Methods, architectures, apparatuses and systems for security handling during subsequent conditional l1 / l2 triggered mobility
The described methods and systems for security handling during subsequent conditional LTM in wireless networks enable secure and efficient key derivation and updates, addressing limitations in existing LTM technologies by facilitating secure handovers between candidate cells.
Patent Information
- Application Number
- PCT/US2025/040502
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-05
- Filing Date
- 2025-08-04
- Publication Date
- 2026-02-12
AI Technical Summary
Existing Rel-18 L1/L2 triggered mobility (LTM) technologies are limited to cells belonging to the same gNB and do not effectively address security handling during subsequent conditional handovers, leading to potential security vulnerabilities and inefficiencies.
Implementing methods and systems for security handling during subsequent conditional LTM by configuring wireless transmit/receive units (WTRUs) to derive and update security keys based on path information and cell identifiers, enabling secure handovers between candidate cells within a group.
Enhances security and efficiency in handover processes by ensuring secure key derivation and context updates, reducing vulnerabilities and latency in conditional handovers across different cells.
Smart Images

Figure US2025040502_12022026_PF_FP_ABST
Abstract
Description
METHODS, ARCHITECTURES, APPARATUSES AND SYSTEMS FOR SECURITY HANDLING DURING SUBSEQUENT CONDITIONAL L1 / L2 TRIGGERED MOBILITYCROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims the benefit of US Patent Application No. 63 / 679,254, filed August 5, 2024, which is incorporated herein by reference in its entirety.TECHNICAL FIELD
[0002] The present disclosure is generally directed to the fields of communications, software and encoding, including methods, architectures, apparatuses, and systems directed to security handling during subsequent conditional layer one / layer two (L1 / L2) triggered mobility (LTM).BACKGROUND
[0003] In Rel-18, the third generation partnership project (3GPP) standardized L1 / L2 triggered mobility (LTM), where a wireless transmit / receive unit (WTRU) may be preconfigured, as in the case of conditional handover (CHO), with radio resource control (RRC) reconfiguration to apply upon being handed over from a source cell to a target cell, where the handover may be performed upon receiving a medium access control (MAC) control element (MAC CE) indicating the cell switch. LTM may enable improvements in handover latency and interruption time compared to layer three based mobility. Rel-18 LTM is limited to cells belonging to a same gNB. Embodiments described herein have been designed with the foregoing in mind.SUMMARY
[0004] Methods, architectures, apparatuses, and systems directed to security handling during subsequent conditional LTM are described herein. In an embodiment, a wireless transmit / receive unit (WTRU) is described. The WTRU may include circuitry including any of a transmitter, a receiver, a processor, and memory. The circuitry may be configured to receive configuration information related to one or more subsequent conditional handovers between cells within a group of candidate cells. In various embodiments, the configuration information may include path information for deriving security keys to be used after a handover from one cell to another cell within the group of candidate cells. In various embodiments, the path information may indicate a plurality of paths associated with a plurality of lists of candidate cells. In various embodiments, a path (e.g., each path) of the plurality of paths may be associated with one list of the plurality of lists of candidate cells. In various embodiments, the circuitry may be configured to determine that a condition for performing a conditional handover to atarget cell may be satisfied. In various embodiments, the target cell may be a candidate cell of a list of the plurality of lists of candidate cells. The circuitry may be configured to perform a conditional handover from a source cell to a target cell within the group of candidate cells e.g., based on the condition being satisfied, where the WTRU may have operated in the source cell using a first key and a security context associated with the first key and where perform the conditional handover may comprise (i) determine a second key based on a source cell identifier (e.g., identifying the source cell) and any of the path information, the first key, a cell switch count and a target cell identifier (e.g., identifying the target cell), (ii) update the security context to be used with the target cell based on the second key, and (iii) send information to the target cell to be used for deriving the second key.
[0005] In an embodiment, a first method implemented in a WTRU is described. The first method may include receiving configuration information related to one or more subsequent conditional handovers between cells within a group of candidate cells. In various embodiments, the configuration information may include path information for deriving security keys to be used after a handover from one cell to another cell within the group of candidate cells. In various embodiments, the path information may indicate a plurality of paths associated with a plurality of lists of candidate cells. In various embodiments, a path (e.g., each path) of the plurality of paths may be associated with one list of the plurality of lists of candidate cells. In various embodiments, the first method may include determining that a condition for performing a conditional handover to a target cell may be satisfied. In various embodiments, the target cell may be a candidate cell of a list of the plurality of lists of candidate cells. The first method may include performing a conditional handover from a source cell to a target cell within the group of candidate cells e.g., based on the condition being satisfied, where the WTRU may have operated in the source cell using a first key and a security context associated with the first key and where performing the conditional handover may include (i) determining a second key based on a source cell identifier (e.g., identifying the source cell) and any of the path information, the first key, a cell switch count and a target cell identifier (e.g., identifying the target cell), (ii) updating the security context to be used with the target cell based on the second key, and (iii) sending information to the target cell to be used for deriving the second key.
[0006] In an embodiment, a network element is described. The network element may include circuitry including any of a transmitter, a receiver, a processor, and memory. The circuitry may be configured to receive, from another network element, configuration information related to one or more subsequent conditional handovers associated with at least one WTRU. In various embodiments, the configuration information may include path information for deriving securitykeys to be used after a handover from one cell to another cell within a group of candidate cells. In various embodiments, the configuration (e.g., path) information may indicate a plurality of paths associated with a plurality of lists of candidate cells. The circuitry may be configured to receive from the at least one WTRU, information associated with key derivation during a conditional handover of the at least one WTRU. The circuitry may be configured to derive a key based on (i) the configuration information received from the other network element and (ii) the information received from the at least one WTRU. The circuitry may be configured to update a security context to be used with the at least one WTRU based on the derived key. The circuitry may be configured to use the security context to serve the at least one WTRU after completion of the conditional handover.
[0007] In an embodiment, a second method implemented in a network element is described. The second method may include receiving, from another network element, configuration information related to one or more subsequent conditional handovers associated with at least one WTRU. In various embodiments, the configuration information may include path information for deriving security keys to be used after a handover from one cell to another cell within a group of candidate cells. In various embodiments, the configuration (e.g., path) information may indicate a plurality of paths associated with a plurality of lists of candidate cells. The second method may include receiving from the at least one WTRU, information associated with key derivation during a conditional handover of the at least one WTRU. The second method may include deriving a key based on (i) the configuration information received from the other network element and (ii) the information received from the at least one WTRU. The second method may include updating a security context to be used with the at least one WTRU based on the derived key. The second method may include using the security context to serve the at least one WTRU after completion of the conditional handover.BRIEF DESCRIPTION OF THE DRAWINGS
[0008] A more detailed understanding may be had from the detailed description below, given by way of example in conjunction with drawings appended hereto. Figures in such drawings, like the detailed description, are examples. As such, the Figures (FIGs.) and the detailed description are not to be considered limiting, and other equally effective examples are possible and likely. Furthermore, like reference numerals ("ref.") in the FIGs. indicate like elements, and wherein:
[0009] FIG. 1 A is a system diagram illustrating an example communications system;
[0010] FIG. IB is a system diagram illustrating an example wireless transmit / receive unit (WTRU) that may be used within the communications system illustrated in FIG. 1 A;
[0011] FIG. 1C is a system diagram illustrating an example radio access network (RAN) and an example core network (CN) that may be used within the communications system illustrated in FIG. 1 A;
[0012] FIG. ID is a system diagram illustrating a further example RAN and a further example CN that may be used within the communications system illustrated in FIG. 1 A;
[0013] FIG. 2 is a diagram illustrating an example of handover procedure;
[0014] FIG. 3 is a diagram illustrating an example mobility scenario;
[0015] FIG. 4 is a diagram illustrating an example of hierarchy generation is 5G;
[0016] FIG. 5 is a diagram illustrating an example of master key update;
[0017] FIG. 6 is a diagram illustrating an example of horizontal key derivation and vertical key derivation;
[0018] FIG. 7 is a diagram illustrating an example method for security handling during subsequent conditional handovers in a WTRU;
[0019] FIG. 8 is a diagram illustrating an example method for security handling during subsequent conditional handovers in a network element; and
[0020] FIG. 9 is a diagram illustrating an example method for security handling during subsequent conditional handovers in a WTRU.DETAILED DESCRIPTION
[0021] In the following detailed description, numerous specific details are set forth to provide a thorough understanding of embodiments and / or examples disclosed herein. However, it will be understood that such embodiments and examples may be practiced without some or all of the specific details set forth herein. In other instances, well-known methods, procedures, components and circuits have not been described in detail, so as not to obscure the following description. Further, embodiments and examples not specifically described herein may be practiced in lieu of, or in combination with, the embodiments and other examples described, disclosed or otherwise provided explicitly, implicitly and / or inherently (collectively "provided") herein. Although various embodiments are described and / or claimed herein in which an apparatus, system, device, etc. and / or any element thereof carries out an operation, process, algorithm, function, etc. and / or any portion thereof, it is to be understood that any embodiments described and / or claimed herein assume that any apparatus, system, device, etc.and / or any element thereof is configured to carry out any operation, process, algorithm, function, etc. and / or any portion thereof.
[0022] Example Communications System
[0023] The methods, apparatuses and systems provided herein are well-suited for communications involving both wired and wireless networks. An overview of various types of wireless devices and infrastructure is provided with respect to FIGs. 1A-1D, where various elements of the network may utilize, perform, be arranged in accordance with and / or be adapted and / or configured for the methods, apparatuses and systems provided herein.
[0024] FIG. 1A is a system diagram illustrating an example communications system 100 in which one or more disclosed embodiments may be implemented. The communications system 100 may be a multiple access system that provides content, such as voice, data, video, messaging, broadcast, etc., to multiple wireless users. The communications system 100 may enable multiple wireless users to access such content through the sharing of system resources, including wireless bandwidth. For example, the communications systems 100 may employ one or more channel access methods, such as code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), single-carrier FDMA (SC-FDMA), zero-tail (ZT) unique-word (UW) discrete Fourier transform (DFT) spread OFDM (ZT UW DTS-s OFDM), unique word OFDM (UW- OFDM), resource block-filtered OFDM, filter bank multicarrier (FBMC), and the like.
[0025] As shown in FIG. 1A, the communications system 100 may include wireless transmit / receive units (WTRUs) 102a, 102b, 102c, 102d, a radio access network (RAN) 104 / 113, a core network (CN) 106 / 115, a public switched telephone network (PSTN) 108, the Internet 110, and other networks 112, though it will be appreciated that the disclosed embodiments contemplate any number of WTRUs, base stations, networks, and / or network elements. Each of the WTRUs 102a, 102b, 102c, 102d may be any type of device configured to operate and / or communicate in a wireless environment. By way of example, the WTRUs 102a, 102b, 102c, 102d, any of which may be referred to as a "station" and / or a "STA", may be configured to transmit and / or receive wireless signals and may include (or be) a user equipment (UE), a mobile station, a fixed or mobile subscriber unit, a subscription-based unit, a pager, a cellular telephone, a personal digital assistant (PDA), a smartphone, a laptop, a netbook, a personal computer, a wireless sensor, a hotspot or Mi-Fi device, an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processingchain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. Any of the WTRUs 102a, 102b, 102c and 102d may be interchangeably referred to as a UE.
[0026] The communications systems 100 may also include a base station 114a and / or a base station 114b. Each of the base stations 114a, 114b may be any type of device configured to wirelessly interface with at least one of the WTRUs 102a, 102b, 102c, 102d, e.g., to facilitate access to one or more communication networks, such as the CN 106 / 115, the Internet 110, and / or the networks 112. By way of example, the base stations 114a, 114b may be any of a base transceiver station (BTS), aNode-B (NB), an eNode-B (eNB), a HomeNode-B (HNB), a Home eNode-B (HeNB), a gNode-B (gNB), a NR Node-B (NR NB), a site controller, an access point (AP), a wireless router, and the like. While the base stations 114a, 114b are each depicted as a single element, it will be appreciated that the base stations 114a, 114b may include any number of interconnected base stations and / or network elements.
[0027] The base station 114a may be part of the RAN 104 / 113, which may also include other base stations and / or network elements (not shown), such as a base station controller (BSC), a radio network controller (RNC), relay nodes, etc. The base station 114a and / or the base station 114b may be configured to transmit and / or receive wireless signals on one or more carrier frequencies, which may be referred to as a cell (not shown). These frequencies may be in licensed spectrum, unlicensed spectrum, or a combination of licensed and unlicensed spectrum. A cell may provide coverage for a wireless service to a specific geographical area that may be relatively fixed or that may change over time. The cell may further be divided into cell sectors. For example, the cell associated with the base station 114a may be divided into three sectors. Thus, in an embodiment, the base station 114a may include three transceivers, i.e., one for each sector of the cell. In an embodiment, the base station 114a may employ multiple-input multiple output (MIMO) technology and may utilize multiple transceivers for each or any sector of the cell. For example, beamforming may be used to transmit and / or receive signals in desired spatial directions.
[0028] The base stations 114a, 114b may communicate with one or more of the WTRUs 102a, 102b, 102c, 102d over an air interface 116, which may be any suitable wireless communication link (e.g., radio frequency (RF), microwave, centimeter wave, micrometer wave, infrared (IR), ultraviolet (UV), visible light, etc.). The air interface 116 may be established using any suitable radio access technology (RAT).
[0029] More specifically, as noted above, the communications system 100 may be a multiple access system and may employ one or more channel access schemes, such as CDMA, TDMA,FDMA, OFDMA, SC-FDMA, and the like. For example, the base station 114a in the RAN 104 / 113 and the WTRUs 102a, 102b, 102c may implement a radio technology such as Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (UTRA), which may establish the air interface 116 using wideband CDMA (WCDMA). WCDMA may include communication protocols such as High-Speed Packet Access (HSPA) and / or Evolved HSPA (HSPA+). HSPA may include High-Speed Downlink Packet Access (HSDPA) and / or High- Speed Uplink Packet Access (HSUPA).
[0030] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as Evolved UMTS Terrestrial Radio Access (E-UTRA), which may establish the air interface 116 using Long Term Evolution (LTE) and / or LTE- Advanced (LTE- A) and / or LTE- Advanced Pro (LTE- A Pro).
[0031] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as NR Radio Access, which may establish the air interface 116 using New Radio (NR).
[0032] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement multiple radio access technologies. For example, the base station 114a and the WTRUs 102a, 102b, 102c may implement LTE radio access and NR radio access together, for instance using dual connectivity (DC) principles. Thus, the air interface utilized by WTRUs 102a, 102b, 102c may be characterized by multiple types of radio access technologies and / or transmissions sent to / from multiple types of base stations (e.g., an eNB and a gNB).
[0033] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement radio technologies such as IEEE 802.11 (i.e., Wireless Fidelity (Wi-Fi), IEEE 802.16 (i.e., Worldwide Interoperability for Microwave Access (WiMAX)), CDMA2000, CDMA2000 IX, CDMA2000 EV-DO, Interim Standard 2000 (IS-2000), Interim Standard 95 (IS-95), Interim Standard 856 (IS-856), Global System for Mobile communications (GSM), Enhanced Data rates for GSM Evolution (EDGE), GSM EDGE (GERAN), and the like.
