Method for managing authentication key related to handover
The handover keychain model in 5G networks addresses key management challenges during handovers, ensuring secure and efficient communication, thus enhancing reliability and reducing latency.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-08-29
- Publication Date
- 2026-03-12
AI Technical Summary
Existing wireless communication systems face challenges in efficiently managing authentication keys during handovers in 5G networks, particularly in scenarios requiring ultra-reliable and low-latency communications, which can impact system performance and security.
A method for managing authentication keys during handovers in 5G networks, involving the use of a handover keychain model and secure key transfer mechanisms to ensure seamless and secure communication between base stations and user equipment.
Enhances the reliability and security of handover processes in 5G networks by maintaining secure communication links and reducing latency, thereby improving overall system performance.
Smart Images

Figure KR2025013269_12032026_PF_FP_ABST
Abstract
Description
Handover-related authentication key management method
[0001] This specification relates to mobile communication.
[0002] 3GPP (3rd generation partnership project) LTE (long-term evolution) is a technology designed to enable high-speed packet communication. Many methods have been proposed to achieve LTE goals, such as reducing costs for users and operators, improving service quality, expanding coverage, and increasing system capacity. As high-level requirements, 3GPP LTE demands reduced cost per bit, improved service availability, flexible use of frequency bands, a simple structure, open interfaces, and appropriate power consumption of terminals.
[0003] Work has begun at the ITU (International Telecommunication Union) and 3GPP to develop requirements and specifications for new radio (NR) systems. 3GPP must identify and develop the technical components necessary to successfully standardize NR in a timely manner, satisfying both urgent market demands and the longer-term requirements presented by the ITU-R (ITU Radio Communication Sector) IMT (International Mobile Telecommunications)-2020 process. Furthermore, NR must be able to utilize any spectrum band up to at least 100 GHz so that it can be used for wireless communication even in the distant future.
[0004] NR aims to be a single technology framework that addresses all deployment scenarios, usage scenarios, and requirements, including enhanced mobile broadband (eMBB), massive machine type communications (mMTC), and ultra-reliable and low latency communications (URLLC). NR must be inherently forward-compatible.
[0005] When the AMF receives an indicator from the target base station, it transmits it to the target base station without increasing the NCC.
[0006] FIG. 1 shows an example of a communication system to which the implementation of the present specification is applied.
[0007] FIG. 2 shows an example of a wireless device to which the implementation of the present specification applies.
[0008] FIG. 3 shows an example of a UE to which the implementation of the present specification applies.
[0009] Figure 4 is a structural diagram of a next-generation mobile communication network.
[0010] FIG. 5 shows an example of a 5G system structure to which the implementation of the present specification is applied.
[0011] FIGS. 6 and FIGS. 7 illustrate examples of registration procedures to which the implementation of the present specification applies.
[0012] Figure 8 shows an example of a key system in 5GS.
[0013] Figure 9 shows an example of a handover keychain model.
[0014] Figure 10 shows an example of NCC handling in Xn handover.
[0015] FIGS. 11 and FIGS. 12 illustrate examples of an LTM procedure according to an embodiment of the present specification.
[0016] FIG. 13 shows an example of an Xn handover procedure according to an embodiment of the present specification.
[0017] Figure 14 illustrates the procedure of AMF according to the disclosure of this specification.
[0018] Figure 15 illustrates the procedure of a target base station according to the disclosure of this specification.
[0019] The following techniques, devices, and systems may be applied to various wireless multiple access systems. Examples of multiple access systems include code division multiple access (CDMA) systems, frequency division multiple access (FDMA) systems, time division multiple access (TDMA) systems, orthogonal frequency division multiple access (OFDMA) systems, single carrier frequency division multiple access (SC-FDMA) systems, and multicarrier frequency division multiple access (MC-FDMA) systems. CDMA may be implemented through wireless technologies such as universal terrestrial radio access (UTRA) or CDMA2000. TDMA may be implemented through wireless technologies such as global system for mobile communications (GSM), general packet radio service (GPRS), or enhanced data rates for GSM evolution (EDGE). OFDMA can be implemented through wireless technologies such as IEEE (Institute of Electrical and Electronics Engineers) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, or E-UTRA (evolved UTRA). UTRA is part of UMTS (universal mobile telecommunications system). 3GPP (3rd generation partnership project) LTE (long-term evolution) is part of E-UMTS (evolved UMTS) using E-UTRA.3GPP LTE uses OFDMA in the downlink (DL) and SC-FDMA in the uplink (UL). Evolutions of 3GPP LTE include LTE-A (advanced), LTE-A Pro, and / or 5G NR (new radio).
[0020] For convenience of explanation, the implementation of this specification is primarily described in relation to a 3GPP-based wireless communication system. However, the technical features of this specification are not limited thereto. For example, the following detailed description is provided based on a mobile communication system corresponding to a 3GPP-based wireless communication system. However, aspects of this specification that are not limited to a 3GPP-based wireless communication system can be applied to other mobile communication systems.
[0021] For terms and technologies used in this specification that are not specifically described, reference may be made to wireless communication standard documents published prior to this specification.
[0022] As used herein, "A or B" can mean "only A," "only B," or "both A and B." Alternatively, as used herein, "A or B" can be interpreted as "A and / or B." For example, as used herein, "A, B or C" can mean "only A," "only B," "only C," or "any combination of A, B and C."
[0023] A slash ( / ) or a comma used in this specification may mean "and / or." For example, "A / B" may mean "A and / or B." Accordingly, "A / B" may mean "only A," "only B," or "both A and B." For example, "A, B, C" may mean "A, B or C."
[0024] In this specification, "at least one of A and B" may mean "only A," "only B," or "both A and B." Additionally, in this specification, the expressions "at least one of A or B" or "at least one of A and / or B" may be interpreted as synonymous with "at least one of A and B."
[0025] Additionally, in this specification, "at least one of A, B and C" may mean "only A," "only B," "only C," or "any combination of A, B and C." Furthermore, "at least one of A, B or C" or "at least one of A, B and / or C" may mean "at least one of A, B and C."
[0026] Additionally, parentheses used in this specification may mean "for example." Specifically, when indicated as "control information (PDCCH)," "PDCCH" may be proposed as an example of "control information." In other words, "control information" in this specification is not limited to "PDCCH," and "PDCCH" may be proposed as an example of "control information." Furthermore, even when indicated as "control information (i.e., PDCCH)," "PDCCH" may be proposed as an example of "control information."
[0027] Technical features described individually within a single drawing in this specification may be implemented individually or simultaneously.
[0028] Although not limited thereto, the various descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed herein may be applied to various fields requiring wireless communication and / or connectivity between devices (e.g., 5G).
[0029] Hereinafter, the present specification will be described in more detail with reference to the drawings. In the following drawings and / or description, the same reference numbers may refer to the same or corresponding hardware blocks, software blocks, and / or functional blocks, unless otherwise indicated.
[0030] FIG. 1 shows an example of a communication system to which the implementation of the present specification is applied.
[0031] The 5G usage scenario shown in FIG. 1 is merely an example, and the technical features of this specification may be applied to other 5G usage scenarios not shown in FIG. 1.
[0032] The three main requirement categories for 5G are (1) enhanced mobile broadband (eMBB), (2) massive machine type communication (mMTC), and (3) ultra-reliable and low latency communications (URLLC).
[0033] Referring to FIG. 1, a communication system (1) includes wireless devices (100a to 100f), a base station (BS; 200), and a network (300). FIG. 1 illustrates a 5G network as an example of a network of the communication system (1), but the implementation of the present disclosure is not limited to a 5G system and can be applied to future communication systems beyond the 5G system.
[0034] The base station (200) and the network (300) may be implemented as wireless devices, and a particular wireless device may operate as a base station / network node in relation to other wireless devices.
[0035] Wireless devices (100a to 100f) represent devices that perform communication using radio access technology (RAT) (e.g., 5G NR or LTE) and may also be referred to as communication / wireless / 5G devices. Wireless devices (100a to 100f) may include, but are not limited to, robots (100a), vehicles (100b-1 and 100b-2), extended reality (XR) devices (100c), portable devices (100d), home appliances (100e), IoT devices (100f), and artificial intelligence (AI) devices / servers (400). For example, vehicles may include vehicles with wireless communication capabilities, autonomous vehicles, and vehicles capable of performing communication between vehicles. Vehicles may include unmanned aerial vehicles (UAVs) (e.g., drones). XR devices may include AR / VR / mixed reality (MR) devices and may be implemented in the form of head-mounted devices (HMDs) and head-up displays (HUDs) mounted on vehicles, televisions, smartphones, computers, wearable devices, home appliances, digital signs, vehicles, robots, etc. Portable devices may include smartphones, smart pads, wearable devices (e.g., smartwatches or smart glasses), and computers (e.g., laptops). Home appliances may include TVs, refrigerators, and washing machines. IoT devices may include sensors and smart meters.
[0036] In this specification, wireless devices (100a to 100f) may be referred to as user equipment (UE). The UE may include, for example, a mobile phone, a smartphone, a laptop computer, a digital broadcasting terminal, a personal digital assistant (PDA), a portable multimedia player (PMP), a navigation system, a slate PC, a tablet PC, an ultrabook, a vehicle, a vehicle with autonomous driving functions, a connected car, a UAV, an AI module, a robot, an AR device, a VR device, an MR device, a holographic device, a public safety device, an MTC device, an IoT device, a medical device, a fintech device (or a financial device), a security device, a weather / environmental device, a 5G service-related device, or a 4th industrial revolution-related device.
[0037] For example, a UAV may be an aircraft that is unmanned and navigated by radio control signals.
[0038] For example, a VR device may include a device for implementing objects or backgrounds in a virtual environment. For example, an AR device may include a device that implements objects or backgrounds in a virtual world by connecting them to objects or backgrounds in the real world. For example, an MR device may include a device that implements objects or backgrounds in a virtual world by merging them with objects or backgrounds in the real world. For example, a holographic device may include a device that implements 360-degree stereoscopic images by recording and reproducing three-dimensional information using the light interference phenomenon that occurs when two laser lights, called holograms, meet.
[0039] For example, a public safety device may include an image relay device or imaging device that can be worn on the user's body.
[0040] For example, MTC devices and IoT devices may be devices that do not require direct human intervention or operation. For instance, MTC devices and IoT devices may include smart meters, vending machines, thermometers, smart light bulbs, door locks, or various sensors.
