technologies for supporting multi-beam transmission and broadbands, definition and operation of BWP (BandWidth Part), new channel coding methods such as a LDPC (Low Density Parity Check) code for large amount of data transmission and a polar code for highly reliable transmission of control information, L2 pre-processing, and network slicing for providing a dedicated network specialized to a specific service.

[0004] Currently, there are ongoing discussions regarding improvement and performance enhancement of initial 5G mobile communication technologies in view of services to be supported by 5G mobile communication technologies, and there has been physical layer standardization regarding technologies such as V2X (Vehicle-to-everything) for aiding driving determination by autonomous vehicles based on information regarding positions and states of vehicles transmitted by the vehicles and for enhancing user convenience, NR-U (New Radio Unlicensed) aimed at system operations conforming to various regulation-related requirements in unlicensed bands, NR UE Power Saving, Non-Terrestrial Network (NTN) which is UE-satellite direct communication for providing coverage in an area in which communication with terrestrial networks is unavailable, and positioning.

[0005] Moreover, there has been ongoing standardization in air interface architecture / protocol regarding technologies such as Industrial Internet of Things (IIoT) for supporting new services through interworking and convergence with other industries, IAB (Integrated Access and Backhaul) for providing a node for network service area expansion by supporting a wireless backhaul link and an access link in an integrated manner, mobility enhancement including conditional handover and DAPS (Dual Active Protocol Stack) handover, and two-step random access for simplifying random access procedures (2-step RACH for NR). There also has been ongoing standardization in system architecture / service regarding a 5G baseline architecture (for example, service based architecture or service based interface) for combining Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) for receiving services based on UE positions.

[0006] As 5G mobile communication systems are commercialized, connected devices that have been exponentially increasing will be connected to communication networks, and it is accordingly expected that enhanced functions and performances of 5G mobile communication systems and integrated operations of connected devices will be necessary. To this end, new research is scheduled in connection with eXtended Reality (XR) for efficiently supporting AR (Augmented Reality), VR (Virtual Reality), MR (Mixed Reality) and the like, 5G performance improvement and complexity reduction by utilizing Artificial Intelligence (AI) and Machine Learning (ML), AI service support, metaverse service support, and drone communication.

[0007] Furthermore, such development of 5G mobile communication systems will serve as a basis for developing not only new waveforms for providing coverage in terahertz bands of 6G mobile communication technologies, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), array antennas and large-scale antennas, metamaterial-based lenses and antennas for improving coverage of terahertz band signals, high-dimensional space multiplexing technology using OAM (Orbital Angular Momentum), and RIS (Reconfigurable Intelligent Surface), but also full-duplex technology for increasing frequency efficiency of 6G mobile communication technologies and improving system networks, AI-based communication technology for implementing system optimization by utilizing satellites and AI (Artificial Intelligence) from the design stage and internalizing end-to-end AI support functions, and next-generation distributed computing technology for implementing services at levels of complexity exceeding the limit of UE operation capability by utilizing ultra-high-performance communication and computing resources.

[0008] Embodiments of the present disclosure provide a method performed by a central unit of a first base station in a wireless communication system, including: receiving, from an access and mobility management function (AMF), a next hop (NH) parameter and a first next hop chaining counter (NCC) value; deriving at least one first security key related to at least one candidate base station based on the NH parameter and the first NCC value; and transmitting, to a distributed unit of the first base station, security related information for supporting a user equipment (UE) during L1 / L2 triggered mobility (LTM) via an F1 application protocol (F1AP) message, wherein the security related information includes the first NCC value.

[0009] Embodiments of the present disclosure provide a method performed by a distributed unit of a base station in a wireless communication system, including: receiving, from a central unit of the base station, security related information for supporting a user equipment (UE) during L1 / L2 triggering mobility (LTM) via an F1 application protocol (F1AP) message, wherein the security related information includes a next hop chaining counter (NCC) value; generating a cell switch command medium access control control element (MAC CE) including the NCC value; and transmitting, to the UE, the cell switch command MAC CE.

[0010] Embodiments of the present disclosure provide a central unit of a first base station in a wireless communication system, including: a transceiver; and at least one processor coupled to the transceiver and configured to: receive, from an access and mobility management function (AMF), a next hop (NH) parameter and a first next hop chaining counter (NCC) value, derive at least one first security key related to at least one candidate base station based on the NH parameter and the first NCC value, and transmit, to a distributed unit of the first base station, security related information for supporting a user equipment (UE) during L1 / L2 triggered mobility (LTM) via an F1 application protocol (F1AP) message, wherein the security related information includes the first NCC value.

[0011] Embodiments of the present disclosure provide a distributed unit of a base station in a wireless communication system, including: a transceiver; and at least one processor coupled to the transceiver and configured to: receive, from a central unit of the base station, security related information for supporting a user equipment (UE) during L1 / L2 triggering mobility (LTM) via an F1 application protocol (F1AP) message, wherein the security related information includes a next hop chaining counter (NCC) value, generate a cell switch command medium access control control element (MAC CE) including the NCC value, and transmit, to the UE, the cell switch command MAC CE.

[0012] The above and other aspects, features and advantages of certain embodiments of the present disclosure will be more apparent from the following description taken in conjunction with the accompanying drawings, in which:

[0013] FIG. 1 is an exemplary system architecture 100 of system architecture evolution (SAE);

[0014] FIG. 2 is an exemplary system architecture 200 according to various embodiments of the present disclosure;

[0015] FIGs. 3a and 3b are sequential flowcharts of a security mechanism scheme 1 when a UE performs "MN LTM without SN change" in dual-connectivity according to embodiments of the present disclosure;

[0016] FIGs. 4a and 4b are sequential flowcharts of a security mechanism scheme 2 when a UE performs "MN LTM without SN change" in dual-connectivity according to embodiments of the present disclosure;

[0017] FIGs. 5a and 5b are sequential flowcharts of a security mechanism scheme 3 when a UE performs "MN LTM without SN change" in dual-connectivity according to embodiments of the present disclosure;

[0018] FIG. 6 is an example flowchart for LTM triggering in an LTM with DC scenario according to embodiments of the present disclosure;

[0019] FIGs. 7a, 7b, and 7c respectively show a flowchart of a method performed by a first node in a wireless communication system according to embodiments of the present disclosure;

[0020] FIGs. 8a, 8b, and 8c respectively show flowcharts of a method performed by a user equipment (UE) in a wireless communication system according to embodiments of the present disclosure;

[0021] FIG. 9 shows a schematic diagram of a node 900 according to embodiments of the present disclosure; and

[0022] FIG. 10 shows a schematic diagram of a user equipment (UE) 1000 according to embodiments of the present disclosure.

[0023] The following description with reference to the accompanying drawings is provided to assist in a comprehensive understanding of various embodiments of the present disclosure as defined by the claims and their equivalents. It includes various specific details to assist in that understanding but these are to be regarded as merely exemplary. Accordingly, those of ordinary skill in the art will recognize that various changes and modifications of the various embodiments described herein can be made without departing from the scope and spirit of the present disclosure. In addition, descriptions of well-known functions and constructions may be omitted for clarity and conciseness.

[0024] The terms and words used in the following description and claims are not limited to the bibliographical meanings, but, are merely used by the inventor to enable a clear and consistent understanding of the present disclosure. Accordingly, it should be apparent to those skilled in the art that the following description of various embodiments of the present disclosure is provided for illustration purpose only and not for the purpose of limiting the present disclosure as defined by the appended claims and their equivalents.

[0025] It is to be understood that the singular forms "a," "an," and "the" include plural referents unless the context clearly dictates otherwise. Thus, for example, reference to "a component surface" includes reference to one or more of such surfaces.

[0026] The term "include" or "may include" refers to the existence of a corresponding disclosed function, operation or component which can be used in various embodiments of the present disclosure and does not limit one or more additional functions, operations, or components. Additionally, the terms such as "include" and / or "have" may be construed to denote a certain characteristic, number, step, operation, constituent element, component or a combination thereof, but may not be construed to exclude the existence of or a possibility of addition of one or more other characteristics, numbers, steps, operations, constituent elements, components or combinations thereof.

[0027] The term "or" used in various embodiments of the present disclosure includes any or all of combinations of listed words. For example, the expression "A or B" may include A, may include B, or may include both A and B.