[0034] The base station 114b in FIG. 1A may be a wireless router, Home Node-B, Home eNode-B, or access point, for example, and may utilize any suitable RAT for facilitating wireless connectivity in a localized area, such as a place of business, a home, a vehicle, a campus, an industrial facility, an air corridor (e.g., for use by drones), a roadway, and the like. In an embodiment, the base station 114b and the WTRUs 102c, 102d may implement a radio technology such as IEEE 802.11 to establish a wireless local area network (WLAN). In an embodiment, the base station 114b and the WTRUs 102c, 102d may implement a radio technology such as IEEE 802.15 to establish a wireless personal area network (WPAN). In anembodiment, the base station 114b and the WTRUs 102c, 102d may utilize a cellular-based RAT (e g., WCDMA, CDMA2000, GSM, LTE, LTE-A, LTE-A Pro, NR, etc.) to establish any of a small cell, picocell or femtocell. As shown in FIG. 1A, the base station 114b may have a direct connection to the Internet 110. Thus, the base station 114b may not be required to access the Internet 110 via the CN 106 / 115.
[0035] The RAN 104 / 113 may be in communication with the CN 106 / 115, which may be any type of network configured to provide voice, data, applications, and / or voice over internet protocol (VoIP) services to one or more of the WTRUs 102a, 102b, 102c, 102d. The data may have varying quality of service (QoS) requirements, such as differing throughput requirements, latency requirements, error tolerance requirements, reliability requirements, data throughput requirements, mobility requirements, and the like. The CN 106 / 115 may provide call control, billing services, mobile location-based services, pre-paid calling, Internet connectivity, video distribution, etc., and / or perform high-level security functions, such as user authentication. Although not shown in FIG. 1A, it will be appreciated that the RAN 104 / 113 and / or the CN 106 / 115 may be in direct or indirect communication with other RANs that employ the same RAT as the RAN 104 / 113 or a different RAT. For example, in addition to being connected to the RAN 104 / 113, which may be utilizing an NR radio technology, the CN 106 / 115 may also be in communication with another RAN (not shown) employing any of a GSM, UMTS, CDMA 2000, WiMAX, E-UTRA, or Wi-Fi radio technology.
[0036] The CN 106 / 115 may also serve as a gateway for the WTRUs 102a, 102b, 102c, 102d to access the PSTN 108, the Internet 110, and / or other networks 112. The PSTN 108 may include circuit-switched telephone networks that provide plain old telephone service (POTS). The Internet 110 may include a global system of interconnected computer networks and devices that use common communication protocols, such as the transmission control protocol (TCP), user datagram protocol (UDP) and / or the internet protocol (IP) in the TCP / IP internet protocol suite. The networks 112 may include wired and / or wireless communications networks owned and / or operated by other service providers. For example, the networks 112 may include another CN connected to one or more RANs, which may employ the same RAT as the RAN 104 / 114 or a different RAT.
[0037] Some or all of the WTRUs 102a, 102b, 102c, 102d in the communications system 100 may include multi-mode capabilities (e.g., the WTRUs 102a, 102b, 102c, 102d may include multiple transceivers for communicating with different wireless networks over different wireless links). For example, the WTRU 102c shown in FIG. 1A may be configured tocommunicate with the base station 114a, which may employ a cellular-based radio technology, and with the base station 114b, which may employ an IEEE 802 radio technology.
[0038] FIG. IB is a system diagram illustrating an example WTRU 102. As shown in FIG. IB, the WTRU 102 may include a processor 118, a transceiver 120, a transmit / receive element 122, a speaker / microphone 124, a keypad 126, a display / touchpad 128, non-removable memory 130, removable memory 132, a power source 134, a global positioning system (GPS) chipset 136, and / or other elements / peripherals 138, among others. It will be appreciated that the WTRU 102 may include any sub-combination of the foregoing elements while remaining consistent with an embodiment.
[0039] The processor 118 may be a general-purpose processor, a special purpose processor, a conventional processor, a digital signal processor (DSP), a plurality of microprocessors, one or more microprocessors in association with a DSP core, a controller, a microcontroller, Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs) circuits, any other type of integrated circuit (IC), a state machine, and the like. The processor 118 may perform signal coding, data processing, power control, input / output processing, and / or any other functionality that enables the WTRU 102 to operate in a wireless environment. The processor 118 may be coupled to the transceiver 120, which may be coupled to the transmit / receive element 122. While FIG. IB depicts the processor 118 and the transceiver 120 as separate components, it will be appreciated that the processor 118 and the transceiver 120 may be integrated together, e.g., in an electronic package or chip.
[0040] The transmit / receive element 122 may be configured to transmit signals to, or receive signals from, a base station (e.g., the base station 114a) over the air interface 116. For example, in an embodiment, the transmit / receive element 122 may be an antenna configured to transmit and / or receive RF signals. In an embodiment, the transmit / receive element 122 may be an emitter / detector configured to transmit and / or receive IR, UV, or visible light signals, for example. In an embodiment, the transmit / receive element 122 may be configured to transmit and / or receive both RF and light signals. It will be appreciated that the transmit / receive element 122 may be configured to transmit and / or receive any combination of wireless signals.
[0041] Although the transmit / receive element 122 is depicted in FIG. IB as a single element, the WTRU 102 may include any number of transmit / receive elements 122. For example, the WTRU 102 may employ MIMO technology. Thus, in an embodiment, the WTRU 102 may include two or more transmit / receive elements 122 (e.g., multiple antennas) for transmitting and receiving wireless signals over the air interface 116.
[0042] The transceiver 120 may be configured to modulate the signals that are to be transmitted by the transmit / receive element 122 and to demodulate the signals that are received by the transmit / receive element 122. As noted above, the WTRU 102 may have multi-mode capabilities. Thus, the transceiver 120 may include multiple transceivers for enabling the WTRU 102 to communicate via multiple RATs, such as NR and IEEE 802.11, for example.
[0043] The processor 118 of the WTRU 102 may be coupled to, and may receive user input data from, the speaker / microphone 124, the keypad 126, and / or the display / touchpad 128 (e.g., a liquid crystal display (LCD) display unit or organic light-emitting diode (OLED) display unit). The processor 118 may also output user data to the speaker / microphone 124, the keypad 126, and / or the display / touchpad 128. In addition, the processor 118 may access information from, and store data in, any type of suitable memory, such as the non-removable memory 130 and / or the removable memory 132. The non-removable memory 130 may include random-access memory (RAM), read-only memory (ROM), a hard disk, or any other type of memory storage device. The removable memory 132 may include a subscriber identity module (SIM) card, a memory stick, a secure digital (SD) memory card, and the like. In other embodiments, the processor 118 may access information from, and store data in, memory that is not physically located on the WTRU 102, such as on a server or a home computer (not shown).
[0044] The processor 118 may receive power from the power source 134 and may be configured to distribute and / or control the power to the other components in the WTRU 102. The power source 134 may be any suitable device for powering the WTRU 102. For example, the power source 134 may include one or more dry cell batteries (e.g., nickel-cadmium (NiCd), nickel-zinc (NiZn), nickel metal hydride (NiMH), lithium-ion (Li-ion), etc.), solar cells, fuel cells, and the like.
[0045] The processor 118 may also be coupled to the GPS chipset 136, which may be configured to provide location information (e.g., longitude and latitude) regarding the current location of the WTRU 102. In addition to, or in lieu of, the information from the GPS chipset 136, the WTRU 102 may receive location information over the air interface 116 from a base station (e.g., base stations 114a, 114b) and / or determine its location based on the timing of the signals being received from two or more nearby base stations. It will be appreciated that the WTRU 102 may acquire location information by way of any suitable location-determination method while remaining consistent with an embodiment.
[0046] The processor 118 may further be coupled to other elements / peripherals 138, which may include one or more software and / or hardware modules / units that provide additional features, functionality and / or wired or wireless connectivity. For example, theelements / peripherals 138 may include an accelerometer, an e-compass, a satellite transceiver, a digital camera (e.g., for photographs and / or video), a universal serial bus (USB) port, a vibration device, a television transceiver, a hands free headset, a Bluetooth® module, a frequency modulated (FM) radio unit, a digital music player, a media player, a video game player module, an Internet browser, a virtual reality and / or augmented reality (VR / AR) device, an activity tracker, and the like. The elements / peripherals 138 may include one or more sensors, the sensors may be one or more of a gyroscope, an accelerometer, a hall effect sensor, a magnetometer, an orientation sensor, a proximity sensor, a temperature sensor, a time sensor; a geolocation sensor; an altimeter, a light sensor, a touch sensor, a magnetometer, a barometer, a gesture sensor, a biometric sensor, and / or a humidity sensor.
[0047] The WTRU 102 may include a full duplex radio for which transmission and reception of some or all of the signals (e.g., associated with particular subframes for both the uplink (e.g., for transmission) and downlink (e.g., for reception) may be concurrent and / or simultaneous. The full duplex radio may include an interference management unit to reduce and or substantially eliminate self-interference via either hardware (e.g., a choke) or signal processing via a processor (e.g., a separate processor (not shown) or via processor 118). In an embodiment, the WTRU 102 may include a half-duplex radio for which transmission and reception of some or all of the signals (e.g., associated with particular subframes for either the uplink (e.g., for transmission) or the downlink (e.g., for reception)).
[0048] FIG. 1C is a system diagram illustrating the RAN 104 and the CN 106 according to an embodiment. As noted above, the RAN 104 may employ an E-UTRA radio technology to communicate with the WTRUs 102a, 102b, and 102c over the air interface 116. The RAN 104 may also be in communication with the CN 106.
[0049] The RAN 104 may include eNode-Bs 160a, 160b, 160c, though it will be appreciated that the RAN 104 may include any number of eNode-Bs while remaining consistent with an embodiment. The eNode-Bs 160a, 160b, 160c may each include one or more transceivers for communicating with the WTRUs 102a, 102b, 102c over the air interface 116. In an embodiment, the eNode-Bs 160a, 160b, 160c may implement MIMO technology. Thus, the eNode-B 160a, for example, may use multiple antennas to transmit wireless signals to, and receive wireless signals from, the WTRU 102a.
[0050] Each of the eNode-Bs 160a, 160b, and 160c may be associated with a particular cell (not shown) and may be configured to handle radio resource management decisions, handover decisions, scheduling of users in the uplink (UL) and / or downlink (DL), and the like. As shownin FIG. 1C, the eNode-Bs 160a, 160b, 160c may communicate with one another over an X2 interface.
[0051] The CN 106 shown in FIG. 1C may include a mobility management entity (MME) 162, a serving gateway (SGW) 164, and a packet data network (PDN) gateway (PGW) 166. While each of the foregoing elements are depicted as part of the CN 106, it will be appreciated that any one of these elements may be owned and / or operated by an entity other than the CN operator.
[0052] The MME 162 may be connected to each of the eNode-Bs 160a, 160b, and 160c in the RAN 104 via an SI interface and may serve as a control node. For example, the MME 162 may be responsible for authenticating users of the WTRUs 102a, 102b, 102c, bearer activation / deactivation, selecting a particular serving gateway during an initial attach of the WTRUs 102a, 102b, 102c, and the like. The MME 162 may provide a control plane function for switching between the RAN 104 and other RANs (not shown) that employ other radio technologies, such as GSM and / or WCDMA.
[0053] The SGW 164 may be connected to each of the eNode-Bs 160a, 160b, 160c in the RAN 104 via the S 1 interface. The SGW 164 may generally route and forward user data packets to / from the WTRUs 102a, 102b, 102c. The SGW 164 may perform other functions, such as anchoring user planes during inter-eNode-B handovers, triggering paging when DL data is available for the WTRUs 102a, 102b, 102c, managing and storing contexts of the WTRUs 102a, 102b, 102c, and the like.
[0054] The SGW 164 may be connected to the PGW 166, which may provide the WTRUs 102a, 102b, 102c with access to packet-switched networks, such as the Internet 110, to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices.
[0055] The CN 106 may facilitate communications with other networks. For example, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to circuit-switched networks, such as the PSTN 108, to facilitate communications between the WTRUs 102a, 102b, 102c and traditional land-line communications devices. For example, the CN 106 may include, or may communicate with, an IP gateway (e.g., an IP multimedia subsystem (IMS) server) that serves as an interface between the CN 106 and the PSTN 108. In addition, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to the other networks 112, which may include other wired and / or wireless networks that are owned and / or operated by other service providers.
[0056] Although the WTRU is described in FIGs. 1A-1D as a wireless terminal, it is contemplated that in certain representative embodiments that such a terminal may use (e.g., temporarily or permanently) wired communication interfaces with the communication network.
[0057] In representative embodiments, the other network 112 may be a WLAN.
[0058] A WLAN in infrastructure basic service set (BSS) mode may have an access point (AP) for the BSS and one or more stations (STAs) associated with the AP. The AP may have an access or an interface to a distribution system (DS) or another type of wired / wireless network that carries traffic into and / or out of the BSS. Traffic to STAs that originates from outside the BSS may arrive through the AP and may be delivered to the STAs. Traffic originating from STAs to destinations outside the BSS may be sent to the AP to be delivered to respective destinations. Traffic between STAs within the BSS may be sent through the AP, for example, where the source STA may send traffic to the AP and the AP may deliver the traffic to the destination STA. The traffic between STAs within a BSS may be considered and / or referred to as peer-to-peer traffic. The peer-to-peer traffic may be sent between (e.g., directly between) the source and destination STAs with a direct link setup (DLS). In certain representative embodiments, the DLS may use an 802. l ie DLS or an 802. l lz tunneled DLS (TDLS). A WLAN using an Independent BSS (IBSS) mode may not have an AP, and the STAs (e.g., all of the STAs) within or using the IBSS may communicate directly with each other. The IBSS mode of communication may sometimes be referred to herein as an "ad-hoc" mode of communication.
[0059] When using the 802.1 lac infrastructure mode of operation or a similar mode of operations, the AP may transmit a beacon on a fixed channel, such as a primary channel. The primary channel may be a fixed width (e.g., 20 MHz wide bandwidth) or a dynamically set width via signaling. The primary channel may be the operating channel of the BSS and may be used by the STAs to establish a connection with the AP. In certain representative embodiments, Carrier sense multiple access with collision avoidance (CSMA / CA) may be implemented, for example in in 802.11 systems. For CSMA / CA, the STAs (e.g., every STA), including the AP, may sense the primary channel. If the primary channel is sensed / detected and / or determined to be busy by a particular STA, the particular STA may back off. One STA (e.g., only one station) may transmit at any given time in a given BSS.
[0060] High throughput (HT) STAs may use a 40 MHz wide channel for communication, for example, via a combination of the primary 20 MHz channel with an adjacent or nonadj acent 20 MHz channel to form a 40 MHz wide channel.
