Method and apparatus of supporting wireless communications based on split radio access network (RAN) architecture
Relocating the RRC function to the DU in the split RAN architecture addresses latency and optimization issues by enabling efficient RRC parameter management and security processing, improving system performance and consistency in 5G wireless communications.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2026-03-12
AI Technical Summary
The existing 3GPP standards for 5G wireless communications systems with a split RAN architecture face issues such as increased control plane latency, inefficient RRC parameter reconfiguration, and difficulty in multi-vendor optimization due to the RRC layer being located in the CU, leading to suboptimal RRC pooling and unnecessary control information overhead.
The RRC function is relocated from the CU to the DU in the split RAN architecture, with the CU determining RRC security-related information and sending it to the DU for processing, ensuring consistent security processing and efficient signaling design, including key management and handover handling for RRC and UP security keys.
This relocation reduces control plane latency, enables efficient RRC parameter management, facilitates multi-vendor optimization, and maintains consistent security processing across handovers, enhancing overall system performance and efficiency.
Smart Images

Figure CN2025089835_12032026_PF_FP_ABST
Abstract
Description
METHOD AND APPARATUS OF SUPPORTING WIRELESS COMMUNICATIONS BASED ON SPLIT RADIO ACCESS NETWORK (RAN) ARCHITECTURETECHNICAL FIELD
[0001] The present disclosure relates to wireless communications, and more specifically to techniques of supporting wireless communications based on a split radio access network (RAN) architecture.BACKGROUND
[0002] A wireless communications system may include one or multiple network communication devices, such as base stations, which may support wireless communications for one or multiple user communication devices, which may be otherwise known as user equipment (UE) , or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like) . Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G) ) .SUMMARY
[0003] An article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a, ” “at least one, ” “one or more, ” and “at least one of one or more” may be interchangeable. As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of” or “one or more of” or “one or both of” ) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C) . Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on. Further, as used herein, including in the claims, a “set” may include one or more elements.
[0004] Some implementations of the methods and apparatuses described herein may further include a distributed unit (DU) of a network equipment (NE) for wireless communication, which may include: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the DU to: receive, from a central unit (CU) of the NE, radio resource control (RRC) security related information, wherein the RRC security related information at least indicates key information related to RRC security keys for protection of RRC signaling between the DU and a UE; and perform security processing on the RRC signaling between the DU and UE based on the RRC security related information.
[0005] In some implementations of the methods and apparatuses described herein, the at least one processor is configured to further cause the DU to: receive a first packet data convergence protocol (PDCP) configuration associated with a first signaling radio bearer (SRB) from the CU, wherein the RRC signaling between the DU and UE over the first SRB is out of security processing; determine a first SRB configuration based on the first PDCP configuration; and send the first SRB configuration including the first PDCP configuration to the UE.
[0006] In some implementations of the methods and apparatuses described herein, the at least one processor is configured to further cause the DU to: receive a second PDCP configuration associated with a second SRB from the CU, wherein the RRC signaling between the DU and UE over the second SRB is security processed based on the RRC security related information; determine a second SRB configuration based on the second PDCP configuration; and send the second SRB configuration including the second PDCP configuration to the UE.
[0007] In some implementations of the methods and apparatuses described herein, the at least one processor is configured to further cause the DU to: receive, from the CU, a third PDCP configuration associated with a data radio bearer (DRB) and a service data adaptation protocol (SDAP) configuration of the DRB; determine a DRB configuration based on the third PDCP configuration and the SDAP configuration; and send the DRB configuration including the third PDCP configuration and the SDAP configuration to the UE.
[0008] In some implementations of the methods and apparatuses described herein, the key information related to RRC security keys includes a first key used for integrity protection of RRC signaling and a second key used for encryption protection of RRC signaling, and the RRC security related information further indicates an integrity algorithm associated with the first key and an encryption algorithm associated with the second key.
[0009] In some implementations of the methods and apparatuses described herein, the at least one processor is configured to further cause the DU to: determine an integrity algorithm and an encryption algorithm associated with the key information.
[0010] In some implementations of the methods and apparatuses described herein, the RRC security related information indicates a third key for the NE, and the at least one processor is configured to further cause the DU to: derive a first key used for integrity protection of RRC signaling and a second key used for encryption protection of RRC signaling based on the third key; and receive an integrity algorithm associated with the first key and an encryption algorithm associated with the second key from the CU or determine an integrity algorithm associated with the first key and an encryption algorithm associated with the second key.
[0011] In some implementations of the methods and apparatuses described herein, the RRC security related information indicates a fourth key associated with the DU, wherein the fourth key is derived based on a third key for the NE, and the at least one processor is configured to further cause the DU to: derive a first key used for integrity protection of RRC signaling and a second key used for encryption protection of RRC signaling based on the fourth key; and receive an integrity algorithm associated with the first key and an encryption algorithm associated with the second key from the CU or determine an integrity algorithm associated with the first key and an encryption algorithm associated with the second key.
[0012] In some implementations of the methods and apparatuses described herein, the at least one processor is configured to further cause the DU to: send an indication to the UE, indicating whether the NE is a CU-DU split architecture.
[0013] In some implementations of the methods and apparatuses described herein, the at least one processor is configured to further cause the DU to: send an indication to the UE, indicating whether the fourth key is used for derivation of the first key and the second key.
[0014] In some implementations of the methods and apparatuses described herein, the RRC security related information further indicates integrity algorithms and encryption algorithms supported by the NE, the integrity algorithm associated with the first key is determined from the integrity algorithms supported by the NE, and the encryption algorithm associated with the second key is determined from the encryption algorithms supported by the NE.
[0015] In some implementations of the methods and apparatuses described herein, the at least one processor is configured to further cause the DU to: indicate to the UE the integrity algorithm associated with the first key and the encryption algorithm associated with the second key.
[0016] In some implementations of the methods and apparatuses described herein, in the case that the UE is handed over from a first cell to a second cell, the at least one processor is configured to further cause the DU to: indicate to the UE one or multiple of whether to retain or change current RRC security keys for protection of RRC signaling used between the DU and the UE and whether to retain or change current user plane (UP) security keys for protection of UP traffics used between the CU and the UE.
[0017] In some implementations of the methods and apparatuses described herein, indicating the UE whether to retain or change a current RRC security or current UP security key includes: indicating a new security key to be used by a key index same as or different from that of the current RRC security key or UP security key.
[0018] In some implementations of the methods and apparatuses described herein, in the case that the UE is handed over from a first cell to a second cell of the DU, the at least one processor is configured to further cause the DU to: indicate the UE to retain current RRC security keys for protection of RRC signaling used between the DU and the UE and current UP security keys for protection of UP traffics used between the CU and the UE; or indicate the UE to retain all current security keys.
[0019] In some implementations of the methods and apparatuses described herein, in the case that the UE is handed over from a first cell of the DU to a second cell of a different DU of the NE, the at least one processor is configured to further cause the DU to: indicate the UE to change the current RRC security keys; and indicate the UE to retain the current UP security keys.
[0020] In some implementations of the methods and apparatuses described herein, the at least one processor is configured to further cause the DU to: derive, based on a counter or an identifier (ID) of the different DU or an index of the ID of the different DU, new RRC security keys from the current RRC security keys, or a third key used for the NE or a fourth key derived from the third key; indicate the counter, or the ID of the different DU or the index of the ID of the different DU to the UE; and send the new RRC security keys to the different DU directly or via the CU.
[0021] In some implementations of the methods and apparatuses described herein, in the case that the UE is handed over from a first cell of the NE to a second cell of a different NE, the at least one processor is configured to further cause the DU to: indicate the UE to change current RRC security keys for protection of RRC signaling used between the DU and the UE and current UP security keys for protection of UP traffics used between the CU and the UE; or indicate the UE to change all current security keys; or indicate the UE to change a key used for deriving RRC security keys.
[0022] Some implementations of the methods and apparatuses described herein may further include a CU of a NE for wireless communication, which may include: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the CU to: determine RRC security related information, wherein the RRC security related information at least indicates key information related to RRC security keys for protection of RRC signaling between a DU of the NE and a UE; and transmit the RRC security related information to the DU.
[0023] In some implementations of the methods and apparatuses described herein, in the case that the UE is handed over from a first cell of the DU to a second cell of a different DU of the NE, the at least one processor is configured to further cause the CU to: indicate to the different DU one or multiple of a counter, current RRC security keys, or a current security key from which the current RRC security keys are derived.
[0024] In some implementations of the methods and apparatuses described herein, in the case that the UE is handed over from a first cell of the NE to a second cell of a different NE, the at least one processor is configured to further cause the CU to: indicate to the different NE a new security key from which new RRC security keys can be derived.