[0028] Unless defined differently, all terms used herein, which include technical terminologies or scientific terminologies, have the same meaning as that understood by a person skilled in the art to which the present disclosure belongs. Such terms as those defined in a generally used dictionary are to be interpreted to have the meanings equal to the contextual meanings in the relevant field of art, and are not to be interpreted to have ideal or excessively formal meanings unless clearly defined in the present disclosure.

[0029] An aspect of the present disclosure relates to wireless communication technology, for example, relates to security mechanisms that need to be considered to ensure the security of data communicated between the UE and the base stations when the UE is handed over among different master base stations (or master nodes (MNs)) or secondary base stations (or secondary nodes (SNs)) due to mobility in dual-connectivity.

[0030] In order to reduce the delay of service interruption during UE mobility and ensure the reliability of UE mobility, Rel-18 formulated technical specifications about LTM (L1 / L2 Triggered Mobility) of cells within a base station (for example, cells within the same gNB-CU, and within the same or different gNB-DUs) and technical specifications for supporting the performing of Subsequent LTM. The main process of LTM is that a gNB-DU determines a target cell and transmits a mobility command to a UE based on an L1 (Layer 1) measurement report reported by the UE. Compared with the previous handover process based on an L3 (Layer 3) measurement report, since the L3 measurement report is obtained based on reprocessing such as linear averaging of the L1 measurement, the faster decision of a mobility command and transmitting the command through an L2 (Layer 2) MAC CE of the gNB-DU in LTM can allow the UE to receive the command faster. In addition, as for an access process of the UE, a random access-less (RACH-less) process can be applied, thereby further reducing the delay of the UE's service interruption during the mobility process. As for the Subsequent LTM, after the UE performs LTM once, configuration of the candidate cells is still retained on the UE and the network side, the UE can report L1 measurement reports to the present serving gNB-DU, and the network side can continue to trigger the UE to perform LTM based on the measurement reports.

[0031] A Conditional Handover (CHO) process is a one-time handover process, that is, the UE evaluates measurement conditions of L3, and if they are satisfied by a candidate cell, the UE switches to the selected candidate cell, and then the configuration of other candidate cells needs to be released. If CHO needs to be performed again, pre-configuration needs to be performed again. Subsequent LTM avoids repeated configuration processes and saves signaling overhead. And due to the existence of the configuration of multiple candidate cells, the reliability of UE mobility is also increased.

[0032] For the LTM, the UE can perform it in a case of single connectivity or in a case of dual-connectivity, such as a scenario of "Inter-MN LTM without SN change" or "Inter-SN LTM without MN change". The "Inter-SN LTM without MN change" may be such a scenario where, for example, the UE accesses from the primary secondary cell (PSCell) of a source SN to the primary secondary cell of another target SN, the UE leaves the connection of the source SN and is about to access the target SN, with the MN remaining unchanged. The "Inter-MN LTM without SN change" may be such a scenario where the UE accesses from the primary cell (PCell) of a source MN to the primary cell of another target MN, the UE leaves the connection of the source MN and is about to access the target MN, with the SN remaining unchanged. In future communications, scenarios such as Subsequent CHO, or Subsequent "Inter-MN CHO without SN change" or Subsequent "Inter-SN CHO without MN change" may be supported.

[0033] In summary, in any of the above procedures, for example, no matter the UE moves between MNs or between SNs, the security mechanism needs to be enhanced to ensure the security of signaling and user data communications between the UE and the base station.

[0034] The methods provided by the embodiments of the present disclosure can ensure the security of signaling and user data communication between the UE and the base station for mobility scenarios related to LTM or CHO, thereby ensuring the reliability and normal use of LTM or CHO.

[0035] The drawings discussed below and various embodiments for describing the principles of the present disclosure in this patent document are only for illustration and should not be interpreted as limiting the scope of the disclosure in any way. Those skilled in the art will understand that the principles of the present disclosure can be implemented in any suitably arranged system or device.

[0036] FIG. 1 is an exemplary system architecture 100 of system architecture evolution (SAE). User equipment (UE) 101 is a terminal device for receiving data. An evolved universal terrestrial radio access network (E-UTRAN) 102 is a radio access network, which includes a macro base station (eNodeB / NodeB) that provides UE with interfaces to access the radio network. A mobility management entity (MME) 103 is responsible for managing mobility context, session context and security information of the UE. A serving gateway (SGW) 104 mainly provides functions of user plane, and the MME 103 and the SGW 104 may be in the same physical entity. A packet data network gateway (PGW) 105 is responsible for functions of charging, lawful interception, etc., and may be in the same physical entity as the SGW 104. A policy and charging rules function entity (PCRF) 106 provides quality of service (QoS) policies and charging criteria. A serving general packet radio service (GPRS) support node (Serving GPRS Support Node, SGSN) 108 is a network node device that provides routing for data transmission in a universal mobile telecommunications system (UMTS). A home subscriber server (HSS) 109 is a home subsystem of the UE, and is responsible for protecting user information including a current location of the user equipment, an address of a serving node, user security information, and packet data context of the user equipment, etc.

[0037] FIG. 2 is an exemplary system architecture 200 according to various embodiments of the present disclosure. Other embodiments of the system architecture 200 can be used without departing from the scope of the present disclosure.

[0038] User equipment (UE) 201 is a terminal device for receiving data. A next generation radio access network (NG-RAN) 202 is a radio access network, which includes a base station (a gNB or an eNB connected to 5G core network 5GC, and the eNB connected to the 5GC is also called ng-gNB) that provides UE with interfaces to access the radio network. An access and mobility management function (AMF) entity 203 is responsible for managing mobility context and security information of the UE. A user plane function (UPF) entity 204 mainly provides functions of user plane. A session management function SMF entity 205 is responsible for session management. A data network (DN) 206 includes, for example, services of operators, access of Internet and service of third parties.

[0039] For convenience of description, some example names involved in the following description of the embodiments of the present disclosure are explained as follows:

[0040] LTM: L1 / L2 Triggered Mobility.

[0041] SCPAC (subsequent CPAC): Subsequent Conditional PSCell Addition or Change. After PSCell addition, PSCell change, PCell change or SCG release, pre-configuration is performed based on the subsequent CPAC configuration of the candidate PSCell, and a Conditional PSCell addition or change process is performed without reconfiguring and restarting Conditional PSCell Change (CPC) / Conditional PSCell Addition (CPA).

[0042] CHO: Conditional Handover. That is, the handover procedure is performed only if a condition is met. The network pre-configures resources for multiple candidate target cells (which may be of the same base station or different base stations) based on the UE's measurement reports, and transmits the corresponding resources and measurement configurations of each cell to the UE in advance, and the UE saves the corresponding resources of each cell and performs measurement for evaluation of the condition. When the UE finds that a certain cell meets the condition, it leaves the source cell, successfully accesses this certain cell and applies the corresponding configuration. The UE then releases all configurations of the other candidate cells, while the node to which the target cell belongs informs the source node which cell was selected. The network side then performs releasing all configurations of the other candidate cells.

[0043] AMF: Access and Mobility Management Function, which is a network element of the 5G core network and is responsible for 5G base station access and mobility management. 5G base stations and AMF are connected through NG-C interfaces.

[0044] NG-RAN (New Generation Radio Access Network) node: a next generation radio access network node. For example, it may be a 5G base station, including gNB or ng-eNB.

[0045] gNB (next Generation Node B): a next generation base station node. For example, it may be a 5G NR (New Radio) base station.

[0046] gNB-DU: gNB-Distributed Unit. The gNB-DU has functions such as Radio Link Control (RLC) protocol, Medium Access Control (MAC) and Physical Layer (Physical Layer, PHY) protocol.

[0047] gNB-CU: gNB-Central Unit. The gNB-CU has functions such as Radio Resource Control (RRC), Service Data Adaptation Protocol (SDAP) and Packet Data Convergence Protocol (PDCP).

[0048] NR-DC (NR-NR Dual Connectivity): next generation radio access network dual connectivity.

[0049] MN: Master Node.

[0050] SN: Secondary Node.

[0051] MCG (Master Cell Group): in MR-DC, it may be a group of serving cells associated with the master node, including SpCell (PCell) and optionally one or more SCells.

[0052] SCG (Secondary Cell Group): in MR-DC, it may be a group of serving cells associated with a secondary node, including SpCell (PSCell) and optionally one or more SCells.

[0053] PSCell: a primary cell of a secondary cell group.

[0054] PCell: a primary cell of a primary cell group.