[0061] Very high throughput (VHT) STAs may support 20 MHz, 40 MHz, 80 MHz, and / or 160 MHz wide channels. The 40 MHz, and / or 80 MHz, channels may be formed by combining contiguous 20 MHz channels. A 160 MHz channel may be formed by combining 8 contiguous 20 MHz channels, or by combining two non-contiguous 80 MHz channels, which may bereferred to as an 80+80 configuration. For the 80+80 configuration, the data, after channel encoding, may be passed through a segment parser that may divide the data into two streams. Inverse fast fourier transform (IFFT) processing, and time domain processing, may be done on each stream separately. The streams may be mapped on to the two 80 MHz channels, and the data may be transmitted by a transmitting STA. At the receiver of the receiving STA, the abovedescribed operation for the 80+80 configuration may be reversed, and the combined data may be sent to a medium access control (MAC) layer, entity, etc.
[0062] Sub 1 GHz modes of operation are supported by 802.1 laf and 802.1 lah. The channel operating bandwidths, and carriers, are reduced in 802.1 laf and 802.1 lah relative to those used in 802.1 In, and 802.1 lac. 802.1 laf supports 5 MHz, 10 MHz and 20 MHz bandwidths in the TV white space (TVWS) spectrum, and 802.1 lah supports 1 MHz, 2 MHz, 4 MHz, 8 MHz, and 16 MHz bandwidths using non-TVWS spectrum. According to a representative embodiment, 802.1 lah may support meter type control / machine-type communications (MTC), such as MTC devices in a macro coverage area. MTC devices may have certain capabilities, for example, limited capabilities including support for (e.g., only support for) certain and / or limited bandwidths. The MTC devices may include a battery with a battery life above a threshold (e.g., to maintain a very long battery life).
[0063] WLAN systems, which may support multiple channels, and channel bandwidths, such as 802.1 In, 802.1 lac, 802.1 laf, and 802.1 lah, include a channel which may be designated as the primary channel. The primary channel may have a bandwidth equal to the largest common operating bandwidth supported by all STAs in the BSS. The bandwidth of the primary channel may be set and / or limited by a STA, from among all STAs in operating in a BSS, which supports the smallest bandwidth operating mode. In the example of 802.1 lah, the primary channel may be 1 MHz wide for STAs (e.g., MTC type devices) that support (e.g., only support) a 1 MHz mode, even if the AP, and other STAs in the BSS support 2 MHz, 4 MHz, 8 MHz, 16 MHz, and / or other channel bandwidth operating modes. Carrier sensing and / or network allocation vector (NAV) settings may depend on the status of the primary channel. If the primary channel is busy, for example, due to a STA (which supports only a 1 MHz operating mode), transmitting to the AP, the entire available frequency bands may be considered busy even though a majority of the frequency bands remains idle and may be available.
[0064] In the United States, the available frequency bands, which may be used by 802.1 lah, are from 902 MHz to 928 MHz. In Korea, the available frequency bands are from 917.5 MHz to 923.5 MHz. In Japan, the available frequency bands are from 916.5 MHz to 927.5 MHz. The total bandwidth available for 802.1 lah is 6 MHz to 26 MHz depending on the country code.
[0065] FIG. ID is a system diagram illustrating the RAN 113 and the CN 115 according to an embodiment. As noted above, the RAN 113 may employ an NR radio technology to communicate with the WTRUs 102a, 102b, 102c over the air interface 116. The RAN 113 may also be in communication with the CN 115.
[0066] The RAN 113 may include gNBs 180a, 180b, 180c, though it will be appreciated that the RAN 113 may include any number of gNBs while remaining consistent with an embodiment. The gNBs 180a, 180b, 180c may each include one or more transceivers for communicating with the WTRUs 102a, 102b, 102c over the air interface 116. In an embodiment, the gNBs 180a, 180b, 180c may implement MIMO technology. For example, gNBs 180a, 180b may utilize beamforming to transmit signals to and / or receive signals from the WTRUs 102a, 102b, 102c. Thus, the gNB 180a, for example, may use multiple antennas to transmit wireless signals to, and / or receive wireless signals from, the WTRU 102a. In an embodiment, the gNBs 180a, 180b, 180c may implement carrier aggregation technology. For example, the gNB 180a may transmit multiple component carriers to the WTRU 102a (not shown). A subset of these component carriers may be on unlicensed spectrum while the remaining component carriers may be on licensed spectrum. In an embodiment, the gNBs 180a, 180b, 180c may implement Coordinated Multi-Point (CoMP) technology. For example, WTRU 102a may receive coordinated transmissions from gNB 180a and gNB 180b (and / or gNB 180c).
[0067] The WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c using transmissions associated with a scalable numerology. For example, OFDM symbol spacing and / or OFDM subcarrier spacing may vary for different transmissions, different cells, and / or different portions of the wireless transmission spectrum. The WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c using subframe or transmission time intervals (TTIs) of various or scalable lengths (e.g., including a varying number of OFDM symbols and / or lasting varying lengths of absolute time).
[0068] The gNBs 180a, 180b, 180c may be configured to communicate with the WTRUs 102a, 102b, 102c in a standalone configuration and / or a non- standalone configuration. In the standalone configuration, WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c without also accessing other RANs (e.g., such as eNode-Bs 160a, 160b, 160c). In the standalone configuration, WTRUs 102a, 102b, 102c may utilize one or more of gNBs 180a, 180b, 180c as a mobility anchor point. In the standalone configuration, WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c using signals in an unlicensed band. In a non-standalone configuration WTRUs 102a, 102b, 102c may communicate with / connect to gNBs 180a, 180b, 180c while also communicating with / connecting to another RAN such aseNode-Bs 160a, 160b, 160c. For example, WTRUs 102a, 102b, 102c may implement DC principles to communicate with one or more gNBs 180a, 180b, 180c and one or more eNode- Bs 160a, 160b, 160c substantially simultaneously. In the non-standalone configuration, eNode- Bs 160a, 160b, 160c may serve as a mobility anchor for WTRUs 102a, 102b, 102c and gNBs 180a, 180b, 180c may provide additional coverage and / or throughput for servicing WTRUs 102a, 102b, 102c.
[0069] Each of the gNBs 180a, 180b, 180c may be associated with a particular cell (not shown) and may be configured to handle radio resource management decisions, handover decisions, scheduling of users in the UL and / or DL, support of network slicing, dual connectivity, interworking between NR and E-UTRA, routing of user plane data towards user plane functions (UPFs) 184a, 184b, routing of control plane information towards access and mobility management functions (AMFs) 182a, 182b, and the like. As shown in FIG. ID, the gNBs 180a, 180b, 180c may communicate with one another over an Xn interface.
[0070] The CN 115 shown in FIG. ID may include at least one AMF 182a, 182b, at least one UPF 184a, 184b, at least one session management function (SMF) 183a, 183b, and at least one Data Network (DN) 185a, 185b. While each of the foregoing elements are depicted as part of the CN 115, it will be appreciated that any of these elements may be owned and / or operated by an entity other than the CN operator.
[0071] The AMF 182a, 182b may be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 113 via an N2 interface and may serve as a control node. For example, the AMF 182a, 182b may be responsible for authenticating users of the WTRUs 102a, 102b, 102c, support for network slicing (e.g., handling of different protocol data unit (PDU) sessions with different requirements), selecting a particular SMF 183a, 183b, management of the registration area, termination of NAS signaling, mobility management, and the like. Network slicing may be used by the AMF 182a, 182b, e.g., to customize CN support for WTRUs 102a, 102b, 102c based on the types of services being utilized by WTRUs 102a, 102b, 102c. For example, different network slices may be established for different use cases such as services relying on ultra-reliable low latency (URLLC) access, services relying on enhanced massive mobile broadband (eMBB) access, services for MTC access, and / or the like. The AMF 182a, 182b may provide a control plane function for switching between the RAN 113 and other RANs (not shown) that employ other radio technologies, such as LTE, LTE-A, LTE-A Pro, and / or non- 3GPP access technologies such as Wi-Fi.
[0072] The SMF 183a, 183b may be connected to an AMF 182a, 182b in the CN 115 via an Ni l interface. The SMF 183a, 183b may also be connected to a UPF 184a, 184b in the CN 115via an N4 interface. The SMF 183a, 183b may select and control the UPF 184a, 184b and configure the routing of traffic through the UPF 184a, 184b. The SMF 183 a, 183b may perform other functions, such as managing and allocating UE IP address, managing PDU sessions, controlling policy enforcement and QoS, providing downlink data notifications, and the like. A PDU session type may be IP -based, non-IP based, Ethernet-based, and the like.
[0073] The UPF 184a, 184b may be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 113 via an N3 interface, which may provide the WTRUs 102a, 102b, 102c with access to packet-switched networks, such as the Internet 110, e.g., to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices. The UPF 184a, 184b may perform other functions, such as routing and forwarding packets, enforcing user plane policies, supporting multi-homed PDU sessions, handling user plane QoS, buffering downlink packets, providing mobility anchoring, and the like.
[0074] The CN 115 may facilitate communications with other networks. For example, the CN 115 may include, or may communicate with, an IP gateway (e.g., an IP multimedia subsystem (IMS) server) that serves as an interface between the CN 115 and the PSTN 108. In addition, the CN 115 may provide the WTRUs 102a, 102b, 102c with access to the other networks 112, which may include other wired and / or wireless networks that are owned and / or operated by other service providers. In an embodiment, the WTRUs 102a, 102b, 102c may be connected to a local Data Network (DN) 185a, 185b through the UPF 184a, 184b via the N3 interface to the UPF 184a, 184b and an N6 interface between the UPF 184a, 184b and the DN 185a, 185b.
[0075] In view of FIGs. 1A-1D, and the corresponding description of FIGs. 1A-1D, one or more, or all, of the functions described herein with regard to any of WTRUs 102a-d, base stations 114a-b, eNode-Bs 160a-c, MME 162, SGW 164, PGW 166, gNBs 180a-c, AMFs 182a- b, UPFs 184a-b, SMFs 183a-b, DNs 185a-b, and / or any other element(s) / device(s) described herein, may be performed by one or more emulation elements / devices (not shown). The emulation devices may be one or more devices configured to emulate one or more, or all, of the functions described herein. For example, the emulation devices may be used to test other devices and / or to simulate network and / or WTRU functions.
[0076] The emulation devices may be designed to implement one or more tests of other devices in a lab environment and / or in an operator network environment. For example, the one or more emulation devices may perform the one or more, or all, functions while being fully or partially implemented and / or deployed as part of a wired and / or wireless communication network in order to test other devices within the communication network. The one or more emulation devices may perform the one or more, or all, functions while being temporarilyimplemented / deployed as part of a wired and / or wireless communication network. The emulation device may be directly coupled to another device for purposes of testing and / or may perform testing using over-the-air wireless communications.
[0077] The one or more emulation devices may perform the one or more, including all, functions while not being implemented / deployed as part of a wired and / or wireless communication network. For example, the emulation devices may be utilized in a testing scenario in a testing laboratory and / or a non-deployed (e.g., testing) wired and / or wireless communication network in order to implement testing of one or more components. The one or more emulation devices may be test equipment. Direct RF coupling and / or wireless communications via RF circuitry (e.g., which may include one or more antennas) may be used by the emulation devices to transmit and / or receive data.
[0078] Throughout embodiments described herein the terms "base station", "network", "cell", and "gNB", collectively "the network" may be used interchangeably to designate any network element such as e.g., a network element acting as a serving base station. Embodiments described herein are not limited to gNBs and are applicable to any other type of base stations.
[0079] For the sake of clarity, satisfying, failing to satisfy a condition, and configuring condition parameter(s) are described throughout embodiments described herein as relative to a threshold (e.g., greater, or lower than) a (e.g., threshold) value, configuring the (e.g., threshold) value, etc. For example, satisfying a condition may be described as being above a (e.g., threshold) value, and failing to satisfy a condition may be described as being below a (e.g., threshold) value. Embodiments described herein are not limited to threshold-based conditions. Any kind of other condition and param eter(s) (such as e.g., belonging or not belonging to a range of values) may be applicable to embodiments described herein.
[0080] Throughout embodiments described herein, (e.g., configuration) information may be described as received by a WTRU from the network, for example, through system information or via any kind of protocol message. Although not explicitly mentioned throughout embodiments described herein, the same (e.g., configuration) information may be preconfigured in the WTRU (e.g., via any kind of pre-configuration methods such as e.g., via factory settings), such that this (e.g., configuration) information may be used by the WTRU without being received from the network.
[0081] Throughout embodiments described herein, the expression "the WTRU may be configured with a set of parameters" is equivalent or may be used interchangeably with "the WTRU may receive configuration information (e.g., from another network element (e.g., gNB)) indicating a set of parameters". Throughout embodiments described herein, the expressions "theWTRU may report something", and "the WTRU may be configured to report something", is equivalent or may be used interchangeably with "the WTRU may transmit (e.g., reporting) information indicating something". Throughout embodiments described herein, the expression "the WTRU may provide ( / be provided) with a set of parameters ( / something)" is equivalent or may be used interchangeably with "the WTRU may transmit ( / receive) information indicating a set of parameters ( / something)".
[0082] In embodiments described herein, "a" and "an" and similar phrases are to be interpreted as "one or more" and "at least one". Similarly, any term which ends with the suffix "(s)" is to be interpreted as "one or more" and "at least one". The term "may" is to be interpreted as "may, for example".
[0083] A symbol " / " (e.g., forward slash) may be used herein to represent "and / or", where for example, "A / B" may imply "A and / or B".
[0084] In embodiments described herein, "list of', "set of' and "one or more of' may be used interchangeably.
[0085] In embodiments described herein, "identity" and "identifier" may be used interchangeably to refer to how a network element (or a WTRU) may be identified.
[0086] In embodiments described herein, a network element may refer to any kind of device including computing resources and networking capabilities, that may be connected to a network. The terms network element and node may be used interchangeably. A network element may be any kind of network infrastructure device and or a WTRU. The architecture depicted at FIG. IB for a WTRU 102 may be applicable more generally to any kind of network element
[0087] Mobility in NR
[0088] FIG. 2 is a diagram illustrating an example of handover procedure, as described in 3GPP technical specification (TS) 38.300 vl8.0.0.
[0089] As shown at 21, the source gNB may initiate handover and may generate a handover request over the Xn interface.
[0090] As shown at 22, the target gNB may perform admission control and may provide (e.g., transmit) the new RRC configuration as part of the handover request acknowledge.
[0091] As shown at 23, the source gNB may provide the RRC configuration to the WTRU by forwarding the RRC reconfiguration message (referred to herein as RRCReconfiguration message) received in the handover request acknowledge. The RRCReconfiguration message may include at least a cell identifier (ID) and (e.g., all) information (e.g., to be used) to access the target cell so that the WTRU may access the target cell e.g., without reading systeminformation. In some examples, the information for contention-based and contention-free random access may be included in the RRCReconfiguration message. The access information to the target cell may include, for example, beam specific information.
[0092] As shown at 24, the WTRU may move the RRC connection to the target gNB and may reply with a RRC reconfiguration complete message (e.g., referred to herein as RRCReconfigurati onC ompl ete) .