[0025] Some implementations of the methods and apparatuses described herein may further include a UE for wireless communication, which may include: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the UE to: receive security related information from a DU of a NE during a handover; and determine, based on the security related information, whether to retain or change current RRC security keys for protection of RRC signaling between the DU and the UE, and whether to retain or change current UP security keys for protection of UP traffics between a CU of the NE and the UE.
[0026] In some implementations of the methods and apparatuses described herein, determining whether to retain or change the current RRC security keys and whether to retain or change the current UP security keys includes one or multiple of: determining to retain the current RRC security keys for protection of RRC signaling in the case that the security related information indicates indexes of new RRC security keys are same as that of the current RRC security keys; determining to change the current RRC security keys for protection of RRC signaling in the case that the security related information indicates indexes of new RRC security keys are different from that of the current RRC security keys; determining to retain the current UP security keys for protection of UP traffics in the case that the security related information indicates indexes of new UP security keys are same as that of the current UP security keys; or determining to change the current UP security keys for protection of UP traffics in the case that the security related information indicates indexes of new UP security keys are different from that of the current UP security keys.
[0027] In some implementations of the methods and apparatuses described herein, in the case of being handed over from a first cell to a second cell of the DU, determining whether to retain or change the current RRC security keys and whether to retain or change the current UP security keys includes one or multiple of: determining to retain the current RRC security keys for protection of RRC signaling in the case that the security related information indicates retaining the current RRC security keys or retain all current security keys; or determining to retain the current UP security keys for protection of UP traffics in the case that the security related information indicates retaining the current UP security keys or retain all current security keys.
[0028] In some implementations of the methods and apparatuses described herein, in the case of being handed over from the DU to a different DU of the NE, determining whether to retain or change the current RRC security keys and whether to retain or change the current UP security keys includes one or multiple of: determining to change the current RRC security keys for protection of RRC signaling in the case that the security related information indicates changing the current RRC security keys to new RRC security keys; or determining to retain the current UP security keys for protection of UP traffics in the case that the security related information indicate retaining the current UP security keys.
[0029] In some implementations of the methods and apparatuses described herein, the security related information includes a counter for the new RRC security keys or an ID of the different DU or an index of the ID of the different DU, and the at least one processor is configured to further cause the UE to: derive, based on the counter or the ID of the different DU or the index of the ID of the different DU, the new RRC security keys from the current RRC security keys, or a current security key from which the current RRC security keys are derived.
[0030] In some implementations of the methods and apparatuses described herein, in the case of being handed over from the NE to a different NE, determining whether to retain or change the RRC security keys and whether to retain or change the UP security keys includes one or multiple of: determining to change the current RRC security keys for protection of RRC signaling to new RRC security keys in the case that the security related information indicates changing the current RRC security keys or changing a current security key used between the NE and the UE; or determining to change the current UP security keys for protection of UP traffics in to new UP security keys the case that the security related information indicate changing the current UP security keys or changing a current security key used between the NE and the UE.
[0031] Some implementations of the methods and apparatuses described herein may further include a method performed by a DU of a NE, which may include: receiving, from a CU of the NE, RRC security related information, wherein the RRC security related information at least indicates key information related to RRC security keys for protection of RRC signaling between the DU and a UE; and performing security processing on the RRC signaling between the DU and UE based on the RRC security related information.BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.
[0033] Figure 2 is a schematic diagram illustrating a legacy internal structure of a NE in accordance with aspects of the present disclosure.
[0034] Figure 3 is a schematic diagram illustrating a novel internal structure of a NE in accordance with aspects of the present disclosure.
[0035] Figure 4a illustrates an example of deriving RRC security keys in accordance with aspects of the present disclosure.
[0036] Figure 4b illustrates another example of deriving RRC security keys in accordance with aspects of the present disclosure.
[0037] Figure 4c illustrates yet another example of deriving RRC security keys in accordance with aspects of the present disclosure.
[0038] Figure 5 illustrates an example of communication procedure between the CU and DU of a NE in accordance with aspects of the present disclosure.
[0039] Figure 6 illustrates an example of a UE in accordance with aspects of the present disclosure.
[0040] Figure 7 illustrates an example of a processor in accordance with aspects of the present disclosure.
[0041] Figure 8 illustrates an example of a DU of a NE in accordance with aspects of the present disclosure.
[0042] Figure 9 illustrates an example of a CU of a NE in accordance with aspects of the present disclosure.
[0043] Figure 10 illustrates a flowchart of method performed by a UE in accordance with aspects of the present disclosure.
[0044] Figure 11 illustrates a flowchart of method performed by a DU in accordance with aspects of the present disclosure.
[0045] Figure 12 illustrates a flowchart of method performed by a CU in accordance with aspects of the present disclosure.DETAILED DESCRIPTION
[0046] 5G system introduces a split RAN architecture (or referred to as CU-DU split architecture or the like) , wherein the internal structure of a RAN node, e.g., a gNB may be split into a CU, e.g., gNB-CU and at least one DU, e.g., gNB-DU. In accordance with legacy 3rd generation partnership project (3GPP) standards, RRC layer (or RRC entity or RRC function or the like) is located in the CU, e.g., gNB-CU, which may cause the following disadvantages: - various procedures, e.g., mobility and RRC setup, etc., may cause extra control plane (CP) latency mainly because the RRC layer resides in CU; - RRC parameters related to radio resources are usually generated by DU, and the reconfiguration of these RRC parameters needs CU involvement; - RRC pooling gains are not realized as DU still owns the most of lower layer tasks; - even if ever deployed in multi-vendor scenarios, joint optimization of CU and DU procedures are not easily achievable due to too many inter-dependencies; and - unnecessary control information over media access control (MAC) layer due to slow RRC procedures.
[0047] Thus, various aspects of the present disclosure propose moving or (re) locate the RRC function to DU from CU, which means several issues need to be solved, e.g., security key management for RRC, signaling design for RRC in DU and signaling design for mobility etc.
[0048] For example, in accordance with some aspects of the present disclosure, considering security processing for RRC messages, the CU may determine RRC security related information and send the RRC security related information to the DU. The RRC security related information at least indicates key information related to RRC security keys for protection of RRC signaling between a DU of the NE and a UE, e.g., a security key for deriving the RRC security keys. After the DU receives the RRC security related information, the DU may perform security processing on the RRC signaling between the DU and UE based on the RRC security related information. The DU may transmit to the UE algorithm information at least based on the RRC security related information, e.g., the encryption algorithm and integrity algorithm associated with the selected security keys, so that the UE side and the NE side perform the consistent security processing.
[0049] When a handover occurs, the NE side, e.g., the source DU may also transmit security related information (which may be transparent for the source DU) to the UE, which explicitly or implicitly provides information related to whether to retain or change current RRC security keys for protection of RRC signaling between the DU and the UE and whether to retain or change current UP security keys for protection of UP traffics between the CU and the UE. If the RRC security keys and the UP security keys will be changed, the security related information may also indicate the information or parameter for deriving the new security keys, e.g., a counter value or a security key or a DU ID or an index of DU ID etc.
[0050] UE may determine whether to retain or change the current RRC security keys and whether to retain or change the current UP security keys based on the security related information. For example, UE may determine to retain the current RRC security keys for protection of RRC signaling in the case that the security related information indicates indexes of new RRC security keys are same as that of the current RRC security keys; determine to change the current RRC security keys for protection of RRC signaling in the case that the security related information indicates indexes of new RRC security keys are different from that of the current RRC security keys, determine to retain the current UP security keys for protection of UP traffics in the case that the security related information indicates indexes of new UP security keys are same as that of the current UP security keys, or determine to change the current UP security keys for protection of UP traffics in the case that the security related information indicates indexes of new UP security keys are different from that of the current UP security keys.
[0051] Aspects of the present disclosure are described in the context of a wireless communications system.
[0052] Figure 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more NE 102, one or more UE 104, and a core network (CN) 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LTE-Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a NR network, such as a 5G network, a 5G-Advanced (5G-A) network, or a 5G ultrawideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi) , IEEE 802.16 (WiMAX) , IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA) , frequency division multiple access (FDMA) , or code division multiple access (CDMA) , etc.
[0053] The one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NE 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, a radio access network (RAN) , a NodeB, an eNodeB (eNB) , a next-generation NodeB (gNB) , or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link, which may be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.
[0054] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For example, an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc. ) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN) . In some implementations, different geographic coverage areas 112 associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102. In some embodiments, the NEs 102 may include one or more relay nodes, integrated access and backhaul (IAB) nodes or wireless access backhaul (WAB) nodes which can provide wireless access services for UEs 104. A relay node (or an IAB node or a WAB node) can directly connect to a BS or hop through one or more relay nodes (or one or more IAB or WAB nodes) before reaching the BS.
[0055] The one or more UE 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Internet-of-Things (IoT) device, an Internet-of-Everything (IoE) device, or machine-type communication (MTC) device, among other examples.