[0055] SpCell: a special cell, that is, the primary cell of a primary cell group or a secondary cell group.

[0056] Cell Switch Command: a command used to indicate cell switch, which may include at least identification information associated with a target cell.

[0057] It should be understood that the terms or names of messages in the present disclosure are only examples, and other names may be adopted. The information that needs to be transmitted between interfaces can be transmitted through new messages which are individually defined, or by adding new information elements (IEs) to the existing messages.

[0058] Exemplary embodiments of the present disclosure are further described below with reference to the accompanying drawings.

[0059] The text and drawings are provided as examples only to help understand the present disclosure. They should not be interpreted as limiting the scope of the present disclosure in any way. Although certain embodiments and examples have been provided, based on the disclosure herein, it will be apparent to those skilled in the art that changes may be made to the illustrated embodiments and examples without departing from the scope of the present disclosure.

[0060] In the present disclosure, KNG-RANmay refer to a key used for communication with a master node (and / or a corresponding primary cell), or may be referred to as a key associated with a master node (and / or a corresponding primary cell); S-Ksn may refer to a key used for communication with a secondary node (and / or a corresponding secondary cell), or may be referred to as a key associated with a secondary node (and / or a corresponding secondary cell); NCC (Next Hop Chaining Counter) may refer to a parameter used to derive or generate a KNG-RAN; and SK-Counter may refer to a parameter used to derive or generate an S-Ksn. The symbol "*" may represent an update of a key or parameter, etc. For example, KNG-RAN* may represent an updated KNG-RAN, and NCC* may represent an updated NCC, etc.

[0061] FIG. 3 is a flowchart of a security mechanism scheme 1 when a UE performs "MN LTM without SN change" in dual-connectivity according to embodiments of the present disclosure.

[0062] The main idea of this example is to use an LTM cell switch command (or referred to as cell switch command) MAC CE to transmit information of a related SK-Counter (Secondary Key-Counter), and the SK-Counter parameter used by the UE is transmitted to the UE explicitly or implicitly by the network side through the MAC CE each time LTM is triggered.

[0063] As shown in FIG. 3, it is assumed that the UE has established dual-connectivity on the source master node MN1 (e.g., which may be referred to as a first node) and the secondary node SN (e.g., which may be referred to as a second node). At this time, the key used for communication between the UE and MN1 is KNG-RAN, and the key used for communication between the UE and SN is S-Ksn.

[0064] In the preparation phase (or preparation process) of Inter-MN LTM, the source master node MN1 performs a handover request process with each candidate MN (e.g., MN2 and / or MN3) on a per candidate cell basis. The source MN1 will calculate a KNG-RAN* used by the candidate MNs (herein, a candidate MN may also refer to one or more candidate cells belonging to it, which will not be described again below), and transmit the KNG-RAN* and a current NCC (Next Hop Chaining Counter) parameter value to each candidate MN. Then, each candidate MN may derive an S-Ksn through the KNG-RAN* and a corresponding SK-Counter, and then transmit the S-Ksn to the SN by carrying it in an SN addition request message. When the candidate MN receives a reply from the SN, it will reply to the source MN1 with a handover request acknowledge message, and a handover command (HO Command) message carried by it may contain information of the NCC and SK-Counter of the candidate MN. In the drawings and the following description, for ease of distinction, the SK-Counter associated with MN1 is represented by SK-Counter 1, the SK-Counter associated with MN2 is represented by SK-Counter 2, and the SK-Counter associated with MN3 is represented by SK-Counter 3.

[0065] After completing the above inter-MN LTM preparation process between the source MN and the candidate MNs for each candidate cell, the source MN1 would have collected the configuration information of each candidate cell, including information of the NCC and SK-Counter value of each candidate cell. The source MN1 may then configure the configuration information of each candidate cell to the UE through an RRC Reconfiguration message. After receiving the NCC and SK-Counter value of each candidate cell, the UE may derive the KNG-RAN*, and then use the SK-Counter to derive the S-Ksn. In this way, the keys used between the UE and the MN and SN on the network side are consistent.

[0066] When UE transmits an L1 measurement report to MN1 and MN1 decides to trigger LTM, MN1 transmits an LTM cell switch command MAC CE to UE. Assume that the UE leaves the connection of MN1 and accesses a candidate cell on the target master node MN2. When the UE successfully accesses the target master node MN2, MN2 will transmit a path switching request message to the AMF, and then the AMF replies a path switching request acknowledge message to the target master node MN2, which may carry an NH (Next Hop) parameter and a new NCC value (for example, NCC*, its value may be NCC+1).

[0067] When MN2 obtains the NH and the new NCC value, it may transmit a derived new KNG-RAN* (e.g., KNG-RAN**) and the new NCC value (e.g., NCC*) to each other candidate MN on a per candidate cell basis. Optionally, a new XnAP message (e.g., LTM Configuration Modification Request message, LTM Modification Request message, or Handover Modification Request message, etc.) may be defined to convey such information or a Handover Request message may be used to convey such information. The message may include one or more of the following information:

[0068] - an LTM modification or update indication (e.g., an LTM indication, whose value may be "modification" or "update", etc.) or an LTM modification or update request

[0069] - a candidate cell ID or target cell ID (e.g., the ID may be a Cell ID or an NR CGI, etc.)

[0070] - an LTM Configuration ID, which corresponds to an LTM candidate cell

[0071] - access stratum security information (AS Security Information), which may include the following information:

[0072] ■ KNG-RAN* (Key NG-RAN Star): the key currently derived and to be used by the target cell / target node

[0073] ■ Next Hop Chaining Counter (NCC): the new NCC value obtained from AMF

[0074] When other candidate MNs (for example, when MN2 is the current source MN, the current other candidate MNs may be MN1 and / or MN3 in FIG. 3) obtain the new KNG-RAN* and the new NCC value, the candidate MN derives a new S-Ksn through the new KNG-RAN*and an SK-Counter, and then transmits the new S-Ksn to the SN through an SN modification request message. The candidate MN then needs to transmit information of the used SK-Counter to MN2 (the current source MN). Optionally, a new XnAP message (e.g., LTM Configuration Modification Request Acknowledge message, LTM Modification Request Acknowledge message, or Handover Modification Request Acknowledge message, etc.) may be defined to convey such information or a Handover Request Acknowledge message may be used to convey such information. The message may include one or more of the following information:

[0075] - an LTM modification or update acknowledge indication

[0076] - a candidate cell ID or target cell ID (e.g., the ID may be a Cell ID or an NR CGI, etc.)

[0077] - an LTM Configuration ID, which corresponds to an LTM candidate cell

[0078] - an SK-Counter (the candidate MN (e.g., MN3) derives the new S-Ksn with the new KNG-RAN* and this SK-Counter)

[0079] - a Next Hop Chaining Count (NCC), the new NCC value obtained from MN2, which may be packaged in an RRC message container

[0080] For each candidate cell, when MN2 completes the above process, MN2 would have collected information including the NCC and SK-Counter value corresponding to each candidate cell. If the MN is in a CU-DU split architecture, the MN2-CU needs to transmit such information to the MN2-DU through an F1AP message, because the trigger of LTM is transmitted to the UE through a MAC CE of the MN2-DU (for example, an LTM cell switch command MAC CE). Optionally, this F1AP message may contain one or more of the following information:

[0081] - a SK-Counter list (containing information of multiple SK-Counters, where each SK-Counter is for a candidate cell)

[0082] ■ a candidate cell ID or target cell ID (e.g., the ID may be a Cell ID or an NR CGI, etc.)

[0083] ■ an LTM Configuration ID, which corresponds to an LTM candidate cell

[0084] ■ a SK-Counter (the candidate MN corresponding to the candidate cell derives the new S-Ksn using the new KNG-RAN* and this SK-Counter)

[0085] - a Next Hop Chaining Count (NCC), which is the new NCC value obtained by MN2 from AMF

[0086] Next, when the UE transmits an L1 measurement report to MN2 or MN2-DU and MN2 or MN2-DU decides to trigger LTM, MN2 or MN2-DU transmits a MAC CE (e.g., an LTM Cell Switch Command MAC CE) to the UE. In order to inform the UE about the NCC and SK-Counter values used by the target cell, so that the UE uses the NCC value for the derivation of a new KNG-RAN* and uses the SK-Counter to derive a new S-Ksn, the content of the Cell Switch Command MAC CE can be enhanced to carry one or more of the following information:

[0087] identification information associated with the target cell. For example, it may be or include a Target Configuration ID, which indicates an LTM candidate cell (for example, the target cell) and has a mapping relationship with the LTM Configuration ID corresponding to the LTM candidate cell, and the value of which corresponds to the value of ltm-CandidateId minus 1

[0088] information associated with the SK-counter associated with the target cell. For example, it may be or include the SK-Counter associated with the target cell (the SK-Counter used when the MN to which the target cell belongs derives an S-Ksn)

[0089] a Next Hop Chaining Count (NCC), which is the new NCC value obtained by MN2 from AMF

[0090] After receiving the NCC and SK-Counter values of the target cell, the UE can derive the KNG-RAN*, and then use the SK-Counter to derive an S-Ksn. In this way, the keys used between the UE and the MN and SN on the network side are consistent.