[0093] Mobility Enhancement in Rel-19
[0094] In Rel-18, 3GPP standardized L1 / L2 triggered mobility (LTM), where a WTRU may be pre-configured, as in the case of conditional handover (CHO), with radio resource control (RRC) reconfiguration to apply upon switching (e.g., being handed over) from a source cell to a target cell, where the switching / handover may be performed upon receiving a MAC CE indicating the cell switch (e.g., the WTRU may not perform autonomous handover as in the case of CHO based on the fulfillment of measurement events). LTM may enable improvements in handover latency and interruption time compared to layer three based mobility. Rel-18 LTM is limited to cells belonging to a same gNB / centralized unit (CU), such that there may be no security considerations (e.g., the packet data convergence protocol (PDCP) termination of the bearers may not change).
[0095] A Rel-19 work item (WI) for LTM enhancements has been approved by 3 GPP, one of the objectives being the support of inter-CU / gNB LTM, which may involve security considerations. Another objective is to introduce conditional LTM (e.g., WTRU executing LTM based on measurement events e.g., without waiting for the LTM MAC CE). Doing subsequent conditional LTM is (e.g., also) within the WI scope (e.g., WTRU doing conditional LTM from a first cell (e.g., x) to a second cell (e.g., y) and then to a third cell (e.g., z), wherein no RRC reconfiguration may be received between the handovers).
[0096] In embodiments described herein the terms "handover" and "cell switching" may be used interchangeably.
[0097] Embodiments are described herein with conditional LTM as an example of conditional handover. Embodiments described herein are not limited to conditional LTM and may be applicable to any kind of handovers, where a WTRU may perform one or more subsequent handovers between cells within a group of candidate cells. In an example, the one or more subsequent handovers may be conditional handovers.
[0098] Security Key Update During Mobility
[0099] In NR, signaling radio bearers (SRBs) are integrity protected and encrypted. In NR data radio bearers (DRBs) are encrypted and may be integrity protected.
[0100] The WTRU may use four different security keys for the different operations (e.g., for integrity protecting or verification, for encryption or decryption) of the data of the SRBs and DRBs, as described herein:
[0101] The WTRU may use a first security key (which may be referred to as KRRCint) for integrity protection of RRC signaling.
[0102] The WTRU may use a second security key (which may be referred to as KRRCenc) for ciphering (also referred to as encryption) of RRC signaling.
[0103] The WTRU may use a third security key (which may be referred to as Kupint) for integrity protection of user data.
[0104] The WTRU may use a fourth security key (which may be referred to as Kupenc) for ciphering of user data.
[0105] The four security keys described herein may be derived from a cell key (which may be referred to as K§NB key). The WTRU may derive the K§NB to be used in the target cell based on the current K§NB that may have been used in the source cell, information about the target cell (e.g., frequency, physical cell identity (PCI)), and some additional parameter provided to the WTRU in the handover (HO) command.
[0106] The source gNB may perform a similar (e.g., the equivalent) derivation of the target gNB's KgNB and may include (e.g., indicate) it in the HO request message during the handover initiation, which the target gNB may use from there on when communicating with the corresponding WTRU.
[0107] In embodiments described herein the terms "cell key", "security key", "KgNB" collectively "key" may be used interchangeably to refer to a security key that may be derived by a WTRU and a gNB to be used in a cell.
[0108] Embodiments described herein allow to enable subsequent conditional LTM without sending to the WTRU any RRC reconfiguration message between subsequent handovers.
[0109] If a handover is performed using legacy HO / CHO, the WTRU may be configured with the (e.g., proper) security configuration to apply upon any of the reception of the HO command and the fulfillment of the measurement event associated with the CHO. For the next HO / CHO, the WTRU may be provided with a further security configuration to apply, etc.
[0110] FIG. 3 is a diagram illustrating an example mobility scenario, where a WTRU may be moving around three cells. The arrows indicate the mobility direction and the numbers (31-38) indicate (e.g., hops in) the trajectory. The mobility pattern (e.g., trajectory, path) in this example may be represented as A - B - C~>A - C - B - A- B.
[0111] If the cells belong to the same CU, (e.g., as supported in Rel-18 LTM) no security update may be (e.g., needed to be) performed during the handover. In case of subsequent LTM as shown in FIG. 3, the WTRU may reuse the same reconfiguration associated with the target cell e.g., apply the same reconfiguration when performing the cell switching to target cell C as shown at 32 or 36, when performing the cell switching to cell B as shown at 31 and 38, when performing the cell switching to cell A as shown at 34 and 37, etc.
[0112] If the cells belong to different CUs, a security update may be (e.g., needed to be) performed during a (e.g., each) cell switch. If subsequent LTM is to be allowed, the WTRU may be provided with the keys to use for a (e.g., each) cell switch. In the example shown at FIG. 3, the WTRU may be provided with different security configuration to apply switching to cell C as shown at 32 and 36. This may be based on the 3GPP security requirement that security keys cannot be reused again. Considering that the WTRU trajectory may not be known at the reception of the LTM configuration, it may be impractical, (e.g., if not impossible) to provide the keys for all possible trajectory combinations. For example, in the case of subsequent conditional LTM, it may be impractical to provide the WTRU with (e.g., all) the reconfiguration information beforehand (e.g., based on the LTM being executed autonomously by the WTRU upon the fulfillment of measurement events). The network may not be able to signal information related to security configuration before the LTM may be executed.
[0113] In an approach the WTRU may be provided with an RRC reconfiguration that may provide security configuration for all the possible targets. In the example shown at FIG. 3, after the WTRU may have performed the cell switch to cell B as shown at 31, it may be provided with a security configuration that it may use on switching to cell A or C after that. After switching to cell C as shown at 32, the WTRU may be provided with security configuration that it may use on subsequent switching to cell A or B, and so on. This is contrary to the objectives of Rel-19 WI (e.g., the WTRU may be expected to perform the subsequent conditional LTMs without (e.g., the need for) reconfiguration (e.g., every time) after triggering a cell switching.
[0114] Embodiments described herein may allow to enable the WTRU to perform the (e.g., required) security updates when performing subsequent conditional LTM between cells belonging to different gNBs, e.g., without (e.g., the need for) RRC reconfiguration between the subsequent LTM cell switching.
[0115] Overview of a Security Key Derivation for Subsequent Conditional LTM
[0116] A security key derivation for subsequent conditional LTM that may be dependent on any of a source cell, a target cell, a hop count and path information is described herein.
[0117] A (e.g., new) KgNB derivation function taking any of the source cell ID, the target cell ID, a cell switching count and the current path information as input is described herein.
[0118] In an example, a WTRU may receive configuration (e.g., information) related to conditional LTM that may indicate one or more of (i) a (e.g., RRC) configuration for multiple LTM candidate cells, (ii) measurement events (e.g., conditions) associated with the candidate cells, and (iii) a set of trajectory / path information (such as e.g., a set of ordered list of (e.g., LTM) candidate cells, each (e.g., ordered list) with an ID).
[0119] In an example, the WTRU may set a cell switching count to zero, and the current path ID to a first path.
[0120] In an example, the WTRU may start evaluating the conditions for the measurement events.
[0121] In an example, upon determining that the measurement event (e.g., condition) for a (e.g., given) candidate cell is fulfilled, the WTRU may perform any of the following operations. The WTRU may determine the target cell to be the (e.g., given) candidate cell. The WTRU may deactivate the measurement event (e.g., condition) associated with the target cell. The WTRU may activate the measurement event (e.g., condition) associated with the source cell. The WTRU may apply the (e.g., RRC) configuration associated with the target cell. The WTRU may determine the KgNB as a function of any of the current KgNB, the source cell ID, the target cell ID, the current cell switching count and the current path ID. The WTRU may derive the SRB and DRB encryption and integrity keys from the KgNB. The WTRU may send an RRC reconfiguration complete message to the target cell (encrypted and integrity protected with the derived keys for the SRB). The WTRU may send information regarding the hop and / or path to the target cell (e.g., any of (i) in plain text in the reconfiguration complete, (ii) as a separate message, e.g., MAC CE, e.g., multiplexed with the complete message, etc.,). The WTRU may update the switching count, e.g., by increasing the cell switching count by one (cell switching count = cell switching count + 1). The WTRU may update the current path ID, if path has changed based on the cell switching.
[0122] Overview of a WTRU Pre-Configured with a Set of Keys for Subsequent Conditional LTM
[0123] A WTRU pre-configured with a set of keys to be used for subsequent conditional LTM is described herein.
[0124] In an example, a WTRU may be configured with a conditional LTM configuration that may include multiple keys, where a (e.g., each) key may be associated with a combination of a source cell, a target cell, a cell switching count, and path information. Upon determining thatthe conditions for the LTM are fulfilled, the WTRU may update its security configuration by applying the key associated with the source cell, the target cell, the current cell switching count and the current path.
[0125] In an example, the WTRU may inform the target cell with information (e.g., in a message multiplexed with the HO complete message) to enable the target cell to derive the key to be used for that WTRU (e.g., or choose a key from a list of previously stored keys at the target cells). The information provided by the WTRU may include one or more of a path ID, actual path information, a key configuration index, a next hop chaining count (NCC) value, a cell switching count, a source cell, etc.
[0126] In an example, a WTRU may receive configuration (e.g., information) related to conditional LTM that may indicate one or more of (i) a (e.g., RRC) configuration for multiple LTM candidate cells, (ii) measurement events (e.g., conditions) associated with the candidate cells, (iii) a set of trajectory / path information (such as e.g., a set of ordered list of (e.g., LTM) candidate cells, each (e.g., ordered list) with an ID), and (iv) list of keys (KgNBs), where a (e.g., each) key may be associated / indexed with one or more of the following of a source cell ID, a target cell ID, a cell switching count and path information.
[0127] In an example, the WTRU may set a cell switching count to zero, and the current path ID to a first path.
[0128] In an example, the WTRU may start evaluating the conditions for the measurement events.
[0129] In an example, upon determining that the measurement event (e.g., condition) for a (e.g., given) candidate cell is fulfilled, the WTRU may perform any of the following operations. The WTRU may determine the target cell to be the (e.g., given) candidate cell. The WTRU may deactivate the measurement event (e.g., condition) associated with the target cell. The WTRU may activate the measurement event (e.g., condition) associated with the source cell. The WTRU may apply the (e.g., RRC) configuration associated with the target cell. The WTRU may determine (e.g., choose, select) the K§NB associated with the one or more of the source cell ID, the target cell ID, the current cell switching count and the current path. The WTRU may derive the SRB and DRB encryption and integrity keys from the KgNB. The WTRU may send an RRC reconfiguration complete message to the target cell (encrypted and integrity protected with the derived keys for the SRB). The WTRU may send information regarding the hop and / or path to the target cell (e.g., any of (i) in plain text in the reconfiguration complete, (ii) as a separate message, e.g., MAC CE, e.g., multiplexed with the complete message, etc.,). The WTRU may update the switching count, e.g., by increasing the cell switching count by one (cellswitching count = cell switching count + 1). The WTRU may update the current path ID, if path has changed based on the cell switching.
[0130] In an example, a WTRU may receive configuration information related to performing one or more subsequent conditional handovers between cells within a group of candidate cells. The configuration information may include, for example, path information for deriving security keys to be used after a handover from one cell to another cell within the group of candidate cells.
[0131] In an example, the WTRU may perform a conditional handover from a source cell to a target cell within the group of candidate cells, wherein the WTRU may have operated in the source cell using a first key and a security context associated with the first key.
[0132] In an example, performing the conditional handover from the source cell to the target cell may include determining a second key based on a source cell identifier and any of the path information, the first key, a cell switch count and a target cell identifier (where e.g., the source cell identifier may identify the source cell and where the target cell identifier may identify the target cell).
[0133] In an example, performing the conditional handover from the source cell to the target cell may include updating the security context to be used with the target cell based on the second key, and sending information to the target cell to be used for deriving the second key.
[0134] Terminology
[0135] In embodiments described herein, path information may refer to information for deriving security keys to be used after a handover from one cell to another cell within a group of candidate cells.
[0136] Key derivation hierarchy is described herein.
[0137] FIG. 4 is a diagram illustrating an example of hierarchy generation is 5G, as described in 3GPP TS 33.501, vl7.6.0. In embodiments described herein the term "mobile equipment (ME)" may be used interchangeably with the terms "UE" and "WTRU".
[0138] The key hierarchy may include the following keys: KAUSF, KSEAF, KAMF, KxASint, KNASenc, KNSIWF, KgNB, K Rcint, KRRCenc, Kupint and KuPenc. Keys related to access stratum (e.g., key for NG-RAN, keys for user plane (UP) traffic, keys for RRC signaling and intermediate keys) are described herein.
[0139] Key for NG-RAN may include KgNB, which is a key that may be derived by ME and AMF from KAMF. K§NB may be further derived by ME and source gNB when performing horizontal or vertical key derivation. The KgNB may be used as I<e\B between ME and ng-eNB.
[0140] Keys for UP traffic may include Kupenc and Kupint. Kupenc is a key that may be derived by ME and gNB from KgNB, which may (e.g., only) be used for the protection of UP traffic with a particular encryption algorithm. Kupint is a key that may be derived by ME and gNB from KgNB, which may (e.g., only) be used for the protection of UP traffic between ME and gNB with a particular integrity algorithm.
[0141] Keys for RRC signaling may include KRRCint and KRRCenc. KRRCint is a key that may be derived by ME and gNB from KgNB, which may (e.g., only) be used for the protection of RRC signaling with a particular integrity algorithm. KRRCenc is a key that may be derived by ME and gNB from KgNB, which may (e.g., only) be used for the protection of RRC signaling with a particular encryption algorithm.
[0142] Intermediate keys may include a next hop (NH) and KgNb. NH is a key that may be derived by ME and AMF to provide forward security. KgNb* is a key that may be derived by ME and gNB when performing a horizontal or vertical key derivation.
[0143] Vertical and Horizontal Key Derivation
[0144] The (e.g., RRC) reconfiguration message that may be received by the WTRU (e.g., during a handover) may contain a master key update (which may be referred to herein as masterKeyUpdate).
[0145] FIG. 5 is a diagram illustrating an example of master key update as described in 3GPP TS 38.331, v. 17.5.0.
[0146] If the keySetChangelndicator is set to "true", then the WTRU may derive or update the KgNB based on the KAMF key.
[0147] If the keySetChangelndicator is set to "false", then the WTRU may derive or update the KgNB based on the current K§NB and depending (e.g., based) on the nextHopChainingCount value (which may be referred to as NCC).
[0148] If the NCC value received by the WTRU is equal to the NCC value associated with the currently active K§NB (e.g., the NCC indicated in the previously received masterKeyUpdate), the WTRU may derive the KgNB from the currently active KgNB, the target PCI and its frequency using the key derivation function defined in 3GPP TS 33.501.