[0056] A UE 104 may be able to support wireless communication directly with other UEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link 114 may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.
[0057] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., S1, N2, N3, or network interface) . In some implementations, the NE 102 may communicate with each other directly. In some other implementations, the NE 102 may communicate with each other or indirectly (e.g., via the CN 106. In some implementations, one or more NE 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC) . An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as a radio heads, smart radio heads, or transmission-reception points (TRPs) .
[0058] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC) , or a 5G core (5GC) , which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME) , an access and mobility management functions (AMF) ) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW) , a Packet Data Network (PDN) gateway (P-GW) , or a user plane function (UPF) ) . In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc. ) for the one or more UEs 104 served by the one or more NE 102 associated with the CN 106.
[0059] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g., via an S1, N2, N3, or another network interface) . The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g., a protocol data unit (PDU) session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g., control information, data, and the like) between the UE 104 and the application server using the established session (e.g., the established PDU session) . The PDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g., one or more network functions of the CN 106) .
[0060] In the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers) ) to perform various operations (e.g., wireless communications) . In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104 may support various frame structures (i.e., multiple frame structures) . The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.
[0061] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., μ=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., μ=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., μ=1) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., μ=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., μ=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., μ=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.
[0062] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames) . Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.
[0063] Additionally or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e., μ=0, μ=1, μ=2, μ=3, μ=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols) . In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing) , a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., μ=0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.
[0064] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz –7.125 GHz) , FR2 (24.25 GHz –52.6 GHz) , FR3 (7.125 GHz –24.25 GHz) , FR4 (52.6 GHz –114.25 GHz) , FR4a or FR4-1 (52.6 GHz –71 GHz) , and FR5 (114.25 GHz –300 GHz) . In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data) . In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.
[0065] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies) . For example, FR1 may be associated with a first numerology (e.g., μ=0) , which includes 15 kHz subcarrier spacing; a second numerology (e.g., μ=1) , which includes 30 kHz subcarrier spacing; and a third numerology (e.g., μ=2) , which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies) . For example, FR2 may be associated with a third numerology (e.g., μ=2) , which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., μ=3) , which includes 120 kHz subcarrier spacing.
[0066] Figure 2 is a schematic diagram illustrating a legacy internal structure of a NE or RAN node, e.g., a gNB in accordance with aspects of the present disclosure.
[0067] Referring to Figure 2, in a split RAN architecture, the internal structure of a RAN node (e.g., NE 102) may be split into a CU 200 and at least one DU 202 (e.g., two DUs shown in Figure 2) . Although a specific number of DUs 202 are depicted in FIG. 2, it is contemplated that any number of DUs 202 may be included in the RAN node.
[0068] The CU 200, e.g., a CU of a gNB (gNB CU, or gNB-CU) and DU 202 e.g., a DU of a gNB (gNB DU, or gNB-DU) are connected with each other by an interface called F1 as specified in 3GPP standard documents. The RRC layer functionality, SDAP layer functionality, and the PDCP layer functionality are located in the CU 200. The CU is responsible for performing security processing for RRC messages, including encryption, decryption, integrity protection and integrity checking etc., and these functions are typically handled by the PDCP layer. The radio link control (RLC) layer functionality, media access control (MAC) layer functionality, and the physical (PHY) layer functionality are located in the DU 202.
[0069] If the RRC function or functionality is moved to the DU, there may be various implementations in accordance with aspects of the present disclosure. For example, Figure 3 is a schematic diagram illustrating a novel internal structure of a NE or RAN node, e.g., a gNB (which may change as the 3GPP evolvement in the future, e.g., being redefined as xNB or the like) in accordance with aspects of the present disclosure, wherein besides the RRC function, the security processing for RRC messages would also be relocated to the DU to maintain consistency and efficiency in the control plane.
[0070] Specifically, referring to Figure 3, similarly, in a split RAN architecture, the internal structure of a RAN node (e.g., NE 102) may be split into a CU 300 and at least one DU 302 (e.g., two DUs shown in Figure 2) . Although a specific number of DUs 302 are depicted in FIG. 3, it is contemplated that any number of DUs 302 may be included in the RAN node. The CU 300, e.g., a CU of a gNB (gNB CU, or gNB-CU) and DU 302 e.g., a DU of a gNB (gNB DU, or gNB-DU) are connected with each other by an interface called F1 as specified in 3GPP standard documents.
[0071] SDAP and PDCP functions for the user plane (e.g., referred to as PDCP-U) are located in the CU. An exemplary PDCP-U includes at least the ciphering, deciphering, integrity protection and integrity verification of PDCP service data units (SDUs) for DRBs etc.
[0072] The RRC function is located in each DU along with the PDCP function dedicated to RRC or for control plane (e.g., referred to as PDCP-C) . An exemplary PDCP-C includes at least the ciphering, deciphering, integrity protection and integrity verification of RRC messages etc. The lower layer functions, such as MAC, RLC and PHY-related functions are also located in the DU.
[0073] Although the RRC function is located in the DU, e.g., gNB-DU, some parameters and / or information for RRC configurations are still generated by the CU, e.g., gNB-CU. The CU will send these parameters and / or information to the DU, and the DU may send these parameters and / or information to the UE, e.g., including them in RRC messages. In accordance with some aspects of the present disclosure, the CU may provide the PDCP configuration (or configuration parameters) of SRB, SDAP and PDCP configuration (or configuration parameters) of DRBs, and other related information (if any) to the gNB-DU. For example, during DRB establishment, the CU may generate the quality of service (QoS) flow-to-DRB mapping (or association or the like) , SDAP configuration parameters, and PDCP configuration parameters, and then transmit the generated parameters and / or information to the DU.
[0074] In addition, in the case of moving RRC functionality to the DU, security processing for RRC messages will also be relocated to the DU to maintain consistency and efficiency in the control plane. Since the user plane remains in the CU, the security functions for the user plane, such as those for DRBs, would continue to be managed by the CU. Thus, security processing for RRC messages will be mainly illustrated in the following.
[0075] Herein, security keys for RRC messages or signaling may also be referred to as RRC security keys, security keys for RRC, or security keys for CP traffic (e.g., SRB) or the like, which includes a security key used for the protection of RRC signaling with an encryption algorithm (hereinafter, a RRC encryption key, e.g., represented by KRRCenc) , and a security key used for the integrity protection of RRC signaling with an integrity algorithm (hereinafter, a RRC integrity key, e.g., represented by KRRCint) . The DU may use KRRCenc for encryption or de-encryption of RRC messages or signaling or SRB, and may use KRRCint for integrity protection or integrity verification of RRC messages or signaling or SRB.
[0076] Similarly, security keys for UP traffics (e.g., DRB) may also be referred to as UP security keys or the like, which includes a security key used for the protection of UP traffics between UE and NE with an encryption algorithm (hereinafter, a UP encryption key, e.g., represented by KUPenc) and a security key used for the integrity protection of UP traffics between UE and NE with an integrity algorithm (hereinafter, a UP integrity key, e.g., KUPint) . The CU may use KUPenc for encryption or de-encryption of user plane traffics, e.g., DRBs, and may use KUPint for integrity protection or integrity verification of user plane traffics.
[0077] Aspects of the present disclosure provide various manners to distribute and manage RRC security keys, and some exemplary implementations are illustrated in the following.
[0078] In some implementations of the present disclosure, a security key (or key for simplification) for NE, e.g., KgNB or the like is used for determining or deriving RRC security keys, which may also be used for other security keys, e.g., UP security keys. In legacy 3GPP technology, KgNB is a key derived by UE or mobile equipment (ME) and a CN entity, e.g., AMF, which may evolve along the 3GPP evolvement and change the name or not, e.g., referred to as key for nodeB or KxNB or the like.
[0079] Figure 4a illustrates an example of deriving RRC security keys in accordance with aspects of the present disclosure.
[0080] Referring to Figure 4a, the CU may receive KgNB or the like from the CN, e.g., from the AMF in an initial UE context setup request message or the like, and then derive or determine the security keys based on the received KgNB or the like. For example, the CU derives RRC security keys based on the received KgNB, including deriving KRRCenc from KgNB, which may only be used for the protection of RRC signaling with a particular encryption algorithm, and deriving KRRCint from KgNB, which may only be used for the protection of RRC signaling with a particular integrity algorithm. Specific derivation can refer to but not limited to the legacy techniques.
[0081] The CU may send the derived RRC security keys to the DU, e.g., in a UE context setup request or UE context modify request message etc., RRC message.
[0082] Regarding the encryption algorithm and integrity algorithm associated with the derived RRC security keys, they can be selected or determined from those supported by the NE by the CU or by the DU.