[0091] When the UE performs LTM and accesses a new MN3, the MN3 performs a path switching process with the AMF, and then obtains a new NH (Next Hop) parameter and a new NCC value from the AMF. And then, the foregoing process is repeated.

[0092] The above solution is a method of directly and explicitly transmitting SK-Counter through a Cell Switch Command MAC CE, which mainly involves enhancements for F1AP and MAC CE. Since MAC CE is an unencrypted and unprotected control information element, from a security perspective, explicit and direct transmission of security parameters such as an SK-Counter may have a risk of leakage.

[0093] Therefore, using a MAC CE to transmit SK-Counter in an implicit way may be considered. Optionally, the following methods may be used:

[0094] Method 1: the UE and the network are pre-configured with information associated with a mapping relationship between SK-Counter and index / identifier (ID) (for example, the following description takes a mapping list information of SK-Counter to index / identifier as an example), and then when LTM is triggered, an index / identifier corresponding to or associated with an SK-Counter (for example, associated with the target cell) is transmitted to the UE through the cell switch command MAC CE.

[0095] In this method, both the UE and the network side MN need to know the mapping list information of SK-Counter to index / identifier in advance. Therefore, in the process of the embodiment of FIG. 3, the RRC reconfiguration message may be considered to be enhanced, which may be enhanced to carry the mapping list information of SK-Counter to index / identifier to transmit the mapping list information of SK-Counter to index / identifier to the UE in advance, so that the UE can store this information in advance. In addition, in order to support Subsequent LTM, each candidate MN may be accessed by the UE, and the MN which is to be served as a source MN next will trigger an LTM cell switch command MAC CE to the UE, which may carry an index / identifier corresponding to or associated with the SK-Counter (for example, associated with the target cell) to the UE. Obviously, each candidate MN also needs to know the mapping list information of SK-Counter to index / identifier. Therefore, in the LTM preparation phase, the source MN1 may transmit the mapping list information of SK-Counter to index / identifier to each candidate MN (e.g., MN2 and / or MN3) by carrying the mapping list information of SK-Counter to index / identifier through an XnAP handover request message or other message, and each candidate MN can store this information. If the MN is in a CU-DU split architecture, the MN-CU needs to carry the mapping list information of SK-Counter to index / identifier through an F1AP message to transmit it to the MN-DU. Optionally, in the LTM preparation phase, each candidate MN-CU may transmit the mapping list information of SK-Counter to index / identifier to each candidate MN-DU through an F1AP UE context setup / modification request message carrying the mapping list information of SK-Counter to index / identifier, and each candidate MN-DU can store this information. This is because the LTM cell switch command is a DU triggered MAC CE.

[0096] Method 2: the UE and the network are pre-configured with a reference SK-Counter information, and then when LTM is triggered, a Delta value (or referred to as a difference value) from the reference SK-Counter or a Delta SK-Counter value is transmitted through the cell switch command MAC CE, and then the UE calculates the actual SK-Counter.

[0097] In this method, both the UE and the network side MN need to know the reference SK-Counter information in advance. Therefore, in the process of the embodiment of FIG. 3, the RRC reconfiguration message may be considered to be enhanced, which may be enhanced to carry the reference SK-Counter information to transmit the reference SK-Counter information to the UE in advance, so that the UE can store this information in advance. In addition, in order to support Subsequent LTM, each candidate MN may be accessed by the UE, and the MN which is to be served as a source MN next will trigger an LTM cell switch command MAC CE to the UE, which may carry a Delta value from the reference SK-Counter or a Delta SK-Counter value to UE. Obviously, each candidate MN also needs to know the reference SK-Counter information. Therefore, in the LTM preparation phase, the source MN1 may transmit the reference SK-Counter information to each candidate MN (e.g., MN2 and / or MN3) by carrying the reference SK-Counter information through an XnAP handover request message or other message, and each candidate MN can store this information. If the MN is in a CU-DU split architecture, the MN-CU needs to carry the reference SK-Counter information through an F1AP message to transmit it to the MN-DU. Optionally, in the LTM preparation phase, the candidate MN may transmit the reference SK-Counter information to each candidate MN-DU through an F1AP UE context setup / modification request message carrying the reference SK-Counter information, and each candidate MN-DU can store this information. This is because the LTM cell switch command is a DU triggered MAC CE.

[0098] FIG. 3 shows an example continuous handover scenario where the UE is handed over from MN1 to MN2 and MN3 in sequence. When any one of MN1, MN2 and MN3 acts as the source MN, other nodes can act as candidate MNs. It should be understood that any step and / or operation performed by any one of MN1, MN2 and MN3 in FIG. 3 can also be performed by another one or more of them, which is not limited herein. For example, the above enhancements to MN2's F1AP and MAC CE and the like can also be performed directly on MN1 before the first handover, and so on. This may be similar to the example scenarios shown in the following drawings, which will not be described again herein.

[0099] In addition, the information associated with the mapping relationship between SK-Counter and index / identifier and / or the information of a reference SK-Counter and the like described above may also be pre-specified by the protocol or pre-configured to the UE and the network side MN through any other message or signaling, which is not limited herein.

[0100] FIG. 4 is a flowchart of a security mechanism scheme 2 when a UE performs "MN LTM without SN change" in dual-connectivity according to embodiments of the present disclosure.

[0101] The solution in the embodiment of FIG. 3 is a solution in which when the network side triggers LTM, SK-Counter information is carried by an LTM cell switch command MAC CE explicitly or implicitly to the UE. Although the method of implicitly transmitting SK-Counter has a certain security guarantee, these parameters must be carried every time the LTM is triggered, which may also cause issues such as the MAC CE field needs to be expanded and the signaling overhead is large. The embodiment of FIG. 4 is one of the optional solutions that does not need to carry relevant SK-Counter information to the UE through an LTM cell switch command MAC CE every time the LTM is triggered.

[0102] The main idea of this example is to preset and store an SK-Counter List based on each MN or candidate cell, and then all the SK-Counter lists are configured to and stored by the UE. When inter-MN LTM is triggered, the UE and the target MN or target cell can use the SK-Counters in the SK-Counter List corresponding to / associated with the target MN or target cell according to some same rule. For example, in the SK-Counter list corresponding to / associated with the target MN or target cell, the UE and the network side (MN or cell) can use the first unused SK-Counter in sequence, and then use the next unused SK-Counter in sequence when a Subsequent LTM is triggered and this MN is accessed again.

[0103] It should be understood that the rule that the UE and the network side sequentially use the first unused SK-Counter in the list is only an example, and the present disclosure may also include any suitable rule, for example, the UE and the network side sequentially use the Nth (N is a positive integer) unused SK-Counter in the list, etc., which is not limited herein.

[0104] If each candidate MN or candidate cell decides to preset its own SK-Counter list, as shown in the flowchart of FIG. 4, in the inter-MN LTM preparation phase, the source master node MN1 performs a handover request process with each candidate MN (e.g., MN2 and / or MN3) on a per candidate cell basis, then the candidate MN or candidate cell decides a SK-Counter list and uses one of the SK-Counters in the SK-Counter list according to a certain rule (for example, using the first unused SK-Counter in the SK-Counter list, and then using the next unused SK-Counter in sequence when a Subsequent LTM is triggered and this MN or cell is accessed again), in conjunction with the KNG-RAN*, to derive the S-Ksn, and then carries and transmits the S-Ksn to the SN through an SN addition request message. When the candidate MN receives a reply from the SN, it will reply to the source MN1 with a handover request acknowledge message. The handover request acknowledge message can be enhanced, in which SK-Counter list information may be carried in the handover request acknowledge message and to be transmitted to the source MN1, or SK-Counter list information may be included in a handover command (HO Command) message carried by the handover request acknowledge message and to be transmitted to the source MN1.