[0149] If the NCC value received by the WTRU is different from the NCC value associated with the currently active KgNB, the WTRU may first synchronize the locally kept NH parameter by computing the NH derivation function defined in TS 33.501 (and increasing the NCC value until it may match the NCC value received). When the NCC values match, the WTRU may compute the KgNB from the synchronized NH parameter, the target PCI and its frequency ARFCN-DL / EARFCN-DL using the function defined in TS 33.501, where ARFCN stands forabsolute radio frequency channel number, and EARFCN stands for E-UTRA absolute radio frequency channel number.
[0150] After the WTRU may have derived the K§NB key according to one of the abovedescribed methods, the WTRU may update the UP security keys for DRBs (e.g., Kupenc and Kupint) and the control plane (CP) security keys (e.g., KRRCint and KRRCenc).
[0151] If an initial access stratum (AS) security context is to be established between the WTRU and the gNB, the AMF and the WTRU may derive a KgNBand a next hop (NH) parameter. The KgNBand the NH may be derived from the KAMF. A NH chaining counter (NCC) may be associated with a (e.g., each) KgNBand NH parameter. A (e.g., every) KgNBmay be associated with the NCC corresponding to the NH value from which it may have been derived. In an example, at initial setup, the KgNBmay be derived (e.g., directly) from KAMF, and may be (e.g., considered to be) associated with a virtual NH parameter with NCC value equal to zero. In an example, at initial setup, the derived NH value may be associated with the NCC value one. On handovers, the basis for the KgNBthat may be used between the WTRU and the target gNB, referred to as KgNB*, may be derived from any of the currently active KgNBand the NH parameter. If KgNB* is derived from the currently active KgNB, this may be referred to as a horizontal key derivation and may be indicated to the WTRU with an NCC that may not increase. If the KgNB* is derived from the NH parameter, the derivation may be referred to as a vertical key derivation and may be indicated to the WTRU with an NCC increase. In an example, KRRcmt, KRRCenc, Kupmt and Kupenc may be derived based on KgNBafter a new KgNBmay have been derived.
[0152] With such key derivation, a gNB with knowledge of a KgNB, shared with a WTRU, is unable to compute any previous KgNBthat may have been used between the same WTRU and a previous gNB, therefore providing backward security. Similarly, a gNB with knowledge of a KgNB, shared with a WTRU, is unable to predict any future KgNBthat may be used between the same WTRU and another gNB after one or more handovers (based on the NH parameters being (e.g., only) computable by the WTRU and the AMF).
[0153] On handovers with vertical key derivation the NH may be further bound to the target PCI and its frequency ARFCN-DL before it may be taken into use as the KgNB in the target gNB. On handovers with horizontal key derivation the currently active KgNB may be further bound to the target PCI and its frequency ARFCN-DL before it may be taken into use as the KgNB in the target gNB. When deriving the K§NB, the PCI and the ARFCN (e.g., absolute frequency of synchronization signal block (SSB) of the target cell), may be used as input to the security key derivation function (KDF).
[0154] FIG. 6 is a diagram illustrating an example of horizontal key derivation (hkd) and vertical key derivation (vkd).
[0155] In Xn handovers the source gNB may perform a vertical key derivation in case it has an unused {NH, NCC} pair. The source gNB may first compute KgNB* from target PCI, its frequency ARFCN-DL / EARFCN-DL, and from currently active KgNB in case of horizontal key derivation or from the NH in case of vertical key derivation.
[0156] In an example, the source gNB may forward the {KgNB*, NCC} pair to the target gNB. The target gNB may use the received KgNB * (e.g., directly) as KgNB to be used with the WTRU. The target gNB may associate the NCC value received from the source gNB with the KgNB. The target gNB may include the received NCC into the prepared HO command message, which may be sent back to the source gNB in a transparent container and forwarded to the WTRU by the source gNB.
[0157] After the target gNB may have completed the handover signaling with the WTRU, the target WTRU may send a path switch request message (which may be referred to as NGAP PATH SWITCH REQUEST message) to the AMF. Upon reception of the NGAP PATH SWITCH REQUEST, the AMF may increase its locally kept NCC value by one and may compute a new (e.g., fresh) NH from its stored data. The AMF may use the KAMF from the currently active 5GNAS security context for the computation of the new (e.g., fresh) NH. The AMF may send the newly computed {NH, NCC} pair to the target gNB in a path switch request acknowledge message (which may be referred to as NGAP PATH SWITCH REQUEST ACKNOWLEDGE message). The target gNB may store the received {NH, NCC} pair for further handovers and may remove other existing unused stored {NH, NCC} pairs e.g., if any.
[0158] LTM Candidate Cell Sets
[0159] One or more LTM candidate cell sets are described herein. The one or more candidate cell sets may be groups of more than one RRC configuration corresponding to a handover configuration for one or more candidate special cells (SpCells) and, for example, secondary cells (SCells). This may be modelled or received (e.g., indicated) as one or more RRC reconfiguration complete messages, one or more cell group configurations, or one or more cell configurations. A (e.g., each of the) candidate cell configurations may include a candidate configuration identifier, and a (e.g., each of the) candidate cell groups may include a candidate cell group identifier. If the grouping is performed at RRC, the switching between different sets of candidate cells may include updating any of the serving cell indexes and candidate configuration indexes which may be used in layer one (LI) and MAC signaling to refer to specific indexes (for example a MAC CE triggering the reconfiguration may include a candidateconfiguration index informing (e.g., indicating) the WTRU which cell to perform the reconfiguration to).
[0160] The one or more candidate cell groups may be configured as a (e.g., single) list (e.g., group) of candidate cell configurations at RRC. The grouping may occur at the early sync or LTM execution phase and may not occur at the configuration phase. The candidate cell set may be considered as a single group in terms of an RRC configuration list (e.g., group), and the cells selected for performing early sync, LI measurements, and LTM execution may depend on a further grouping into multiple subsets of the overall candidate cell list (e.g., set). In other words, the grouping itself may not be performed at RRC using candidate configuration identifiers, the grouping may be executed (e.g., performed) as part of the early sync or the LTM execution procedure.
[0161] In embodiments described herein a list of candidate cells may be an ordered list comprising zero or one or more occurrences of a candidate cell of a plurality of candidate cells, wherein the list of ordered candidate cells (e.g., A, B, C, A) may refer to a sequence of cell switching (e.g., A to B, followed by B to C, followed by C to A) between the candidate cells of the list.
[0162] Throughout embodiments described herein, referring to an LTM candidate configuration may apply to any type of preconfigured cell information. For example, a WTRU may be configured with one or more conditional reconfigurations such as e.g., any of conditional handover (CHO), conditional primary secondary cell (PSCell) addition (CPA) or conditional PSCell change (CPC) which may be valid before and / or after a cell change, and / or valid in a part of the cells.
[0163] Embodiments are described herein with LTM as an example, based on subsequent conditional LTM being within the scope of Rel-19 work item on mobility enhancements. Embodiments described herein are not limited to LTM and may be equally applicable to other kinds of mobility (e.g., not currently being discussed in 3GPP), such as e.g., subsequent CHO.
[0164] Throughout embodiments described herein, the terms horizontal key derivation and horizontal handover may be used interchangeably.
[0165] Throughout embodiments described herein, the terms vertical key derivation and vertical handover may be used interchangeably.
[0166] For the sake of simplicity, embodiments are described herein with the example of deriving the KgNB. In embodiments described, after the WTRU may have derived the KgNB for the target, the WTRU may update the UP security keys for DRBs (e.g., Kupenc and Kupint) and the CP security keys (e.g., KRRCint and KRRCenc) and may use those new keys to communicatewith the target (e.g., starting from the HO complete message that may be sent after the LTM cell switching may have been performed).
[0167] Throughout embodiments described herein, the terms "HO complete message" and "reconfiguration complete message" may be used interchangeably. Embodiments are described herein with the example of RRC reconfiguration (e.g., messages), at the RRC level. Embodiments described herein are not limited to RRC reconfigurations, and are applicable to any kind of reconfiguration at any kind of protocol layer.
[0168] Subsequent Conditional LTM Configuration
[0169] In one example, the WTRU may be provided with LTM configuration for multiple target cells, where a (e.g., each) configuration may be associated with (e.g., include) triggering condition for executing the LTM configuration to the corresponding target cell.
[0170] In one example, the LTM configurations for the different target cells may be independent (e.g., the WTRU may be allowed to perform conditional LTM from any source cell to any target cell). For example, the WTRU may be in cell x and may receive a configuration including conditional LTM configuration about cells a, b and c (and (e.g., also) regarding cell x, which may not be monitored in the beginning based on the WTRU (e.g., already) being in cell x). The WTRU may monitor the triggering conditions for conditional LTM regarding cells a, b and c, and if the conditions for cell a are fulfilled, the WTRU may execute the switching to cell a, and may start monitoring the conditions for cells x, b and c, and so on.
[0171] In one example, the LTM configurations for the different target cells may depend on each other (e.g., the WTRU may be configured with information indicating which conditional LTM target cells may be allowed from a (e.g., given) source cell). For example, the WTRU may be in cell x and may receive a configuration including conditional LTM configuration about cells a, b and c (and (e.g., also) regarding cell x, which may not be monitored in the beginning based on the WTRU (e.g., already) being in cell x). The WTRU may be further configured with information indicating that (i) b and c may be candidate target cells from x, (ii) c and a may be candidate target cells from b, and so on. As the WTRU may be in cell x, the WTRU may monitor the triggering conditions for cell b and c, and may not monitor the triggering conditions for cell a. For example, as the WTRU may be in cell b, the WTRU may monitor the conditions for the cells c and a and may not monitor the triggering conditions for cell x, and so on.
[0172] In one example, the dependency may be bidirectional (e.g., if switching from a to b may be allowed, then b to a may be (e.g., also) allowed).
[0173] In one example, the dependency may be unidirectional (e.g., switching from a to b may be allowed, switching from b to a may not be allowed).
[0174] In one example, the dependency between the LTM configuration may be configured within the LTM configuration of a (e.g., each) target cell. For example, an information element may be included in an LTM candidate configuration that may indicate a list of candidate target cells from the (e.g., given) candidate cell. In another example, an information element may be included in an LTM candidate configuration that may indicate a list of LTM cells that may not be candidate target cells from the (e.g., given) candidate cell.
[0175] In one example, the dependency between the LTM target cells may be configured outside the LTM configuration of a (e.g., each) target. For example, the WTRU may be configured with a table / mapping that may associate source cells with one or more target cells.
[0176] In one example, the triggering conditions (e.g., thresholds) for executing a conditional LTM towards a (e.g., given) target cell may be the same for multiple (e.g., all) source cells.
[0177] In one example, the triggering conditions for executing a conditional LTM towards a (e.g., given) target cell may depend on the source cell. For example, a WTRU may be configured to use a first A3 -like threshold (first threshold) for conditional LTM to cell A from source cell X, and to use another threshold (second threshold) for conditional LTM to cell A from source cell Y.
[0178] In one example, the same triggering condition (e.g., threshold) may be specified (e.g., indicated) for multiple target cells. For example, the WTRU may be configured with one A3- like threshold to be used for (e.g., all) LTM target cells from any LTM source cell. In another example, the configuration may be for a group of cells (e.g., one threshold for a subset of the LTM candidate cells, another threshold for the rest of the LTM candidate cells).
[0179] In one example, the triggering conditions according to any of the example described herein may be based on layer three (L3) measurement events (e.g., conditional A3 like events).
[0180] In one example, the triggering conditions according to any of the example described herein may be based on LI measurement events (e.g., conditional A3 like events, evaluated with LI measurements as input and not evaluated with L3 measurements as used in legacy radio resource management (RRM)).
[0181] Counting of Cell Switching
[0182] In one example, the WTRU may be configured to keep account of the number of cell switching after the reception of the subsequent conditional LTM configuration. For example, the WTRU may initialize the counter value to zero upon the reception of the LTMconfiguration, and after (e.g., each time) a conditional LTM cell switching may be performed, the WTRU may increment the counter value by one.
[0183] In one example, the WTRU may be configured to keep multiple counters depending on whether the conditional LTM triggering has resulted in a security key update or not. Several examples are described herein.
[0184] In a first example, one counter (e.g., may be maintained) for conditional LTM that may require (e.g., be associated with) security key updates, and another counter (e.g., may be maintained) for conditional LTM that may not require (e.g., be associated with) any security update.
[0185] In a second example, different counters may be maintained for (e.g., associated with) different target cells (e.g., a counter value may indicate being the nth switching to the corresponding target cell).
[0186] In a third example, different counters may be maintained for (e.g., associated with) different source cells (e.g., a counter value may indicate being the nth switching out of the corresponding source cell).
[0187] In a fourth example, counters may correspond to (may be maintained for) a sourcetarget pair (e.g., a counter value may indicate being the nth switching from the source cell to the target cell).
[0188] In one example, (e.g., only unique, different) cell switching may be counted (e.g., if a WTRU perform cell switching from A->B->C->A->B, the cell switching counter may be set to be three and not four, based on the first and last switching involving the same source and target cell (A->B)).
[0189] Path Information Maintenance
[0190] In one example, the subsequent conditional LTM configurations may be associated with path information, where a path may comprise a sequence of cell switching (e.g., an ordered list of cells). For example, the subsequent LTM may comprise three cells, A, B and C, and the WTRU may be in cell A when the subsequent conditional LTM configurations may be received. In this example, (e.g., possible) paths may include:1. A -> B -> C2. A-> B -> C-> A3. A-> B -> C-> B4. A-> B -> C-> B->A5. A-> C -> B6. Etc.
[0191] In an example, a (e.g., each) path may be associated with a path identity / identifier (e.g., an integer value).
[0192] The WTRU may be configured to monitor on which path / trajectory the WTRU may currently be on. In some examples, the paths may be overlapping (e.g., paths 1, 2, 3 and 4 above). In that case, the WTRU may be configured to consider (e.g., determine) the current path to be one of the following (among the overlapping paths): (i) the path with the lowest ID, (ii) the path with the highest ID, (iii) the path with the longest number of hops, etc.
[0193] For example, the path with the lowest ID may be configured to be the path during overlapping paths. In the example of overlapping path described above, at the beginning, the WTRU may determine to be in path 1, and may determine to be in path 2 once it may have performed the switching from C to A.
[0194] New Key Derivation Function
[0195] In legacy NR, the key derivation function (KDF) to generate the KgNB to be used at a target gNB takes the following input parameters (as described in 3GPP TS 33.501, section A.l l):FC = 0x70P0 = PCI (target physical cell id)L0 = length of PCI (i.e. 0x00 0x02)Pl = ARFCN-DL (the absolute frequency of SSB of the target PCell as specified in clause 13.3 of 3GPP TS 38.300)LI = length of ARFCN-DL (i.e. 0x00 0x03)Input Key (the 256-bit NH when the index NCC in the handover increases, otherwise the current 256-bit K§NB (that was being used at the source gNB).
[0196] In one example, the WTRU may use a KDF that may take the source cell information as input (e.g., PCI of the source cell, ARFCN-DL of the source cell, etc.,). In an example, the LTM candidate configuration ID (e.g., the ID used in the LTM configuration to identify a (e.g., given) LTM target cell) may (e.g., also) be used as an input to the KDF.
