Communication device, base station, and communication method

The communication device and base station configuration addresses the security key update issue in LTM by managing key updates through RRC messages, ensuring secure and reliable inter-gNB-CU mobility.

WO2026100429A1PCT designated stage Publication Date: 2026-05-15DENSO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
DENSO CORP
Filing Date
2025-10-29
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Current mobile communication systems lack provisions for updating security keys during Layer 1/Layer 2 triggered mobility (LTM) when cell mobility between different base stations is supported, posing a security risk.

Method used

A communication device and base station configuration that includes updating security keys during LTM cell switches, using a control unit to manage security key updates through radio resource control (RRC) messages, ensuring proper key management across different base stations.

Benefits of technology

Ensures secure and seamless cell switching by properly updating security keys during inter-gNB-CU mobility, enhancing system security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025038028_15052026_PF_FP_ABST
    Figure JP2025038028_15052026_PF_FP_ABST
Patent Text Reader

Abstract

A communication device (100) according to an embodiment is a communication device. The communication device includes: a control unit (120) that updates a security key for a layer 1 / layer 2 triggered mobility (LTM) cell switch from a first cell (C1) to a second cell (C2); and a transmission unit (111) that transmits, to the second cell, a radio resource control (RRC) message including update information relating to an update of the security key for the LTM cell switch.
Need to check novelty before this filing date? Find Prior Art

Description

Communication equipment, base stations, and communication methods Cross-references to related applications

[0001] This application is based on Patent Application No. 2024-195481, filed on 7 November 2024, and claims the benefit of priority thereunder, the entirety of which is incorporated herein by reference.

[0002] This disclosure relates to communication equipment, base stations, and communication methods.

[0003] In mobile communication systems that conform to the technical specifications of the 3GPP (Third Generation Partnership Project), a standardization project for mobile communication systems, Layer 1 / Layer 2 triggered mobility (L1 / L2-Triggered Mobility: LTM) is introduced (see Non-Patent Literature 1).

[0004] In LTM, the base station switches the serving cell of the communication device by sending a cell switch command to the communication device via a medium access control element (MAC CE) based on the L1 measurement report received from the communication device. Compared to cell switching based on radio resource control (RRC) messages, the communication device can perform cell switching dynamically and reduce mobility delay.

[0005] 3GPP TS 38.300 V18.3.0 “NR; NR and NG-RAN Overall description; Stage-2”

[0006] The communication device according to the first embodiment includes a control unit that updates a security key to a Layer 1 / Layer 2 triggered mobility (LTM) cell switch from a first cell to a second cell, and a transmission unit that transmits a radio resource control (RRC) message containing update information regarding the update of the security key to the LTM cell switch to the second cell.

[0007] The base station according to the second embodiment includes a receiving unit that receives a radio resource control (RRC) message containing update information regarding the update of the security key for a Layer 1 / Layer 2 triggered mobility (LTM) cell switch from a communication device that updates the security key for the LTM cell switch.

[0008] The third aspect of the communication method is a communication method performed by a communication device. This communication method includes the steps of updating a security key for a Layer 1 / Layer 2 triggered mobility (LTM) cell switch from a first cell to a second cell, and transmitting a radio resource control (RRC) message containing update information regarding the update of the security key for the LTM cell switch to the second cell.

[0009] The purpose, features, and advantages of this disclosure will become clearer with reference to the attached drawings and the detailed description below. Figure 1 is a diagram showing the configuration of a mobile communication system according to the embodiment. Figure 2 is a diagram showing an example of the configuration of a protocol stack according to the embodiment. Figure 3 is a diagram showing the configuration of a UE according to the embodiment. Figure 4 is a diagram showing the configuration of a base station according to the embodiment. Figure 5 is a sequence diagram (1) for explaining an example of operation according to the embodiment. Figure 6 is a sequence diagram (2) for explaining an example of operation according to the embodiment. Figure 7 is a sequence diagram (3) for explaining an example of operation according to the embodiment. Figure 8 is a diagram for explaining the hierarchical structure of an RRC reset message according to the embodiment. Figure 9 is a diagram for explaining an example of operation according to the embodiment.

[0010] A mobile communication system according to an embodiment will be described with reference to the drawings. In the drawings, identical or similar parts are denoted by the same or similar reference numerals.

[0011] Currently, discussions are underway to extend the functionality of the LTM to support cell mobility between different base stations (so-called inter-gNB-CU (Central Unit)). However, since there are no provisions for updating the security keys of communication devices in the LTM, there are concerns that security key updates may not be performed properly if cell mobility between different base stations is supported in the LTM.

[0012] Therefore, one of the objectives is to provide a communication device, base station, and communication method that enable the proper updating of security keys in LTM.

[0013] (System Configuration) First, the configuration of the mobile communication system 1 according to this embodiment will be described with reference to Figure 1. The mobile communication system 1 is, for example, a system that conforms to the 3GPP Technical Specifications (TS). In the following, the mobile communication system 1 will be described using as an example a 5th Generation System (5G system) of the 3GPP standard, that is, a mobile communication system based on NR (New Radio) radio access.

[0014] The mobile communication system 1 includes a network 10 and a user equipment (UE) 100 that communicates with the network 10. The network 10 includes an NG-RAN (Next Generation Radio Access Network) 20, which is a 5G radio access network, and a 5GC (5G Core Network) 30, which is a 5G core network.

[0015] UE100 is a communication device that communicates via base station 200. UE100 may be a device used by a user. UE100 may be a mobile device such as a smartphone or other mobile phone terminal, tablet terminal, notebook PC, communication module, or communication card. UE100 may be a vehicle (e.g., car, train, etc.) or a device installed thereon (e.g., Vehicle UE). UE100 may be a transport vehicle other than a vehicle (e.g., ship, airplane, etc.) or a device installed thereon (e.g., Aerial UE). UE100 may be a sensor or a device installed thereon. Note that UE100 may also be referred to by other names such as terminal, terminal device, mobile station, mobile terminal, mobile device, mobile unit, subscriber station, subscriber terminal, subscriber device, subscriber unit, wireless station, wireless terminal, wireless device, wireless unit, remote station, remote terminal, remote device, or remote unit. Furthermore, UE100 is just one example of a terminal, and terminals may include factory equipment, etc.

[0016] NG-RAN20 includes a plurality of base stations 200. Each base station 200 manages at least one cell. One or more base stations 200 may correspond to one or more cells. In this embodiment, base stations 200 may be replaced by cells. A cell constitutes the smallest unit of a communication area. One cell belongs to one frequency (carrier frequency). The term "cell" may represent a wireless communication resource, or it may represent a communication target of UE100. Each base station 200 can perform wireless communication with UE100 located within its own cell. Base stations 200 communicate with UE100 using the RAN protocol stack. Details of the protocol stack will be described later. Base stations 200 are also connected to other base stations 200 (which may be referred to as adjacent base stations) via the Xn interface. Base stations 200 communicate with adjacent base stations via the Xn interface. Furthermore, the base station 200 provides NR user plane and control plane protocol termination for UE100 and is connected to 5GC30 via the NG interface. Such an NR base station 200 is sometimes referred to as gNodeB (gNB).

[0017] 5GC30 includes a core network device 300. The core network device 300 includes, for example, an AMF (Access and Mobility Management Function) and / or a UPF (User Plane Function). The AMF performs mobility management for the UE100. The UPF provides functions specifically for U-plane processing. The AMF and UPF are connected to the base station 200 via an NG interface.

[0018] (Example of protocol stack configuration) Next, an example of the protocol stack configuration according to this embodiment will be described with reference to Figure 2.

[0019] The protocol for the radio section between UE100 and base station 200 comprises a physical (PHY) layer, a MAC (Medium Access Control) layer, an RLC (Radio Link Control) layer, a PDCP (Packet Data Convergence Protocol) layer, and an RRC (Radio Resource Control) layer.

[0020] The PHY layer performs encoding and decoding, modulation and demodulation, antenna mapping and demapping, and resource mapping and demapping. Data and control information are transmitted between the PHY layer of UE100 and the PHY layer of base station 200 via a physical channel.

[0021] The MAC layer performs data priority control, retransmission processing using Hybrid ARQ (HARQ), and random access procedures. Data and control information are transmitted between the MAC layer of UE100 and the MAC layer of base station 200 via the transport channel. The MAC layer of base station 200 includes a scheduler. The scheduler determines the transport format for the uplink and downlink (transport block size, modulation and coding scheme (MCS)) and the resources to be allocated to UE100.

[0022] The RLC layer transmits data to the receiving RLC layer using the functions of the MAC layer and PHY layer. Data and control information are transmitted between the RLC layer of UE100 and the RLC layer of base station 200 via a logical channel.

[0023] The PDCP layer performs header compression / decompression, encryption / decryption.

[0024] A Service Data Adaptation Protocol (SDAP) layer may be provided as a layer above the PDCP layer. The SDAP layer maps IP flows, which are the units in which the core network performs Quality of Service (QoS) control, to wireless bearers, which are the units in which the Access Stratum (AS) performs QoS control.