[0105] In the drawings and the following description, for ease of distinction, the SK-Counter list associated with MN1 or candidate cell 1 is represented by SK-Counter list 1, the SK-Counter list associated with MN2 or candidate cell 2 is represented by SK-Counter list 2, and the SK-Counter list associated with MN3 or candidate cell 3 is represented by SK-Counter list 3.

[0106] For each candidate cell, after completing the above inter-MN LTM preparation process between the source MN and the candidate MN, the source MN1 would have collected the configuration information of each candidate cell, including the SK-Counter list information corresponding to each candidate MN or candidate cell. A candidate MN may preset the same SK-Counter list for different candidate cells on this MN, so as to a technical scheme in which a same SK-Counter list is configured for the same MN. Then the source MN1 may transmit the SK-Counter list information configured for each candidate cell to the UE through an RRC reconfiguration message and the UE stores this information. Then when the UE receives an LTM cell switch command MAC CE triggered by the network side, it uses the SK-Counter list information corresponding to the target cell or corresponding to the candidate MN to which the target cell belongs, and uses one of the SK-Counters in the SK-Counter list according to the same rule (for example, using the first unused SK-Counter in the SK-Counter list, and then using the next unused SK-Counter in sequence when a Subsequent LTM is triggered and this MN or cell is accessed again), in conjunction with the KNG-RAN*, to derive the S-Ksn. This ensures that the keys used between the UE and SN are consistent.

[0107] When the UE performs an LTM handover and accesses a target MN (for example, MN2), a path switching request process between the target MN and the AMF will further occur similarly, in which the target MN obtains new NH and NCC parameters from the AMF, or uses other possible security mechanisms between UE and MN. In a word, next, MN2 will serve as a source MN and continue to distribute new KNG-RAN* and new NCC values to other candidate MNs. And then, the candidate MN uses one of the SK-Counters in the SK-Counter list according to the same rule (for example, using the first unused SK-Counter in the SK-Counter list, and then using the next unused SK-Counter in sequence when a Subsequent LTM is triggered and this MN or cell is accessed again), in conjunction with the new KNG-RAN*, to derive the S-Ksn. Then, the new S-Ksn is carried by an SN modification request message and transmitted to the SN. Similarly, when the UE performs an LTM handover again, it uses the SK-Counter list information corresponding to the target cell or corresponding to the candidate MN to which the target cell belongs, and uses one of the SK-Counters in the SK-Counter list according to the same rule (for example, using the first unused SK-Counter in the SK-Counter list, and then using the next unused SK-Counter in sequence when a Subsequent LTM is triggered and this MN or cell is accessed again), in conjunction with the new KNG-RAN*, to derive the S-Ksn. This ensures that the keys used between the UE and SN are consistent.

[0108] Although it is specified that the UE and the network side MN or cell apply the same rule for using the SK-Counter in the SK-Counter list, but in order to avoid an abnormal situation in which security keys do not match due to the mismatch of the SK-Counters applied by the UE and the network side, the UE may transmit an RRC Reconfiguration Complete message to the target MN (or target cell) after accessing the target cell, and may carry information of a selected SK-Counter therein to notify the target MN. Then, the MN may perform a check about whether the SK-Counter matches. If the MN finds that the SK-Counter used for the last S-Ksn transmitted to the SN is inconsistent with the selected SK-Counter on the UE side, it may use the selected SK-Counter and the KNG-RAN* to derive a new S-Ksn and transmit it to the SN, thereby updating the S-Ksn. This again ensures that the keys used between the UE and SN are consistent.

[0109] When the UE performs LTM and accesses a new MN3, the MN3 performs a path switching process with the AMF, and then obtains a new NH (Next Hop) parameter and a new NCC value from the AMF. And then, the foregoing process is repeated.

[0110] FIG. 5 is a flowchart of a security mechanism scheme 3 when a UE performs "MN LTM without SN change" in dual-connectivity according to embodiments of the present disclosure.

[0111] The main idea of this example is that an SK-Counter list is configured based on the UE and stored by the UE, and each MN on the network side is also configured with and stores the same SK-Counter list. When the UE performs subsequent inter-MN LTM, the UE and the candidate MN use the SK-Counter in the list according to some same rule. For example, when the UE is configured to perform an initial LTM, it uses the first unused SK-Counter in the SK-Counter list, and as a subsequent inter-MN LTM is triggered, it uses the next unused SK-Counter in the list in sequence.

[0112] If the SK-Counter list information is determined by the source MN1, as shown in the flow chart of FIG. 5, when in the inter-MN LTM preparation phase, the source master node MN1 performs a handover request process with each candidate MN (e.g., MN2 and / or MN3) on a per candidate cell basis, then the source MN transmits the determined SK-Counter list to each candidate MN through an XnAP handover request message. Then each candidate MN uses one of the SK-Counters in the SK-Counter list according to a certain rule (for example, using the first unused SK-Counter in the SK-Counter list for an initially configured LTM, and using the next unused SK-Counter in sequence as a subsequent inter-MN LTM is triggered), in conjunction with the KNG-RAN*, to derive the S-Ksn, and then carries and transmits the S-Ksn to the SN through an SN addition request message. When the candidate MN receives a reply from the SN, it will reply to the source MN1 with a handover request acknowledge message.

[0113] After completing the above inter-MN LTM preparation process between the source MN and the candidate MN for each candidate cell, the source MN1 then may transmit each candidate cell's configuration message and information of an SK-Counter list to the UE through an RRC reconfiguration message and the UE stores the same. Then when the UE receives an LTM cell switch command MAC CE triggered by the network side, it uses the SK-Counter list information, and uses one of the SK-Counters in the SK-Counter list according to the same rule (for example, using the first unused SK-Counter in the SK-Counter list for an initially configured LTM, and using the next unused SK-Counter in sequence as a subsequent inter-MN LTM is triggered), in combination with the KNG-RAN*, to derive the S-Ksn. This ensures that the keys used between the UE and SN are consistent.

[0114] When the UE performs an LTM handover and accesses a target MN (for example, MN2), a path switching request process between the target MN and the AMF will further occur similarly, in which the target MN obtains new NH and NCC parameters from the AMF, or uses other possible security mechanisms between UE and MN. In a word, next, MN2 will serve as a source MN and may distribute new KNG-RAN* and new NCC values to other candidate MNs before the next triggering of LTM. Optionally, the current source MN2 may transmit at least one of the following indications and / or information about SK-Counter to other candidate MNs (e.g., currently, the MN1 and / or MN3) (likewise, before switching to MN2, MN1 may also transmit at least one of the following indications and / or information about SK-Counter to other candidate MNs, including MN2):

[0115] - information about which SK-Counter in the SK-Counter list the source MN2 has used, that is, information about which SK-Counter in the SK-Counter list the UE has used

[0116] - information about which SK-Counter in the SK-Counter list should be used when the candidate MN is accessed by the UE in the next inter-MN LTM, that is, information about which SK-Counter in the SK-Counter list should be used when the UE performs the next inter-MN LTM

[0117] After the other candidate MNs obtain the above indications and / or information, they can determine which SK-Counter in the list will be used next to derive a new S-Ksn in conjunction with the KNG-RAN*, and derive the new S-Ksn accordingly. Then, the candidate MN may carry and transmit the new S-Ksn to the SN through an SN modification request message. Because the candidate MN does not know how many times of LTMs the UE has performed, it is unclear that if the UE accesses the candidate MN through the next LTM, which SK-Counter should be used according to the same rule (for example, the UE uses the first unused SK-Counter in the SK-Counter list for an initially configured LTM, and uses the next unused SK-Counter in sequence as a subsequent inter-MN LTM is triggered). In order to ensure that the SK-Counters used by the UE and the network side are consistent, after each performing of LTM, the current source MN needs to notify the other current candidate MNs about information of the SK-Counter to be used if the UE accesses the corresponding candidate MN when a next inter-MN LTM is performed or other associated SK-Counter indication information. Optionally, the source MN2 may transmit the above information when triggering the LTM. In this case, it may only transmit the above SK-Counter related information (that is, information about which SK-Counter was used last time or information about which SK-Counter will be used next time) to the target MN. For example, an XnAP cell switch notification message required by inter-MN LTM may be used to notify the information to the target MN. In this way, signalling may be saved, because the information only needs to be transmitted to the target MN, but not to all other candidate MNs in advance.