[0083] Exemplary optional or supported encryption algorithms may include but not limited to EPS encryption algorithm (EEA) 1, EEA2 and EEA3, which may be: 128-EEA1 SNOW 3G based algorithm; 128-EEA2 AES based algorithm; and 128-EEA3 ZUC based algorithm.
[0084] Exemplary optional encryption algorithms may include but not limited to EPS integrity algorithm (EIA) 1, EIA2 and EIA3, which may be: 128-EIA1 SNOW 3G based algorithm; 128-EIA2 AES based algorithm; and 128-EIA3 ZUC based algorithm.
[0085] In some cases, the CU may select or determine the encryption algorithm and integrity algorithm associated with the derived RRC security keys. For example, the CU may select one of the optional encryption algorithms and send the selected encryption algorithm to the DU in a RRC message, e.g., in a UE context setup request or UE context modify request message etc., together with the selected KRRCenc. The CU may also select one of the optional integrity algorithms and send the selected integrity algorithm to the DU in a RRC message, e.g., in a UE context setup request or UE context modify request message etc., together with the selected KRRCint.
[0086] In some cases, the CU may indicate to the DU the optional or supported encryption algorithms and integrity algorithms to the DU. Based on the supported encryption algorithms and integrity algorithms, the DU may determine or select the encryption algorithm and integrity algorithm for RRC signaling protection.
[0087] The DU may indicate the selected (by CU or DU) encryption algorithm and integrity algorithm to the UE. The UE may derive the RRC security keys from KgNB or the like by itself. Specific derivation can refer to but not limited to the legacy techniques.
[0088] The DU and UE may use the derived KRRCenc for encryption or de-encryption of a RRC message delivered between the DU and UE with the selected (by the CU or DU) encryption algorithm, and may use the derived KRRCint for integrity protection or integrity verification of a RRC message delivered between the DU and UE with the selected (by the CU or DU) integrity algorithm.
[0089] Figure 4b illustrates another example of deriving RRC security keys in accordance with aspects of the present disclosure, which only differs from Figure 4a in that the DU rather than the CU will derive the RRC security keys.
[0090] Referring to Figure 4b, the CU may receive KgNB or the like from the CN, e.g., from the AMF in an initial UE context setup request message or the like. The CU may indicate the received KgNB or the like to the DU, e.g., in a UE context setup request or UE context modify request message etc., RRC message.
[0091] The DU may derive the RRC security keys based on the received KgNB. For example, the DU may derive KRRCenc from KgNB, which may only be used for the protection of RRC signaling with a particular encryption algorithm, and derive KRRCint from KgNB, which may only be used for the protection of RRC signaling with a particular integrity algorithm. Specific derivation can refer to but not limited to the legacy techniques.
[0092] Similarly, in some cases, the CU may select or determine the encryption algorithm and integrity algorithm associated with the derived RRC security keys, and indicate the selected encryption algorithm and integrity algorithm to the DU. In some cases, the CU may indicate to the DU the optional or supported encryption algorithms and integrity algorithms to the DU, e.g., EEA1, EEA2 and EEA3 and EIA1, EIA2 and EIA3. The DU may select or determine an encryption algorithm and integrity algorithm associated with the derived RRC security keys, e.g., from EEA1, EEA2 and EEA3 and from EIA1, EIA2 and EIA3 respectively. All these operations are identical or similar to that illustrated in view of Figure 4a, and thus will not repeat.
[0093] In some other implementations of the present disclosure, an intermediate key based on KgNB or the like, e.g., represented by KDU or the like is introduced for the determination of RRC security keys by the DU. To keep the consistent understanding of whether KgNB or KDU is used for deriving the RRC security keys at the UE and RAN side, the NE may send an indication to the UE, indicating whether the NE is a CU-DU split architecture or not. For example, gNB may provide two code points {aggregated, non-aggregated} in the system information to UE, wherein the code point "aggregated" means non CU-DU split architecture, while the code point "disaggregation" means CU-DU split architecture. If the UE receives the indication of "CU-DU split architecture, " the UE may derive the KDU from KgNB, and then derives the RRC security keys, e.g., KRRCint and KRRCenc from KDU. If the UE receives the indication of "non CU-DU split architecture, " the UE may derive the RRC security keys, e.g., KRRCint and KRRCenc from KgNB directly. In some other examples, NE may send an indication to the UE, indicating whether the KDU is used for determination of RRC security keys.
[0094] Figure 4c illustrates yet another example of deriving RRC security keys in accordance with aspects of the present disclosure, wherein KDU is used.
[0095] Referring to Figure 4c, the CU may receive KgNB or the like from the CN, e.g., from the AMF in an initial UE context setup request message or the like. The CU may derive KDU or the like from the received KgNB, which is used for deriving of the security keys, e.g., RRC security keys, and provide the KDU or the like for the DU, e.g., in a UE context setup request or UE context modify request message etc., RRC message.
[0096] The DU may derive the RRC security keys based on the received KDU. For example, the DU may derive KRRCenc from KDU, which may only be used for the protection of RRC signaling with a particular encryption algorithm, and derive KRRCint from KDU, which may only be used for the protection of RRC signaling with a particular integrity algorithm.
[0097] Similarly, in some cases, the CU may select or determine the encryption algorithm and integrity algorithm associated with the derived RRC security keys, and indicate the selected encryption algorithm and integrity algorithm to the DU. In some cases, the CU may indicate to the DU the optional or supported encryption algorithms and integrity algorithms to the DU, and the DU may select or determine an encryption algorithm and integrity algorithm associated with the derived RRC security keys. All these operations are identical or similar to that illustrated in view of Figure 4a, and thus will not repeat.
[0098] Regarding security processing for UP traffics, e.g., DRBs, it is still performed by the CU. For example, the CU may also derive UP security keys based on the received KgNB, including deriving KUPenc from KgNB, which may only be used for the protection of UP traffics between UE and NE with a particular encryption algorithm, and deriving KUPint from KgNB, which may only be used for the protection of UP traffics between UE and NE with a particular integrity algorithm. The CU may also determine the encryption algorithm and integrity algorithm associated with UP security keys. The CU and UE may use the selected KUPenc for encryption or de-encryption of user plane traffics with the selected encryption algorithm, and may use the selected KUPint for integrity protection or integrity verification of user plane with the selected integrity algorithm.
[0099] Besides the RRC security related information transmission, considering other communication changes introduced by RRC function relocated to the DU, aspects of the present disclosure also propose improved communication procedures between the CU and DU, wherein signaling between the CU and DU are carefully designed.
[0100] Figure 5 illustrates an example of communication procedure between the CU and DU of a NE, e.g., gNB in accordance with aspects of the present disclosure, wherein only one DU is illustrated as an example. For simplification and clarity, details are mainly considering the changes caused by RRC function relocation.
[0101] Referring to Figure 5, at step 501, a UE may send a RRC setup request message to the DU, including RRC cause and UE ID etc., to request setup a RRC connection with the NE.In some cases, it may be understood as that the UE sends the RRC setup request message via SRB0.
[0102] At step 503, if the UE is admitted by the DU, the DU may transfer the RRC setup request message to the CU, e.g., via an initial uplink (UL) RRC message transfer message. The initial UL RRC message transfer message may further include the cell-radio network temporary identifier (C-RNTI) allocated by the DU.
[0103] After receiving the initial UL RRC message transfer message, the CU may generate a PDCP configuration (hereinafter, first PDCP configuration) , which is related to the configuration of a type of SRB (hereinafter, the first type of SRB, or SRB1) . For example, the first PDCP configuration is a PDCP configuration of SRB1 or the like. The CU may send the first PDCP configuration to the DU at step 505, e.g., in a downlink (DL) RRC message transfer message in response to the UL RRC message transfer message.
[0104] An example of the first PDCP configuration, e.g., PDCP configuration of SRB1 may include the following parameters or information as shown in table 1. Table 1
[0105] An exemplary "PDCP-Config" parameter may further include the following parameters or information as shown in table 1-1. Table 1-1
[0106] Based on the first PDCP configuration from the CU, the DU may generate the remaining configuration information or parameters of the first type SRB, e.g., the remaining configuration information or parameters of SRB1, including but not limited to parameters related to RLC bearer for SRB1, MAC cell group configuration, e.g., mac-CellGroupConfig, physical cell group configuration, e.g., physicalCellGroupConfig and special cell (Spcell) configuration, e.g., spCellConfig. Regarding MAC cell group configuration, it includes or configures MAC parameters applicable for the entire cell group. Regarding physical cell group configuration, it includes or configures cell-group specific layer 1 (L1) parameters. Regarding Spcell configuration, it includes or configures parameters for the SpCell of this cell group. The DU may send the configuration of the first type SRB, e.g., the configuration of SRB1 to the UE at step 507, including the first PDCP configuration and parameters relates to RLC bearer for SRB1, mac-CellGroupConfig, physicalCellGroupConfig and spCellConfig, e.g., in a RRC setup message or the like.