[0041] For example, a medical device may be a device used for the purpose of diagnosing, treating, alleviating, curing, or preventing a disease. For example, a medical device may be a device used to diagnose, treat, alleviate, or correct an injury or damage. For example, a medical device may be a device used for the purpose of examining, replacing, or modifying a structure or function. For example, a medical device may be a device used for the purpose of regulating pregnancy. For example, a medical device may include a therapeutic device, a driving device, a (in vitro) diagnostic device, a hearing aid, or a surgical device.
[0042] For example, a security device may be a device installed to prevent potential risks and maintain safety. For example, a security device may be a camera, closed-circuit TV (CCTV), a recorder, or a black box.
[0043] For example, a fintech device may be a device capable of providing financial services such as mobile payments. For example, a fintech device may include a payment device or a POS system.
[0044] For example, a weather / environment device may include a device that monitors or predicts the weather / environment.
[0045] Wireless devices (100a to 100f) can be connected to a network (300) via a base station (200). AI technology can be applied to the wireless devices (100a to 100f), and the wireless devices (100a to 100f) can be connected to an AI server (400) via the network (300). The network (300) can be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR) network, and a network after 5G. The wireless devices (100a to 100f) can communicate with each other via the base station (200) / network (300), but can also communicate directly (e.g., sidelink communication) without going through the base station (200) / network (300). For example, vehicles (100b-1, 100b-2) can communicate directly (e.g., V2V (vehicle-to-vehicle) / V2X (vehicle-to-everything) communication). Also, IoT devices (e.g., sensors) can communicate directly with other IoT devices (e.g., sensors) or other wireless devices (100a to 100f).
[0046] Wireless communication / connections (150a, 150b, 150c) can be established between wireless devices (100a to 100f) and / or between wireless devices (100a to 100f) and base station (200) and / or between base station (200). Here, the wireless communication / connections can be established through various RATs (e.g., 5G NR), such as uplink / downlink communication (150a), sidelink communication (150b) (or D2D (device-to-device) communication), and communication between base stations (150c) (e.g., relay, IAB (integrated access and backhaul)). Through the wireless communication / connections (150a, 150b, 150c), wireless devices (100a to 100f) and base station (200) can transmit / receive wireless signals to / from each other. For example, wireless communication / connection (150a, 150b, 150c) may transmit / receive signals through various physical channels. To this end, based on various proposals in this specification, at least some of the following may be performed: a process for setting various configuration information for transmitting / receiving wireless signals, a process for various signal processing (e.g., channel encoding / decoding, modulation / demodulation, resource mapping / demapping, etc.), and a resource allocation process.
[0047] AI refers to the field of researching artificial intelligence or the methodologies to create it, while machine learning refers to the field of researching methodologies to define and solve various problems within the realm of artificial intelligence. Machine learning is also defined as an algorithm that improves performance on a task through continuous experience.
[0048] A robot can be defined as a machine that automatically processes or operates a given task based on its own capabilities. Specifically, a robot capable of perceiving its environment, making decisions, and performing actions on its own can be called an intelligent robot. Robots can be categorized into industrial, medical, household, and military applications based on their intended use or field. Robots are equipped with a drive unit, including an actuator or motor, enabling them to perform various physical actions, such as moving robot joints. Furthermore, mobile robots include wheels, brakes, and propellers in their drive unit, enabling them to drive on the ground or fly in the air.
[0049] Autonomous driving refers to the technology of driving on one's own, while autonomous vehicles refer to vehicles that drive without, or with minimal, user intervention. For example, autonomous driving can include technologies such as lane keeping, automatic speed control like adaptive cruise control, autonomous driving along a set route, and autonomous driving based on a set destination. Vehicles encompass all types of vehicles: those with internal combustion engines, hybrid vehicles with both internal combustion engines and electric motors, and electric vehicles with only electric motors. These vehicles can include not only cars but also trains and motorcycles. Autonomous vehicles can be viewed as robots with autonomous driving capabilities.
[0050] Extended reality is a general term for VR, AR, and MR. VR technology provides real-world objects and backgrounds as CG images only, AR technology provides virtual CG images over images of real objects, and MR technology is a CG technology that mixes and combines virtual objects with the real world. MR technology is similar to AR in that it displays real and virtual objects together. However, there is a difference: while AR uses virtual objects to complement real objects, MR uses virtual and real objects equally.
[0051] NR supports multiple numerologies, or subcarrier spacing (SCS), to support diverse 5G services. For example, an SCS of 15 kHz supports wide areas in traditional cellular bands; an SCS of 30 kHz / 60 kHz supports dense urban areas, lower latency, and wider carrier bandwidth; and an SCS of 60 kHz or higher supports bandwidths greater than 24.25 GHz to overcome phase noise.
[0052] The NR frequency band can be defined by two types of frequency ranges (FR1 and FR2). The numerical values of the frequency ranges can be changed. For example, the two types of frequency ranges (FR1 and FR2) can be as shown in Table 1 below. For convenience of explanation, among the frequency ranges used in NR systems, FR1 can mean the "sub-6GHz range," and FR2 can mean the "above 6GHz range," which can be referred to as millimeter wave (mmW).
[0053] Frequency Range Definition Frequency Range Subcarrier Spacing FR1 450 MHz - 6000 MHz 15, 30, 60 kHz FR2 24 250 MHz - 52600 MHz 60, 120, 240 kHz
[0054] As described above, the numerical values of the frequency range of the NR system may change. For example, FR1 may include a band of 410 MHz to 7125 MHz as shown in Table 2 below. That is, FR1 may include a frequency band of 6 GHz (or 5850, 5900, 5925 MHz, etc.) or higher. For example, the frequency band of 6 GHz (or 5850, 5900, 5925 MHz, etc.) or higher included within FR1 may include an unlicensed band. The unlicensed band may be used for various purposes, for example, for communication for vehicles (e.g., autonomous driving).
[0055] Frequency Range Definition Frequency Range Subcarrier Spacing FR1 4 10 MHz - 7 125 MHz 15, 30, 60 kHz FR2 24 250 MHz - 5 2600 MHz 60, 120, 240 kHz
[0056] Here, the wireless communication technology implemented in the wireless device of this specification may include LTE, NR, and 6G, as well as narrowband IoT (NB-IoT) for low-power communication. For example, NB-IoT technology may be an example of low-power wide-area network (LPWAN) technology and may be implemented according to standards such as LTE Cat NB1 and / or LTE Cat NB2, but is not limited to the names mentioned above. Additionally, or generally, the wireless communication technology implemented in the wireless device of this specification may perform communication based on LTE-M technology. For example, LTE-M technology may be an example of LPWAN technology and may be referred to by various names such as enhanced MTC (eMTC). For example, LTE-M technology may be implemented in at least one of various standards such as 1) LTE CAT 0, 2) LTE Cat M1, 3) LTE Cat M2, 4) LTE non-BL (non-bandwidth limited), 5) LTE-MTC, 6) LTE MTC, and / or 7) LTE M, and is not limited to the names mentioned above. Additionally or generally, wireless communication technology implemented in the wireless device of this specification may include at least one of ZigBee, Bluetooth, and / or LPWAN for low-power communication, and is not limited to the names mentioned above. For example, ZigBee technology may create personal area networks (PANs) related to small / low-power digital communication based on various standards such as IEEE 802.15.4, and may be referred to by various names.
[0057] FIG. 2 shows an example of a wireless device to which the implementation of the present specification applies.
[0058] In FIG. 2, the first wireless device (100) and / or the second wireless device (200) may be implemented in various forms depending on the use example / service. For example, {the first wireless device (100) and the second wireless device (200)} may correspond to at least one of {wireless devices (100a–100f) and base station (200)}, {wireless devices (100a–100f) and wireless devices (100a–100f)} and / or {base station (200) and base station (200)} of FIG. 1. The first wireless device (100) and / or the second wireless device (200) may be composed of various components, devices / parts and / or modules.
[0059] The first wireless device (100) may include at least one transceiver such as a transceiver (106), at least one processing chip such as a processing chip (101), and / or one or more antennas (108).
[0060] The processing chip (101) may include at least one processor, such as a processor (102), and at least one memory, such as a memory (104). Additionally and / or generally, the memory (104) may be placed outside the processing chip (101).
[0061] The processor (102) can control the memory (104) and / or the transceiver (106) and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed herein. For example, the processor (102) may process information within the memory (104) to generate a first information / signal and transmit a wireless signal containing the first information / signal through the transceiver (106). The processor (102) may receive a wireless signal containing a second information / signal through the transceiver (106) and process the second information / signal to store the obtained information in the memory (104).
[0062] Memory (104) may be connected to the processor (102) so as to be operable. Memory (104) may store various types of information and / or instructions. Memory (104) may store firmware and / or software code (105) that implements code, instructions, and / or a set of instructions that perform the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this specification when executed by the processor (102). For example, firmware and / or software code (105) may implement instructions that perform the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this specification when executed by the processor (102). For example, firmware and / or software code (105) may control the processor (102) to perform one or more protocols. For example, firmware and / or software code (105) may control the processor (102) to perform one or more wireless interface protocol layers.
[0063] Here, the processor (102) and memory (104) may be part of a communication modem / circuit / chip designed to implement a RAT (e.g., LTE or NR). A transceiver (106) may be connected to the processor (102) and may transmit and / or receive a wireless signal through one or more antennas (108). Each transceiver (106) may include a transmitter and / or receiver. The transceiver (106) may be interchangeably used with an RF (radio frequency) unit. In this specification, the first wireless device (100) may represent a communication modem / circuit / chip.
[0064] The second wireless device (200) may include at least one transceiver such as a transceiver (206), at least one processing chip such as a processing chip (201), and / or one or more antennas (208).
[0065] The processing chip (201) may include at least one processor, such as a processor (202), and at least one memory, such as a memory (204). Additionally and / or alternatively, the memory (204) may be placed outside the processing chip (201).
[0066] The processor (202) may control the memory (204) and / or the transceiver (206) and may be configured to implement the descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed herein. For example, the processor (202) may process information in the memory (204) to generate third information / signal and transmit a wireless signal including the third information / signal via the transceiver (206). The processor (202) may receive a wireless signal including fourth information / signal via the transceiver (206) and store information obtained by processing the fourth information / signal in the memory (204).
[0067] A memory (204) may be operatively connected to the processor (202). The memory (204) may store various types of information and / or instructions. The memory (204) may store firmware and / or software code (205) that implements instruction codes, commands and / or sets of instructions that, when executed by the processor (202), perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed herein. For example, the firmware and / or software code (205) may implement instructions that, when executed by the processor (202), perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed herein. For example, the firmware and / or software code (205) may control the processor (202) to perform one or more protocols. For example, the firmware and / or software code (205) may control the processor (202) to perform one or more air interface protocol layers.