[0118] Similarly, on the UE side, when inter-MN LTM handover occurs again, the next unused SK-Counter in a corresponding SK-Counter list will be used in conjunction with the new KNG-RAN* to derive an S-Ksn. This ensures that the keys used between the UE and SN are consistent.

[0119] Although it is specified that the UE and the network side MN apply the same rule for using the SK-Counter in the SK-Counter list, but in order to avoid an abnormal situation in which security keys do not match due to the mismatch of the SK-Counters applied by the UE and the network side, the UE may transmit an RRC Reconfiguration Complete message to the target MN after accessing the target cell, and may carry information of a selected SK-Counter therein to notify the target MN. Then, the MN may perform a check about whether the SK-Counter matches. If the MN finds that the SK-Counter used for the last S-Ksn transmitted to the SN is inconsistent with the selected SK-Counter on the UE side, it may use the selected SK-Counter and the KNG-RAN* to derive a new S-Ksn and transmit it to the SN, thereby updating the S-Ksn. This again ensures that the keys used between the UE and SN are consistent.

[0120] When the UE performs LTM and accesses a new MN3, the MN3 performs a path switching process with the AMF, and then obtains a new NH (Next Hop) parameter and a new NCC value from the AMF. And then, the foregoing process is repeated.

[0121] FIG. 6 is an example flowchart for LTM triggering in an LTM with DC scenario according to embodiments of the present disclosure. In FIG. 6, S-MN represents a source master node, C-MN represents a candidate master node, S-SN represents a source secondary node, and C-SN represents a candidate secondary node.

[0122] The inter-MN LTM described above is all triggered by the MN. Since a process of MN triggered Inter-SN change is supported in the traditional L3 measurement based handover, a process of "Inter-SN LTM without MN change" triggered by the MN (i.e., a process in which the UE performs LTM between different SNs with MN unchanged and SN changed, i.e., a SCG LTM process) may also be supported for an Inter SN LTM scenario. Meanwhile, the UE also supports an intra-MN or inter-MN LTM process triggered by the MN, that is, a MCG LTM process. In both of the two processes, the UE transmits a layer 1 measurement report to the MN or the gNB-DU serving the UE under the MN(601), and then the MN or the gNB-DU serving the UE under the MN decides to trigger LTM handover (602)and transmits a cell switch command MAC CE to the UE which carries the LTM Configuration ID information of the target cell, etc(603).

[0123] Currently, regarding the indication of the target cell in the MAC CE of the Cell Switch Command, in order to avoid introducing excessive bits for indication through explicit cell ID or NR CGI, a method in which the target cell is indicated by indicating the Target Configuration ID mapping to each LTM candidate cell is adopted. In this way, for the case of supporting a maximum of 8 LTM candidate cells, only 3 bits need to be introduced.

[0124] If the UE supports a primary-secondary cell (PSCell) handover process for inter-SN LTM triggered by the MN and a primary cell (PCell) handover process for intra-MN or inter-MN LTM triggered by the MN, when the MN transmits a cell switch command MAC CE to the UE, it needs to clearly indicate to the UE whether it is an SCG LTM triggered by the MN or an MCG LTM triggered by the MN. Otherwise, the UE cannot correctly determine whether it is an MCG LTM triggered by the MN or an SCG LTM triggered by the MN only through the existing information indicated by the MAC CE, which may cause erroneous behavior. Obviously this situation needs to be avoided. Therefore, the content of the Cell Switch Command MAC CE may be considered to be enhanced, and optional schemes are as follows:

[0125] Scheme 1: add 1 bit or 2 bits to indicate whether this MAC CE is for MCG LTM or SCG LTM. Optionally, cell group ID (CellGroupId) information is indicated by the indicated numerical value, for example a value of 0 represents MCG and a value of 1 represents SCG.

[0126] Scheme 2: add 3 bits (e.g., 6 bits in total) to extend the indication of Target Configuration ID. In this way, the first 3 bits can be used to indicate the MCG LTM target cell configuration ID, and the second 3 bits can be used to indicate the SCG LTM target cell configuration ID, or vice versa.

[0127] Scheme 3: add 1 bit to extend the indication of Target Configuration ID. In this way, plus the original 3 bits, it can be expanded to 4 bits to represent the LTM Configuration ID, and its representation range can be larger. For example, values 0 to 7 can be used to indicate the target cell configuration ID of MCG LTM, corresponding to ltm-CandidateId-1; and values 8 to 15 can be used to indicate the target cell configuration ID of the SCG LTM, corresponding to ltm-CandidateId+7, or vice versa.

[0128] After receiving the MAC CE, the UE performs correct behavior and performs MCG LTM or SCG LTM behavior according to the indication(604). If it is an MCG LTM ( 604-1), the UE detaches the currently connected MCG primary cell (PCell)and accesses to the target primary cell (PCell) without changing the SN. If it is an SCG LTM (604-2), the UE detaches the currently connected SCG primary secondary cell (PSCell) and accesses the target PSCell without changing the MN.

[0129] As for the Subsequent LTM or CHO, the above schemes or embodiments of the present disclosure can be used alone, can be reused, or can be used in combination of any two or more schemes or embodiments, which are all within the protection scope of the present disclosure. In addition, any one or more steps in all example aspects, embodiments, drawings or methods of the present disclosure may be performed alone or in any combination with any other step or steps, which is not limited herein. Additionally, the messages used in the example descriptions of the present disclosure are merely example messages in corresponding scenarios. For future communication systems or technologies, any information involved in the present disclosure may be transmitted through new messages or new IEs. For example, any information involved in the present disclosure may be transmitted through any suitable existing or future message, or transmitted separately.

[0130] The security mechanism schemes between the UE and the SN in the above embodiments involves the mechanism of KNG-RANchange between the UE and the MN, which may be performed based on the existing mechanism in the traditional Xn-based handover scenario. For a scenario of Subsequent LTM with DC, the change may also be performed by using other new mechanisms. However, no matter what the mechanism of the KNG-RANchange between the UE and MN is, the derivation of S-Ksn is performed based on the MN using KNG-RANand SK-Counter. The security mechanism schemes of the UE and SN described above are applicable on the basis of any possible mechanism of KNG-RANchange. That is, the security mechanism schemes of the UE and SN described in the present disclosure is not limited to the mechanism of KNG-RANchange between the UE and the MN introduced in the embodiments. On the basis of other possible mechanisms of KNG-RANchange between the UE and the MN, the above security mechanism schemes of the UE and SN are also applicable, and are all within the scope of protection of the present disclosure. In addition, the Scheme 1, Scheme 2 and Scheme 3, etc. set forth in the scenario regarding subsequent "Inter-MN LTM without SN change" in the embodiments can also be equally applied to scenarios such as "Inter-MN LTM with SN change", or any other mobility scenarios in DC in the future, such as subsequent "Inter-MN CHO with SN change" or "Inter-MN CHO without SN change". In short, it should be within the scope of protection for future communication systems or technologies that are consistent with or similar to the ideas in the present disclosure.

[0131] It should be understood that, depending on the application scenario, the various example aspects, methods, steps, processes, etc. shown above in conjunction with the drawings can be combined and implemented in any manner, and are not limited herein.

[0132] Next, FIG. 7A shows a flowchart of a method 700 performed by a first node in a wireless communication system according to embodiments of the present disclosure.

[0133] The method 700 performed by a first node in a wireless communication system according to embodiments of the present disclosure may include: in step S701, receiving first information from a candidate node, wherein the first information includes information associated with one or more first SK-counters respectively associated with one or more candidate cells; and in step S702, transmitting a cell switch command to a user equipment (UE), wherein the cell switch command includes identification information associated with a target cell and second information associated with a second SK-counter, wherein the second SK-counter is an SK-counter associated with the target cell among the one or more first SK-counters, and the target cell is one of the one or more candidate cells, wherein the second SK-counter is used by the UE to generate a key associated with a second node.

[0134] In some implementations, the second information includes the second SK-counter.

[0135] In some implementations, the method further includes: transmitting, to the UE, fifth information associated with a mapping relationship of SK-counter to index; and transmitting the fifth information to the candidate node, wherein the second information includes an index associated with the second SK-counter.