[0197] In one example, the WTRU may be configured to consider the current number of cell switching as input to the KDF (as calculated according to any embodiment described herein).
[0198] In one example, the WTRU may be configured to consider the current path ID as an input to the KDF (as maintained according to any embodiment described herein).
[0199] In one example, the WTRU may be configured to consider a combination of the above inputs (e.g., all together).
[0200] For example, the WTRU may have been configured with the following two paths: (i) A-> B -> C-> B, and (ii) A-> B -> C-> A.
[0201] Upon performing the first conditional LTM towards cell B, the WTRU may perform the following: K§NB at cell B = KDF (K§NB at cell A, path ID=1, PCI of cell A, frequency of cell A, PCI of cell B, frequency of Cell B, number of switching =1).
[0202] Upon performing the second conditional LTM towards cell C, the WTRU may perform the following: K§NB at cell C = KDF (K§NB at cell B, path ID=1, PCI of cell B, frequency of cellB, PCI of cell C, frequency of Cell C, number of switching =2).
[0203] Upon performing the third conditional LTM towards cell B, the WTRU may perform the following: K§NB at cell B = KDF (K§NB at cell C, path ID=1, PCI of cell C, frequency of cellC, PCI of cell B, frequency of Cell B, number of switching =3).If the third conditional LTM was towards cell A instead of cell B (e.g., path now becoming path =2), the WTRU may perform the following: KgNB at cell A = KDF (KgNB at cell C, path ID=2, PCI of cell C, frequency of cell C, PCI of cell A, frequency of Cell A, number of switching =3).
[0204] In one example, the WTRU may use a KDF that may take a counter value associated with the cell switching count and that may be different from the cell switching count. For example, the WTRU may have been pre-configured with a mapping (e.g., association) of cell switching values to (e.g., with) the counter value(s) (e.g., cell switching 1 is mapped to counter value of 5, cell switching 2 is mapped to counter value of 1, etc.,). If the WTRU is configured with such a mapping (e.g., association) between the actual cell switching count and the counter value to be used for the key derivation function, this counter value may be the one the WTRU may send (e.g., indicate) in the information related to key derivation to the target cell, (and not the actual cell switching count).
[0205] WTRU Provided with Multiple Keys for Multiple Subsequent Cell Switching
[0206] In (e.g., legacy) NR, the WTRU may derive the KgNB to be used at the target using the current KgNB and the information received in the HO command (e.g., the masterKeyUpdate information element (IE) included in the RRC reconfiguration message).
[0207] In one example, the WTRU may be provided with a list of KgNBs that it may use for after a (e.g., each possible) conditional cell switching. The association between the keys may depend (e.g., be based on) one or more of (i) the source cell, (ii) the target cell, (iii) the cell switching count, and (iv) the current path (and / or the path after the ongoing cell switching).
[0208] For example, considering the source cell where the WTRU may receive the subsequent conditional LTM configuration may be cell A, and considering cells B, C, and D as being part of the subsequent conditional LTM candidate list, if three cell switching may be to be coveredin the subsequent conditional LTM configuration, the (e.g., possible) trajectories / paths for the WTRU may be:- A -> B o -> C■ -> D■ -> B■ -> A o -> D■ ->A■ ->B■ ->C o ->A■ ->B■ ->C■ ->D- A-> C o -> B■ -> A■ -> C■ -> D o -> D■ ->A■ ->B■ ->C o ->A■ ->B■ ->C■ ->D- A-> D o -> B■ -> A■ -> C■ -> D o -> C■ ->A■ ->B■ ->D o ->A■ ->B■ ->C■ ->D
[0209] The association between the keys and the other information such as cell switch count and path information can be captured in a tabular form as described herein in Table 1 :Table 1 : Associations between keys and corresponding information
[0210] Embodiments described herein are not limited to the path ID numbering (e.g., 1.1., 1.2, 1.3) illustrated in Table 1. Other types of number, identifying scheme may be applicable to embodiments described herein.
[0211] Upon determining that the conditions for a subsequent conditional LTM may be fulfilled, the WTRU may set the KgNB as the key corresponding to the current path and current cell switch count.
[0212] HO Complete Message and Related Information
[0213] A HO complete message and related information is described herein.
[0214] In one example, the WTRU may provide information related to the key derivation the WTRU may have employed (e.g., used) to the target cell upon / after executing the conditional LTM. This may be used by the target cell / network element to identify / determine the security keys to use for this WTRU and to be able to decode and integrity verify the data from the WTRU (including the first message, the reconfiguration complete (e.g.,RRCReconfigurationComplete) message, that the WTRU may send upon the execution of the conditional LTM).
[0215] In one example, the information may indicate the current number of cell switching. In another example, this information may be related to the number of cell switching towards this cell (e.g., indicating third time switching to this cell), or it may be related to the cell switching involving the source and the target (e.g., indicating second time switching from current source cell to current target cell), etc.
[0216] In one example, the information may indicate the path ID.
[0217] In one example, the information may include the (e.g., complete, overall) path information (e.g., any of the trajectory the WTRU may have taken since the reception of the subsequent LTM configuration, the last n hops the WTRU may have taken, where n may be referred to a configurable integer value, etc.).
[0218] In one example, the information may indicate the identity / identifier of the source cell (e.g., any of PCI, LTM candidate configuration ID, etc.).
[0219] In one example, the information may indicate a combination of any of the above.
[0220] In one example, the WTRU may send the information with a complete message such as e.g., the RRCReconfigurationComplete message. Any other complete message for sending this information at any of RRC or lower layers, e.g., MAC CE may be applicable to embodiments described herein.
[0221] In one example, the WTRU may send the information in a separate (e.g., RRC) message that may not be encrypted or / and integrity protected, followed by the (e.g., RRC) complete message that may be encrypted, and integrity protected.
[0222] In one example, the complete message may be sent together with the information related to the key derivation by multiplexing the two in the same transport block. For example, the example information related to the key derivation may be included in a MAC CE (e.g., any of a new MAC CE, an extension of the cell radio network temporary identifier (C-RNTI) MAC CE that may be multiplexed with the complete message in (e.g., legacy) NR for identifying the WTRU at the target, etc.).
[0223] In one example, the WTRU may have been provided with multiple C-RNTIs for a (e.g., given) target LTM configuration, where a (e.g., each) C-RNTI may correspond to a different path and / or number of switching. For example, in a path configuration such as e.g., A->B->C->B->D->B, the LTM configuration regarding cell B may include three C-RNTI values, the first to be used during the first switching from cell A, the second one to be used during the second switching from cell C, and the third one to be used during the third switchingfrom cell D, and so on. This may allow the WTRU to employ the (e.g., legacy, existing) mechanism of multiplexing the C-RNTI MAC CE with the complete message (e.g., the target cell may be implicitly informed about what security keys to use, e.g., during the subsequent conditional preparation phase, communication can be made (e.g., towards the target cell) regarding the association of the C-RNTI value with a security key / context).
[0224] Network Aspects
[0225] In one example, the cells involved in the subsequent conditional LTM, during the preparation phase (e.g., before the configuration (e.g., information) may be sent to the WTRU), may communicate the (e.g., required) security keys (e.g., KgNBs to be used) for the different paths (e.g., each possible path) and / or the switching count between each other. For example, the WTRU may provide the key derivation related information (according to any embodiment described herein) to the target cell, which may be able to identify (e.g., determine) the K§NB to be used for that WTRU (e.g., and derive the CP and UP encryption and integrity protection keys).
[0226] In one example, the target cell may be able to derive the K§NB based on the key derivation related information provided by the WTRU according to any embodiment described herein.
[0227] In one example, after a (e.g., each) subsequent conditional LTM may be complete (e.g., based on the complete message (e.g., RRCReconfigurationComplete message) being received at the network), the target cell, which may be the current source cell, may calculate the K§NB to be used at different (e.g., each possible) target cell for the next cell switching and may send it to them (e.g., the target cells may use that key if the WTRU ends up switching to them). For example, cells A, B, C and D may be the cells involved in the subsequent conditional LTM, and the WTRU may have been in cell A in the beginning (e.g., when the WTRU may get configured for subsequent conditional LTM). Initially, cells B, C and D may be provided with KgNbs that cell A may have calculated. If the WTRU executes conditional LTM towards cell B, then cell B may calculate the new keys for cells A, C and D and may send it to them, and so on. The KDF used for this derivation may be the same as the one used by the WTRU as described herein (e.g., taking any of the path ID, number of switching since reception of subsequent conditional LTM, source cell information etc.).
[0228] In an example, the actions on the network side may be one or more of the following examples of actions (to enable any of the embodiments described herein for the WTRU, such that the keys used by the WTRU, and the target cell / network element may be in sync).
[0229] In a first example of network action, after each cell switching, the network may update the (e.g., possible, potential, candidate) target cell(s) about the cell switching that occurred, such that they may be ready for the WTRU with the appropriate key.
[0230] In a second example of network action, the target cells may perform the key derivation themselves based on the input provided by the WTRU with the HO complete message. This may represent a change from legacy operation where target cells may get the key from the source and may not be deriving it. In an example, the key derivation may be performed in one go (e.g., the target cell may get the additional input information from the WTRU and may perform the key derivation in one step). In another example, the target cell may perform multiple key derivations to be in sync with the WTRU. For example, considering the WTRU path to be A->B->C->D, the target D may perform the key derivation using count value =3, or may perform three consecutive key derivations to account for (e.g., each of) the cell switching before WTRU may arrive to cell D.
[0231] In a second example of network action, the target cells may get a multitude of keys for the different (e.g., each possible) cell switching / path. This may be aligned with legacy operation, where the target cell may get the keys from the source cell.
[0232] Interworking with Network Triggered Cell Switching or Handover
[0233] In one example, a WTRU may be configured with subsequent conditional LTM configuration and may be monitoring the triggering conditions for the target cells. The WTRU may be configured to perform one or more of the following examples of operation upon a reception of an indication from the network to perform a cell switching / HO (e.g., any of reception of an LTM MAC CE, reception of an RRC reconfiguration indicating a HO to a target cell, etc.).
[0234] In a first example of operation, the WTRU may release the subsequent conditional LTM configuration.
[0235] In a second example of operation, the WTRU may deactivate the subsequent conditional LTM configuration (e.g., keeping the configuration stored, and stopping monitoring the triggering conditions for any of the target cells).
[0236] In a third example of operation, the WTRU may keep monitoring the triggering conditions for the target cells, and upon the fulfillment of the conditions, the WTRU may send a measurement report and may not execute the conditional LTM.
[0237] In a fourth example of operation, the WTRU may not change behavior (e.g., WTRU behavior may remain the same as before the reception of the network triggered cell switching or HO).
[0238] In one example, the determination of one or more of the above operations may depend on whether the network triggered cell switching / HO was to one of the LTM target cells. For example, the WTRU may be configured to apply one of the above-described behaviors (e.g., release the configuration, stop monitoring the triggering conditions, trigger measurement reports and no execution of the cell switching upon the fulfillment of the trigger conditions, etc.,) if the network triggered switching / HO was towards a cell that may not be one of the LTM target cells. If the switching was towards one of the target cells, the WTRU may be configured to continue with (e.g., keep) the subsequent conditional LTM operation as if the switching was triggered conditionally (e.g., update the cell switching counter values, update path information, etc.,), and may keep monitoring the triggering conditions for the target cells. In another example, the behavior may be the other way around (e.g., release the conditional LTM configuration if the network is triggering a cell switching / HO to one of the LTM target cells and keep the configuration if the cell switching was not to one of the target cells). A combination of the above-described behaviors may be applicable to embodiments described herein (e.g., if the network triggered cell switching was towards an LTM candidate cell, the WTRU may keep monitoring the triggering conditions for the LTM target cells, send measurement reports and not execute the LTM; and if the cell switching was to a cell that may not be an LTM candidate cell, the WTRU may release the subsequent conditional LTM configuration, etc.).
[0239] In various embodiments, the differentiation may not (e.g., only) based on whether the network triggered cell switching was towards a cell outside the LTM candidate cell and may be based on whether the network triggered cell switching included a security update. For example, if the WTRU was in cell X and the network triggered cell switching was towards cell Y belonging to the same gNB as cell X, switching between the two cells may not involve (e.g., require) security update. The WTRU may be configured to continue (e.g., keep) the conditional LTM monitoring as before if the network triggered cell switching / HO did not result in any security update.
[0240] In one example, the WTRU may be configured to continue the cell switching counter maintenance according to any of the solutions above even after a network triggered cell switching or HO.
[0241] In one example, the WTRU may be configured to continue (e.g., keep) maintaining the cell switching counter according to any embodiments described herein (e.g., even) after a network triggered cell switching / HO if the cell switching was towards one of the LTM target cells that the WTRU may be monitoring.
[0242] In one example, the WTRU may be configured to reset the counter value to zero after a network triggered cell switching / HO.
[0243] In one example, the WTRU may reset the counter value to zero if the network triggered cell switching / HO was not to one of the LTM candidate cells that the WTRU may be monitoring for conditional LTM.
[0244] In one example, the WTRU may reset the counter value to zero if the network triggered cell switching / HO was to one of the LTM candidate cells that the WTRU may be monitoring for conditional LTM.
[0245] Actions Related to Reaching the End of a Configured Path
[0246] Actions (e.g., operations) related to reaching the end of a configured path are described herein.
[0247] In one example, a WTRU may be configured with subsequent conditional LTM configuration and may monitor the triggering conditions for the target cells. The WTRU may be configured to perform one or more of the following operations upon performing the last cell switching (e.g., of a path) indicated / configured in the subsequent conditional LTM configuration:
[0248] In a first example of operation, the WTRU may release the subsequent conditional LTM configuration.
[0249] In a second example of operation, the WTRU may deactivate the subsequent conditional LTM configuration (e.g., the WTRU may keep the configuration stored, and stop monitoring the triggering conditions for any of the target cells).
[0250] In a third example of operation, the WTRU may keep monitoring the triggering conditions for the target cells, and upon the fulfillment of the conditions, the WTRU may send a measurement report and may not execute the conditional LTM.
[0251] In a fourth example of operation, the WTRU may not change behavior (e.g., WTRU behavior may remain the same as before the reception of the network triggered cell switching / HO).
[0252] In an example, the WTRU may release the subsequent LTM configuration associated with the current path that may have been exhausted and may keep the configuration related to the other paths (e.g., the WTRU may not change behavior for these paths, keep monitoring the conditions, trigger measurement report and not execute the LTM, etc.).
[0253] In one example, the WTRU may be configured to apply any of the behavior that may be associated to reaching the end of a path based on the number of cell switching satisfying a condition (e.g., becoming larger than a (e.g., configured) threshold).
[0254] Other Aspects
[0255] In one example, the WTRU may be configured (e.g., to operate) the key derivation based on the current KgNB, and any security key update information provided in the reconfiguration message associated with the LTM target cell. The WTRU may maintain cell switching counter and path information, and may inform the target cell about it upon conditional LTM execution, based on any embodiment described herein (e.g., multiplex a MAC CE with the reconfiguration complete message that may include one or more of cell switching counter, source cell information, path ID, and detailed path information, etc.).