[0068] Here, the processor (202) and memory (204) may be part of a communication modem / circuit / chip designed to implement a RAT (e.g., LTE or NR). A transceiver (206) may be connected to the processor (202) and may transmit and / or receive wireless signals via one or more antennas (208). Each transceiver (206) may include a transmitter and / or a receiver. The transceiver (206) may be used interchangeably with the RF unit. In the present specification, the second wireless device (200) may represent a communication modem / circuit / chip.
[0069] Hereinafter, hardware elements of the wireless device (100, 200) will be described in more detail. Although not limited thereto, one or more protocol layers may be implemented by one or more processors (102, 202). For example, one or more processors (102, 202) may implement one or more layers (e.g., functional layers such as a physical (PHY) layer, a media access control (MAC) layer, a radio link control (RLC) layer, a packet data convergence protocol (PDCP) layer, a radio resource control (RRC) layer, and a service data adaptation protocol (SDAP) layer). One or more processors (102, 202) may generate one or more protocol data units (PDUs), one or more service data units (SDUs), messages, control information, data, or information according to the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed herein. One or more processors (102, 202) can generate signals (e.g., baseband signals) including PDUs, SDUs, messages, control information, data or information according to the descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed herein and provide the signals to one or more transceivers (106, 206). One or more processors (102, 202) can receive signals (e.g., baseband signals) from one or more transceivers (106, 206) and obtain PDUs, SDUs, messages, control information, data or information according to the descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed herein.
[0070] One or more processors (102, 202) may be referred to as a controller, a microcontroller, a microprocessor, and / or a microcomputer. One or more processors (102, 202) may be implemented by hardware, firmware, software, and / or a combination thereof. For example, one or more application-specific integrated circuits (ASICs), one or more digital signal processors (DSPs), one or more digital signal processing devices (DSPDs), one or more programmable logic devices (PLDs), and / or one or more field programmable gate arrays (FPGAs) may be included in one or more processors (102, 202). For example, one or more processors (102, 202) may be composed of a set of communication control processors, application processors (APs), electronic control units (ECUs), central processing units (CPUs), graphic processing units (GPUs), and memory control processors.
[0071] One or more memories (104, 204) may be coupled to one or more processors (102, 202) and may store various forms of data, signals, messages, information, programs, codes, instructions, and / or commands. The one or more memories (104, 204) may be configured as random access memory (RAM), dynamic RAM (DRAM), read-only memory (ROM), erasable programmable ROM (EPROM), flash memory, volatile memory, nonvolatile memory, hard drive, register, cache memory, computer-readable storage media, and / or combinations thereof. The one or more memories (104, 204) may be located internally and / or externally to the one or more processors (102, 202). Additionally, the one or more memories (104, 204) may be coupled to the one or more processors (102, 202) via various technologies, such as wired or wireless connections.
[0072] One or more transceivers (106, 206) can transmit user data, control information, wireless signals / channels, etc., referred to in the descriptions, functions, procedures, proposals, methods, and / or flowcharts disclosed herein to one or more other devices. One or more transceivers (106, 206) can receive user data, control information, wireless signals / channels, etc., referred to in the descriptions, functions, procedures, proposals, methods, and / or flowcharts disclosed herein from one or more other devices. For example, one or more transceivers (106, 206) can be coupled to one or more processors (102, 202) and can transmit and receive wireless signals. For example, one or more processors (102, 202) can control one or more transceivers (106, 206) to transmit user data, control information, wireless signals, etc., to one or more other devices. Additionally, one or more processors (102, 202) can control one or more transceivers (106, 206) to receive user data, control information, wireless signals, etc. from one or more other devices.
[0073] One or more transceivers (106, 206) may be coupled to one or more antennas (108, 208). Additionally and / or alternatively, one or more transceivers (106, 206) may include one or more antennas (108, 208). One or more transceivers (106, 206) may be configured to transmit and receive user data, control information, wireless signals / channels, etc., as described in the descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed herein via one or more antennas (108, 208). In the present specification, one or more antennas (108, 208) may be multiple physical antennas or multiple logical antennas (e.g., antenna ports).
[0074] One or more transceivers (106, 206) may convert received user data, control information, wireless signals / channels, etc. from RF band signals to baseband signals in order to process the received user data, control information, wireless signals / channels, etc. using one or more processors (102, 202). One or more transceivers (106, 206) may convert processed user data, control information, wireless signals / channels, etc. from baseband signals to RF band signals using one or more processors (102, 202). For this purpose, one or more transceivers (106, 206) may include an (analog) oscillator and / or a filter. For example, one or more transceivers (106, 206) may up-convert an OFDM baseband signal to an OFDM signal via an (analog) oscillator and / or filter under the control of one or more processors (102, 202) and transmit the up-converted OFDM signal at a carrier frequency. One or more transceivers (106, 206) may receive an OFDM signal at a carrier frequency and down-convert the OFDM signal to an OFDM baseband signal via an (analog) oscillator and / or filter under the control of one or more processors (102, 202).
[0075] Although not illustrated in FIG. 2, the wireless device (100, 200) may further include additional components. The additional components (140) may be configured in various ways depending on the type of the wireless device (100, 200). For example, the additional components (140) may include at least one of a power unit / battery, an input / output (I / O) device (e.g., an audio I / O port, a video I / O port), a driving device, and a computing device. The additional components (140) may be connected to one or more processors (102, 202) via various technologies, such as a wired or wireless connection.
[0076] In an implementation of this specification, the UE may operate as a transmitting device in the uplink (UL; uplink) and as a receiving device in the downlink (DL; downlink). In an implementation of this specification, the base station may operate as a receiving device in the UL and as a transmitting device in the DL. For technical convenience, it is generally assumed that the first wireless device (100) operates as a UE and the second wireless device (200) operates as a base station. For example, a processor (102) connected to, mounted on, or released to the first wireless device (100) may be configured to perform UE operations according to an implementation of this specification or to control a transceiver (106) to perform UE operations according to an implementation of this specification. A processor (202) connected to, mounted on, or released to the second wireless device (200) may be configured to perform base station operations according to an implementation of this specification or to control a transceiver (206) to perform base station operations according to an implementation of this specification.
[0077] In this specification, the base station may be referred to as Node B, eNode B, or gNB.
[0078] FIG. 3 shows an example of a UE to which the implementation of the present specification applies.
[0079] Referring to FIG. 3, the UE (100) can correspond to the first wireless device (100) of FIG. 2.
[0080] The UE (100) includes a processor (102), memory (104), transceiver (106), one or more antennas (108), a power management module (141), a battery (142), a display (143), a keypad (144), a SIM (Subscriber Identification Module) card (145), a speaker (146), and a microphone (147).
[0081] The processor (102) may be configured to implement the descriptions, functions, procedures, proposals, methods and / or flowcharts disclosed herein. The processor (102) may be configured to control one or more other components of the UE (100) to implement the descriptions, functions, procedures, proposals, methods and / or flowcharts disclosed herein. A layer of a radio interface protocol may be implemented in the processor (102). The processor (102) may include an ASIC, other chipsets, logic circuits and / or data processing devices. The processor (102) may be an application processor. The processor (102) may include at least one of a DSP, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), and a modem (modulator and demodulator). An example of the processor (102) is the SNAPDRAGON manufactured by Qualcomm®. TM Series processors, EXYNOS made by Samsung® TM Series processors, A-series processors made by Apple®, HELIO made by MediaTek® TM ATOM series processors made by Intel® TM It can be found in the series processors or the corresponding next-generation processors.
[0082] Memory (104) is coupled to the processor (102) so as to be operable and stores various information for operating the processor (102). Memory (104) may include ROM, RAM, flash memory, memory card, storage medium and / or other storage device. When the implementation is implemented in software, the technology described herein may be implemented using modules (e.g., procedures, functions, etc.) that perform the descriptions, functions, procedures, proposals, methods and / or operation flowcharts disclosed herein. Modules may be stored in memory (104) and executed by the processor (102). Memory (104) may be implemented within the processor (102) or outside the processor (102), in which case it may be communicatively coupled to the processor (102) through various methods known in the technology.
[0083] A transceiver (106) is coupled to operate with a processor (102) and transmits and / or receives a wireless signal. The transceiver (106) includes a transmitter and a receiver. The transceiver (106) may include a baseband circuit for processing a wireless frequency signal. The transceiver (106) controls one or more antennas (108) to transmit and / or receive a wireless signal.
[0084] The power management module (141) manages the power of the processor (102) and / or the transceiver (106). The battery (142) supplies power to the power management module (141).
[0085] The display (143) outputs the result processed by the processor (102). The keypad (144) receives input to be used by the processor (102). The keypad (144) can be displayed on the display (143).
[0086] A SIM card (145) is an integrated circuit that securely stores an International Mobile Subscriber Identity (IMSI) and associated keys, and is used to identify and authenticate subscribers in mobile devices such as mobile phones and computers. Additionally, many SIM cards can store contact information.
[0087] The speaker (146) outputs sound-related results processed by the processor (102). The microphone (147) receives sound-related input to be used by the processor (102).
[0088] Figure 4 is a structural diagram of a next-generation mobile communication network.
[0089] 5GC (5G Core) may include various components, and in FIG. 5, some of them include AMF (Access and Mobility Management Function) (410), SMF (Session Management Function) (420), PCF (Policy Control Function) (430), UPF (User Plane Function) (440), AF (Application Function) (450), UDM (Unified Data Management) (460), and N3IWF (Non-3GPP (3rd Generation Partnership Project) Inter Working Function) (490).
[0090] The UE (100) is connected to the data network via the UPF (440) through the NG-RAN (Next Generation Radio Access Network) including the gNB (20).
[0091] The UE (100) can also receive data services through untrusted non-3GPP access, such as a WLAN (Wireless Local Area Network). To connect the non-3GPP access to the core network, an N3IWF (490) may be deployed.
[0092] The illustrated N3IWF (490) performs the function of managing interworking between non-3GPP access and 5G systems. When the UE (100) is connected to non-3GPP access (e.g., WiFi referred to as IEEE 801.11), the UE (100) can be connected to the 5G system through the N3IWF (490). The N3IWF (490) performs control signing with the AMF (410) and connects to the UPF (440) via the N3 interface for data transmission.