[0136] In some implementations, the method further includes: transmitting, to the UE, sixth information associated with a reference SK-counter; and transmitting the sixth information to the candidate node, wherein the second information includes information associated with a difference between the second SK-counter and the reference SK-counter.

[0137] In some implementations, the method further includes: transmitting, by a central unit of the first node, a first message to a distributed unit of the first node, wherein the first message includes an SK-counter list including the one or more first SK-counters, wherein the cell switch command is transmitted to the UE by the distributed unit of the first node.

[0138] In some implementations, the cell switch command further includes third information, wherein the third information includes at least one of the following: information about primary cell group (MCG) Layer 1 / Layer 2 triggered Mobility (LTM), and information about secondary cell group (SCG) Layer 1 / Layer 2 triggered Mobility (LTM).

[0139] FIG. 7B shows a flowchart of a method 710 performed by a first node in a wireless communication system according to embodiments of the present disclosure.

[0140] The method 710 performed by the first node in the wireless communication system according to embodiments of the present disclosure may include: in step S711, receiving seventh information from a candidate node, wherein the seventh information includes information related to one or more SK-counter lists respectively associated with one or more candidate cells; in step S712, transmitting the seventh information to a user equipment (UE); and in step S713, transmitting a cell switch command to the UE, wherein the cell switch command includes identification information associated with a target cell, wherein a first unused SK-counter in an SK-counter list associated with the target cell among the one or more SK-counter lists is used by the UE to generate a key associated with a second node.

[0141] In some implementations, information associated with the first unused SK-counter is transmitted by the UE to a target node associated with the target cell.

[0142] FIG. 7C shows a flowchart of a method 720 performed by a first node in a wireless communication system according to embodiments of the present disclosure.

[0143] The method 720 performed by the first node in the wireless communication system according to embodiments of the present disclosure may include: in step S721, transmitting a second SK-counter list associated with a user equipment (UE) to a candidate node; in step S722, transmitting the second SK-counter list to the UE; and in step S723, transmitting a cell switch command to the UE, wherein the cell switch command includes identification information associated with a target cell among one or more candidate cells, wherein a first unused SK-counter in the second SK-counter list is used by the UE to generate a key associated with a second node.

[0144] In some implementations, information associated with the first unused SK-counter is transmitted by the UE to a target node associated with the target cell.

[0145] In some implementations, the method further includes: transmitting fourth information to a target node associated with the target cell, wherein the fourth information includes at least one of: information about SK-counters that have been used in the second SK-counter list; and information about an SK-counter to be used by the UE for a next access in the second SK-counter list.

[0146] FIG. 8A shows a flowchart of a method 800 performed by a user equipment (UE) in a wireless communication system according to embodiments of the present disclosure.

[0147] A method 800 performed by a user equipment (UE) in a wireless communication system according to embodiments of the present disclosure may include: in step S801, receiving a cell switch command from a first node, wherein the cell switch command includes identification information associated with a target cell and second information associated with a second SK-counter, wherein the second SK-counter is an SK-counter associated with the target cell among one or more first SK-counters, wherein the one or more first SK-counters are respectively associated with one or more candidate cells, and the target cell is one of the one or more candidate cells; and in a step S802, generating a key associated with the second node based on the second SK-counter.

[0148] In some implementations, the second information includes the second SK-counter.

[0149] In some implementations, the method further includes: receiving, from the first node, fifth information associated with a mapping relationship of SK-counter to index, wherein the second information includes an index associated with the second SK-counter.

[0150] In some implementations, the method further includes: receiving sixth information associated with a reference SK-counter from the first node, wherein the second information includes information associated with a difference between the second SK-counter and the reference SK-counter.

[0151] In some implementations, the first node includes a central unit and a distributed unit, and the cell switch command is transmitted to the UE by the distributed unit of the first node; wherein a first message is transmitted by the central unit of the first node to the distributed unit of the first node, the first message including an SK-counter list, which includes the one or more first SK-counters.

[0152] In some implementations, the cell switch command further includes third information, wherein the third information includes at least one of the following: information about primary cell group (MCG) Layer 1 / Layer 2 triggered Mobility (LTM), and information about secondary cell group (SCG) Layer 1 / Layer 2 triggered Mobility (LTM).

[0153] FIG. 8B shows a flowchart of a method 810 performed by a user equipment (UE) in a wireless communication system according to embodiments of the present disclosure.

[0154] The method 810 performed by a user equipment (UE) in a wireless communication system according to embodiments of the present disclosure may include: in step S811, receiving seventh information from a first node, wherein the seventh information includes information related to one or more SK-counter lists respectively associated with one or more candidate cells; receiving a cell switch command from the first node, wherein the cell switch command includes identification information associated with a target cell; and in step S812, generating a key associated with a second node based on a first unused SK-counter in an SK-counter list associated with the target cell among the one or more SK-counter lists.

[0155] In some implementations, the method further includes: transmitting information associated with the first unused SK-counter to a target node associated with the target cell.

[0156] FIG. 8C shows a flowchart of a method 820 performed by a user equipment (UE) in a wireless communication system according to embodiments of the present disclosure.

[0157] The method 820 performed by a user equipment (UE) in a wireless communication system according to embodiments of the present disclosure may include: in step S821, receiving, from a first node, a second SK-counter list associated with the UE; in step S822, receiving a cell switch command from the first node, wherein the cell switch command includes identification information associated with a target cell among one or more candidate cells; and in step S823, generating a key associated with a second node based on a first unused SK-counter in the second SK-counter list, wherein the second SK-counter list is transmitted by the first node to candidate nodes associated with the one or more candidate cells.

[0158] In some implementations, the method further includes: transmitting information associated with the first unused SK-counter to a target node associated with the target cell.

[0159] It should be understood that methods 700, 710, 720, 800, 810, 820, etc. according to embodiments of the present disclosure may also include one or more of any methods or steps described in conjunction with various embodiments, examples, aspects, drawings, etc. of the present disclosure.

[0160] Next, FIG. 9 shows a schematic diagram of a node 900 according to embodiments of the present disclosure.

[0161] As shown in FIG. 9, a node (or node device, for example, the first node or the second node as described above, etc.) 900 according to embodiments of the present disclosure may include a transceiver 910 and a processor 920. The transceiver 910 may be configured to transmit and receive signals. The processor 920 may be coupled to transceiver 910 and may be configured to (e.g., control transceiver 910 to) perform methods performed by any node according to embodiments of the present disclosure.

[0162] FIG. 10 shows a schematic diagram of a user equipment (UE) 1000 according to embodiments of the present disclosure.

[0163] As shown in FIG. 10, a user equipment 1000 according to embodiments of the present disclosure may include a transceiver 1010 and a processor 1020. The transceiver 1010 may be configured to transmit and receive signals. The processor 1020 may be coupled to transceiver 1010 and may be configured to (e.g., control transceiver 1010 to) perform methods performed by user equipment (UE) according to embodiments of the present disclosure. In the present disclosure, a processor may also be referred to as a controller.

[0164] Embodiments of the present disclosure provide a method performed by a first node in a wireless communication system, including: receiving first information from a candidate node, wherein the first information includes information associated with one or more first SK-counters respectively associated with one or more candidate cells; and transmitting a cell switch command to a user equipment (UE), wherein the cell switch command includes identification information associated with a target cell and second information associated with a second SK-counter, wherein the second SK-counter is an SK-counter associated with the target cell among the one or more first SK-counters, and the target cell is one of the one or more candidate cells, wherein the second SK-counter is used by the UE to generate a key associated with a second node.

[0165] Embodiments of the present disclosure provide a method performed by a first node in a wireless communication system, including: receiving seventh information from a candidate node, wherein the seventh information includes information related to one or more SK-counter lists respectively associated with one or more candidate cells; transmitting the seventh information to a user equipment (UE); and transmitting a cell switch command to the UE, wherein the cell switch command includes identification information associated with a target cell, wherein a first unused SK-counter in an SK-counter list associated with the target cell among the one or more SK-counter lists is used by the UE to generate a key associated with a second node.

[0166] Embodiments of the present disclosure provide a method performed by a first node in a wireless communication system, including: transmitting a second SK-counter list associated with a user equipment (UE) to a candidate node; transmitting the second SK-counter list to the UE; and transmitting a cell switch command to the UE, wherein the cell switch command includes identification information associated with a target cell among one or more candidate cells, wherein a first unused SK-counter in the second SK-counter list is used by the UE to generate a key associated with a second node.