[0256] In one example, the WTRU may be configured with a threshold corresponding to the (e.g., maximum, upper bound) number of subsequent cell switching the WTRU may perform in total e.g., without requiring RRC reconfiguration. If multiple counters were being monitored according to any embodiment described herein, a different threshold may be associated with a (e.g., each) counter. If the number of cell switching is above the threshold, the WTRU may be configured to stop monitoring the triggering conditions for any of the target cells in the subsequent conditional LTM configuration and / or release the subsequent conditional LTM configurations (e.g., altogether). In another example, the WTRU may be configured to keep the conditional LTM configurations, trigger a measurement report upon the fulfillment of the triggering conditions of the conditional LTM, and not execute the LTM.
[0257] In one example, the WTRU may be configured to reset the counter to zero upon a conditional LTM being triggered that may bring the WTRU back to the original cell where the subsequent LTM may have been received. The WTRU may be further configured to stop monitoring the triggering conditions for any of the target cells and / or release the subsequent conditional LTM configurations (e.g., altogether).
[0258] In one example, the WTRU may perform the key derivation based on the current KgNB, and any security key update information provided in the reconfiguration message associated with the LTM target cell. The WTRU may inform the target cell with some information that may enable the target cell with the key derivation or key fetching. For example, the transmitted information may include any information according to any embodiment described herein. For example, the WTRU may include the switching count, the path index / id, the actual path taken so far, etc., along with the HO complete message, as described herein.
[0259] In one example, the WTRU may be providing some of the information that the WTRU may have used in the masterKeyUpdate (e.g., such as NCC) towards the target cell (e.g., along with the HO complete). The information may include the exact value (e.g., the exact NCC) or a translated (e.g., adapted) version of this. For example, the WTRU may have been (e.g.,previously) configured on how to map (e.g., associate) the actual NCC it may be configured to use to the NCC value it may be signaling (e.g., indicating) to the target cell. For example, the WTRU may be configured to indicate an NCC value of one if the actual value applied may have been five, a NCC value of two if the actual value applied may have been eight, and so on. The target cells may be provided with this mapping (e.g., association) information, such that they may be able to remap the signaled (e.g., indicated) value from the WTRU to the actual value to be used for key derivation (or the key lookup), such that the keys used at the WTRU, and the target cell may match.
[0260] In one example, the WTRU may be configured with multiple masterKeyUpdate configurations associating target cells with source cells (e.g., in the LTM configuration of the target cells, as a separate mapping (e.g., association) table between the source and target cells, etc.,). For example, a (e.g., given) target cell X may have two masterKeyUpdate configurations, one masterKeyUpdate configuration to be applied if the source cell was cell A or cell B, and another masterKeyUpdate configuration to apply if the source cell was cell C or cell D, etc. For example, the first masterKeyUpdate may be associated with a horizontal HO while the second one may be associated with a vertical handover, and so on. If the WTRU can ping pong (e.g., alternate) between cells without (e.g., the need for) reconfiguration, there may be more than one pair of masterKeyUpdate configurations for a (e.g., given) source-target pair.
[0261] FIG. 7 is a diagram illustrating an example method 700 for security handling during subsequent conditional handovers, implemented in a WTRU. The WTRU may include circuitry including any of transmitter, a receiver, a processor, and memory. The circuitry may be configured to carry out the method 700. As shown at 710, the method 700 may include receiving path information related to a conditional handover. In various embodiments, the path information may indicate a plurality of paths associated with a plurality of lists of candidate cells. In various embodiments, a path (e.g., each path) of the plurality of paths may be associated with one list of the plurality of lists of candidate cells. As shown at 720, the method 700 may include determining that a condition for performing the conditional handover to a target cell may be satisfied. In various embodiments, the target cell may be a candidate cell of a list of the plurality of lists of candidate cells. As shown at 730, the method 700 may include performing the conditional handover to the target cell based on the condition being satisfied. In various embodiment, performing the conditional handover may include (i) determining a second key based on the path information and any of a first key, a source cell identifier and a target cell identifier, (ii) updating a security context to be used with the target cell based on the second key, and (iii) sending information to the target cell to be used for deriving the second key.
[0262] In various embodiments, determining the second key may comprise deriving the second key as a function of the path information and any of the first key, the source cell identifier and the target cell identifier.
[0263] In various embodiments, receiving path information may comprise receiving configuration information including the path information. In various embodiments, the configuration information may indicate a plurality of keys. In various embodiments, a (e.g., each) key of the plurality of keys may be associated with any of a source cell, a target cell, a cell switching count and a path.
[0264] In various embodiments, determining the second key may comprise selecting the second key from the plurality of keys based on of any of the source cell identifier, the target cell identifier and the path information.
[0265] In various embodiments, the path information may indicate the plurality of lists of candidate cells.
[0266] In various embodiments, a list (e.g., each list) of the plurality of lists of candidate cells may be an ordered list of candidate cells.
[0267] In various embodiments, the ordered list of candidate cells may represent a sequence of cell switching between the candidate cells of the ordered list.
[0268] In various embodiments, determining the second key may comprise determining the second key based on a cell switching count.
[0269] In various embodiments, the cell switching count may indicate a number of cell switching / handovers that may have occurred since the path information related to the conditional handover may have been received.
[0270] In various embodiments, the path information may indicate a path identifier for a (e.g., each) path of the plurality of paths.
[0271] In various embodiments, determining the second key may comprise determining the second key based on the path identifier.
[0272] In various embodiments, the information to be used for deriving the second key may indicate the path identifier.
[0273] In various embodiments, the information to be used for deriving the second key may indicate the source cell identifier.
[0274] In various embodiments, performing the conditional handover may comprise deriving an SRB encryption key and an SRB integrity key from the second key.
[0275] In various embodiments, performing the conditional handover may comprise sending a reconfiguration complete message to the target cell encrypted with the SRB encryption key and integrity protected with the SRB integrity key.
[0276] In various embodiments, sending the information to the target cell may comprise sending the information to the target cell in a message before (e.g., sending) the reconfiguration complete message.
[0277] In various embodiments, the message may not be encrypted and may not be integrity protected.
[0278] In various embodiments, sending the information to the target cell may comprise multiplexing the information with the reconfiguration complete message in a same transport block.
[0279] FIG. 8 is a diagram illustrating an example method 800 for security handling during subsequent conditional handovers, implemented in a network element. The network element may include circuitry including any of transmitter, a receiver, a processor, and memory. The circuitry may be configured to carry out the method 800. As shown at 810, the method 800 may include receiving, from another network element, configuration information related to one or more subsequent conditional handovers associated with at least one WTRU. In various embodiments, the configuration information may include path information for deriving security keys to be used after a handover from one cell to another cell within a group of candidate cells. In various embodiments, the configuration (e.g., path) information may indicate a plurality of paths associated with a plurality of lists of candidate cells. In various embodiments, a path (e.g., each path) of the plurality of paths may be associated with one list of the plurality of lists of candidate cells. As shown at 820, the method 800 may include receiving from the at least one WTRU, information associated with key derivation during a conditional handover of the at least one WTRU. As shown at 830, the method 800 may include deriving a key based on (i) the configuration information received from the other network element and (ii) the information received from the at least one WTRU. As shown at 840, the method 800 may include updating a security context to be used with the at least one WTRU based on the derived key. As shown at 850, the method 800 may include using the security context to serve the at least one WTRU after completion of the conditional handover.
[0280] In various embodiments, the network element may be a target base station of the conditional handover of the at least one WTRU.
[0281] FIG. 9 is a diagram illustrating an example method 900 for security handling during subsequent conditional handovers, implemented in a WTRU. The WTRU may include circuitryincluding any of transmitter, a receiver, a processor, and memory. The circuitry may be configured to carry out the method 900. As shown at 910, the method 900 may include receiving configuration information related to performing one or more subsequent conditional handovers between cells within a group of candidate cells. In various embodiments, the configuration information may include path information for deriving security keys to be used after a handover from one cell to another cell within the group of candidate cells. As shown at 920, the method 900 may include performing a conditional handover from a source cell to a target cell within the group of candidate cells. In various embodiments, the WTRU may have operated in the source cell using a first key and a security context associated with the first key. In various embodiments, performing the conditional handover may comprise (i) determining a second key based on a source cell identifier and any of the first key, a cell switch count, a target cell identifier and the path information, (ii) updating the security context to be used with the target cell based on the second key, and (iii) sending information to the target cell to be used for deriving the second key. In various embodiments, the source cell identifier may identify the source cell, and the target cell identifier may identify the target cell.
[0282] In various embodiments, determining the second key may comprise deriving the second key as a function of the source cell identifier and any of the path information, the first key, the cell switch count, and the target cell identifier.
[0283] In various embodiments, the configuration information may indicate a plurality of keys. In various embodiments, a (e.g., each) key of the plurality of keys may be associated with any of the source cell, the target cell, the cell switching count and a path.
[0284] In various embodiments, determining the second key may comprise selecting the second key from the plurality of keys based on any of the source cell identifier, the target cell identifier and the path information.
[0285] In various embodiments, the path information may indicate a plurality of paths. In various embodiments, a (e.g., each) path of the plurality of paths may be associated with a list of candidate cells.
[0286] In various embodiments, the list of candidate cells may be an ordered list of candidate cells.
[0287] In various embodiments, the ordered list of candidate cells may represent a sequence of cell switching between the candidate cells of the ordered list.
[0288] In various embodiments, the cell switching count may indicate a number of cell switching / handovers that may have occurred since the configuration information related to the conditional handover may have been received.
[0289] In various embodiments, the configuration information may indicate a path identifier for a (e.g., each) path of the plurality of paths.
[0290] In various embodiments, determining the second key may comprise determining the second key based on the path identifier.
[0291] In various embodiments, the information to be used for deriving the second key may indicate the path identifier.
[0292] In various embodiments, the information to be used for deriving the second key may indicate the source cell identifier.
[0293] In various embodiments, performing the conditional handover may comprise deriving an SRB encryption key and an SRB integrity key from the second key.
[0294] In various embodiments, performing the conditional handover may comprise sending a reconfiguration complete message to the target cell encrypted with the SRB encryption key and integrity protected with the SRB integrity key.
[0295] In various embodiments, sending the information to the target cell may comprise sending the information to the target cell in a message before (e.g., sending) the reconfiguration complete message.
[0296] In various embodiments, the message may not be encrypted and may not be integrity protected.
[0297] In various embodiments, sending the information to the target cell may comprise multiplexing the information with the reconfiguration complete message in a same transport block.
[0298] Any feature / characteristic / variant described in relation to (e.g., following the description of) the method 700 implemented in WTRU and illustrated at FIG. 7 may also be applicable to the method 900 implemented in a WTRU and illustrated at FIG. 9, and vice versa.
[0299] Any feature / characteristic / variant described in relation to (e.g., following the description of) any of the method 700 and the method 900 implemented in WTRU and illustrated at FIG. 7 and FIG. 9 may also be applicable to the method 800 implemented in network element and illustrated at FIG. 8, and vice versa.
[0300] While not explicitly described, embodiments described herein may be employed in any combination or sub-combination. For example, the present principles are not limited to the described variants, and any arrangement of variants and embodiments can be used.
[0301] Besides, any characteristic, variant or embodiment described for a method is compatible with an apparatus device comprising means for processing the disclosed method, with a device comprising circuitry, including any of a transmitter, a receiver, a processor, anda memory, the circuitry being operable (e.g., configured) to process the disclosed method, with a computer program product comprising program code instructions and with a non-transitory computer-readable storage medium storing program instructions.
[0302] Although features and elements are provided above in particular combinations, one of ordinary skill in the art will appreciate that each feature or element can be used alone or in any combination with the other features and elements. The present disclosure is not to be limited in terms of the particular embodiments described in this application, which are intended as illustrations of various aspects. Many modifications and variations may be made without departing from its spirit and scope, as will be apparent to those skilled in the art. No element, act, or instruction used in the description of the present application should be construed as critical or essential to the invention unless explicitly provided as such. Functionally equivalent methods and apparatuses within the scope of the disclosure, in addition to those enumerated herein, will be apparent to those skilled in the art from the foregoing descriptions. Such modifications and variations are intended to fall within the scope of the appended claims. The present disclosure is to be limited only by the terms of the appended claims, along with the full scope of equivalents to which such claims are entitled. It is to be understood that this disclosure is not limited to particular methods or systems.
[0303] The foregoing embodiments are discussed, for simplicity, with regard to the terminology and structure of infrared capable devices, i.e., infrared emitters and receivers. However, the embodiments discussed are not limited to these systems but may be applied to other systems that use other forms of electromagnetic waves or non-electromagnetic waves such as acoustic waves.
[0304] It is also to be understood that the terminology used herein is for the purpose of describing particular embodiments only, and is not intended to be limiting. As used herein, the term "video" or the term "imagery" may mean any of a snapshot, single image and / or multiple images displayed over a time basis. As another example, when referred to herein, the terms "user equipment" and its abbreviation "UE", the term "remote" and / or the terms "head mounted display" or its abbreviation "HMD" may mean or include (i) a wireless transmit and / or receive unit (WTRU); (ii) any of a number of embodiments of a WTRU; (iii) a wireless-capable and / or wired-capable (e.g., tetherable) device configured with, inter alia, some or all structures and functionality of a WTRU; (iii) a wireless-capable and / or wired-capable device configured with less than all structures and functionality of a WTRU; or (iv) the like. Details of an example WTRU, which may be representative of any WTRU recited herein, are provided herein with respect to FIGs. 1 A-1D. As another example, various disclosed embodiments herein supra andinfra are described as utilizing a head mounted display. Those skilled in the art will recognize that a device other than the head mounted display may be utilized and some or all of the disclosure and various disclosed embodiments can be modified accordingly without undue experimentation. Examples of such other device may include a drone or other device configured to stream information for providing the adapted reality experience.
[0305] In addition, the methods provided herein may be implemented in a computer program, software, or firmware incorporated in a computer-readable medium for execution by a computer or processor. Examples of computer-readable media include electronic signals (transmitted over wired or wireless connections) and computer-readable storage media. Examples of computer- readable storage media include, but are not limited to, a read only memory (ROM), a random access memory (RAM), a register, cache memory, semiconductor memory devices, magnetic media such as internal hard disks and removable disks, magneto-optical media, and optical media such as CD-ROM disks, and digital versatile disks (DVDs). A processor in association with software may be used to implement a radio frequency transceiver for use in a WTRU, UE, terminal, base station, RNC, or any host computer.
[0306] Variations of the method, apparatus and system provided above are possible without departing from the scope of the invention. In view of the wide variety of embodiments that can be applied, it should be understood that the illustrated embodiments are examples only, and should not be taken as limiting the scope of the following claims. For instance, the embodiments provided herein include handheld devices, which may include or be utilized with any appropriate voltage source, such as a battery and the like, providing any appropriate voltage.