[0093] The illustrated AMF (410) can manage access and mobility in a 5G system. The AMF (410) can perform the function of managing Non-Access Stratum (NAS) security. The AMF (410) can perform the function of handling mobility in an idle state.
[0094] The illustrated UPF (440) is a type of gateway through which user data is transmitted and received. The UPF node (440) can perform all or part of the user plane functions of the S-GW (Serving Gateway) and P-GW (Packet Data Network Gateway) of 4th generation mobile communication.
[0095] The UPF (440) acts as a boundary point between the next generation radio access network (NG-RAN) and the core network, and is an element that maintains the data path between the gNB (20) and the SMF (420). Additionally, when the UE (100) moves across the area served by the gNB (20), the UPF (440) acts as a mobility anchor point. The UPF (440) can perform the function of handling PDUs. For mobility within the NG-RAN (Next Generation Radio Access Network defined in 3GPP Release-15 or later), packets can be routed through the UPF. Additionally, the UPF (440) may also function as an anchor point for mobility with other 3GPP networks (RANs defined prior to 3GPP Release-15, e.g., UTRAN, E-UTRAN (Evolved-UMTS (Universal Mobile Telecommunications System) Terrestrial Radio Access Network)) or GERAN (GSM (Global System for Mobile Communication) / EDGE (Enhanced Data rates for Global Evolution) Radio Access Network). The UPF (440) may correspond to a termination point of a data interface toward a data network.
[0096] The illustrated PCF (430) is a node that controls the operator's policy.
[0097] The illustrated AF (450) is a server for providing various services to the UE (100).
[0098] The illustrated UDM (460) is a type of server that manages subscriber information, such as the HSS (Home subscriber Server) of 4th generation mobile communication. The UDM (460) stores and manages the subscriber information in a Unified Data Repository (UDR).
[0099] The illustrated SMF (420) can perform the function of assigning the IP (Internet Protocol) address of the UE. Also, the SMF (420) can control the PDU (protocol data unit) session.
[0100] For reference, the reference numerals for AMF (410), SMF (420), PCF (430), UPF (440), AF (450), UDM (460), N3IWF (490), gNB (20), or UE (100) may be omitted below.
[0101] Fifth-generation mobile communication supports multiple numerologies or subcarrier spacings (SCS) to support various 5G services. For example, when the SCS is 15 kHz, it supports a wide area in traditional cellular bands; when the SCS is 30 kHz / 60 kHz, it supports dense-urban environments, lower latency, and wider carrier bandwidth; and when the SCS is 60 kHz or higher, it supports a bandwidth greater than 24.25 GHz to overcome phase noise.
[0102] FIG. 5 shows an example of a 5G system structure to which the implementation of the present specification is applied.
[0103] The 5G system (5GS) structure consists of the following network functions (NF).
[0104] - AUSF (Authentication Server Function)
[0105] - AMF (Access and Mobility Management Function)
[0106] - DN (Data Network), 예를 들어 운영자 서비스, 인터넷 접속 또는 타사 서비스
[0107] - USDF (Unstructured Data Storage Function)
[0108] - NEF (Network Exposure Function)
[0109] - I-NEF (Intermediate NEF)
[0110] - NRF (Network Repository Function)
[0111] - NSSF (Network Slice Selection Function)
[0112] - PCF (Policy Control Function)
[0113] - SMF (Session Management Function)
[0114] - UDM (Unified Data Management)
[0115] - UDR (Unified Data Repository)
[0116] - UPF (User Plane Function)
[0117] - UCMF (UE radio Capability Management Function)
[0118] - AF (Application Function)
[0119] - UE (User Equipment)
[0120] - (R)AN ((Radio) Access Network)
[0121] - 5G-EIR (5G-Equipment Identity Register)
[0122] - NWDAF (Network Data Analytics Function)
[0123] - CHF (CHarging Function)
[0124] Additionally, the following network features may be considered:
[0125] - N3IWF (Non-3GPP InterWorking Function)
[0126] - TNGF (Trusted Non-3GPP Gateway Function)
[0127] - W-AGF (Wireline Access Gateway Function)
[0128] Figure 5 shows the 5G system structure in a non-roaming case using a reference point representation that shows how various network functions interact with each other.
[0129] In Fig. 5, for clarity of the point-to-point diagram, UDSF, NEF, and NRF are not described. However, all network functions shown can interact with UDSF, UDR, NEF, and NRF as needed.
[0130] For clarity, the connection between UDR and other NFs (e.g., PCF) is not shown in FIG. 4. For clarity, the connection between NWDAF and other NFs (e.g., PCF) is not shown in FIG. 4.
[0131] The 5G system architecture includes the following benchmarks:
[0132] - N1: Reference point between UE and AMF.
[0133] - N2: Reference point between (R)AN and AMF.
[0134] - N3: Reference point between (R)AN and UPF.
[0135] - N4: Reference point between SMF and UPF.
[0136] - N6: Reference point between the UPF and the data network.
[0137] - N9: Reference point between two UPFs.
[0138] The following reference points show the interactions that exist between the NF services of NF.
[0139] - N5: Reference point between PCF and AF.
[0140] - N7: Reference point between SMF and PCF.
[0141] - N8: Reference point between UDM and AMF.
[0142] - N10: Reference point between UDM and SMF.
[0143] - N11: Reference point between AMF and SMF.
[0144] - N12: Reference point between AMF and AUSF.
[0145] - N13: Reference point between UDM and AUSF.
[0146] - N14: Reference point between two AMFs.
[0147] - N15: Reference point between PCF and AMF for non-roaming scenarios, reference point between PCF and AMF of the visited network for roaming scenarios.
[0148] - N16: Reference point between two SMFs (in the case of roaming, between the SMF of the visited network and the SMF of the home network)
[0149] - N22: Reference point between AMF and NSSF.
[0150] In some cases, two NFs may need to be connected to each other to service the UE.
[0151] <Registration Procedure>
[0152] The registration procedure is described. Refer to Section 4.2.2.2 of 3GPP TS 23.502 V16.3.0 (2019-12).
[0153] FIGS. 6 and FIGS. 7 illustrate examples of registration procedures to which the implementation of the present specification applies.
[0154] The UE must register with the network to receive services, enable mobility tracking, and enable reachability. The UE initiates the registration process using one of the following registration types.
[0155] - Initial registration for the 5GS; or
[0156] - Mobility registration update; or
[0157] - Periodic registration update; or
[0158] - Emergency registration
[0159] The general registration procedure of Figures 6 and 7 applies to all registration procedures described above, but the periodic registration update does not need to include all parameters used in other registration procedures.
[0160] The general registration procedure of Figures 6 and 7 is used when a UE is registered to a 3GPP connection when it is already registered to a non-3GPP connection, and vice versa. To register a UE to a 3GPP connection when it is already registered to a non-3GPP connection scenario, an AMF change may be required.
[0161] First, the procedure of Fig. 6 is explained.
[0162] (1) Step 1: The UE transmits a Registration Request message to the (R)AN. The Registration Request message corresponds to an AN message.
[0163] A registration request message may include AN parameters. For NG-RAN, AN parameters include, for example, 5G-S-TMSI (5G SAE temporary mobile subscriber identity) or GUAMI (globally unique AMF ID), a selected PLMN (public land mobile network) ID (or PLMN ID and NID (network identifier)), and requested NSSAI (Requested network slice selection assistance information). AN parameters also include an establishment cause. The establishment cause provides the reason for requesting the establishment of an RRC connection. Whether and how the UE includes the requested NSSAI as part of the AN parameters depends on the value of the access stratum connection establishment NSSAI inclusion mode parameter.
[0164] A registration request message may include a registration type. The registration type indicates whether the UE wants to perform an initial registration (i.e., the UE is in RM-DEREGISTERED state), or a mobility registration update (i.e., the UE is in RM-REGISTERED state and the registration procedure is initiated because the UE moves, or the UE wants to update its capabilities or protocol parameters, or because the UE requests a change in the set of network slices it is allowed to use), or a periodic registration update (i.e., the UE is in RM-REGISTERED state and the registration procedure is initiated because the periodic registration update timer has expired), or an emergency registration (i.e., the UE is in restricted service state).
[0165] When a UE performs initial registration, the UE specifies the UE ID in the registration request message as follows, listed in order of decreasing priority.
[0166] i) If the UE has a valid EPS (evolved packet system) GUTI (globally unique temporary identifier), the 5G-GUTI mapped from the EPS GUTI;
[0167] ii) Native 5G-GUTI assigned by the PLMN for which the UE is attempting to register (if available);
[0168] iii) Native 5G-GUTI assigned by a PLMN equivalent to the PLMN for which the UE is attempting to register;
[0169] iv) Native 5G-GUTI assigned by other PLMNs (if available);
[0170] v) Otherwise, the UE includes SUCI (subscriber concealed identifier) in the registration request message.
[0171] If the UE performing the initial registration has both a valid EPS GUTI and a native 5G-GUTI, the UE also marks the native 5G-GUTI as an additional GUTI. If one or more native 5G-GUTIs are available, the UE selects the 5G-GUTIs from items (ii)-(iv) in the list above in decreasing order of priority.
[0172] When the UE performs initial registration with native 5G-GUTI, the UE displays relevant GUAMI information in AN parameters. When the UE performs initial registration with SUCI, the UE does not display GUAMI information in AN parameters.
[0173] In the case of emergency registration, SUCI is included if the UE does not have a valid 5G-GUTI, and PEI is included if the UE does not have a SUPI (subscriber permanent identifier) and does not have a valid 5G-GUTI. In other cases, a 5G-GUTI is included, which indicates the last serving AMF.
[0174] The registration request message may also include security parameters, PDU session status, etc. Security parameters are used for authentication and integrity protection. The PDU session status indicates a previously established PDU session in the UE. When the UE is connected to two AMFs belonging to different PLMNs via a 3GPP connection and a non-3GPP connection, the PDU session status indicates the established PDU session of the current PLMN in the UE.
[0175] (2) Step 2: (R)AN selects AMF.
[0176] If 5G-S-TMSI or GUAMI is not included, or if 5G-S-TMSI or GUAMI does not represent a valid AMF, (R)AN selects an AMF based on (R)AT and the requested NSSAI, if available.
[0177] If the UE is in the CM-CONNECTED state, (R)AN can forward a registration request message to the AMF based on the UE's N2 connection.
[0178] If (R)AN cannot select a suitable AMF, (R)AN performs AMF selection by forwarding a registration request message to the AMF configured in (R)AN.