[0025] The RRC layer controls the logical channel, transport channel, and physical channel in response to the establishment, re-establishment, and release of the radio bearer. RRC signaling for various settings is transmitted between the RRC layer of UE100 and the RRC layer of base station 200. If there is an RRC connection between the RRC layer of UE100 and the RRC layer of base station 200, UE100 is in the RRC connected state. If there is no RRC connection between the RRC layer of UE100 and the RRC layer of base station 200, UE100 is in the RRC idle state. If the RRC connection between the RRC layer of UE100 and the RRC layer of base station 200 is suspended, UE100 is in the RRC inactive state.

[0026] In UE100, the NAS layer, located above the RRC layer, performs session management and mobility management for UE100. NAS signaling is transmitted between the NAS layer of UE100 and the NAS layer of the core network device 300.

[0027] Furthermore, the UE100 has an application layer and other components in addition to the wireless interface protocol.

[0028] (Wireless Frame Configuration) In a 5G system, downlink transmission and uplink transmission are configured within a wireless frame with a duration of 10 ms. For example, a wireless frame is represented by a system frame number (SFN: System Frame Number) from 0 to 1023. For example, a wireless frame is composed of 10 subframes. For example, one subframe may be 1 ms. Also, one subframe may be composed of one or more slots. For example, the number of symbols constituting one slot is usually 14 with normal CP (Cyclic Prefix) and 12 with extended CP. Also, the number of slots constituting one subframe varies according to the set subcarrier spacing. For example, for normal CP, when the subcarrier spacing is set to 15 kHz, the number of slots per subframe is 1 (i.e., 14 symbols), when the subcarrier spacing is set to 30 kHz, the number of slots per subframe is 2 (i.e., 28 symbols), when the subcarrier spacing is set to 60 kHz, the number of slots per subframe is 4 (i.e., 56 symbols), and when the subcarrier spacing is set to 120 kHz, the number of slots per subframe is 8 (i.e., 112 symbols). Also, for extended CP, when the subcarrier spacing is set to 60 kHz, the number of slots per subframe is 4 (i.e., 48 symbols). That is, based on the subcarrier spacing set by the base station 200, the number of slots constituting one subframe is determined. Also, based on the subcarrier spacing set by the base station 200, the number of symbols constituting one subframe is determined. That is, based on the subcarrier spacing set by the base station 200, the number of symbols constituting a 1-ms subframe is determined, and the length (length in the time direction) of each symbol changes.

[0029] (Configuration of User Equipment) Referring to FIG. 3, the configuration of the UE 100 according to the embodiment will be described. The UE 100 includes a communication unit 110 and a control unit 120.

[0030] The communication unit 110 performs wireless communication with the base station 200 by transmitting and receiving radio signals to and from the base station 200. The communication unit 110 has at least one transmitting unit 111 and at least one receiving unit 112. The transmitting unit 111 and the receiving unit 112 may be configured to include a plurality of antennas and an RF (Radio Frequency) circuit. The antenna converts a signal into radio waves and radiates the radio waves into space. The antenna also receives radio waves in space and converts the radio waves into signals. The RF circuit performs analog processing of the signals transmitted and received via the antenna. The RF circuit may include a high-frequency filter, an amplifier, a modulator, and a low-pass filter, etc.

[0031] The control unit 120 performs various controls on the UE 100. The control unit 120 controls communication with the base station 200 via the communication unit 110. The operations of the UE 100 described above and below may be operations controlled by the control unit 120. The control unit 120 may include at least one processor capable of executing a program and a memory for storing the program. The processor may execute the program to perform the operations of the control unit 120. The control unit 120 may include a digital signal processor that performs digital processing of signals transmitted and received via the antenna and RF circuit. This digital processing includes processing of the RAN protocol stack. The memory stores the program executed by the processor, parameters related to the program, and data related to the program. Memory may include at least one of ROM (Read Only Memory), EPROM (Erasable Programmable Read Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memory), RAM (Random Access Memory), and flash memory. All or part of the memory may be contained within the processor.

[0032] (Base station configuration) Referring to Figure 4, the configuration of the base station 200 according to this embodiment will be described. The base station 200 has a communication unit 210, a network communication unit 220, and a control unit 230.

[0033] The communication unit 210 receives, for example, a radio signal from the UE 100 and transmits a radio signal to the UE 100. The communication unit 210 includes at least one transmission unit 211 and at least one reception unit 212. The transmission unit 211 and the reception unit 212 may be configured to include an RF circuit. The RF circuit performs analog processing of signals transmitted and received via an antenna. The RF circuit may include a high-frequency filter, an amplifier, a modulator, a low-pass filter, and the like.

[0034] The network communication unit 220 transmits and receives signals to and from a network. The network communication unit 220 receives, for example, a signal from an adjacent base station connected via an Xn interface, which is an interface between base stations, and transmits a signal to the adjacent base station. Further, the network communication unit 220 receives, for example, a signal from a core network device 300 connected via an NG interface and transmits a signal to the core network device 300.

[0035] The control unit 230 performs various controls in the base station 200. The control unit 230 controls, for example, communication with the UE 100 via the communication unit 210. Further, the control unit 230 controls, for example, communication with nodes (e.g., adjacent base stations, core network devices 300) via the network communication unit 220. The operations of the base station 200 described above and below may be operations under the control of the control unit 230. The control unit 230 may include at least one processor capable of executing a program and a memory that stores the program. The processor may execute the program to perform the operations of the control unit 230. The control unit 230 may include a digital signal processor that performs digital processing of signals transmitted and received via an antenna and an RF circuit. The digital processing includes processing of the RAN protocol stack. Note that the memory stores a program executed by the processor, parameters related to the program, and data related to the program. All or part of the memory may be included in the processor.

[0036] The base station 200 may be a node having gNB-CU (Central Unit) functionality and gNB-DU (Distributed Unit) functionality. The base station 200 may also be a node having gNB-CU functionality but no gNB-DU functionality. In this case, another node may have gNB-DU functionality, and the base station 200 may communicate with the UE 100 via that other node. Furthermore, the base station 200 may be a node having gNB-CU functionality and multiple gNB-DU functionality. In this case, a cell may be managed by one gNB-DU, and one gNB-DU may be managed by one gNB-CU. Furthermore, the node may have a gNB-CU-CP (Control Plane) function, multiple gNB-CU-UP functions (User Plane), and multiple gNB-DU functions. In this case, a cell may be managed by one gNB-DU, and one gNB-DU may be managed by one gNB-CU-CP and one gNB-CU-UP. In this embodiment, one gNB-CU-CP and one gNB-CU-UP may be referred to as gNB-CU.

[0037] (Operation Example) An operation example will be described with reference to Figures 5 to 9. Previously stated explanations may be omitted. In the mobile communication system 1 of this operation example, there are base stations 201, 202, and 203 as base stations 200. Each of base stations 201, 202, and 203 manages a different cell. Base station 202 may be, for example, a neighboring base station to base station 201. Base station 203 may be a neighboring base station to base station 202. In this operation example, base station 201 manages cell C1, base station 202 manages cell C2, and base station 203 manages cell C3. Although the description of base station 203 is omitted in Figures 5 and 6, the operation of base station 201 with respect to base station 203 may be the same as that of base station 202, and the operation of base station 203 may be the same as that of base station 202.

[0038] UE100 may be in an RRC connected state with cell C1 managed by base station 201. Hereafter, UE100 will communicate with base station 201 in cell C1 until it performs an LTM cell switch to the target cell. Cell C1 may be referred to as a source cell or a serving cell. Cell C1 may also be referred to as a P cell.

[0039] Furthermore, for UE100, communication with base stations 200 (base stations 201 / base stations 202 / base stations 203) may also be communication with cells (cell C1 / cell C2 / cell C3). Therefore, for UE100, receiving information / messages from base stations 200 may be receiving information / messages from cells, and sending information / messages to base stations 200 may be sending information / messages to cells. In other words, in this embodiment, cell movement between different base stations (inter-gNB-CU) may include movement between cells associated with different CUs. Also, cell movement within the same base station (intra-gNB-CU) may include movement between cells associated with the same CU. The LTM for cell movement between different base stations is also called the inter-CU LTM. Also, cell movement within the same base station is also called the intra-CU LTM.

[0040] The following describes an example of operation in LTM. LTM is a cell switch procedure triggered by the network via MAC CE based on L1 measurements. LTM may include the following procedures: LTM Preparation, Early Synchronization, LTM Cell Switch Execution, and LTM Cell Switch Completion. In LTM Preparation, for example, the processes from steps S120 to S160 may be executed. In Early Synchronization, for example, the process in step S170 may be executed. In LTM Cell Switch Execution, for example, the processes from steps S210 to S250 may be executed. In LTM Cell Switch Completion, for example, the process in step S260 may be executed. Furthermore, when the LTM cell switch is completed, the processes from steps S260 to S290 may be executed.

[0041] Step S110: The transmitter 111 of UE 100 may transmit capability information to the base station 201. The receiver 212 of base station 201 may receive capability information from UE 100. The capability information may include, for example, information indicating whether or not it supports cell movement between different base stations (inter-gNB-CU) by LTM (i.e., inter-CU LTM). The capability information may also include, for example, information indicating whether or not it supports cell movement between the same base stations (intra-gNB-CU) by LTM (i.e., intra-CU LTM). For example, the transmitter 111 of UE 100 may transmit an RRC message to base station 201 that includes capability information including information indicating that it supports inter-CU LTM and / or information indicating intra-CU LTM.