[0167] Embodiments of the present disclosure provide a method performed by a user equipment (UE) in a wireless communication system, including: receiving a cell switch command from a first node, wherein the cell switch command includes identification information associated with a target cell and second information associated with a second SK-counter, wherein the second SK-counter is an SK-counter associated with the target cell among one or more first SK-counters, wherein the one or more first SK-counters are respectively associated with one or more candidate cells, and the target cell is one of the one or more candidate cells; and generating a key associated with the second node based on the second SK-counter.

[0168] Embodiments of the present disclosure provide a method performed by a user equipment (UE) in a wireless communication system, including: receiving seventh information from a first node, wherein the seventh information includes information related to one or more SK-counter lists respectively associated with one or more candidate cells; receiving a cell switch command from the first node, wherein the cell switch command includes identification information associated with a target cell; and generating a key associated with a second node based on a first unused SK-counter in an SK-counter list associated with the target cell among the one or more SK-counter lists.

[0169] Embodiments of the present disclosure provide a method performed by a user equipment (UE) in a wireless communication system, including: receiving, from a first node, a second SK-counter list associated with the UE; receiving a cell switch command from the first node, wherein the cell switch command includes identification information associated with a target cell among one or more candidate cells; and generating a key associated with a second node based on a first unused SK-counter in the second SK-counter list, wherein the second SK-counter list is transmitted by the first node to candidate nodes associated with the one or more candidate cells.

[0170] Embodiments of the present disclosure provide a node device in a wireless communication system, including: a transceiver configured to transmit and receive signals; and a processor coupled to the transceiver and configured to perform methods performed by any node in a wireless communication system according to embodiments of the present disclosure.

[0171] Embodiments of the present disclosure provide a user equipment (UE) in a wireless communication system, including: a transceiver configured to transmit and receive signals; and a processor coupled to the transceiver and configured to perform methods performed by a user equipment (UE) in a wireless communication system according to embodiments of the present disclosure.

[0172] Embodiments of the present disclosure provide a computer-readable medium having computer-readable instructions stored thereon, which when executed by a processor implement methods performed by any node and / or a user equipment (UE) in a wireless communication system according to embodiments of the present disclosure.

[0173] The methods performed by the node and / or user equipment (UE) in a wireless communication system provided by the present disclosure can effectively support the security of signaling and user data communication between the UE and the base station in mobile scenarios by exchanging security-related information between the nodes and / or user equipment.

[0174] Embodiments of the present disclosure further provide a computer-readable medium having computer-readable instructions stored thereon, which when executed by a processor can be used to implement any method according to embodiments of the present disclosure.

[0175] Various embodiments of the present disclosure may be implemented as computer-readable codes embodied on a computer-readable recording medium from a specific perspective. A computer-readable recording medium is any data storage device that can store data readable by a computer system. Examples of computer-readable recording media may include read-only memory (ROM), random access memory (RAM), compact disk read-only memory (CD-ROM), magnetic tape, floppy disk, optical data storage device, carrier wave (e.g., data transmission via the Internet), etc. Computer-readable recording media can be distributed by computer systems connected via a network, and thus computer-readable codes can be stored and executed in a distributed manner. Furthermore, functional programs, codes and code segments for implementing various embodiments of the present disclosure can be easily explained by those skilled in the art to which embodiments of the present disclosure are applied.

[0176] It will be understood that embodiments of the present disclosure may be implemented in the form of hardware, software, or a combination of hardware and software. The software may be stored as program indications or computer-readable codes executable on a processor on a non-transitory computer-readable medium. Examples of non-transitory computer-readable recording media include magnetic storage media (such as ROM, floppy disk, hard disk, etc.) and optical recording media (such as CD-ROM, digital video disk (DVD), etc.). Non-transitory computer-readable recording media may also be distributed on computer systems coupled to a network, so that computer-readable codes are stored and executed in a distributed manner. The medium can be read by a computer, stored in a memory, and executed by a processor. Various embodiments may be implemented by a computer or a portable terminal including a controller and a memory, and the memory may be an example of a non-transitory computer-readable recording medium suitable for storing program (s) with indications for implementing embodiments of the present disclosure. The present disclosure may be realized by a program with code for concretely implementing the apparatus and method described in the claims, which is stored in a machine (or computer)-readable storage medium. The program may be electronically carried on any medium, such as a communication signal transmitted via a wired or wireless connection, and the present disclosure suitably includes its equivalents.

[0177] What has been described above is only the specific implementation of the present disclosure, but the scope of protection of the present disclosure is not limited thereto. Anyone who is familiar with this technical field may make various changes or substitutions within the technical scope disclosed in the present disclosure, and these changes or substitutions should be covered within the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure should be based on the scope of protection of the claims.

Claims

1.A method performed by a central unit of a first base station in a wireless communication system, the method comprising:receiving, from an access and mobility management function (AMF), a next hop (NH) parameter and a first next hop chaining counter (NCC) value;deriving at least one first security key related to at least one candidate base station based on the NH parameter and the first NCC value; andtransmitting, to a distributed unit of the first base station, security related information for supporting a user equipment (UE) during L1 / L2 triggered mobility (LTM) via an F1 application protocol (F1AP) message,wherein the security related information includes the first NCC value.2.The method of claim 1, further comprising:transmitting, to at least one candidate base station, the at least one first security key via a configuration update message,wherein the at least one first security key is per candidate cell.3.The method of claim 1, further comprising:before receiving the NH parameter and the first NCC value, receiving, from a second base station, a handover request message including a second security key and a second NCC value.4.The method of claim 1, wherein the F1AP message includes a UE context modification request.5.The method of claim 2, wherein the configuration update message includes an LTM configuration update message.6.The method of claim 1, wherein the F1AP message includes at least one of:a candidate cell identifier (ID),target cell ID,an LTM configuration ID, oran SK-Counter.7.A method performed by a distributed unit of a base station in a wireless communication system, the method comprising:receiving, from a central unit of the base station, security related information for supporting a user equipment (UE) during L1 / L2 triggering mobility (LTM) via an F1 application protocol (F1AP) message, wherein the security related information includes a next hop chaining counter (NCC) value;generating a cell switch command medium access control control element (MAC CE) including the NCC value; andtransmitting, to the UE, the cell switch command MAC CE.8.The method of claim 7,wherein the cell switch command MAC CE includes at least one of:identification information associated with a target cell, orinformation associated with the SK-counter corresponding to the target cell.9.A central unit of a first base station in a wireless communication system, the central unit of the first base station comprising:a transceiver; andat least one processor coupled to the transceiver and configured to:receive, from an access and mobility management function (AMF), a next hop (NH) parameter and a first next hop chaining counter (NCC) value,derive at least one first security key related to at least one candidate base station based on the NH parameter and the first NCC value, andtransmit, to a distributed unit of the first base station, security related information for supporting a user equipment (UE) during L1 / L2 triggered mobility (LTM) via an F1 application protocol (F1AP) message,wherein the security related information includes the first NCC value.10.The central unit of the first base station of claim 9, wherein at least one processor is further configured to:transmit, to at least one candidate base station, the at least one first security key via a configuration update message,wherein the at least one first security key is per candidate cell.11.The central unit of the first base station of claim 9, wherein at least one processor is further configured to:before receiving the NH parameter and the first NCC value, receive, from a second base station, a handover request message including a second security key and a second NCC value.12.The central unit of the first base station of claim 9, wherein the F1AP message includes a UE context modification request.13.The central unit of the first base station of claim 10, wherein the configuration update message includes an LTM configuration update message.14.The central unit of the first base station of claim 9, wherein the F1AP message includes at least one of:a candidate cell identifier (ID),target cell ID,an LTM configuration ID, ora SK-Counter.15.A distributed unit of a base station in a wireless communication system, the distributed unit of the base station comprising:a transceiver; andat least one processor coupled to the transceiver and configured to:receive, from a central unit of the base station, security related information for supporting a user equipment (UE) during L1 / L2 triggering mobility (LTM) via an F1 application protocol (F1AP) message, wherein the security related information includes a next hop chaining counter (NCC) value,generate a cell switch command medium access control control element (MAC CE) including the NCC value, andtransmit, to the UE, the cell switch command MAC CE.

Citation Information

Patent Citations

  • Mobility features for next generation cellular networks

    US20230388871A1

  • Security update for subsequent ltm

    WO2024146138A1