[0179] (3) Step 3: (R)AN sends a registration request message to the new AMF. The registration request message corresponds to the N2 message.
[0180] The registration request message may include all information and / or part of the information contained in the registration request message received from the UE described in Step 1.
[0181] The registration request message may include N2 parameters. When NG-RAN is used, the N2 parameters include the selected PLMN ID (or PLMN ID and NID), location information and cell ID associated with the cell where the UE is camping, and a UE context request indicating that a UE context including security information in NG-RAN must be established. When NG-RAN is used, the N2 parameters also include the cause for establishment.
[0182] If the registration type indicated by the UE is a periodic registration update, steps 4-19 described below may be omitted.
[0183] (4) Step 4: If the UE's 5G-GUTI is included in the registration request message and the serving AMF has changed since the last registration procedure, the new AMF may invoke the Namf_Communication_UEContextTransfer service operation to the previous AMF, including the full registration request non-access stratum (NAS) message to request the UE's SUPI and UE context.
[0184] (5) Step 5: The previous AMF can respond to the new AMF for the Namf_Communication_UEContextTransfer call, including the UE's SUPI and UE context.
[0185] (6) Step 6: If SUCI is not provided by the UE or not retrieved from the previous AMF, the new AMF may initiate an ID request procedure by sending an Identity Request message to request SUCI from the UE.
[0186] (7) Step 7: The UE may respond with an Identity Response message containing SUCI. The UE derives SUCI using the provided public key of the home PLMN (HPLMN).
[0187] (8) Step 8: The new AMF may decide to call AUSF to initiate UE authentication. In this case, the new AMF selects AUSF based on SUPI or SUCI.
[0188] (9) Step 9: Authentication / security may be established by UE, new AMF, AUSF and / or UDM.
[0189] (10) Step 10: If the AMF has changed, the new AMF may call the Namf_Communication_RegistrationCompleteNotify service operation to notify the old AMF that the UE registration with the new AMF is complete. If the authentication / security procedure fails, the registration is rejected and the new AMF may call the Namf_Communication_RegistrationCompleteNotify service operation with a reject indication reason code to the old AMF. The old AMF may continue as if the UE context transfer service operation was not received.
[0190] (11) Step 11: If the PEI is not provided by the UE or has not been retrieved from the previous AMF, the new AMF may initiate an Identity Request procedure by sending an Identity Request message to the UE to retrieve the PEI. The PEI is transmitted in encryption, except in cases where the UE cannot perform emergency registration and be authenticated.
[0191] (12) Step 12: Optionally, the new AMF can call the N5g-eir_EquipmentIdentityCheck_Get service operation to start ME ID checking.
[0192] Now, the procedure of Fig. 7 following the procedure of Fig. 6 is explained.
[0193] (13) Step 13: If you perform Step 14 below, the new AMF can select a UDM based on SUPI, and the UDM can select a UDR instance.
[0194] (14) Step 14: New AMFs can be registered with UDM.
[0195] (15) Step 15: The new AMF can select PCF.
[0196] (16) Step 16: The new AMF may optionally establish / modify AM policy associations.
[0197] (17) Step 17: The new AMF can send update / release SM context messages (e.g., Nsmf_PDUSession_UpdateSMContext and / or Nsmf_PDUSession_ReleaseSMContext) to the SMF.
[0198] (18) Step 18: If the new AMF and the previous AMF are in the same PLMN, the new AMF can send a request to modify the UE context to N3IWF / TNGF / W-AGF.
[0199] (19) Step 19: N3IWF / TNGF / W-AGF can send a UE context modification response to the new AMF.
[0200] (20) Step 20: After the new AMF receives a response message from N3IWF / TNGF / W-AGF in Step 19, the new AMF can register with UDM.
[0201] (21) Step 21: The new AMF sends a Registration Accept message to the UE.
[0202] The new AMF sends a registration acceptance message to the UE indicating that the registration request has been accepted. If the new AMF assigns a new 5G-GUTI, the 5G-GUTI is included. If the UE is already in the RM-REGISTERED state via another connection on the same PLMN, the UE uses the 5G-GUTI received in the registration acceptance message for both registrations. If the registration acceptance message does not include a 5G-GUTI, the UE uses the 5G-GUTI assigned to the existing registration for the new registration as well. If the new AMF assigns a new registration area, it transmits the registration area to the UE via the registration acceptance message. If the registration acceptance message does not contain a registration area, the UE considers the previous registration area to be valid. Mobility Restrictions are included when mobility restrictions apply to the UE and the registration type is not an urgent registration. The new AMF indicates the PDU session established for the UE in the PDU session state. The UE locally removes internal resources associated with PDU sessions that are not marked as established in the received PDU session state. When a UE connects to two AMFs belonging to different PLMNs via a 3GPP connection and a non-3GPP connection, the UE locally removes internal resources associated with the PDU session of the current PLMN that are not indicated as established in the received PDU session state. If PDU session state information is present in the registration acceptance message, the new AMF instructs the UE on the PDU session state.
[0203] The Allowed NSSAI provided in the registration acceptance message is valid in the registration area and applies to all PLMNs having a tracking area included in the registration area. The Mapping of Allowed NSSAI is to map the HPLMN S-NSSAI to each S-NSSAI of the Allowed NSSAI. The Mapping of Configured NSSAI is to map the HPLMN S-NSSAI to each S-NSSAI of the Configured NSSAI for the serving PLMN.
[0204] Additionally, optionally, the new AMF performs UE policy association establishment.
[0205] (22) Step 22: If the UE successfully updates itself, it can send a Registration Complete message to the new AMF.
[0206] The UE may send a registration complete message to the new AMF to confirm that a new 5G-GUTI has been allocated.
[0207] (23) Step 23: In the case of registration via a 3GPP connection, if the new AMF does not release the signaling connection, the new AMF may send RRC Inactive Assistance information to the NG-RAN. In the case of registration via a non-3GPP connection, if the UE is in a CM-CONTENED state on the 3GPP connection, the new AMF may send RRC Inactive Assistance information to the NG-RAN.
[0208] (24) Step 24: AMF can perform information updates on UDM.
[0209] (25) Step 25: The UE can execute network slice-specific authentication and authorization (NSSAA) procedures.
[0210] Key hierarchy
[0211] Figure 8 shows an example of a key system in 5GS.
[0212] The following is a detailed explanation of the key hierarchy generation keys for 5GS.
[0213] The authentication-related keys (see Fig. 8) include K and CK / IK. In the case of EAP-AKA', the CK' and IK' keys are derived from CK and IK.
[0214] The key system (see Fig. 8) includes K AUSF , K SEAF , K AMF , K NASint , K NASenc , K N3IWF , K gNB , K RRCint , K RRCenc , K UPint and K UPenc is included.
[0215] Key for Home Network AUSF:
[0216] - K AUSF In the case of EAP-AKA', ME and AUSF are keys derived from CK' and IK', and CK' and IK' are received by AUSF as part of the AV transformed by ARPF. Or,
[0217] - K AUSF In the case of 5G AKA, ME and ARPF are keys derived from CK and IK, and K AUSF It is received by AUSF as part of the 5G HE AV converted from ARPF.
[0218] - K SEAF is an anchor key from which ME and AUSF are derived from KAUSF. K SEAFAUSF provides to the SEAF of the serving network.
[0219] Key for AMF in the serving network:
[0220] - K AMF is a key from which ME and SEAF are derived from KSEAF. K AMF is additionally derived when ME and source AMF perform horizontal key derivation.
[0221] Keys for NAS signaling:
[0222] - K NASint ME and AMF are keys derived from KAMF, and are used only for NAS signaling protection using specific integrity algorithms.
[0223] - K NASenc ME and AMF are keys derived from KAMF, and are used only for NAS signaling protection using specific encryption algorithms.
[0224] Keys for NG-RAN:
[0225] - K gNB is a key from which ME and AMF are derived from KAMF. K gNB is additionally derived when ME and source gNB perform horizontal or vertical key derivation. K gNB is between ME and ng-eNB eNB is used as.
[0226] Keys for UP traffic:
[0227] - K UPenc is a key derived from KgNB by ME and gNB, used only for protecting UP traffic using a specific encryption algorithm.
[0228] - K UPint It is a key derived from KgNB by ME and gNB, used only for protecting UP traffic between ME and gNB using a specific integrity algorithm.
[0229] Keys for RRC signaling:
[0230] - KRRCint is a key derived by ME and gNB from KgNB and is used only for RRC signaling protection using a specific integrity algorithm.
[0231] - K RRCenc is a key derived from KgNB by ME and gNB and is used only for RRC signaling protection using a specific encryption algorithm.
[0232] Middle Key:
[0233] - NH is a key derived by ME and AMF to provide forward secrecy.
[0234] - K NG-RAN * is the key derived by the ME and NG-RAN (i.e., gNB or ng-eNB) when performing horizontal or vertical key derivation using KDF.
[0235] - K AMF ' is a key that the ME and AMF can derive when the UE moves from one AMF to another during inter-AMF mobility, and uses KDF.
[0236] Key for non-3GPP access:
[0237] - K N3IWF ME and AMF are K for non-3GPP access AMF It is the key derived from. K N3IWF It is not transmitted between N3IWF.
[0238] Key Handling in Handovers
[0239] Figure 9 shows an example of a handover keychain model.
[0240] K during handover NG-RAN * / The general principles for key processing in NH are shown in Figure 9.
[0241] The following is an outline of the key processing model to clarify the intended structure of key derivation.
[0242] Whenever the initial AS security context needs to be established between the UE and the gNB / ng-eNB, the AMF and the UE K gNB and the next hop parameter (NH) must be derived. K gNB Wow NH is K AMF It is derived from. The NH chaining counter (NCC) is each K gNB and is connected to the NH parameters. All K gNB is connected to the NCC corresponding to the derived NH value. K at initial setup gNB is K AMF It is directly derived from and is subsequently considered to be associated with a virtual NH parameter with an NCC value of 0. At initial setup, the derived NH value is associated with an NCC value of 1.
[0243] Note 1: NH derivation associated with NCC=1 in the UE may be delayed until the first handover performing vertical key derivation.
[0244] Note 1a: K in N2 handover AMF Due to changes or synchronization between the AS security context and the NAS security context, K gNB When it is updated, K gNB is derived. In inter-RAT handover, K gNB is derived. K in UE context modification gNB is derived.