[0042] The capability information may also include information regarding the security of UE100. This information may include, for example, information indicating the 5G security capability of UE100. The control unit 230 of the base station 201 may control the security of communication with UE100 based on the information regarding the security of UE100.

[0043] Step S120: The transmitter 111 of UE100 transmits a measurement report (message) to the base station 201. The receiver 212 of base station 201 receives the measurement report from UE100.

[0044] The control unit 230 of the base station 201 may decide to set LTM. The control unit 230 may start LTM preparation. As part of LTM preparation, the control unit 230 may select candidate target cells for LTM (hereinafter referred to as LTM candidate cells as appropriate) based on measurement reports. The control unit 230 may, for example, select LTM candidate cells from among the cells managed by the base station 201.

[0045] The control unit 230 may determine LTM candidate cells based, for example, on capability information. If the UE 100 supports only cell movement between the same base stations using LTM, the control unit 230 may select only cells managed by its own station as LTM candidate cells. On the other hand, if the UE 100 also supports cell movement between different base stations using LTM, the control unit 230 may select cells managed by base stations other than its own station as LTM candidate cells. If the control unit 120 selects cells belonging to other stations as LTM candidate cells, it may execute the process in step S130.

[0046] Step S130: The network communication unit 220 of base station 201 may send a Handover Request message to base station 202, for example, requesting the preparation of resources for handover. The network communication unit 220 of base station 202 may receive the Handover Request message from base station 201. Note that the message in step S130 may be a message other than a Handover Request message. This message may be, for example, a message used to request the preparation of an LTM (LTM cell switch).

[0047] The handover request message may include information requesting an LTM cell switch to the base station 202's cell by the LTM. The handover request message may also include information identifying an LTM candidate cell among the cells managed by the base station 202.

[0048] The control unit 230 of the base station 201 may include information regarding the security used in the base station 201 in the handover request message. This information may include information regarding security in communication with the UE 100 (e.g., information indicating 5G security capability) and information regarding the algorithms used in security (e.g., information indicating the encryption algorithm (e.g., cipheringAlgorithm) and information indicating the integrity algorithm (e.g., integrityProtAlgorithm)).

[0049] Here, the control unit 230 of the base station 201 controls the security key (for example, K NG-RAN *) may be derived. The control unit 230 may, for example, if there is an unused pair of NH (Next Hop parameter) and an unused NCC (NH Chaining Counter) (i.e., an unused pair of {NH, NCC}), use the unused pair of {NH, NCC} to derive a security key (e.g., K NG-RAN *) may be derived. The control unit 230 will determine the current active key (e.g., K) if there are no unused {NH, NCC} pairs. gNBThe control unit 230 may derive the security key from the following: The control unit 230 may derive the security key from an unused {NH,NCC} pair or the current active key, in addition to, for example, the physical cell identifier (PCI) of the candidate cell of the target cell. The control unit 230 may also derive the security key from information on the downlink frequency of the candidate cell. The control unit 230 may also derive the security key from, for example, the absolute radio frequency channel number (ARFCN) indicating the downlink frequency. The control unit 230 of the base station 201 may include the derived security key in the handover request message. The control unit 230 of the base station 201 may also include the NCC associated with the derived security key in the handover request message.

[0050] Furthermore, the control unit 230 of the base station 201 does not need to include the security key and NCC in the handover request message. The control unit 230 also does not need to include the security key and / or NCC in the message regarding the cell switch in step S240 described later.

[0051] On the other hand, the control unit 230 of the base station 202 may, for example, determine whether or not to approve the LTM cell switch to the base station 202's cell based on the handover request message. If the control unit 230 approves the LTM cell switch, it may perform the following processing.

[0052] Step S140: The network communication unit 220 of base station 202 may send a Handover Request Acknowledge message to base station 201 to inform the source base station (i.e., base station 201) about the resources prepared at the target. The network communication unit 220 of base station 201 receives the Handover Request Acknowledge message from base station 202. This message may be used to notify acknowledgment of preparation for LTM.

[0053] The handover request approval message contains information about the cell managed by base station 202 and may include information that should be included in the configuration information for LTM. The configuration information for LTM may be, for example, LTM configuration information (e.g., LTM-Config) used to provide LTM settings. For example, the control unit 230 of base station 202 may include at least some or all of the LTM candidate settings (or LTM candidate setting information) for the LTM candidate cell of base station 202 (e.g., cell C2) in the handover request approval message. The control unit 230 may also include, for example, an RRC reset message used to set candidate settings in LTM, or an LTM candidate setting (ltm-CandidateConfig) including such an RRC reset message, in the handover request approval message. Note that LTM candidate settings may be appropriately referred to as LTM candidate setting information.

[0054] Furthermore, if the base station 202's control unit 230 includes the derived security key in the handover request message, it will also include the security key (for example, K NG-RAN *) Use the security key (for example, K) with the UE100. gNB ) may be used as such. The control unit 230 may associate the NCC with the security key if it is included in the handover request message. The control unit 230 of the base station 202 may also include the NCC included in the handover request message in the generated RRC reset message or LTM candidate setting. Alternatively, the control unit 230 may include the NCC in the handover command message included in the handover request approval message. Therefore, the control unit 230 may include the NCC in the RRC reset message (specifically the LTM candidate setting) notified by the handover command.

[0055] If the control unit 230 does not approve the LTM cell switch, it may, for example, send a handover preparation failure message to the source base station (i.e., base station 201) to inform the base station 201 that the handover preparation has failed.

[0056] The control unit 230 of base station 201 generates an RRC reset message to UE 100 before processing in step S150. The control unit 230 may, for example, include LTM configuration information (e.g., LTM-Config) in the RRC reset message (see E1 and E12 in Figure 8). Here, if the control unit 230 receives an RRC reset message from base station 202, it may generate an LTM candidate configuration that includes the RRC reset message. Alternatively, the control unit 230 may generate not only an LTM candidate configuration for base station 201 itself, but also an LTM candidate configuration for base station 202. The control unit 230 may generate an RRC reset message that includes the generated LTM configuration information.

[0057] LTM setting information may be information used to provide (one or more) LTM settings. The control unit 230 may include in the LTM setting information, for example, a list for releasing LTM candidate settings (hereinafter sometimes referred to as the LTM candidate release list (e.g., ltm-CandidateToReleaseList)). The control unit 230 may also include in the LTM setting information a list for adding or changing LTM candidate settings (hereinafter sometimes referred to as the LTM addition / modification list (e.g., ltm-CandidateToAddModList)) (see E22 in Figure 8).

[0058] The LTM candidate release list may be a list of LTM candidate settings to remove. The LTM candidate release list may consist of identifiers (e.g., ltm-CandidateId) to identify LTM candidate settings.

[0059] The LTM addition / modification list may be a list composed of LTM candidate information (e.g., LTM-Candidate) (see E31 and E32 in Figure 8). The LTM addition / modification list may also be a list of LTM candidate settings to be added and / or modified. LTM candidate settings may include, for example, at least one of the following pieces of information. As mentioned above, LTM setting information may include LTM candidate information. Also, LTM setting information may include LTM candidate settings. That is, LTM candidate information may correspond to LTM candidate settings. LTM setting information, LTM candidate information, and LTM candidate settings may be interchangeable. - Identifier of the LTM candidate setting (e.g., ltm-CandidateId) - Physical cell identifier of the LTM candidate setting included in the LTM candidate setting (e.g., ltm-CandidatePCI) - LTM candidate setting information (e.g., ltm-CandidateConfig)

[0060] The identifier for an LTM candidate setting may be the physical cell identifier (PCI) of a special cell (Sp cell). The special cell may be a P cell. For dual connection operation, the special cell may be an MCG P cell or an SCG PS cell. The LTM candidate setting information may include an RRC reset message used to set the LTM candidate setting. The RRC reset message may be a command to modify the RRC connection. That is, each of the one or more LTM candidate settings in the list may correspond to one or more LTM candidate cells. An LTM candidate setting (and / or information contained in an LTM candidate setting) may be replaced by an LTM candidate cell. Similarly, an LTM candidate cell may be replaced by an LTM candidate setting (and / or information contained in an LTM candidate setting).

[0061] Here, the control unit 230 of the base station 201 may include update information regarding security key updates (hereinafter sometimes referred to as first update information) in the configuration information for LTM. Firstly, the first update information may be included in another field (for example, field E21 in Figure 8) located in parallel with the field where the LTM candidate addition / modification list is set in the LTM configuration information (for example, LTM-Config). Secondly, the first update information may be included in another field (for example, fields E311, E321 in Figure 8) located in parallel with the field where the LTM candidate identifier (for example, ltm-CandidateId) and / or LTM candidate information (for example, ltm-Candidateconfig) is set in each LTM candidate information (for example, LTM-Candidate). In other words, the first update information may be included in each of one or more LTM candidate settings. Thirdly, the first update information may be included, for example, in a field (for example, fields E51, E52 in Figure 8) within the RRC reset message in the LTM candidate information (for example, fields E41, E42 in Figure 8). Here, the first update information may be included in another field (for example, field E11 in Figure 8) located in parallel with the field where the LTM candidate information is set in the RRC reset message within the LTM candidate information.