[0107] After receiving the configuration of the first type of SRB, e.g., in the RRC setup message or the like, the UE may send a RRC connection setup complete message or the like to the DU at step 509, indicating that RRC connection between the UE and NE is successfully set up (or RRC setup is complete or the like) .
[0108] After receiving the RRC connection setup complete message or the like, the DU may send an indication to the CU at step 511, indicating that the RRC setup is complete, e.g., in a UL RRC message transfer message or the like.
[0109] Then, the CU may send an initial UE message to the CN, e.g., to AMF at step 513 and the AMF may send an initial context setup request message to the CU at step 515. The AMF may also indicate the KgNB or the like to the CU in the initial context setup request message.
[0110] Based on the initial context setup request, the CU may send to the DU a UE context setup request message to establish the UE context in the DU at step 517. The CU may include RRC security related information to the DU, which at least include the key information related to RRC security keys.
[0111] For example, as illustrated above, in some cases, the CU may generate the RRC security keys and optionally select the security algorithms associated with the RRC security keys. The CU may include the RRC security keys and optionally with the selected security algorithms in the UE context setup request message. In some case, the CU may send KgNB or KDU to the DU in the UE context setup request message, so that the DU can generate the RRC security keys. In the case that the CU does not select security algorithms for the RRC security keys (determined or not) , the CU may also indicate the supported security algorithms to the DU at step 517.
[0112] In addition, after receiving the KgNB or the like, the CU may also generate other security keys and select the associated security algorithms, e.g., UP security keys and the associated security algorithm thereof, which is similar to the legacy and will not repeat.
[0113] In some cases, if the CU has already have the KgNB or the like, the CU may send the RRC security related information at step 505, e.g., with the first PDCP configuration.
[0114] After receiving the initial context setup request, the DU may send a security mode command message to the UE at step 519 and send a UE context setup response message to the CU at step 521.
[0115] In the case that the CU does not provide the RRC security keys, the DU may determine the RRC security keys based on the RRC security related information. In the case that the CU does not provide the security algorithms (RRC security keys are provided or not) , the DU may also select the associated algorithms. The DU may indicate the selected (by CU or DU) security algorithm associated with the RRC security keys to the UE in the security mode command message.
[0116] After receiving the security mode command message, the UE may respond with a security mode complete message at step 523, which means that the RRC messages will be security processed. Based on the security mode complete message received at step 523, the DU may send an indication to the CU at step 525, indicating that the security mode command procedure with UE is complete, e.g., in an UL RRC message transfer message.
[0117] The security related information, e.g., the KgNB or the counter value for deriving the security keys etc., may change after the security mode command procedure is complete. Accordingly, the CU may send the updated RRC security related information to the DU, e.g., via UE context modify request message.
[0118] After the security mode command procedure with UE is complete, the CU may try to establish a type of SRB that needs security processing (hereinafter, the second type of SRB or SRB2) and / or a PDU session.
[0119] For example, the CU may generate a PDCP configuration (hereinafter, second PDCP configuration) , which is related to the configuration of a second type of SRB. For example, the second PDCP configuration is a PDCP configuration of one or multiple of SRB3 or SRB4 etc. The CU may send the second PDCP configuration to the DU at step 527, e.g., in a DL RRC message transfer message, which is similar to the first PDCP configuration and will not repeat.
[0120] In some cases, the CU may generate the second PDCP configuration before receiving the security mode command message, and send the second PDCP configuration to the DU at step 517, e.g., together with the RRC security related information.
[0121] Based on the second PDCP configuration from the CU, the DU may generate the remaining configuration information or parameters of the second type SRB, e.g., the remaining configuration information or parameters of SRB3 and / or SRB4 etc., including but not limited to parameters related to RLC bearer for SRB3 and / or SRB4 etc., (or RLC layer configuration) , MAC cell group configuration (or MAC layer configuration) , e.g., mac-CellGroupConfig, physical cell group configuration (or physical layer configuration) , e.g., physicalCellGroupConfig and Spcell configuration etc., e.g., spCellConfig. The DU may send the configuration of the second type of SRB (one or multiple) to the UE at step 529, e.g., in a RRC reconfiguration message.
[0122] In some cases, the CU may receive a PDU session setup request from the CN, e.g. from the AMF, e.g., in the initial context setup request. The CU may try to establish a PDU session as requested. For example, the CU may perform QoS to DRB mapping or association, e.g., mapping one or more QoS flows to a single DRB, which is associated with a DRB ID decided by the CU. The CU may also generate the SDAP configuration of DRB and PDCP configuration of DRB. The CU may also send the QoS to DRB mapping or association information, the SDAP configuration of DRB and PDCP configuration of DRB to the DU, e.g., included in the DL RRC message transfer message at step 527.
[0123] Examples of information and / or parameters that the CU may send to the DU are illustrated in table 2, which may be included in a CU to DU RRC transparent container. Table 2
[0124] An exemplary "PDCP-Config" parameter in table 2 may further include the following parameters or information as shown in table 2-1. Table 2-1
[0125] An exemplary "SDAP-Config" parameter in table 2 may further include the following parameters or information as shown in table 2-2. Table 2-2
[0126] After receiving the SDAP and PDCP configuration of DRB, the DU may generate the low layer configuration of the DRB, e.g., RLC layer configuration, MAC layer configuration and physical layer configuration etc. The DU may also transmit the configuration of DRB at step 529, including the SDAP configuration, PDCP configuration and lower layer configuration to the UE, e.g., in the RRC reconfiguration message.
[0127] Similarly, in some cases, the CU may generate the PDCP configuration of the DRB before receiving the security mode command message, and send the PDCP configuration of the DRB to the DU at step 517, e.g., together with the RRC security related information.
[0128] After receiving the configuration of the second type of SRB and / or the configuration of the DRB, the UE may send a RRC reconfiguration complete message to the DU at step 531, and accordingly, the DU may send an indication to the CU at step 533, indicating that the RRC reconfiguration with UE is complete, e.g., in a UL RRC message transfer. After receiving the indication from the DU, the CU may send an initial context setup response message to the AMF at step 535, which means that the initial UE context setup is complete.
[0129] In some cases, the CN may send the PDU session setup request in another stage, e.g., after receiving the initial context setup response. The CU and DU may setup the DRB accordingly, which is similar to that illustrated above.
[0130] In some scenarios, the UE may move from one cell (referred to as source cell or old cell or the like) of a first DU (referred to as source DU or old DU or the like) of a first NE (referred to as source NE or old NE or the like) to another cell (referred to as source cell or old cell or the like) of a second DU (referred to as a target DU or new DU or the like) of a second NE (referred to as target NE or new NE or the like) . The source DU and the target DU may be the same DU or different DUs, which may belong to the same NE or different NE. That is, the source NE and target NE may be the same or different, or the CU of the source NE (referred to as a source CU or old CU or the like) and the CU of the target NE (referred to as target CU or new CU or the like) may be the same or different.
[0131] In the case that the source DU and the target DU belong to the same NE or the source CU and target CU are the same one, the corresponding RRC function is (re) located to the target DU, while the UP remains terminated at the same CU. That means that the RRC security keys may need to be updated, whereas the UP security keys may remain unchanged. In the case that the source DU and the target DU belong to different NEs or the source CU and target CU are different, the corresponding RRC function is relocated to the target DU, and the UP will be terminated at the different CU. That means that both the RRC security keys and UP security keys may need to be updated.
[0132] Thus, aspects of the present disclosure also propose improved mechanisms for triggering and performing the handover over the novel CU-DU split architecture. Based on the security related information, e.g., received in a handover commend message, the UE may determine whether to retain or change current security keys, e.g., whether to retain or change the current RRC security keys and whether to retain or change the current UP security keys. The security related information may indicate the UE shall retain or keep or maintain a current security key in various manners. For example, in some implementations of the present disclosure, the security related information may indicate whether the UE shall retain or keep or maintain a current security key by an explicit indication. In some implementations of the present disclosure, the security related information may indicate whether the UE shall retain or keep or maintain a current security key by an implicit manner. For example, the security related information may indicate a security index or ID same as or different from the current security key index, wherein the same security index or ID means that the UE shall retain the current security key while the different security index or ID means that the UE shall change the current security key. For another example, the security related information may indicate or provide the information for determining or deriving the new security keys, e.g., a counter value, e.g., an integer from 0 to 31 received from the CN, or a key (e.g., KgNB or KDU) , or DU ID or DU ID index etc., for deriving the new security key, and the new security key may be the same as or different from the current security keys (or old security keys or the like) . In some implementations of the present disclosure, the security related information may indicate that the UE shall change a current security key by an explicit indication and also provide the information or parameters for deriving the new security key. In some implementations of the present disclosure, it is may be default that the UE shall retain a current security key without any indication.