[0245] AMF serves K to gNB / ng-eNB gNB Whether to transmit the key or the {NH, NCC} pair is described in the subsection below. The AMF does not transmit the NH value to the gNB / ng-eNB during initial connection setup. The gNB / ng-eNB must initialize the NCC value to 0 after receiving the NGAP initial context setup request message.
[0246] Note 2: Since the AMF does not transmit the NH value to the gNB / ng-eNB during the initial connection setup, the NH value associated with NCC value 1 cannot be used in the next Xn handover or the next handover within the gNB / ng-eNB-CU. Horizontal key derivation is applied in the next Xn handover or the next handover within the gNB-CU / ng-eNB-CU.
[0247] UE and gNB / ng-eNB are K gNB It protects communication between them. K to be used between UE and target gNB / ng-eNB during handover and transition from RRC_INACTIVE to RRC_CONNECTED state. gNB K, the foundation of NG-RAN * is the currently active K gNB Or it is derived from the NH parameter. K NG-RAN * This currently active K gNB When derived from , it is called horizontal key derivation, and K NG-RAN * When derived from these NH parameters, it is called vertical key derivation.
[0248] Since NH parameters can only be calculated by the UE and AMF, the NH parameters are configured to be provided from the AMF to the gNB / ng-eNB to ensure forward security.
[0249] In a handover using vertical key derivation, NH sends K gNB Before being used as a target PCI and frequency ARFCN-DL, it is additionally bound to the target PCI and frequency ARFCN-DL. In handover using horizontal key derivation, the currently active K gNB is K in target gNB / ng-eNB gNB Before being used, it is additionally bound to the target PCI and frequency ARFCN-DL.
[0250] <Xn 핸드오버에서 NCC 핸들링>
[0251] Figure 10 shows an example of NCC handling in Xn handover.
[0252] 1) Step 1
[0253] The terminal can transmit a measurement report to the source base station.
[0254] 2) Step 2
[0255] Based on the measurement report, the source base station can decide to handover.
[0256] 3) Step 3
[0257] The source base station can send a HandoverRequest message to the target base station.
[0258] The source base station is K gNB Based on the target PCI and DL ARFCN values, input K gNB * can be determined. The above HandoverRequest message is the K gNB * and may include NCC values.
[0259] 4) Step 4
[0260] The target base station can send a HandoverRequestAcknowledge message to the source base station. At this time, the target base station can create and send a HandoverCommand, which is an RRC Container. To inform the terminal of the NCC value, the target base station may include the NCC value received from the source base station in step 3 in the HandoverCommand.
[0261] 5) Step 5
[0262] The source base station can send an RRCReconfiguration message to the terminal.
[0263] The RRCReconfiguration message may contain a HandoverCommand containing an NCC value.
[0264] 6) Step 6
[0265] The source base station can send an SNStatusTransfer message to the target base station.
[0266] 7) Step 7
[0267] The terminal can perform the RACH procedure.
[0268] The terminal can access the target base station.
[0269] 8) Step 8
[0270] The terminal can send an RRCReconfigurationComplete message to the target base station.
[0271] 9) Step 9
[0272] The target base station can send a PathSwitchRequest message to the AMF.
[0273] Based on this, AMF can increase the NCC value by one.
[0274] Based on this, AMF can generate new NH.
[0275] 10) Step 10
[0276] AMF can send a PathSwitchRequestAcknowledge message to the target base station.
[0277] The PathSwitchRequestAcknowledge message may include a newly generated NH and an increased NCC value.
[0278] 11) step 11
[0279] The target base station can send a UEContextRelease message to the source base station. Based on this, the source base station can delete the terminal's UE context.
[0280] The application of security technology is essential even in handover, a technology designed to support terminal mobility. As a terminal accesses a new target node, the new target node may need to generate a new security key to protect the signaling between the terminal and the base station. To this end, K AMF Based on this, AMF and terminals are K gNB And NH (Next Hop) can be generated. In this case, all K gNB NH is used in association with NCC (Next Hop Chaining Count).
[0281] LTM (L1 / L2 Triggered Mobility) is a procedure in which the gNB receives an L1 measurement report from the UE and, based on this, changes the UE's serving cell through a cell switch command signaled via MAC CE. The cell switch command represents an LTM candidate configuration prepared in advance by the gNB and provided to the UE via RRC signaling. Subsequently, the UE can switch to the target configuration in accordance with the cell switch command. The LTM procedure can be used to reduce mobility latency. LTM is a mobility feature that evolves existing handover procedures to enable faster handover execution.
[0282] To ensure the security of these new mobility features, security key support operations must be executed correctly. On the other hand, the fast handover procedures of the LTM must also be taken into consideration.
[0283] To this end, horizontal key derivation using the same NCC value may be required. Once horizontal key derivation is performed, there is no need to increase the NCC value. Consequently, there is no need to transmit the value generated / held by the target node or AMF to the terminal.
[0284] However, in conventional technology, since the relevant security-related parameters must be transmitted, the parameters / values may be transmitted repeatedly for backward compatibility. From a security perspective, the same security-related parameters should be exposed as little as possible.
[0285] To address these issues, this specification supports horizontal key derivation in handover procedures such as LTM, and proposes methods to use a new indicator (or ignore the transmitted value) or mask and hide duplicate security keys during path switching.
[0286] To address this issue, this specification proposes a method to support horizontal key derivation during the pass switching process of mobility procedures. Furthermore, this specification proposes a method for indicator handling procedures that consider backward compatibility with previous versions in related signaling.
[0287] The following drawings are intended to illustrate specific examples of the present specification. The names of specific devices and the names of specific signals, messages, and fields depicted in the drawings are provided for illustrative purposes only, and the technical features of this specification are not limited to the specific names used in the drawings.
[0288] FIGS. 11 and FIGS. 12 illustrate examples of an LTM procedure according to an embodiment of the present specification.
[0289] 0) step 0
[0290] The terminal may be in the RRC_CONNECTED state.
[0291] 1) Step 1
[0292] Through the previous procedure, measurement conditions (or measurement reporting conditions) may be set for the terminal.
[0293] When the measurement condition (or measurement report condition) is met, the terminal can perform measurement and transmit a measurement report to the source base station (e.g., source gNB / ng-eNB).
[0294] 2) Step 2
[0295] The source base station (e.g., source gNB / ng-eNB) can determine whether to initiate the LTM procedure.
[0296] A source base station (e.g., source gNB / ng-eNB) provides K-band signals for candidate cells of surrounding target base stations (e.g., target gNB). gNB * can be created.
[0297] The candidate cell of the target base station may be one of the cells served by the target base station. For example, the target base station may serve one or more cells. The candidate cells of the target base station may be one or more cells served by the target base station.
[0298] 3) Step 3
[0299] The source base station (e.g., source gNB / ng-eNB) creates a newly created K gNB * The NCC value can be included in the handover request and transmitted to the target base station (e.g., target gNB).
[0300] 4) Step 4
[0301] The target base station (e.g., target gNB) can transmit a Handover Request Acknowledge to the source base station (e.g., source gNB / ng-eNB). The Handover Request Acknowledge may include a received NCC value.
[0302] 5) Step 5
[0303] The source base station (e.g., source gNB / ng-eNB) can transmit an RRC Reconfiguration message to the terminal. The RRC Reconfiguration message may include information about candidate cells.
[0304] Based on this, the terminal can configure the received candidate cell for future access.
[0305] 6) Step 6
[0306] The terminal can send an RRC Reconfiguration Complete message to the source base station (e.g., source gNB / ng-eNB).
[0307] 7) Step 7
[0308] Afterwards, the terminal can send a measurement report to the source base station (e.g., source gNB / ng-eNB).
[0309] Based on this, the source base station can decide to perform LTM for the terminal.
[0310] The source base station (e.g., source gNB / ng-eNB) can perform LTM procedures (LTM execution).
[0311] 8) Step 8
[0312] The source base station can transmit an LTM Cell Switch Command over MAC CE to the terminal.
[0313] The terminal selects a new K for the candidate cell of the target base station. gNB ** can be created.
[0314] 9) Step 9
[0315] A source base station (e.g., source gNB / ng-eNB) can transmit a Cell Switch Notification to a target base station (e.g., target gNB / ng-eNB).
[0316] The above Cell Switch Notification can be transmitted based on the fact that the corresponding handover is an LTM procedure. Therefore, the target base station can recognize that the corresponding handover is an LTM procedure based on the above Cell Switch Notification.
[0317] 10) Step 10
[0318] The terminal can access a specific cell of the target base station (e.g., one of the candidate cells) via RACH (or without RACH).
[0319] 11) step 11
[0320] If the cell switch is successfully performed (e.g., if the terminal successfully accesses a specific cell of the target base station), the terminal can send an RRC Reconfiguration Complete message to the target base station.
[0321] 12) Step 12
[0322] A target base station (e.g., target gNB / ng-eNB) can transmit an NGAP message (PATH SWITCH REQUEST) to an AMF. The PATH SWITCH REQUEST may be a message for a terminal handover. The AMF may be an AMF serving the terminal.
[0323] Based on the NGAP message (PATH SWITCH REQUEST), the AMF can increase its existing NCC value by one. Additionally, the AMF can calculate / determine a new NH using the information it possesses.
[0324] The path switch request message transmitted by the target base station to the AMF may include an indicator (e.g., Mobility for Horizontal Key Derivation) to avoid increasing the NCC (or not generating a new NH).
[0325] Based on the fact that the target base station recognizes in Step 9 that the handover is an LTM procedure, the indicator may be included in the path switch request message.
[0326] If the above indicator is set to 'true', AMF may not increase NCC.
[0327] If the above indicator is set to 'true', the AMF may not recalculate (or determine) NH.
[0328] If the above indicator is set to 'true', then in step 13, when the AMF transmits a Path Switch Request ACK to the target base station, the AMF may perform the following:
[0329] - Option 1) AMF can transmit to the target base station with NCC as the previous usage value and NH as a meaningless value (e.g., 0000). Here, the meaningless value can be a preset value.
[0330] - option 2) AMF can be transmitted to the target base station by setting both NCC and NH to the previous usage values and setting 'Security Context Ignorance Indicator' to 'true'.
[0331] 13) Step 13
[0332] The AMF can send an NGAP message (PATH SWITCH REUQEST ACKOWLEDGE) to the target base station (e.g., target gNB / ng-eNB).
[0333] The path switch request ACK (PATH SWITCH REUQEST ACKOWLEDGE) may include a pair of NH and NCC determined in step 12 (e.g., {NH, NCC})).