[0062] The first update information may include information indicating the execution of a security key update (e.g., master key update information (e.g., MasterKeyUpdate)). The first update information (e.g., master key update information included in the first update information) is a new security key K gNB It may include information indicating whether or not to derive (e.g., keySetChangeIndicator).

[0063] The first update information (for example, the master key update information included in the first update information) may include information indicating the NCC (NH Chaining Counter) used for deriving (or updating) the security key (hereinafter referred to as NCC information (e.g., nextHopChainingCount)). The NCC information may be a single parameter (i.e., a single NCC), a list of NCCs (i.e., one or more NCCs), or a list for each base station 200 (e.g., a set of one or more cells (candidate cells)) (i.e., a list of multiple NCCs). The list for each base station 200 may also be a list for each determination identifier as described later. The NCC (value) may be a parameter or value used for deriving (or updating) the security key to be updated next.

[0064] Furthermore, if the control unit 230 receives an NCC included in the handover request approval message from the base station 202, it may include the received NCC in the list of the base station 202.

[0065] The first update information (and / or master key update information) may include information used to determine whether or not to perform a security key update (hereinafter also referred to as a determination identifier). The determination identifier may be information used to indicate whether or not to perform a security key update. That is, the determination identifier may be information used to determine whether or not UE100 performs a security key update. The determination identifier may be information used to determine whether or not to perform a PDCP re-establishment. The determination identifier may be, for example, an identifier used to determine whether or not a security update should be performed. The determination identifier may be an identifier that identifies the cell set for the serving cell. The determination identifier may be an identifier used to determine whether or not to perform a security key update (or security update) when an LTM cell switch is performed. The determination identifier may be, for example, used to identify whether or not the corresponding cells are in the same set, or to identify the base station (e.g., gNB-CU) to which the corresponding cells belong. The determination identifier may also be used to identify whether or not the source cell and the target cell are different. The decision identifier may also be called securityCellSetId or servingSecurityCellSetId. The decision identifier may be a new identifier introduced, for example, in Release 19 or later of the 3GPP technical specification. The decision identifier may also be called ltm-SecurityCellsetID or LTM-NoResetID.

[0066] The determination identifier may also be called a cell set identifier. Here, a cell set may simply be a set, or it may be a security cell set. Hereafter, a cell set will also be simply referred to as a set. Furthermore, the cell set identifier may also be called a security cell set identifier. For example, the determination identifier may be used to identify whether each of one or more LTM candidate settings containing the first update information (and / or master key update information, and / or determination identifier) ​​corresponds to the same set (e.g., whether or not they are included in the same set). That is, the determination identifier may be used to identify whether each of one or more LTM candidate settings containing the first update information (and / or master key update information, and / or determination identifier) ​​is associated with the same base station (e.g., gNB-CU). Furthermore, the determination identifier may be used to identify whether each of the one or more LTM candidate settings containing the first update information (and / or master key update information, and / or determination identifier) ​​is associated with the same base station (e.g., gNB-CU) and / or a different base station (e.g., gNB-CU). The determination identifier may also be used to identify whether the cells (e.g., LTM candidate cells) corresponding to each of the one or more LTM candidate settings containing the first update information (and / or master key update information, and / or determination identifier) ​​correspond to the same set (whether or not they are included in the same set). In other words, the determination identifier may be used to identify whether the cells (e.g., LTM candidate cells) corresponding to each of the one or more LTM candidate settings containing the first update information (and / or master key update information, and / or determination identifier) ​​are associated with the same base station (e.g., gNB-CU). Furthermore, the determination identifier may be used to identify whether the cell corresponding to each of the one or more LTM candidate settings containing update information (and / or master key update information, and / or determination identifier) ​​is associated with the same base station (e.g., gNB-CU) and / or a different base station (e.g., gNB-CU).

[0067] Here, if the update information (and / or the master key update information, and / or the determination identifier) ​​is not included in the configuration information for LTM (i.e., if the first update information (and / or the master key update information, and / or the determination identifier) ​​is not present in the configuration information for LTM), the UE 100 does not need to perform a security key update. That is, if the first update information (and / or the master key update information, and / or the determination identifier) ​​is not included in the configuration information for LTM, the UE 100 may determine that each of the one or more LTM candidate settings corresponds to a different set. Also, if the first update information (and / or the master key update information, and / or the determination identifier) ​​is not included in the configuration information for LTM, the UE 100 may determine that each of the one or more LTM candidate settings is associated with a different base station (e.g., gNB-CU). Furthermore, if the first update information (and / or master key update information, and / or determination identifier) ​​is not included in the configuration information for LTM, it may be determined that the cells corresponding to each of the one or more LTM candidate settings (e.g., LTM candidate cells) correspond to different sets. Also, if the first update information (and / or master key update information, and / or determination identifier) ​​is not included in the configuration information for LTM, it may be determined that the cells corresponding to each of the one or more LTM candidate settings (e.g., LTM candidate cells) are associated with different base stations (e.g., gNB-CUs). Here, the update information may be the first identifier and / or second identifier, as described later.

[0068] In other words, UE100 may determine whether to perform a security key update based on whether the first update information (and / or master key update information, and / or determination identifier) ​​is included in the configuration information for LTM (whether the update information (and / or master key update information, and / or determination identifier) ​​exists in the configuration information for LTM). In other words, UE100 does not need to perform a security key update if the first update information (and / or master key update information, and / or determination identifier) ​​is not included in the configuration information for LTM. Also, UE100 does not need to perform a security key update if the first update information (and / or master key update information, and / or determination identifier) ​​is included in the configuration information for LTM and the determination identifier indicates that the security key update should not be performed. Furthermore, UE100 may perform a security key update if the first update information (and / or master key update information, and / or determination identifier) ​​is included in the configuration information for LTM, and the determination identifier indicates that a security key update should be performed (for example, including information indicating that a security key update should be performed, as described later).

[0069] Here, whether the first update information (and / or master key update information, and / or determination identifier) ​​is included in the configuration information for LTM may correspond to whether it is included in another field located in parallel with the field where the LTM candidate addition / modification list is set within the LTM configuration information (e.g., LTM-Config). Alternatively, whether the first update information (and / or master key update information, and / or determination identifier) ​​is included in the configuration information for LTM may correspond to whether it is included in another field located in parallel with the field where the LTM candidate identifier (e.g., ltm-CandidateId) and / or LTM candidate information (e.g., ltm-Candidateconfig) is set within each LTM candidate information (e.g., LTM-Candidate). In other words, whether the update information (and / or master key update information, and / or determination identifier) ​​is included in the configuration information for LTM may correspond to whether it is included in each of the one or more LTM candidate settings. Furthermore, whether the first update information (and / or master key update information, and / or determination identifier) ​​is included in the configuration information for LTM may correspond to whether or not it is included in a field in the RRC reset message within the LTM candidate information. That is, whether or not the first update information (and / or master key update information, and / or determination identifier) ​​is included in the configuration information for LTM may correspond to whether or not it is included in another field located in parallel with the field where the LTM candidate information is set in the RRC reset message within the LTM candidate information. Note that if the RRC message from base station 201 includes the determination identifier of the serving cell, the determination identifier of the LTM candidate cell may be included in all the configuration information for LTM (for example, each LTM candidate information).

[0070] The control unit 120 may store the determination identifier associated with cell C1 as the determination identifier of the (current) serving cell (i.e., an identifier that identifies the cell for the serving cell). The control unit 120 may store the determination identifier as a variable for storage. The control unit 120 may store the determination identifier in the variable VarServingSecurityCellSetID, or in a newly defined variable. The newly defined variable may be called VarServingSecurityCellSetID-19. The control unit 120 may determine, for example, that the determination identifier contained in field E1 or field E21 in Figure 8 is associated with cell C1 (or the serving cell).

[0071] The first update information may include information regarding the downlink frequency (e.g., absolute radio frequency channel number (ARFCN)). This downlink frequency information may be information used for updating security keys. The downlink frequency information may indicate the frequencies of PCI and / or synchronization signals (SS) and physical broadcast channel (PBCH) blocks (SSB). For example, the first update information containing downlink frequency information may be included in each of one or more LTM candidate configurations, thereby indicating the downlink frequency information corresponding to each of one or more LTM candidate configurations. That is, the first update information may include information regarding the downlink frequency for a cell (e.g., an LTM candidate cell) corresponding to each of the one or more LTM candidate configurations containing the first update information. For example, the first update information contained in each of the one or more LTM candidate settings may include information regarding the downlink frequency corresponding to the physical cell identifier (e.g., ltm-CandidatePCI) contained in each of the one or more LTM candidate settings.