[0133] Some exemplary implementations are illustrated in the following view of different handover scenarios, e.g., intra-CU handover including intra-DU handover and inter-DU handover, and inter-CU handover. Although specific examples of security related information are illustrated in different scenarios, it does not mean that there is a limited relationship between the security related information and the handover scenarios. Persons skilled in the art would optionally determine or select using which type of security related information to indicate the UE to retain or change current security keys in a specific handover scenario under the teaching and suggestion of the present disclosure.
[0134] In the scenarios of intra-DU handover, both the source cell and target cell belong to the same DU, and both RRC security keys and UP security keys may not need to change. Thus, in accordance with some aspects of the present disclosure, the source DU may indicate to the UE, e.g., in a handover command message or the like the following security related information: UE shall retain the current RRC security keys, e.g., current KRRCint and KRRCenc; UE shall retain the current UP security keys, e.g., KUPenc and KUPint; UE shall retain the current RRC security keys and current UP security keys; or UE shall retain all the current security keys.
[0135] For example, in some implementations of the present disclosure, a current RRC security keys may be assigned an index by the NE. In the handover command message, the NE, e.g., the DU may send another index of RRC security key. If the security key index in handover command message is the same as the current one, the UE will retain the current RRC security key. If the security key index in handover command message is different from the current one, the UE will change the current RRC security key to be that with the different index. Similarly, a current UP security key may be assigned an index by the NE. In the handover command message, the NE, e.g., the DU may send another index of UP security key. If the security key index in handover command message is the same as the current one, the UE will retain the current UP security key. If the security key index in handover command message is different from the current one, the UE will change the current UP security key to be that with the different index.
[0136] In the scenarios of inter-DU handover, the source cell and target cell belong to different DUs but the same CU, and the RRC security keys may need to change while the UP security keys may not need to change. In accordance with some aspects of the present disclosure, the source DU may indicate to the UE, e.g., in a handover command message or the like the following security related information: UE shall change the current RRC security keys, e.g., current KRRCint and KRRCenc; and UE shall retain the current UP security keys, e.g., KUPenc and KUPint.
[0137] For the new RRC security keys, they can be indicated or provided or derived in various manners.
[0138] For example, in some implementations of the present disclosure, the new RRC security keys will be derived from the current RRC security keys based on a counter value (Counter) , e.g., an integer from 0 to 31, which may be sent to the DU by the CU. For example, a new RRC integrity key, e.g., K*RRCint = KDF (KRRCint, Counter) , while a new RRC encryption key K*RRCenc= KDF (KRRCenc, Counter) .
[0139] At the RAN side, the source DU may derive the new RRC security keys, e.g., K*RRCint and K*RRCenc and send them to the target DU in a handover request message directly or via the CU. For example, in the case that the source DU has a direct interface with the target DU, the source DU may send the handover request message over the direct interface to the target DU directly.
[0140] The source DU (even if the target DU initiates the transmission, which is transparent to the source DU) may also send the counter value for deriving the RRC security keys to the UE. After receiving the counter value, the UE may derive the new RRC security keys from the current RRC security keys based on the counter value.
[0141] In some implementations of the present disclosure, the new RRC security keys may be derived from the current key for deriving security keys, e.g., current KgNB or KDU etc., based on a counter value (Counter) , e.g., an integer from 0 to 31. For example, K*RRCint =KDF (KgNB, Counter) , while K*RRCenc= KDF (KgNB, Counter) . For another example, K*RRCint = KDF (KDU, Counter) , while K*RRCenc= KDF (KDU, Counter) .
[0142] The source DU may derive the new RRC security keys, e.g., K*RRCint and K*RRCenc and send them to the target DU in a handover request message directly or via the CU. For example, in the case that the source DU has a direct interface with the target DU, the source DU may send the handover request over the direct interface to the target DU directly.
[0143] The source DU (even if the target DU initiates the transmission, which is transparent to the source DU) may also send the counter value to the UE. After receiving the counter value, the UE may derive the new RRC security keys based on the counter value from KgNB or KDU.
[0144] In some implementations of the present disclosure, the new RRC security keys may be derived from the current key for deriving the RRC security keys, e.g., KgNB or KDU by the target DU. For example, when handing over a UE to a target DU, the CU may send the current KgNB or KDU and a counter value to the target DU, e.g., in a handover preparation related signalling. The target DU may derive the new RRC security keys, e.g., K*RRCint and K*RRCenc from the current KgNB or KDU based on a counter value.
[0145] Similarly, the source DU (even if the target DU initiates the transmission, which is transparent to the source DU) may also send the counter value for deriving the new RRC security keys to the UE. After receiving the counter value, the UE may derive the new RRC security keys from the current KgNB or KDU based on the counter value.
[0146] In some implementations of the present disclosure, the new RRC security keys may be derived from a DU ID (e.g., target DU ID) or an index of DU ID, e.g., an index of target DU ID. For example, the new RRC security keys may be derived from the current RRC security keys, e.g., KRRCint and KRRCenc based on a target DU ID or an index of target DU ID. For example, K*RRCint = KDF (KRRCint, DU ID) , while K*RRCenc= KDF (KRRCenc, DU ID) . For another example, the new RRC security keys are derived from the current KgNB or KDU or the like based on a target DU ID or an index of a target DU ID, e.g., K*RRCint = KDF (KgNB, DU ID) , while K*RRCenc= KDF (KgNB, DU ID) .
[0147] In the scenarios of inter-CU handover (or inter-gNB handover or the like) , the source cell and target cell belong to the different NEs or different CUs, both RRC security keys and UP security keys needs to change. In accordance with some aspects of the present disclosure, the source NE, e.g., by the source DU may indicate to the UE, e.g., in a handover command message or the like the following security related information: UE shall change the current RRC security keys, e.g., current KRRCint and KRRCenc, and shall change the current UP security keys, e.g., KUPenc and KUPint; or UE shall change the current key for deriving the security keys, e.g., KgNB or KDU.
[0148] In some implementations of the present disclosure, the source NE may decide to change the current KgNB or K*DU or the like to a new key, e.g., K*gNB or K*DU or the like. The source NE may send K*gNB or K*DU to the target NE. The target NE may use K*gNB or K*DU to derive the new RRC security keys and the new UP security keys. The source NE may also indicate the supported security algorithms to the target NE, so that the target NE can select or determine the security algorithms for the new security keys. The target NE may indicate the selected security algorithms to the UE via the source NE.
[0149] After receiving an indication of indicating to change the security keys or change the key for deriving the security keys, the UE may derive the new key, e.g., K*gNB or K*DU and further uses it to derive the new RRC security keys and the new UP security keys.
[0150] Figure 6 illustrates an example of a UE 600 in accordance with aspects of the present disclosure. The UE 600 may include a processor 602, a memory 604, a controller 606, and a transceiver 608. The processor 602, the memory 604, the controller 606, or the transceiver 608, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0151] The processor 602, the memory 604, the controller 606, or the transceiver 608, or various combinations or components thereof may be implemented in hardware (e.g., circuitry) . The hardware may include a processor, a digital signal processor (DSP) , an application-specific integrated circuit (ASIC) , or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0152] The processor 602 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof) . In some implementations, the processor 602 may be configured to operate the memory 604. In some other implementations, the memory 604 may be integrated into the processor 602. The processor 602 may be configured to execute computer-readable instructions stored in the memory 604 to cause the UE 600 to perform various functions of the present disclosure.
[0153] The memory 604 may include volatile or non-volatile memory. The memory 604 may store computer-readable, computer-executable code including instructions when executed by the processor 602 cause the UE 600 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 604 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0154] In some implementations, the processor 602 and the memory 604 coupled with the processor 602 may be configured to cause the UE 600 to perform one or more of the functions described herein (e.g., executing, by the processor 602, instructions stored in the memory 604) . For example, the processor 602 may support wireless communication at the UE 600 in accordance with examples as disclosed herein. The UE 600 may be configured to support a means for receiving security related information from a DU of a NE during a handover; and a means for determining, based on the security related information, whether to retain or change current RRC security keys for protection of RRC signaling between the DU and the UE, and whether to retain or change current UP security keys for protection of UP traffics between a CU of the NE and the UE.
[0155] The controller 606 may manage input and output signals for the UE 600. The controller 606 may also manage peripherals not integrated into the UE 600. In some implementations, the controller 606 may utilize an operating system such as or other operating systems. In some implementations, the controller 606 may be implemented as part of the processor 602.
[0156] In some implementations, the UE 600 may include at least one transceiver 608. In some other implementations, the UE 600 may have more than one transceiver 608. The transceiver 608 may represent a wireless transceiver. The transceiver 608 may include one or more receiver chains 610, one or more transmitter chains 612, or a combination thereof.