[0307] Moreover, in the embodiments provided above, processing platforms, computing systems, controllers, and other devices that include processors are noted. These devices may include at least one Central Processing Unit ("CPU") and memory. In accordance with the practices of persons skilled in the art of computer programming, reference to acts and symbolic representations of operations or instructions may be performed by the various CPUs and memories. Such acts and operations or instructions may be referred to as being "executed," "computer executed" or "CPU executed."
[0308] One of ordinary skill in the art will appreciate that the acts and symbolically represented operations or instructions include the manipulation of electrical signals by the CPU. An electrical system represents data bits that can cause a resulting transformation or reduction of the electrical signals and the maintenance of data bits at memory locations in a memory system to thereby reconfigure or otherwise alter the CPU's operation, as well as other processing of signals. The memory locations where data bits are maintained are physical locations thathave particular electrical, magnetic, optical, or organic properties corresponding to or representative of the data bits. It should be understood that the embodiments are not limited to the above-mentioned platforms or CPUs and that other platforms and CPUs may support the provided methods.
[0309] The data bits may also be maintained on a computer readable medium including magnetic disks, optical disks, and any other volatile (e.g., Random Access Memory (RAM)) or non-volatile (e.g., Read-Only Memory (ROM)) mass storage system readable by the CPU. The computer readable medium may include cooperating or interconnected computer readable medium, which exist exclusively on the processing system or are distributed among multiple interconnected processing systems that may be local or remote to the processing system. It should be understood that the embodiments are not limited to the above-mentioned memories and that other platforms and memories may support the provided methods.
[0310] In an illustrative embodiment, any of the operations, processes, etc. described herein may be implemented as computer-readable instructions stored on a computer-readable medium. The computer-readable instructions may be executed by a processor of a mobile unit, a network element, and / or any other computing device.
[0311] There is little distinction left between hardware and software implementations of aspects of systems. The use of hardware or software is generally (but not always, in that in certain contexts the choice between hardware and software may become significant) a design choice representing cost versus efficiency tradeoffs. There may be various vehicles by which processes and / or systems and / or other technologies described herein may be effected (e.g., hardware, software, and / or firmware), and the preferred vehicle may vary with the context in which the processes and / or systems and / or other technologies are deployed. For example, if an implementer determines that speed and accuracy are paramount, the implementer may opt for a mainly hardware and / or firmware vehicle. If flexibility is paramount, the implementer may opt for a mainly software implementation. Alternatively, the implementer may opt for some combination of hardware, software, and / or firmware.
[0312] The foregoing detailed description has set forth various embodiments of the devices and / or processes via the use of block diagrams, flowcharts, and / or examples. Insofar as such block diagrams, flowcharts, and / or examples include one or more functions and / or operations, it will be understood by those within the art that each function and / or operation within such block diagrams, flowcharts, or examples may be implemented, individually and / or collectively, by a wide range of hardware, software, firmware, or virtually any combination thereof. In an embodiment, several portions of the subject matter described herein may be implemented viaApplication Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), digital signal processors (DSPs), and / or other integrated formats. However, those skilled in the art will recognize that some aspects of the embodiments disclosed herein, in whole or in part, may be equivalently implemented in integrated circuits, as one or more computer programs running on one or more computers (e.g., as one or more programs running on one or more computer systems), as one or more programs running on one or more processors (e.g., as one or more programs running on one or more microprocessors), as firmware, or as virtually any combination thereof, and that designing the circuitry and / or writing the code for the software and or firmware would be well within the skill of one of skill in the art in light of this disclosure. In addition, those skilled in the art will appreciate that the mechanisms of the subject matter described herein may be distributed as a program product in a variety of forms, and that an illustrative embodiment of the subject matter described herein applies regardless of the particular type of signal bearing medium used to actually carry out the distribution. Examples of a signal bearing medium include, but are not limited to, the following: a recordable type medium such as a floppy disk, a hard disk drive, a CD, a DVD, a digital tape, a computer memory, etc., and a transmission type medium such as a digital and / or an analog communication medium (e.g., a fiber optic cable, a waveguide, a wired communications link, a wireless communication link, etc.).
[0313] Those skilled in the art will recognize that it is common within the art to describe devices and / or processes in the fashion set forth herein, and thereafter use engineering practices to integrate such described devices and / or processes into data processing systems. That is, at least a portion of the devices and / or processes described herein may be integrated into a data processing system via a reasonable amount of experimentation. Those having skill in the art will recognize that a typical data processing system may generally include one or more of a system unit housing, a video display device, a memory such as volatile and non-volatile memory, processors such as microprocessors and digital signal processors, computational entities such as operating systems, drivers, graphical user interfaces, and applications programs, one or more interaction devices, such as a touch pad or screen, and / or control systems including feedback loops and control motors (e.g., feedback for sensing position and / or velocity, control motors for moving and / or adjusting components and / or quantities). A typical data processing system may be implemented utilizing any suitable commercially available components, such as those typically found in data computing / communication and / or network computing / communication systems.
[0314] The herein described subject matter sometimes illustrates different components included within, or connected with, different other components. It is to be understood that such depicted architectures are merely examples, and that in fact many other architectures may be implemented which achieve the same functionality. In a conceptual sense, any arrangement of components to achieve the same functionality is effectively "associated" such that the desired functionality may be achieved. Hence, any two components herein combined to achieve a particular functionality may be seen as "associated with" each other such that the desired functionality is achieved, irrespective of architectures or intermedial components. Likewise, any two components so associated may also be viewed as being "operably connected", or "operably coupled", to each other to achieve the desired functionality, and any two components capable of being so associated may also be viewed as being "operably couplable" to each other to achieve the desired functionality. Specific examples of operably couplable include but are not limited to physically mateable and / or physically interacting components and / or wirelessly interactable and / or wirelessly interacting components and / or logically interacting and / or logically interactable components.
[0315] With respect to the use of substantially any plural and / or singular terms herein, those having skill in the art can translate from the plural to the singular and / or from the singular to the plural as is appropriate to the context and / or application. The various singular / plural permutations may be expressly set forth herein for sake of clarity.
[0316] It will be understood by those within the art that, in general, terms used herein, and especially in the appended claims (e.g., bodies of the appended claims) are generally intended as "open" terms (e.g., the term "including" should be interpreted as "including but not limited to," the term "having" should be interpreted as "having at least," the term "includes" should be interpreted as "includes but is not limited to," etc.). It will be further understood by those within the art that if a specific number of an introduced claim recitation is intended, such an intent will be explicitly recited in the claim, and in the absence of such recitation no such intent is present. For example, where only one item is intended, the term "single" or similar language may be used. As an aid to understanding, the following appended claims and / or the descriptions herein may include usage of the introductory phrases "at least one" and "one or more" to introduce claim recitations. However, the use of such phrases should not be construed to imply that the introduction of a claim recitation by the indefinite articles "a" or "an" limits any particular claim including such introduced claim recitation to embodiments including only one such recitation, even when the same claim includes the introductory phrases "one or more" or "at least one" and indefinite articles such as "a" or "an" (e.g., "a" and / or "an" should be interpreted to mean "atleast one" or "one or more"). The same holds true for the use of definite articles used to introduce claim recitations. In addition, even if a specific number of an introduced claim recitation is explicitly recited, those skilled in the art will recognize that such recitation should be interpreted to mean at least the recited number (e.g., the bare recitation of "two recitations," without other modifiers, means at least two recitations, or two or more recitations). Furthermore, in those instances where a convention analogous to "at least one of A, B, and C, etc." is used, in general such a construction is intended in the sense one having skill in the art would understand the convention (e.g., "a system having at least one of A, B, and C" would include but not be limited to systems that have A alone, B alone, C alone, A and B together, A and C together, B and C together, and / or A, B, and C together, etc.). In those instances where a convention analogous to "at least one of A, B, or C, etc." is used, in general such a construction is intended in the sense one having skill in the art would understand the convention (e.g., "a system having at least one of A, B, or C" would include but not be limited to systems that have A alone, B alone, C alone, A and B together, A and C together, B and C together, and / or A, B, and C together, etc.). It will be further understood by those within the art that virtually any disjunctive word and / or phrase presenting two or more alternative terms, whether in the description, claims, or drawings, should be understood to contemplate the possibilities of including one of the terms, either of the terms, or both terms. For example, the phrase "A or B" will be understood to include the possibilities of "A" or "B" or "A and B." Further, the terms "any of' followed by a listing of a plurality of items and / or a plurality of categories of items, as used herein, are intended to include "any of," "any combination of," "any multiple of," and / or "any combination of multiples of' the items and / or the categories of items, individually or in conjunction with other items and / or other categories of items. Moreover, as used herein, the term "set" is intended to include any number of items, including zero. Additionally, as used herein, the term "number" is intended to include any number, including zero. And the term "multiple", as used herein, is intended to be synonymous with "a plurality".
[0317] In addition, where features or aspects of the disclosure are described in terms of Markush groups, those skilled in the art will recognize that the disclosure is also thereby described in terms of any individual member or subgroup of members of the Markush group.
[0318] As will be understood by one skilled in the art, for any and all purposes, such as in terms of providing a written description, all ranges disclosed herein also encompass any and all possible subranges and combinations of subranges thereof. Any listed range can be easily recognized as sufficiently describing and enabling the same range being broken down into at least equal halves, thirds, quarters, fifths, tenths, etc. As a non-limiting example, each rangediscussed herein may be readily broken down into a lower third, middle third and upper third, etc. As will also be understood by one skilled in the art all language such as "up to," "at least," "greater than," "less than," and the like includes the number recited and refers to ranges which can be subsequently broken down into subranges as discussed above. Finally, as will be understood by one skilled in the art, a range includes each individual member. Thus, for example, a group having 1-3 cells refers to groups having 1, 2, or 3 cells. Similarly, a group having 1-5 cells refers to groups having 1, 2, 3, 4, or 5 cells, and so forth.
[0319] Moreover, the claims should not be read as limited to the provided order or elements unless stated to that effect. In addition, use of the terms "means for" in any claim is intended to invoke 35 U.S.C. §112, 6 or means-plus-function claim format, and any claim without the terms "means for" is not so intended.
Claims
CLAIMSWhat is claimed is:
1. A wireless transmit / receive unit (WTRU) comprising circuitry, including any of a transmitter, a receiver, a processor, and memory, configured to: receive configuration information related to performing one or more subsequent conditional handovers between cells within a group of candidate cells, wherein the configuration information includes path information for deriving security keys to be used after a handover from one cell to another cell within the group of candidate cells, and perform a conditional handover from a source cell to a target cell within the group of candidate cells, wherein the WTRU operated in the source cell using a first key and a security context associated with the first key, and wherein being configured to perform the conditional handover comprises being configured to: determine a second key based on a source cell identifier and any of the path information, the first key, a cell switch count and a target cell identifier, wherein the source cell identifier identifies the source cell, and wherein the target cell identifier identifies the target cell; update the security context to be used with the target cell based on the second key; and send information to the target cell to be used for deriving the second key.
2. The WTRU of claim 1, wherein being configured to determine the second key comprises being configured to derive the second key as a function of the source cell identifier and any of the path information, the first key, the cell switch count, and the target cell identifier.
3. The WTRU of claim 1, wherein the configuration information indicates a plurality of keys, and wherein each key of the plurality of keys is associated with any of the source cell, the target cell, the cell switching count and a path.
4. The WTRU of claim 3, wherein being configured to determine the second key comprises being configured to select the second key from the plurality of keys based on any of the source cell identifier, the target cell identifier and the path information.
5. The WTRU of any of claims 1 to 4, wherein the path information indicates a plurality of paths, and wherein each path of the plurality of paths is associated with a list of candidate cells.
6. The WTRU of claim 5, wherein the list of candidate cells is an ordered list of candidate cells.
7. The WTRU of any of claims 1 to 6, wherein the information to be used for deriving the second key indicates the cell switching count.
8. The WTRU of any of claims 1 to 7, wherein the cell switching count indicates a number of cell switching that occurred since the configuration information related to the conditional handover has been received.
9. The WTRU of any of claims 1 to 8, wherein the path information indicates a path identifier for each path of the plurality of paths.
10. The WTRU of claim 9, wherein being configured to determine the second key comprises being configured to determine the second key based on the path identifier.
11. The WTRU of claim 10, wherein the information to be used for deriving the second key indicates the path identifier.
12. The WTRU of any of claims 1 to 11, wherein the information to be used for deriving the second key indicates the source cell identifier.
13. The WTRU of any of claims 1 to 12, wherein being configured to perform the conditional handover comprises being configured to derive a signaling radio bearer (SRB) encryption key and an SRB integrity key from the second key.
14. The WTRU of claim 13, wherein being configured to perform the conditional handover comprises being configured to send a reconfiguration complete message to the target cell encrypted with the SRB encryption key and integrity protected with the SRB integrity key.
15. The WTRU of claim 14, wherein being configured to send the information to the target cell comprises being configured to send the information to the target cell in a message before the reconfiguration complete message.
16. The WTRU of claim 15, wherein the message is not encrypted and not integrity protected.
17. The WTRU of claim 14, wherein being configured to send the information to the target cell comprises being configured to multiplex the information with the reconfiguration complete message in a same transport block.
18. A method implemented in a wireless transmit / receive unit (WTRU), wherein the method comprises: receiving configuration information related to performing one or more subsequent conditional handovers between cells within a group of candidate cells, wherein the configuration information includes path information for deriving security keys to be used after a handover from one cell to another cell within the group of candidate cells; and performing a conditional handover from a source cell to a target cell within the group of candidate cells, wherein the WTRU operated in the source cell using a first key and a security context associated with the first key, and wherein performing the conditional handover comprises: determining a second key based on a source cell identifier and any of the first key, a cell switch count, a target cell identifier and the path information, wherein the source cell identifier identifies the source cell, and wherein the target cell identifier identifies the target cell; updating the security context to be used with the target cell based on the second key; and sending information to the target cell to be used for deriving the second key.
19. A network element comprising circuitry, including any of a transmitter, a receiver, a processor, and memory, configured to: receive, from another network element, configuration information related to performing one or more subsequent conditional handovers associated with at least one wireless transmit / receive unit (WTRU), wherein the configuration information includes path information for deriving security keys to be used after a handover from one cell to another cell within a group of candidate cells; receive, from the at least one WTRU, information associated with key derivation during a conditional handover of the at least one WTRU; derive a key based on (i) the configuration information received from the other network element and (ii) the information received from the at least one WTRU; update a security context to be used with the at least one WTRU based on the derived key; and use the security context to serve the at least one WTRU after completion of the conditional handover.
20. A method implemented in a network element, wherein the method comprises: receiving, from another network element, configuration information related to performing one or more subsequent conditional handovers associated with at least one wireless transmit / receive unit (WTRU), wherein the configuration information includes path information for deriving security keys to be used after a handover from one cell to another cell within a group of candidate cells; receiving, from the at least one WTRU, information associated with key derivation during a conditional handover of the at least one WTRU; deriving a key based on (i) the configuration information received from the other network element and (ii) the information received from the at least one WTRU; updating a security context to be used with the at least one WTRU based on the derived key; and using the security context to serve the at least one WTRU after completion of the conditional handover.
Citation Information
Patent Citations
Security update for subsequent ltm
WO2024146138A1