[0072] The first update information may include information regarding security settings. This information may include information indicating the security algorithm and security key for the radio bearer (hereinafter referred to as security setting information (e.g., securityConfig)). The security setting information may be included in information used to add, modify, and release radio bearers (e.g., radio bearer configuration information (e.g., RadioBearerConfig)). For example, the inclusion of the first update information containing security setting information in each of one or more LTM candidate configurations may indicate the security setting information corresponding to each of one or more LTM candidate configurations. That is, the first update information may include security setting information for the cells (e.g., LTM candidate cells) corresponding to each of the one or more LTM candidate configurations containing the first update information.

[0073] The first update information (and security configuration information) may include information regarding the configuration of the algorithms used in security. This information may include, for example, information indicating the security algorithm for the radio bearer (e.g., security algorithm configuration information (e.g., securityAlgorithmConfig)). The security algorithm configuration information may include information indicating the encryption algorithm used for signaling radio bearers (SRBs) and data radio bearers (DRBs) (e.g., cipheringAlgorithm) and information indicating the integrity algorithm used for SRBs and DRBs (e.g., integrityProtAlgorithm). For example, the first update information containing information regarding algorithm configurations may be included in each of one or more LTM candidate configurations, thereby indicating information regarding the algorithm configurations corresponding to each of one or more LTM candidate configurations. In other words, the first update information may include information regarding the algorithm settings for each cell (e.g., LTM candidate cell) corresponding to one or more LTM candidate settings that include the first update information.

[0074] The first update information (and security configuration information) may include information on security keys used to generate keys for each security algorithm. This information may, for example, indicate whether a bearer configured in the list within the wireless bearer configuration information is used as a master or secondary key for deriving encryption and / or integrity protection keys (e.g., key used information (e.g., keyToUse)). For example, the inclusion of the first update information containing security key information in each of one or more LTM candidate configurations may indicate the security key information corresponding to each of one or more LTM candidate configurations. That is, the first update information may include security key information for the cells (e.g., LTM candidate cells) corresponding to each of the one or more LTM candidate configurations containing the first update information.

[0075] The control unit 230 may include information regarding the re-establishment of the PDCP in the configuration information for the LTM. The control unit 120 may include at least one of the following as such information: radio bearer configuration information (e.g., RadioBearerConfig) and security configuration information (e.g., securityConfig). For example, the information regarding the re-establishment of the PDCP corresponding to each of the one or more LTM candidate configurations may be indicated by including first update information containing information regarding the re-establishment of the PDCP in each of the one or more LTM candidate configurations. That is, the first update information may include information regarding the re-establishment of the PDCP for each of the one or more LTM candidate configurations containing the first update information (e.g., LTM candidate cell).

[0076] Step S150: The transmitting unit 211 of the base station 201 may transmit an RRC reset message containing LTM setting information from cell C1 to UE100. The receiving unit 112 of UE100 may receive the RRC reset message from the base station 201 (or cell C1) as an RRC message. As a result, UE100 can receive the LTM setting information from cell C1 via the RRC message.

[0077] Step S160: The transmitter 111 of UE100 may send an RRC reset completion message to the base station 201 (cell C1). The receiver 212 of base station 201 may receive the RRC reset completion message from UE100 in cell C1.

[0078] Step S170: The control unit 120 of UE100 may perform downlink (DL) synchronization with LTM candidate cells before receiving a cell switch command. UE100 may perform DL synchronization based on SSB. For example, the control unit 120 of UE100 may perform DL synchronization based on SSB transmitted from each LTM candidate cell.

[0079] The control unit 120 of UE100 may perform uplink (UL) synchronization with the LTM candidate cell before receiving the cell switch command. Furthermore, if UE-based timing advance (TA) measurement (e.g., UE-based TA measurement) is configured, the control unit 120 may perform timing advance (TA) acquisition when the LTM cell switch is executed. The control unit 120 may also perform TA acquisition based on the cell switch command described later.

[0080] Step S180: Subsequently, as shown in Figure 6, the control unit 120 of UE100 may perform measurements (e.g., L1 measurements) in the candidate cells set by the LTM candidate setting. The L1 measurement may be, for example, a measurement filtered at layer 1. UE100 may transmit a lower-layer measurement report (hereinafter, L1 measurement report) based on the L1 measurement to the base station 201. For example, the transmitting unit 111 of UE100 performs L1 measurements in each candidate cell set by the LTM setting information and then transmits an L1 measurement report to the base station 201. The receiving unit 212 of the base station 201 receives the L1 measurement report from UE100. The L1 measurement report is a lower-layer measurement report based on the L1 measurement. The L1 measurement report is transmitted at a layer lower than the RRC layer. Note that the measurement report in step S120 is transmitted at the RRC layer.

[0081] The control unit 230 of the base station 201 may determine the target cell in LTM (i.e., the LTM target cell) based on the L1 measurement report. The control unit 230 may also determine whether to have the UE 100 execute a RACH-less LTM (RACH-less LTM), in which the UE 100 performs uplink transmission without executing an RA procedure between the UE 100 and the base station 201, or to have the UE 100 execute a RACH-based LTM (RACH-base LTM), in which the RA procedure is executed between the UE 100 and the base station 201. In other words, one or more LTM candidate cells may correspond to the target cell. For example, one or more LTM candidate cells that are targeted by a cell switch (i.e., an LTM cell switch) may be referred to as the target cell.

[0082] The control unit 230 generates a MAC CE for sending a cell switch command. This MAC CE may be referred to as, for example, an LTM cell switch command MAC CE. This MAC CE may be a cell switch command that triggers an LTM cell switch (execution). Hereinafter, the LTM cell switch command MAC CE may be referred to as a cell switch command as appropriate. The cell switch command may also be referred to as an LTM cell switch command. The cell switch command may be used to perform a cell switch to a target cell. For example, the control unit 230 may decide to perform a cell switch to a target cell. The control unit 230 may also control the transmission of a cell switch command that includes a target setting identifier indicating the index of the target cell's candidate setting (e.g., an identifier for the LTM candidate setting) in order to trigger a cell switch to a target cell. The cell switch command may include, for example, at least one of the following pieces of information (i.e., fields):

[0083] A cell switch command may include, for example, information from at least one of the following: a target setting identifier, a timing advance command, and a C field.

[0084] The target configuration identifier (e.g., Target Configuration ID) may indicate the index of the target configuration to be applied to the LTM cell switch. That is, the target configuration identifier may correspond to the configuration corresponding to the target cell (e.g., LTM candidate configuration). As mentioned above, for example, the target configuration identifier may correspond to the index of the target cell's candidate configuration (e.g., the identifier of the LTM candidate configuration).

[0085] A timing advance command (e.g., Timing Advance Command) may indicate whether a TA is valid for the LTM target cell. For example, if the field of the timing advance command is set to FFF, the field may indicate that no valid timing adjustment is available for the Primary Timing Advance Group (PTAG) of the LTM target cell. On the other hand, if a value other than FFF is set for the field, the field may indicate an index value (i.e., a TA value) used to control the amount of timing adjustment that the MAC entity of UE100 should apply. As described below, for example, if the value of the field is set to FFF, a RACH-based LTM may be executed. Alternatively, if a value other than FFF is set for the field, a RACH-less LTM may be executed.

[0086] The C field may indicate the presence of a contention-free random access release field. If the value of the C field is set to "1", it may indicate the presence of fields that indicate information used for contention-free random access (e.g., the Random Access Preamble index field, S / U field, SS / PBCH index field, PRACH Mask index field, and / or Repetition number field). If the value of the C field is set to "0", it may indicate that the above fields do not exist. In other words, if the value of the C field is set to "1", the Random Access Preamble index, uplink carrier (S: Supreme uplink carrier, or U: Normal uplink carrier), SS / PBCH index, PRACH Mask index, and / or Repetition number indicated using the above field may be used for random access procedures in RACH-based LTM.

[0087] Step S190: The transmitter 211 of the base station 201 transmits a cell switch command to the UE 100 via MAC CE. The receiver 112 of the UE 100 receives the cell switch command from the base station 201 via MAC CE.

[0088] The control unit 120 of UE100 performs an indication from the MAC layer to the RRC layer based on the reception of a cell switch command. This may trigger an LTM cell switch to the target cell, cell C2. That is, based on the reception of a cell switch command, the MAC layer of UE100 may notify the RRC layer of UE100 of an indication to trigger an LTM cell switch. The control unit 120 may perform an LTM cell switch, which is a cell switch from cell C1 to cell C2, based on the LTM configuration information. Here, the indication may include an LTM candidate configuration identifier (i.e., a target configuration identifier), and / or first update information (and / or information contained in the first update information). The control unit 120 may perform (trigger) an LTM cell switch in the RRC layer based on the indication from the MAC layer. When the control unit 120 performs (triggers) an LTM cell switch, it may perform the following processing.

[0089] Step S200: The control unit 120 of the UE100 may perform detachment from the source (source cell (cell C1) / source base station (i.e., base station 201)) and apply target settings. During the processing of this step, the control unit 120 may perform the following processing.

[0090] The control unit 120 of UE100 may determine the LTM candidate setting for the target cell based on the target setting identifier included in the cell switch command. For example, the control unit 120 may perform control to set (identify) an LTM candidate setting in the RRC layer that includes an identifier for the LTM candidate setting corresponding to the target setting identifier from the MAC layer included in the cell switch command. Alternatively, for example, the control unit 120 may perform control to set an LTM candidate setting in UE100 that is associated with the same LTM candidate setting identifier as the target setting identifier included in the cell switch command. The control unit 120 may apply the determined LTM candidate setting. In this way, the control unit 120 may perform the application of the target setting.