[0157] A receiver chain 610 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 610 may include one or more antennas for receive the signal over the air or wireless medium. The receiver chain 610 may include at least one amplifier (e.g., a low-noise amplifier (LNA) ) configured to amplify the received signal. The receiver chain 610 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 610 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.
[0158] A transmitter chain 612 may be configured to generate and transmit signals (e.g., control information, data, packets) . The transmitter chain 612 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM) , frequency modulation (FM) , or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM) . The transmitter chain 612 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 612 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0159] Figure 7 illustrates an example of a processor 700 in accordance with aspects of the present disclosure. The processor 700 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 700 may include a controller 702 configured to perform various operations in accordance with examples as described herein. The processor 700 may optionally include at least one memory 704, which may be, for example, an L1 / L2 / L3 cache. Additionally, or alternatively, the processor 700 may optionally include one or more arithmetic-logic units (ALUs) 706. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses) .
[0160] The processor 700 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 700) or other memory (e.g., random access memory (RAM) , read-only memory (ROM) , dynamic RAM (DRAM) , synchronous dynamic RAM (SDRAM) , static RAM (SRAM) , ferroelectric RAM (FeRAM) , magnetic RAM (MRAM) , resistive RAM (RRAM) , flash memory, phase change memory (PCM) , and others) .
[0161] The controller 702 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 700 to cause the processor 700 to support various operations in accordance with examples as described herein. For example, the controller 702 may operate as a control unit of the processor 700, generating control signals that manage the operation of various components of the processor 700. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.
[0162] The controller 702 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 704 and determine subsequent instruction (s) to be executed to cause the processor 700 to support various operations in accordance with examples as described herein. The controller 702 may be configured to track memory address of instructions associated with the memory 704. The controller 702 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 702 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 700 to cause the processor 700 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 702 may be configured to manage flow of data within the processor 700. The controller 702 may be configured to control transfer of data between registers, arithmetic logic units (ALUs) , and other functional units of the processor 700.
[0163] The memory 704 may include one or more caches (e.g., memory local to or included in the processor 700 or other memory, such RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementations, the memory 704 may reside within or on a processor chipset (e.g., local to the processor 700) . In some other implementations, the memory 704 may reside external to the processor chipset (e.g., remote to the processor 700) .
[0164] The memory 704 may store computer-readable, computer-executable code including instructions that, when executed by the processor 700, cause the processor 700 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 702 and / or the processor 700 may be configured to execute computer-readable instructions stored in the memory 704 to cause the processor 700 to perform various functions. For example, the processor 700 and / or the controller 702 may be coupled with or to the memory 704, the processor 700, the controller 702, and the memory 704 may be configured to perform various functions described herein. In some examples, the processor 700 may include multiple processors and the memory 704 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.
[0165] The one or more ALUs 706 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 706 may reside within or on a processor chipset (e.g., the processor 700) . In some other implementations, the one or more ALUs 706 may reside external to the processor chipset (e.g., the processor 700) . One or more ALUs 706 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 706 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 706 be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 706 may support logical operations such as AND, OR, exclusive-OR (XOR) , not-OR (NOR) , and not-AND (NAND) , enabling the one or more ALUs 706 to handle conditional operations, comparisons, and bitwise operations.
[0166] The processor 700 may support wireless communication in accordance with examples as disclosed herein. The processor 700 may be configured to or operable to support a means for receiving security related information from a DU of a NE during a handover; and a means for determining, based on the security related information, whether to retain or change current RRC security keys for protection of RRC signaling between the DU and the UE, and whether to retain or change current UP security keys for protection of UP traffics between a CU of the NE and the UE.
[0167] Figure 8 illustrates an example of a DU 800 of a UE in accordance with aspects of the present disclosure. The DU 800 may include a processor 802, a memory 804, a controller 806, and a transceiver 808. The processor 802, the memory 804, the controller 806, or the transceiver 808, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0168] The processor 802, the memory 804, the controller 806, or the transceiver 808, or various combinations or components thereof may be implemented in hardware (e.g., circuitry) . The hardware may include a processor, a digital signal processor (DSP) , an application-specific integrated circuit (ASIC) , or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0169] The processor 802 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof) . In some implementations, the processor 802 may be configured to operate the memory 804. In some other implementations, the memory 804 may be integrated into the processor 802. The processor 802 may be configured to execute computer-readable instructions stored in the memory 804 to cause the DU 800 to perform various functions of the present disclosure.
[0170] The memory 804 may include volatile or non-volatile memory. The memory 804 may store computer-readable, computer-executable code including instructions when executed by the processor 802 cause the DU 800 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 804 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0171] In some implementations, the processor 802 and the memory 804 coupled with the processor 802 may be configured to cause the DU 800 to perform one or more of the functions described herein (e.g., executing, by the processor 802, instructions stored in the memory 804) . For example, the processor 802 may support wireless communication at the DU 800 in accordance with examples as disclosed herein. The DU 800 may be configured to support a means for receiving, from a CU of the NE, RRC security related information, wherein the RRC security related information at least indicates key information related to RRC security keys for protection of RRC signaling between the DU and a UE; and a means for performing security processing on the RRC signaling between the DU and UE based on the RRC security related information.
[0172] The controller 806 may manage input and output signals for the DU 800. The controller 806 may also manage peripherals not integrated into the DU 800. In some implementations, the controller 806 may utilize an operating system such as or other operating systems. In some implementations, the controller 806 may be implemented as part of the processor 802.
[0173] In some implementations, the DU 800 may include at least one transceiver 808. In some other implementations, the DU 800 may have more than one transceiver 808. The transceiver 808 may represent a wireless transceiver. The transceiver 808 may include one or more receiver chains 810, one or more transmitter chains 812, or a combination thereof.
[0174] A receiver chain 810 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 810 may include one or more antennas for receive the signal over the air or wireless medium. The receiver chain 810 may include at least one amplifier (e.g., a low-noise amplifier (LNA) ) configured to amplify the received signal. The receiver chain 810 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 810 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.
[0175] A transmitter chain 812 may be configured to generate and transmit signals (e.g., control information, data, packets) . The transmitter chain 812 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM) , frequency modulation (FM) , or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM) . The transmitter chain 812 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 812 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0176] Figure 9 illustrates an example of a CU 900 of a NE in accordance with aspects of the present disclosure. The CU 900 may include a processor 902, a memory 904, a controller 906, and a transceiver 908. The processor 902, the memory 904, the controller 906, or the transceiver 908, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0177] The processor 902, the memory 904, the controller 906, or the transceiver 908, or various combinations or components thereof may be implemented in hardware (e.g., circuitry) . The hardware may include a processor, a digital signal processor (DSP) , an application-specific integrated circuit (ASIC) , or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0178] The processor 902 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof) . In some implementations, the processor 902 may be configured to operate the memory 904. In some other implementations, the memory 904 may be integrated into the processor 902. The processor 902 may be configured to execute computer-readable instructions stored in the memory 904 to cause the CU 900 to perform various functions of the present disclosure.
[0179] The memory 904 may include volatile or non-volatile memory. The memory 904 may store computer-readable, computer-executable code including instructions when executed by the processor 902 cause the CU 900 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 904 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0180] In some implementations, the processor 902 and the memory 904 coupled with the processor 902 may be configured to cause the CU 900 to perform one or more of the functions described herein (e.g., executing, by the processor 902, instructions stored in the memory 904) . For example, the processor 902 may support wireless communication at the CU 900 in accordance with examples as disclosed herein. The CU 900 may be configured to support a means for determining RRC security related information, wherein the RRC security related information at least indicates key information related to RRC security keys for protection of RRC signaling between a DU of the NE and a UE; and a means for transmitting the RRC security related information to the DU.
[0181] The controller 906 may manage input and output signals for the CU 900. The controller 906 may also manage peripherals not integrated into the CU 900. In some implementations, the controller 906 may utilize an operating system such as or other operating systems. In some implementations, the controller 906 may be implemented as part of the processor 902.
[0182] In some implementations, the CU 900 may include at least one transceiver 908. In some other implementations, the CU 900 may have more than one transceiver 908. The transceiver 908 may represent a wireless transceiver. The transceiver 908 may include one or more receiver chains 910, one or more transmitter chains 912, or a combination thereof.
[0183] A receiver chain 910 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 910 may include one or more antennas for receive the signal over the air or wireless medium. The receiver chain 910 may include at least one amplifier (e.g., a low-noise amplifier (LNA) ) configured to amplify the received signal. The receiver chain 910 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 910 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.