[0334] For example, the AMF can transmit the pair of NH and NCC determined in step 12 (e.g., {NH, NCC})) to the target base station.
[0335] Based on this, the target base station can store the pair of NH and NCC received (e.g., {NH, NCC}). At this time, the target base station can remove the previously stored pair of NH and NCC.
[0336] - Option 1) If the NCC received by the target base station is the same as the previously used value (e.g., the NCC value received in step 3), the target base station can ignore the newly received NCC and NH values.
[0337] - Option 2) If the target base station receives the 'Security Context Ignorance Indicator' set to 'true', the target base station can ignore the newly received NCC and NH values. For example, the target base station can use the NCC and NH values it previously used.
[0338] 14) Step 14
[0339] The target base station can generate a new key based on the NCC and NH values.
[0340] If the target base station ignores the NCC and NH values received from the AMF in Step 13, the target base station can generate a new key using the NCC and NH values it previously had (e.g., received in Step 3).
[0341] The target base station (e.g., target gNB / ng-eNB) can forward the newly generated key to a candidate cell of a neighboring gNB / ng-eNB for subsequent LTM procedures.
[0342] 15) Step 15
[0343] The target base station (e.g., target gNB / ng-eNB) can transmit the NCC value to the terminal through RRC reconfiguration.
[0344] The terminal can send an RRC Reconfiguration Complete message to the target base station (e.g., target gNB / ng-eNB).
[0345] The following drawings are intended to illustrate specific examples of the present specification. The names of specific devices and the names of specific signals, messages, and fields depicted in the drawings are provided for illustrative purposes only, and the technical features of this specification are not limited to the specific names used in the drawings.
[0346] FIG. 13 shows an example of an Xn handover procedure according to an embodiment of the present specification.
[0347] 0) step 0
[0348] The source base station (e.g., source gNB / ng-eNB) and the target base station (e.g., target gNB / ng-eNB) can share configurations with each other through the Xn setup procedure.
[0349] 1) Step 1
[0350] The terminal can be registered with 5GC through the registration process.
[0351] Once the initial setup between the terminal and the base station is complete, the terminal may be in an RRC active state.
[0352] In this step, measurement-related information may be configured on the terminal so that, depending on the situation, the terminal can hand over to a nearby base station. For example, measurement-related conditions (e.g., measurement conditions, measurement reporting conditions) may be configured on the terminal.
[0353] 2) Step 2
[0354] The terminal can detect signal strength for a set frequency range.
[0355] If measurement-related conditions are met (e.g., the terminal determines that there is a base station with a stronger signal strength than the base station it is currently accessing), the terminal may transmit a measurement report to the source base station (e.g., source gNB / ng-eNB).
[0356] 3) Step 3
[0357] The source base station (e.g., source gNB / ng-eNB) can decide whether to initiate a terminal handover by considering the situation.
[0358] A subsequent step can be performed based on the source base station deciding to initiate the terminal's handover.
[0359] 4) Step 4
[0360] If the source base station decides to initiate a handover, it can perform actions to prepare for the handover.
[0361] The source base station (e.g., source gNB / ng-eNB) can send an XnAP message (handover request) to the target base station (e.g., target gNB / ng-eNB). At this time, the source base station (e.g., source gNB / ng-eNB) sends K to the target base station (e.g., target gNB / ng-eNB). NG-RAN * and NCC (Next Hop Chaining Count) can be transmitted together.
[0362] Through this, the target base station (e.g., target gNB / ng-eNB) can use the new gNB security key.
[0363] The target base station (e.g., target gNB / ng-eNB) receives K NG-RAN * is the terminal's K gNB It can be used like this.
[0364] 5) Step 5
[0365] The target base station (e.g., target gNB / ng-eNB) can send an XnAP message (Handover Request Acknowledge) to the source base station (e.g., source gNB / ng-eNB).
[0366] At this time, in order to provide information about the target node to the terminal, the target base station (e.g., target gNB / ng-eNB) may include a transparent container (HandoverCommand) in the HandoverRequestAcknowledge. At this time, the target base station may include the NCC received from the source base station in step 4 in the transparent container (HandoverCommand).
[0367] 6) Step 6
[0368] The source base station (e.g., source gNB / ng-eNB) can extract a HandoverCommand message from a received XnAP message (HandoverRequestAcknowledge) and deliver it to the terminal. The extracted HandoverCommand may include an NCC value.
[0369] The HandoverCommand extracted above can be transmitted to the terminal via an RRC Reconfiguration message. The RRC Reconfiguration message may include information about the target node (e.g., NCC).
[0370] 7) Step 7
[0371] The source base station (e.g., source gNB / ng-eNB) can transmit the UL / DL PDCP SN and HFN (Hyper Frame Number) status to the target base station via XnAP messages (e.g., SnStatus Transfer).
[0372] The source base station can buffer DL traffic coming from the UPF and forward it to the target base station.
[0373] 8) Step 8
[0374] The terminal can connect to the target base station via random access based on the RRC Reconfiguration message received in step 6.
[0375] 9) Step 9
[0376] Once the connection is complete, the terminal can send an RRC reconfiguration complete message to the target base station (e.g., target gNB / ng-eNB).
[0377] 10) Step 10
[0378] The target base station (e.g., target gNB / ng-eNB) can send an NGAP message (PATH SWITCH REQUEST) to the AMF.
[0379] Based on this, AMF can increase its existing NCC value by one and calculate a new NH using the information AMF possesses.
[0380] If an indicator (an indicator to avoid incrementing the NCC or generating a new NH) (e.g., Mobility for Horizontal Key Derivation) in the PATH SWITCH REQUEST message received by the AMF is set to 'true', the AMF may not increment the NCC and may not recalculate the NH.
[0381] If the operator prefers Horizontal Key Derivation, network settings for Horizontal Key Derivation may be configured at the target base station. Based on this, the target base station may include the corresponding indicator in the path switch request message transmitted to the AMF.
[0382] Afterwards, when AMF sends NGAP message (PATH SWITCH REUQEST ACKOWLEDGE) to Target gNB / ng-eNB, AMF can perform the following actions:
[0383] - Option 1) AMF can transmit to the target base station with NCC as the previous usage value and NH as a meaningless value (e.g., 0000). Here, the meaningless value can be a preset value.
[0384] - option 2) AMF can be transmitted to the target base station by setting both NCC and NH to the previous usage values and setting 'Security Context Ignorance Indicator' to 'true'.
[0385] 11) step 11
[0386] The target base station (e.g., target gNB / ng-eNB) can receive an NGAP message (PATH SWITCH REQUEST ACKNOWLEDGE) from the AMF.
[0387] The PATH SWITCH REUQEST ACKOWLEDGE may include a pair of NH and NCC (e.g., {NH, NCC}) determined in step 10.
[0388] For example, the AMF can transmit the pair of NH and NCC (e.g., {NH, NCC}) determined in step 10 to the target base station.
[0389] Based on this, the target base station can store the pair of NH and NCC received (e.g., {NH, NCC}). At this time, the target base station can remove the previously stored pair of NH and NCC.
[0390] - Option 1) If the NCC received by the target base station is the same as the previous used value, the target base station may ignore the newly received NCC and NH values.
[0391] - Option 2) If the target base station receives the 'Security Context Ignorance Indicator' set to 'true', the target base station can ignore the newly received NCC and NH values. For example, the target base station can use the NCC and NH values it previously used.
[0392] If the target base station ignores the NCC and NH values received from the AMF, the target base station can generate a new key using the previously used NCC and NH values.
[0393] 12) Step 12
[0394] To release the terminal resources held by the source base station, the target base station (e.g., target gNB / ng-eNB) can send an XnAP message (UEContextRelase) to the source base station.
[0395] Messages for the path switch operation of NGAP (e.g., path switch request, path switch request ACK) will be described below. A new indicator may be defined. This enables support in the aforementioned LTM or Xn-Handover procedure.
[0396] Table 3 shows the path switch request message.
[0397] IE / Group NamePresenceRangeIE type and referenceSemantics descriptionCriticalityAssigned CriticalityMessage TypeM9.3.1.1YESrejectRAN UE NGAP IDM9.3.3.2YESrejectSource AMF UE NGAP IDMAMF UE NGAP ID9.3.3.1YESrejectUser Location InformationM9.3.1.16YESignoreUE Security CapabilitiesM9.3.1.86YESignore<New IE> Mobility for Horizontal Key DerivationOENUMERATED (true, ...)YESignorePDU Session Resource to be Switched in Downlink List1YESreject
[0398] The above 'Mobility for Horizontal Key Derivation' may be an indicator (an indicator for not increasing NCC or an indicator for not creating a new NH).
[0399] Table 4 shows the PATH SWITCH REQUEST ACKNOWLEDGE message.
[0400] IE / Group NamePresenceRangeIE type and referenceSemantics descriptionCriticalityAssigned CriticalityMessage TypeM9.3.1.1YESrejectAMF UE NGAP IDM9.3.3.1YESignoreRAN UE NGAP IDM9.3.3.2YESignoreUE Security CapabilitiesO9.3.1.86YESrejectSecurity ContextM9.3.1.88YESrejectNew Security Context IndicatorO9.3.1.55YESrejectPDU Session Resource Switched List1YESignore
[0401] The above 'Security Context' may include the contents of Table 5.
[0402] The 'Security Context'IE can provide security-related parameters to NG-RAN nodes that are used to derive security keys for user plane traffic and RRC signaling messages and generate security parameters for subsequent mobility.
[0403] IE / Group NamePresenceRangeIE type and referenceSemantics descriptionNext Hop Chaining CountMINTEGER (0..7)Next Hop Chaining Counter (NCC) defined in TS 33.501
[0013] .Next-Hop NHMSecurity Key9.3.1.87The NH together with the NCC is used to derive the security configuration as defined in TS 33.501
[0013] .<New IE> Security Context Ignorance IndicatorOENUMERATED (true, ...)Both NCC and NH shall be ignored if it sets true
[0404] 'Security Context' can contain NCC and NH.
[0405] The 'Security Context' may include a Security Context Ignorance Indicator. In this case, the target base station may ignore both the NCC and NH values received from the AMF. For example, the target base station may use the NCC and NH values previously used.
[0406] According to embodiments of the present specification, the following operations may be performed:
[0407] - If the first network control node (e.g. AMF) receives an indicator that induces horizontal key derivation when receiving a PATH SWITCH REQUEST, the first network control node (e.g. AMF) may not increase the NCC value and may not generate a new NH.