[0091] The control unit 120 may apply the RRC reset message in the LTM candidate setting information, which is identified by the LTM candidate setting identifier, i.e., the target setting identifier, received from the lower layer (i.e., the MAC layer). The control unit 120 may also perform receiving processing for the RRC reset message. In this way, the control unit 120 may perform processing on the RRC reset message in the LTM candidate setting information while the LTM cell switch is running. That is, the control unit 120 may perform application and / or receiving processing of the RRC reset message at the RRC layer.

[0092] Step S201: The control unit 120 may perform a security key update determination. The control unit 120 may determine whether or not to perform a security key update based on the first update information. The control unit 120 may determine whether or not to perform a security key update by, for example, at least one of the following determination methods.

[0093] Firstly, the control unit 120 may determine whether or not to perform a security key update based on whether or not the LTM configuration information includes the first update information. The control unit 120 may determine to perform a security key update if the LTM configuration information (for example, field E21 in the LTM configuration information) includes the first update information. On the other hand, the control unit 120 may determine not to perform a security key update if the LTM configuration information (for example, field E21 in the LTM configuration information) does not include the first update information.

[0094] Secondly, the control unit 120 may determine whether or not to perform a security key update based on whether or not the LTM candidate setting information includes the first update information. The control unit 120 may determine to perform a security key update if the LTM candidate setting information set in UE 100 among one or more LTM candidate setting information includes the first update information. Here, the LTM candidate setting information to be set may be, for example, the LTM candidate setting information indicated by the target setting identifier included in the cell switch command (LTM candidate setting information corresponding to the target setting identifier). The LTM candidate setting information may also be associated with the cell after the cell switch. On the other hand, the control unit 120 may determine not to perform a security key update if the LTM candidate setting information set in UE 100 among one or more LTM candidate setting information does not include the first update information.

[0095] Thirdly, the control unit 120 may make a decision based on the information contained in the first update information. The control unit 120 may decide to perform a security key update if the first update information contains information indicating the execution of a security key update. On the other hand, the control unit 120 may decide not to perform a security key update if the first update information does not contain information indicating the execution of a security key update. The information indicating the execution of a security key update may be master key update information, or a new security key K gNB This could also be information indicating whether or not to derive (for example, keySetChangeIndicator).

[0096] Fourth, the control unit 120 may determine whether or not to perform a security key update based on the determination identifier. The control unit 120 may determine to perform a security key update if the value of the determination identifier stored as the determination identifier of cell C1 (hereinafter referred to as the first identifier) ​​is different from (i.e., not equal to) the value of the determination identifier of cell C2 included in the first update information (hereinafter referred to as the second identifier). On the other hand, the control unit 120 may determine not to perform a security key update if the value of the first identifier and the value of the second identifier are equal. For example, the first identifier may be the determination identifier of the serving cell. The second identifier may also be the determination identifier in the first update information included in each of the one or more LTM candidate settings. As described above, the control unit 120 may set (specify) an LTM candidate setting that includes the identifier of the LTM candidate setting corresponding to the target setting identifier based on the target setting identifier (i.e., the value of the target setting identifier) ​​included in the cell switch command. Furthermore, the control unit 120 may determine to perform a security key update if the value of the first identifier and the value of the second identifier included in the set (specified) LTM candidate setting are different (i.e., not equal) (i.e., it may perform a security key update when an LTM cell switch is performed). Also, the control unit 120 may determine not to perform a security key update if the value of the first identifier and the value of the second identifier included in the set (specified) LTM candidate setting are equal (i.e., it does not need to perform a security key update when an LTM cell switch is performed).

[0097] Furthermore, the control unit 120 may determine to perform a security key update if the first identifier is not included in the configuration information for LTM (and / or the first update information). Furthermore, the control unit 120 may determine to perform a security key update if the first identifier is not included in the corresponding variable. Furthermore, as described above, the control unit 120 may determine not to perform a security key update if the first identifier is not included in the configuration information for LTM (and / or the first update information). Furthermore, the control unit 120 may determine not to perform a security key update if the first identifier is not included in the corresponding variable. Furthermore, the control unit 120 may determine not to perform a security key update if the second identifier is not included in the configuration information for LTM (and / or the first update information). Furthermore, the control unit 120 may determine not to perform a security key update if the second identifier is not included in the corresponding variable.

[0098] Furthermore, if the first identifier and the second identifier are different (i.e., not equal), the control unit 120 may store the value of the second identifier as a new variable instead of the value of the first identifier. Also, if the value of the first identifier and the value of the second identifier are different (i.e., not equal), and the corresponding variable contains the value of the first identifier, the control unit 120 may replace the variable with the value of the second identifier (or replace the value of the first identifier with the value of the second identifier). Hereafter, the value of the first identifier will also be simply referred to as the first identifier. Similarly, the value of the second identifier will also be simply referred to as the second identifier.

[0099] The determination identifier corresponding to the second identifier may be set in fields E311, E321, etc., of the LTM candidate information, or in fields E51, E52, etc., of the RRC reset message within the LTM candidate information. It may also be set in field E21 of the LTM setting information as a list of determination identifiers. In this case, the determination identifier may be associated with the identifier of the LTM candidate setting and / or the physical cell identifier of the LTM candidate setting. The control unit 120 may use the determination identifier associated with the applicable LTM candidate setting and / or target cell as the second identifier.

[0100] If the first update information (or LTM setting information) does not include the determination identifier, the control unit 120 may determine not to execute the security key update. Even if the LTM setting information and / or the LTM candidate setting information includes information indicating the execution of the above security key update, if the first update information (or the LTM setting information) does not include the determination identifier, the control unit 120 may determine not to execute the security key update.

[0101] If the control unit 120 determines to execute the security key update, it may execute the process of step S202. If the control unit 120 determines not to execute the security key update, it may skip the process of step S202.

[0102] Step S202: When the control unit 120 of the UE 100 executes the LTM cell switch from cell C1 to cell C2, it updates the security key. The control unit 120 executes the security key update process as follows, for example. As the security key update process, the control unit 120 may execute the AS security key update process. As the security key, the key for the base station (for example, K gNB ) may be updated or derived.

[0103] The key for the base station may be a key derived by the UE 100 (for example, ME (Mobile Equipment)) and the AMF from the key for the AMF (for example, K AMF ). The key for the base station may be further derived by the ME and the source base station when horizontal and vertical key derivations are executed. The key for the AMF may be a key derived from the UE 100 (for example, ME) and the SEAF (Security Anchor Function). Also, the key for the base station may be derived by referring to the key of the current base station. At this time, cell specific information (for example, the PCI of the target cell, the downlink frequency, etc.) may be used for the derivation of the key for the base station.

[0104] As the security key update process, the control unit 120 may execute either the first update process or the second update process.

[0105] In the first update process, the control unit 120 may perform an update (or derivation) of the security key as a security key update process, based on the current base station key or NH (Next Hop parameter). The control unit 120 may also perform an update (or derivation) of the security key using NCC information. For example, if the NCC information is one parameter (i.e., one NCC), the control unit 120 may update the security key using that NCC.

[0106] The control unit 120 may update the NCC by increasing it to a predetermined value (for example, 1) in response to the security key update. The control unit 120 may update the NCC before updating the security key. The control unit 120 may update the security key using the updated NCC. Alternatively, the control unit 120 may update the NCC after updating the security key. The control unit 120 may use the updated NCC when performing the next LTM cell switch. The control unit 120 may store (save) the (updated) NCC. The control unit 120 may store (store) the updated NCC as the NCC to be used at the timing of the next LTM between different base stations (the next Inter-CU LTM).

[0107] If the NCC information is a list of NCCs, the control unit 120 may select an NCC from the list. The control unit 120 may select the first NCC in the list. In this case, the control unit 120 may delete the selected NCC. The control unit 120 may select the first unused NCC in the list. If an NCC is associated with a determination identifier in the list, the control unit 120 may select the NCC associated with the determination identifier corresponding to the second identifier.

[0108] If the NCC information is a list for each base station (i.e., if multiple lists are set as NCC information), the control unit 120 may, for example, use a list of NCCs associated with a determination identifier. The control unit 120 may select the first unused NCC in the list, or it may select the first unused NCC.

[0109] Furthermore, the control unit 120 may store the NCC selected for use in updating the security key as a variable in the UE 100. The control unit 120 may store the selected NCC as an existing variable or as a new variable. Therefore, the control unit 120 may store the NCC selected for use in updating the security key during LTM cell switch execution as a second variable, which is a variable separate from the first variable (existing variable) where a general NCC is stored. The control unit 120 may also store (save) the updated NCC as the first variable or as the second variable. The second variable may store the value of the NCC used when performing LTM (Inter-CU LTM) between different base stations.

[0110] In the second update process, the control unit 120 sets a key for AMF (for example, K AMF Based on this, you may perform a security key update (or derivation).