[0184] A transmitter chain 912 may be configured to generate and transmit signals (e.g., control information, data, packets) . The transmitter chain 912 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM) , frequency modulation (FM) , or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM) . The transmitter chain 912 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 912 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0185] Figure 10 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a UE as described herein. In some implementations, the UE may execute a set of instructions to control the function elements of the UE to perform the described functions.
[0186] At step 1001, the method may include receiving security related information from a DU of a NE during a handover. The operations of step 1001 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1001 may be performed by a UE as described with reference to Figure 6.
[0187] At step 1003, the method may include determining, based on the security related information, whether to retain or change current RRC security keys for protection of RRC signaling between the DU and the UE, and whether to retain or change current UP security keys for protection of UP traffics between a CU of the NE and the UE. The operations of step 1003 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of step 1003 may be performed by a UE as described with reference to Figure 6.
[0188] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0189] Figure 11 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a DU as described herein. In some implementations, the DU may execute a set of instructions to control the function elements of the DU to perform the described functions.
[0190] At step 1101, the method may include receiving, from a CU of the NE, RRC security related information, wherein the RRC security related information at least indicates key information related to RRC security keys for protection of RRC signaling between the DU and a UE. The operations of step 1101 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of step 1101 may be performed by a DU as described with reference to Figure 8.
[0191] At step 1103, the method may include performing security processing on the RRC signaling between the DU and UE based on the RRC security related information. The operations of step 1103 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of step 1103 may be performed by a DU as described with reference to Figure 8.
[0192] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0193] Figure 12 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a CU as described herein. In some implementations, the CU may execute a set of instructions to control the function elements of the CU to perform the described functions.
[0194] At step 1201, the method may include determining RRC security related information, wherein the RRC security related information at least indicates key information related to RRC security keys for protection of RRC signaling between a DU of the NE and a UE.The operations of step 1201 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of step 1201 may be performed by a CU as described with reference to Figure 9.
[0195] At step 1203, the method may include transmitting the RRC security related information to the DU. The operations of step 1203 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of step 1203 may be performed by a CU as described with reference to Figure 9.
[0196] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0197] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.
Claims
A distributed unit (DU) of a network equipment (NE) for wireless communication, comprising:at least one memory; andat least one processor coupled with the at least one memory and configured to cause the DU to:receive, from a central unit (CU) of the NE, radio resource control (RRC) security related information, wherein the RRC security related information at least indicates key information related to RRC security keys for protection of RRC signaling between the DU and a user equipment (UE) ; andperform security processing on the RRC signaling between the DU and UE based on the RRC security related information.The DU of claim 1, wherein the at least one processor is configured to further cause the DU to:receive, from the CU, a third packet data convergence protocol (PDCP) configuration associated with a data radio bearer (DRB) and a service data adaptation protocol (SDAP) configuration of the DRB;determine a DRB configuration based on the third PDCP configuration and the SDAP configuration; andsend the DRB configuration including the third PDCP configuration and the SDAP configuration to the UE.The DU of claim 1, wherein the key information related to RRC security keys includes a first key used for integrity protection of RRC signaling and a second key used for encryption protection of RRC signaling, and the RRC security related information further indicates an integrity algorithm associated with the first key and an encryption algorithm associated with the second key.The DU of claim 1, wherein the at least one processor is configured to further cause the DU to:determine an integrity algorithm and an encryption algorithm associated with the key information.The DU of claim 1, wherein the RRC security related information indicates a third key for the NE, and the at least one processor is configured to further cause the DU to:derive a first key used for integrity protection of RRC signaling and a second key used for encryption protection of RRC signaling based on the third key; andreceive an integrity algorithm associated with the first key and an encryption algorithm associated with the second key from the CU or determine an integrity algorithm associated with the first key and an encryption algorithm associated with the second key.The DU of claim 1, wherein the RRC security related information indicates a fourth key associated with the DU, wherein the fourth key is derived based on a third key for the NE, and the at least one processor is configured to further cause the DU to:derive a first key used for integrity protection of RRC signaling and a second key used for encryption protection of RRC signaling based on the fourth key; andreceive an integrity algorithm associated with the first key and an encryption algorithm associated with the second key from the CU or determine an integrity algorithm associated with the first key and an encryption algorithm associated with the second key.The DU of claim 5 or 6, wherein the at least one processor is configured to further cause the DU to:send an indication to the UE, indicating whether the NE is a CU-DU split architecture.The DU of claim 6, wherein the at least one processor is configured to further cause the DU to:send an indication to the UE, indicating whether the fourth key is used for derivation of the first key and the second key.The DU of claim 4, 5 or 6, wherein the RRC security related information further indicates integrity algorithms and encryption algorithms supported by the NE, the integrity algorithm associated with the first key is determined from the integrity algorithms supported by the NE, and the encryption algorithm associated with the second key is determined from the encryption algorithms supported by the NE.The DU of claim 1, wherein in the case that the UE is handed over from a first cell to a second cell, the at least one processor is configured to further cause the DU to:indicate to the UE one or multiple of whether to retain or change current RRC security keys for protection of RRC signaling used between the DU and the UE and whether to retain or change current user plane (UP) security keys for protection of UP traffics used between the CU and the UE.The DU of claim 10, wherein indicating the UE whether to retain or change a current RRC security or current UP security key comprises:indicating a new security key to be used by a key index same as or different from that of the current RRC security key or UP security key.The DU of claim 1, wherein in the case that the UE is handed over from a first cell to a second cell of the DU, the at least one processor is configured to further cause the DU to:indicate the UE to retain current RRC security keys for protection of RRC signaling used between the DU and the UE and current user plane (UP) security keys for protection of UP traffics used between the CU and the UE; orindicate the UE to retain all current security keys.The DU of claim 1, wherein in the case that the UE is handed over from a first cell of the DU to a second cell of a different DU of the NE, the at least one processor is configured to further cause the DU to:indicate the UE to change the current RRC security keys; andindicate the UE to retain the current UP security keys.The DU of claim 1, wherein in the case that the UE is handed over from a first cell of the NE to a second cell of a different NE, the at least one processor is configured to further cause the DU to:indicate the UE to change current RRC security keys for protection of RRC signaling used between the DU and the UE and current user plane (UP) security keys for protection of UP traffics used between the CU and the UE; orindicate the UE to change all current security keys; orindicate the UE to change a key used for deriving RRC security keys.A central unit (CU) of a network equipment (NE) for wireless communication, comprising:at least one memory; andat least one processor coupled with the at least one memory and configured to cause the CU to:determine radio resource control (RRC) security related information, wherein the RRC security related information at least indicates key information related to RRC security keys for protection of RRC signaling between a distributed unit (DU) of the NE and a user equipment (UE) ; andtransmit the RRC security related information to the DU.The CU of claim 15, wherein in the case that the UE is handed over from a first cell of the DU to a second cell of a different DU of the NE, the at least one processor is configured to further cause the CU to:indicate to the different DU one or multiple of a counter, current RRC security keys, or a current security key from which the current RRC security keys are derived.The CU of claim 15, wherein in the case that the UE is handed over from a first cell of the NE to a second cell of a different NE, the at least one processor is configured to further cause the CU to:indicate to the different NE a new security key from which new RRC security keys can be derived.A user equipment (UE) for wireless communication, comprising:at least one memory; andat least one processor coupled with the at least one memory and configured to cause the UE to:receive security related information from a distributed unit (DU) of a network equipment (NE) during a handover; anddetermine, based on the security related information, whether to retain or change current radio resource control (RRC) security keys for protection of RRC signaling between the DU and the UE, and whether to retain or change current user plane (UP) security keys for protection of UP traffics between a central unit (CU) of the NE and the UE.The UE of claim 18, wherein determining whether to retain or change the current RRC security keys and whether to retain or change the current UP security keys comprises one or multiple of:determining to retain the current RRC security keys for protection of RRC signaling in the case that the security related information indicates indexes of new RRC security keys are same as that of the current RRC security keys;determining to change the current RRC security keys for protection of RRC signaling in the case that the security related information indicates indexes of new RRC security keys are different from that of the current RRC security keys;determining to retain the current UP security keys for protection of UP traffics in the case that the security related information indicates indexes of new UP security keys are same as that of the current UP security keys; ordetermining to change the current UP security keys for protection of UP traffics in the case that the security related information indicates indexes of new UP security keys are different from that of the current UP security keys.A method performed by a distributed unit (DU) of a network equipment (NE) , comprising:receiving, from a central unit (CU) of the NE, radio resource control (RRC) security related information, wherein the RRC security related information at least indicates key information related to RRC security keys for protection of RRC signaling between the DU and a user equipment (UE) ; andperforming security processing on the RRC signaling between the DU and UE based on the RRC security related information.
Citation Information
Patent Citations
Data security protection method and communication device
CN119584104A
Control signaling processing method, device, and system
US20190253895A1
Method and apparatus for performing handover in mobile communication system
US20200137638A1