[0408] - Option 1) The first network control node (eg AMF) can send an NGAP PATH SWITCH REQUEST ACKNOWLEDGE to the second network control node (eg gNB or ng-eNB) without generating a new {NCC, NH}. At this time, the first network control node (eg AMF) sends the NCC value as a value previously stored by the first network node or a previously used value. At this time, the first network control node (eg AMF) can send the NH by masking it with a specific value such as 0000… .000 (256 bits length).
[0409] - Option 1) If the NCC value received by the second network control node (e.g. gNB or ng-eNB) via NGAP PATH SWITCH REQUEST ACK is the same as the previously stored value, the newly received NH value can be ignored.
[0410] - Option 2) The first network control node (eg AMF) may send an NGAP PATH SWITCH REQUEST ACKNOWLEDGE to the second network control node (eg gNB or ng-eNB) without generating a new {NCC, NH}. At this time, the first network control node (eg AMF) may send a previously stored value or a previously used value as the NCC value. At this time, the first network control node (eg AMF) may send NH as a previously known value. At this time, the first network control node (eg AMF) may send it with the Security Context Ignorance Indicator set to true.
[0411] - Option 2) If the Security Context Ignorance Indicator received by the second network control node (eg gNB or ng-eNB) via NGAP PATH SWITCH REQUEST ACK is true, the second network control node (eg gNB or ng-eNB) may ignore all newly received NCC and NH values.
[0412] The following drawings are intended to illustrate specific examples of the present specification. The names of specific devices and the names of specific signals, messages, and fields depicted in the drawings are provided for illustrative purposes only, and the technical features of this specification are not limited to the specific names used in the drawings.
[0413] Figure 14 illustrates the procedure of AMF according to the disclosure of this specification.
[0414] 1. AMF (Access and Mobility management Function) can receive a path switch request for UE (User Equipment) from a target base station.
[0415] 2. Based on the above path switch request, the AMF can increase the NCC (Next Hop Chaining Count).
[0416] Based on the above path switch request including a horizontal key derivation indicator, the AMF may skip the step of increasing the NCC.
[0417] 3. The above AMF can transmit a response message to the target base station.
[0418] The above response message may include the NCC.
[0419] The above AMF can derive NH (Next Hop) based on the above NCC.
[0420] Based on the above path switch request including a horizontal key derivation indicator, the AMF may skip the step of deriving the NH.
[0421] The above response message may include the NH.
[0422] Based on the above path switch request including a horizontal key derivation indicator, the response message may include NH of a preset value.
[0423] Based on the above path switch request including a horizontal key derivation indicator, the response message may include a previously used NH.
[0424] Based on the above path switch request including a horizontal key derivation indicator, the response message may include a security context ignorance indicator.
[0425] The following drawings are intended to illustrate specific examples of the present specification. The names of specific devices and the names of specific signals, messages, and fields depicted in the drawings are provided for illustrative purposes only, and the technical features of this specification are not limited to the specific names used in the drawings.
[0426] Figure 15 illustrates the procedure of a target base station according to the disclosure of this specification.
[0427] 1. Based on the cell switch performed for the UE (User Equipment), the target base station can transmit a path switch request for the UE to the AMF (Access and Mobility management Function).
[0428] The above path switch request may include a horizontal key derivation indicator.
[0429] The target base station can receive a response message from the AMF.
[0430] The above response message may include NCC (Next Hop Chaining Count) and NH (Next Hop).
[0431] Based on the above path switch request including a horizontal key derivation indicator, the response message may include NH of a preset value.
[0432] Based on the above path switch request including a horizontal key derivation indicator, the response message may include a security context ignorance indicator.
[0433] Based on the above NCC and the above NH, the target base station can generate a new key.
[0434] The target base station can transmit the new key to the candidate cell of the UE.
[0435] An RRC reset message can be sent to the UE.
[0436] The above RRC reset message may include the above NCC.
[0437] Hereinafter, a device for performing communication according to some embodiments of the present specification will be described.
[0438] For example, a device may include a processor, a transceiver, and memory.
[0439] For example, a processor may be configured to be operatively coupled with memory and a processor.
[0440] The operations performed by the processor include: receiving, by the AMF, a path switch request for a UE (User Equipment) from a target base station; increasing, by the AMF, a Next Hop Chaining Count (NCC) based on the path switch request; skipping, by the AMF, the step of increasing the NCC based on the path switch request including a horizontal key derivation indicator, and transmitting, by the AMF, a response message to the target base station, wherein the response message may include the NCC.
[0441] Below, a processor of a device for providing communication according to some embodiments of the present specification is described.
[0442] The operations performed by the processor include: receiving, by the AMF, a path switch request for a UE (User Equipment) from a target base station; increasing, by the AMF, a Next Hop Chaining Count (NCC) based on the path switch request; skipping, by the AMF, the step of increasing the NCC based on the path switch request including a horizontal key derivation indicator, and transmitting, by the AMF, a response message to the target base station, wherein the response message may include the NCC.
[0443] Hereinafter, a non-volatile computer-readable medium storing one or more commands for providing mobile communication according to some embodiments of the present specification is described.
[0444] According to some embodiments of the present disclosure, the technical features of the present disclosure may be implemented directly in hardware, software executed by a processor, or a combination of the two. For example, a method performed by a wireless device in wireless communication may be implemented in hardware, software, firmware, or any combination thereof. For example, the software may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, a hard disk, a removable disk, a CD-ROM, or other storage media.
[0445] Some examples of storage media are coupled to the processor, allowing the processor to read information from the storage media. Alternatively, the storage media may be integrated into the processor. The processor and storage media may reside in an ASIC. In other examples, the processor and storage media may reside as separate components.
[0446] Computer-readable media may include tangible and non-volatile computer-readable storage media.
[0447] For example, nonvolatile computer-readable media may include random access memory (RAM), such as synchronized dynamic random access memory (SDRAM), read-only memory (ROM), non-volatile random access memory (NVRAM), read-only memory (EEPROM), flash memory, magnetic or optical data storage media, or any other media that can be used to store instructions or data structures. Nonvolatile computer-readable media may also include combinations of the above.
[0448] Additionally, the methods described herein can be realized at least in part by a computer-readable communication medium that carries or transmits code in the form of instructions or data structures and that can be accessed, read, and / or executed by a computer.
[0449] According to some embodiments of the present disclosure, a non-transitory computer-readable medium has one or more instructions stored thereon. The one or more stored instructions can be executed by a processor of a base station.
[0450] The stored one or more commands include: receiving, by an AMF, a path switch request for a UE (User Equipment) from a target base station; incrementing, by the AMF, a Next Hop Chaining Count (NCC) based on the path switch request; skipping, by the AMF, the step of incrementing the NCC based on the path switch request including a horizontal key derivation indicator, and transmitting, by the AMF, a response message to the target base station, wherein the response message may include the NCC.
[0451] This specification may have various effects.
[0452] For example, authentication is performed using the same NCC, enabling faster handover.
[0453] The effects that can be achieved through specific examples of this specification are not limited to the effects listed above. For example, a person with ordinary skill in the relevant technical field may understand or derive various technical effects from this specification. Accordingly, the specific effects of this specification are not limited to those explicitly described herein, but may include various effects that can be understood or derived from the technical features of this specification.
[0454] The claims set forth in this specification may be combined in various ways. For example, the technical features of the method claims of this specification may be combined to implement a device, and the technical features of the device claims of this specification may be combined to implement a method. Furthermore, the technical features of the method claims and the technical features of the device claims of this specification may be combined to implement a device, and the technical features of the method claims and the technical features of the device claims of this specification may be combined to implement a method. Other implementations are within the scope of the claims.
Claims
1. As a method, A step in which the AMF (Access and Mobility management Function) receives a path switch request for the UE (User Equipment) from the target base station; A step in which the AMF increases the NCC (Next Hop Chaining Count) based on the above path switch request; Based on the fact that the above path switch request includes a horizontal key derivation indicator, the above AMF skips the step of increasing the NCC, and The above AMF includes the step of transmitting a response message to the target base station, and The above response message is a method including the above NCC.
2. In Paragraph 1, The above AMF further includes a step of deriving NH (Next Hop) based on the above NCC, and Based on the fact that the above path switch request includes a horizontal key derivation indicator, the above AMF skips the step of deriving the NH, and The above response message is a method including the above NH.
3. In paragraph 1, A method in which the response message includes an NH of a preset value, based on the above path switch request including a horizontal key derivation indicator.
4. In paragraph 1, Based on the fact that the above path switch request includes a horizontal key derivation indicator, the above response message includes a previously used NH, and A method in which the response message includes a security context ignorance indicator, based on the fact that the above path switch request includes a horizontal key derivation indicator.
5. As a method, Based on the fact that a cell switch for the UE (User Equipment) has been performed, the target base station transmits a path switch request for the UE to the AMF (Access and Mobility management Function); The above path switch request includes a horizontal key derivation indicator, and The above target base station includes the step of receiving a response message from the AMF, and The above response message includes NCC (Next Hop Chaining Count) and NH (Next Hop).
6. In Paragraph 5, A method in which the response message includes an NH of a preset value, based on the above path switch request including a horizontal key derivation indicator.
7. In paragraph 5, A method in which the response message includes a security context ignorance indicator, based on the fact that the above path switch request includes a horizontal key derivation indicator.
8. In any one of the clauses 5 to 8, Based on the above NCC and the above NH, the target base station generates a new key; A method further comprising the step of the target base station transmitting the new key to a candidate cell of the UE.
9. In any one of paragraphs 5 to 8, Further comprising the step of transmitting an RRC reset message to the UE, A method wherein the RRC reset message includes the NCC.
10. As an AMF (Access and Mobility management Function) that performs communication, At least one transmitter and receiver; Contains at least one processor, The operation performed by the at least one processor is an AMF method according to any one of claims 1 to 4.
11. As a target base station performing communication, At least one transmitter and receiver; Contains at least one processor, A UE wherein the operation performed by at least one processor is a method according to any one of claims 5 to 9.
12. As an apparatus in mobile communication, at least one processor; and It includes at least one memory that stores instructions and is operablely electrically connected to at least one processor, and A device in which the operation performed based on the execution of the above instruction by the at least one processor is a method according to any one of claims 1 to 4.
13. A non-volatile computer-readable storage medium that records commands, A non-volatile computer-readable storage medium in which the above instructions, when executed by one or more processors, cause the one or more processors to perform a method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Path switching method, mobility anchor, and base station
US20170164244A1