[0111] Here, the control unit 120 receives a new security key K gNB The control unit 120 may switch between the first update process and the second update process based on information indicating whether or not to derive a new security key K. gNB If it does not indicate that a new security key K should be derived (for example, if keySetChangeIndicator is set to "false"), the first update process may be executed. On the other hand, if keySetChangeIndicator is set to a new security key K, the control unit 120 will perform the first update process. gNBIf it is not indicated that the result should be derived (for example, keySetChangeIndicator is set to "true"), the second update process may be executed.

[0112] Alternatively, if the LTM setting information or the LTM candidate setting information set in UE100 includes master key update information, the control unit 120 may execute the first update process without executing the second update process, regardless of keySetChangeIndicator. The control unit 120 may assume that keySetChangeIndicator is always set to "false" if master key update information is included. The control unit 120 may execute the first update process if it determines that the security key should be updated, or it may assume that keySetChangeIndicator is always set to "false".

[0113] When the control unit 120 performs a security key update process, it may derive a security key associated with the base station key. The security key may include, for example, a key for RRC signaling (hereinafter appropriately referred to as the RRC key) and a key for UP traffic (hereinafter appropriately referred to as the UP traffic key).

[0114] The RRC key is a key for the base station (for example, K gNB ) may be a key derived by UE100 (e.g., ME) and base station 200. The RRC key is a key used solely for protecting RRC signaling along with a specific integrity algorithm (e.g., K RRCint ) and a key used solely for protecting RRC signaling along with a specific encryption algorithm (e.g., K RRCenc ) and may have.

[0115] The UP traffic key may be a key derived by UE100 (e.g., ME) and base station 200. The UP traffic key is a key used solely for protecting UP traffic between UE100 (e.g., ME) and base station 200, along with a specific integrity algorithm (e.g., K UPenc) and a key (e.g., K) used solely for protecting UP traffic between UE100 (e.g., ME) and base station 200, along with a specific encryption algorithm. UPint ) and may have.

[0116] If the LTM setting information or LTM candidate setting information set in UE100 includes security algorithm setting information, the control unit 120 will determine the RRC key (K) based on the information indicating the encryption algorithm included in that information (e.g., cipheringAlgorithm). RRCenc ) and UP traffic key (K UPenc ) and derive the RRC key (K) based on information indicating the integrity algorithm (e.g., integrityProtAlgorithm). RRCint ) and UP traffic key (K UPint ) and may be derived. On the other hand, if the control unit 120 does not include security algorithm setting information in the LTM setting information or the LTM candidate setting information set in UE100, it may derive the RRC key (K RRCenc ) and UP traffic key (K UPenc ) and derive the RRC key (K) based on information indicating the currently set integrity algorithm (e.g., integrityProtAlgorithm). RRCint ) and UP traffic key (K UPint You may derive the following:

[0117] The control unit 120 may perform processing for PDCP processing. When the control unit 120 performs an LTM cell switch based on LTM configuration information, it may perform processing for PDCP processing based on information regarding PDCP re-establishment. When the control unit 120 performs a security key update based on the execution of an LTM cell switch, it may perform processing for PDCP processing based on information regarding PDCP re-establishment. As processing for PDCP processing, the control unit 120 may, for example, re-establish a PDCP entity. The control unit 120 may apply the integrity algorithm, encryption algorithm, and security key provided from the RRC layer to the PDCP entity.

[0118] Step S210: The network communication unit 220 of base station 201 may send a message relating to cell switching to base station 202. The network communication unit 220 of base station 202 may receive the message from base station 201. The message may be a message indicating that cell switching is being performed (for example, a Cell Switch notification message). The message may include information indicating that UE 100 has switched to a cell of base station 202. The message may include information indicating that the cell of base station 202 is the target cell of UE 100.

[0119] The control unit 230 of the base station 201 may include the derived security key and / or NCC in the cell switch notification message, similar to step S130. The control unit 230 may include the security key and / or NCC in the cell switch notification message if, for example, the handover request message does not include the derived security key and / or NCC. The control unit 230 does not have to include the security key and / or NCC in the cell switch notification message if the handover request message does include the derived security key and / or NCC. Alternatively, the control unit 230 may or may not include the security key and / or NCC in the cell switch notification message, regardless of whether the handover request message includes the derived security key and / or NCC.

[0120] Furthermore, the control unit 230 of base station 201 may include the LTM setting information contained in the RRC reset message in step S150 in the cell switch notification message. This allows the control unit 230 of base station 202 to understand the operation of the LTM (particularly the subsequent LTM) in UE 100 after cell switching to cell C2.

[0121] Step S220: If the control unit 120 of UE100 decides to execute a RACH-based LTM, it executes a random access (RA) procedure. As described above, the control unit 120 may decide whether to execute a RACH-based LTM or a RACH-less LTM based on the value included in the timing advance command. The control unit 120 may decide, for example, as follows:

[0122] Firstly, the control unit 120 may decide to execute RACHless LTM if the value of the timing advance command is not set to FFF. In this case, the control unit 120 may consider that RACHless LTM is being executed in the MAC layer. The control unit 120 may indicate that it will skip the random access procedure from the MAC layer to the upper layer. That is, the control unit 120 of UE 100 may skip the processing in step S220.

[0123] Secondly, if TA measurement is set and the TA for the LTM target has been successfully measured (i.e., TA measurement has been successful), the control unit 120 may decide to execute RACH-less LTM. In this case, the control unit 120 may perform the same operations as when the first decision was made.

[0124] Thirdly, the control unit 120 may decide to execute RACH-based LTM in cases other than those described above (i.e., (a) when the value of the timing advance command is set to FFF and TA measurement is not set, or (b) when TA measurement fails). In this case, the control unit 120 may consider that RACH-based LTM is in progress at the MAC layer.

[0125] Step S230: The control unit 120 of UE100 may complete the LTM cell switch procedure by sending an RRC reset completion message to the target cell, cell C2. If UE100 is performing a RACH-based LTM, the control unit 120 of UE100 may consider the LTM cell execution procedure to have been successfully performed (i.e., LTM completion has been performed) when the random access procedure has been successfully completed. On the other hand, if UE100 is performing a RACH-less LTM, the transmitter unit 111 of UE100 may send an uplink transmission (e.g., the first uplink data) to the base station 201. If UE100 determines that the network has successfully received the uplink transmission, the control unit 120 of UE100 may consider the LTM execution procedure to have been successfully performed (i.e., LTM completion has been performed).

[0126] Here, the transmitting unit 111 may send an RRC message containing information regarding the updating of the security key (hereinafter referred to as the second update information as appropriate) to cell C2 (base station 202). Specifically, when the LTM cell switch operation is completed, the transmitting unit 111 may send an RRC reset completion message containing the second update information as an RRC message. Accordingly, the control unit 120 may include the following information in the second update information in the RRC message. The RRC message containing the second update information may be, for example, an RRC reconfiguration completion message used to confirm the successful completion of RRC connection reconfiguration, an RRC reconfiguration completion message generated when applying an RRC reconfiguration message included in the LTM candidate setting (see E41 and E42 in Figure 8), an RRC reconfiguration completion message sent after step S220 is executed, an RRC reconfiguration completion message sent without executing step S220, or an RRC reconfiguration message used to send information (confirmation information) indicating that RRC reconfiguration has been successfully completed.

[0127] The second update information may include, for example, information indicating the NCC (e.g., nextHopChainingCount), which is a parameter used to derive the security key. The information indicating the NCC may indicate the NCC used when performing an LTM (Inter-CU LTM) between different base stations. The information indicating the NCC may indicate the NCC used when performing a subsequent LTM (between different base stations). The information indicating the NCC may indicate the NCC used to derive the security key applied during PDCP re-establishment. In the case of a subsequent LTM, after each LTM cell switch is completed, the procedure of early synchronization, LTM cell switch execution, and LTM cell switch completion may be repeated without releasing (other) LTM candidate settings. Therefore, in a subsequent LTM, after the LTM cell switch is completed, early synchronization may be performed without performing LTM preparation.

[0128] The information indicating the NCC may indicate the NCC used to update the security key when performing an LTM cell switch to cell C2. The control unit 120 of UE100 may select the NCC used to update (derive) the security key in step S202 described above as the information indicating the NCC.

[0129] Furthermore, the information indicating the NCC may indicate the NCC used to derive the next security key after updating the security key when performing an LTM cell switch to cell C2. Therefore, the information indicating the NCC may indicate the NCC that is scheduled to be used at the timing of the next LTM between different base stations (the next Inter-CU LTM). The information indicating the NCC may, for example, indicate the NCC updated in step S202 described above. The control unit 120 may, for example, use a value obtained by increasing a predetermined value (for example, 1) to the NCC used to update (derive) the security key in step S202 described above as the information indicating the NCC. If the NCC information is a list of NCCs, the control unit 120 may select an unused NCC (or a valid NCC) from among the multiple NCCs. The control unit 120 may select the NCC at the top of the list. In this case, the control unit 120 may delete the NCC used to update the security key. Alternatively, the control unit 120 may select the first unused NCC from among the one or more NCCs in the list. Alternatively, the control unit 120 may randomly select an NCC from among the unused NCCs. The control unit 120 may delete the NCC used to update the security key. The control unit 120 may also store the NCCs that have been used to update the security key.

[0130] The control unit 120 may, for example, in step S202, select the NCC stored as a variable as information indicating the NCC to be included in the second update information. The control unit 120 may also select the value stored as a second variable as information indicating the NCC to be included in the second update information.

[0131] The second update information includes, for example, information indicating the security key (for example, security key K gNB) may be included. Note that security key K gNB is, K gNB * It may also be written as follows. The security key may be calculated in UE100 based on the execution of an LTM cell switch to cell C2.

[0132] The second update information may include information for identifying base station 202 and / or the central unit (CU) of base station 202. This information may include, for example, one or more of the following: the target cell determination identifier, the target cell physical cell identifier (PCI), and / or information indicating the downlink frequency of the target cell's SSB. This information may also be used to derive a security key based on the execution of an LTM cell switch to cell C2. The control unit 120 may include this information in the RRC message along with information indicating the security key.

[0133] The control unit 120 may determine whether or not to include the second update information in the RRC message. For example, if the security key is updated when executing the LTM cell switch, the control unit 120 may perform control to include the second update information in the RRC message. On the other hand, if the security key is not updated when executing the LTM cell switch, the control unit 230 may perform control to not include the update information in the RRC message. For example, the control unit 120 may determine whether or not to include the second update information in the RRC message using the same criteria as for determining whether or not to perform the security key update, similar to step S201. For example, if the security key is updated, the control unit 120 may determine to include the second update information in the RRC message. If the security key is not updated, the control unit 120 may determine not to include the second update information in the RRC message.

[0134] The control unit 120 may make a determination based on a flag indicating that a security key update has been performed. If the flag indicates that a security key update has been performed, the control unit 120 may determine to include the second update information in the RRC message. Otherwise, the control unit 120 may determine not to include the second update information in the RRC message.

[0135] The control unit 120 may determine to include the second update information in the RRC message if it has used (or selected) the NCC value based on the execution of the LTM cell switch. The control unit 120 may determine not to include the second update information in the RRC message if it has not used (or selected) the NCC value. The control unit 120 may also determine to include the second update information in the RRC message if the NCC is stored in the second variable mentioned above. On the other hand, the control unit 120 may determine not to include the second update information in the RRC message if the NCC is not stored in the second variable mentioned above.

[0136] For example, as shown in Figure 9, when a new NCC (new nextHopChainingCount value) is selected based on the execution (trigger) of an LTM cell switch, the RRC reset completion message may include a second update information (e.g., selectedNextHopChainingCount) and set the selected new NCC (new nextHopChainingCount value) in the second update information.

[0137] Furthermore, the second update information may include, for example, information indicating that it does not possess information indicating an unused NCC used to derive a security key when executing an LTM cell switch (hereinafter appropriately referred to as NCC non-possession information). The control unit 120 may include the NCC non-possession information in the second update information, or the control unit 120 may include the NCC non-possession information separately in the RRC message.

[0138] The control unit 120 may include information indicating unheld NCCs in the second update information if it does not have information indicating unused NCCs used to derive security keys when executing an LTM cell switch. The control unit 120 may also include information indicating unheld NCCs in the second update information if, as a result of updating the NCCs, the value of the NCCs becomes equal to or greater than the maximum value (e.g., 7). The maximum value may be, for example, the maximum number of NCCs that can be set in UE100. Furthermore, the control unit 120 may include information indicating unheld NCCs in the second update information if there are no more unused or valid NCCs in a list of NCCs. If the control unit 120 has multiple lists of NCCs (e.g., a list for each determination identifier), it may include information indicating unheld NCCs in the second update information if there are one or more lists that no longer contain unused or valid NCCs.

[0139] The NCC non-holding information may include, for example, a one-bit flag indicating an unused NCC used to derive a security key when performing an LTM cell switch. The NCC non-holding information may also include information (e.g., a decision identifier) ​​indicating one or more lists of unused or valid NCCs that have been depleted.

[0140] The receiving unit 212 of the base station 202 may receive an RRC reset completion message from the UE 100 as an RRC message containing second update information in cell C2. If the RRC reset completion message from the UE 100 contains second update information, the control unit 230 of the base station 202 may determine whether the security key of the UE 100 is appropriate based on the second update information. The determination made by the control unit 230 will be described later.

[0141] Step S240: The network communication unit 220 of the base station 202 may send a PATH SWITCH REQUEST message to the core network device (e.g., AMF) 300. The network communication unit of the core network device 300 may receive the PATH SWITCH REQUEST message from the base station 202. The PATH SWITCH REQUEST message may be a message that triggers the 5GC 30 to direct the downlink (DL) data path of the UE 100 to the target base station (i.e., base station 202). The PATH SWITCH REQUEST message may be a message sent by a network node (e.g., NG-RAN node) to notify the AMF of a new serving node (e.g., new serving NG-RAN node).

[0142] Based on the receipt of the pass switch request message, 5GC30 may switch the DL data path to base station 202. Also, based on the receipt of the pass switch request message, the control unit of core network device 300 may increment a predetermined value (for example, 1) in the NCC (value) held locally in core network device 300 to calculate (compute) a new fresh NH. After that, core network device 300 may perform the following processing.

[0143] Step S250: The network communication unit of the core network device (AMF) 300 may send a PATH SWITCH REQUEST ACKNOWLEDGE message to the base station 202. The network communication unit 220 of the base station 202 may receive the PATH SWITCH REQUEST ACKNOWLEDGE message from the core network device 300.

[0144] The pass switch request approval message may be a message sent by the AMF to notify a network node (e.g., NG-RAN node) that the pass switch has been successfully completed at 5GC30. The core network device 300 may confirm the pass switch request message with the pass switch request approval message. The pass switch request approval message may include a calculated NH and NCC pair. The NCC may be an NCC with a predetermined value incremented.

[0145] Step S260: The control unit 230 of the base station 202 may perform a security-related determination. Based on the second update information, the control unit 230 may determine whether the security key of the UE 100 is appropriate.

[0146] Firstly, the control unit 230 may determine whether the security key updated in UE 100 is appropriate. The control unit 230 may determine whether the security key indicated by the information indicating the security key included in the second update information is the same as the security key received from base station 201. The security key received from base station 201 may be included in the handover request message or in the cell switch notification message.

[0147] The control unit 230 may derive a security key based on information indicating the NCC included in the second update information. The control unit 230 may derive a security key based on information for identifying the base station 202 and / or the CU of base station 202 included in the second update information. The control unit 230 may determine whether the derived security key is the same as the security key received from base station 201.

[0148] The control unit 230 may determine that the security key in UE 100 is appropriate if the derived security key and the security key received from the base station 201 are the same. On the other hand, the control unit 230 may determine that the security key in UE 100 is inappropriate if the derived security key and the security key received from the base station 201 are different.

[0149] Secondly, the control unit 230 may determine whether the NCC used to derive the next security key is appropriate after updating the security key when performing an LTM cell switch in UE 100. The control unit 230 may, for example, determine whether the NCC received from the core network device 300 is the same as the NCC indicated by the information indicating the NCC included in the second update information (hereinafter, the NCC received from UE 100). The NCC received from UE 100 may, for example, be the NCC used to derive the next security key after updating the security key when performing an LTM cell switch to cell C2.

[0150] The control unit 230 may determine that the security key in UE 100 is appropriate if the NCC received from the core network device 300 and the NCC received from UE 100 are the same. On the other hand, the control unit 230 may determine that the security key in UE 100 is inappropriate if the NCC received from the core network device 300 and the NCC received from UE 100 are different.

[0151] Furthermore, the control unit 230 may identify the NCC to be used in deriving the next security key in UE 100 (hereinafter referred to as the UE-side NCC) based on the NCC received from the base station 201. The control unit 230 may identify the UE-side NCC by, for example, the same operation as UE 100 in step S202. Specifically, the control unit 230 may identify the value obtained by increasing a predetermined value to the NCC received from the base station 201 as the UE-side NCC. Alternatively, the control unit 230 may identify the first NCC in the list of NCCs set in UE 100 as the UE-side NCC. The control unit 230 may identify the UE-side NCC based on the LTM setting information received from the base station 201 in step S210, for example.

[0152] The control unit 230 may determine that the security key in UE 100 is appropriate if the identified UE-side NCC and the NCC received from UE 100 are the same. On the other hand, the control unit 230 may determine that the security key in UE 100 is inappropriate if the identified UE-side NCC and the NCC received from UE 100 are different.

[0153] If the control unit 230 determines that the security key in UE 100 is appropriate, it does not need to perform the process in step S270. On the other hand, if the control unit 230 determines that the security key in UE 100 is inappropriate, it may perform the process in step S270. Therefore, the control unit 230 may or may not perform the process in step S270 based on the second update information.

[0154] Furthermore, the control unit 230 may execute the process in step S270 if the second update information includes NCC unheld information. The control unit 230 does not need to execute the process in step S270 if the second update information does not include NCC unheld information.

[0155] When the control unit 230 executes the process in step S270, it may, for example, include information indicating the NCC in the RRC reset message. If the derived security key and the security key received from the base station 201 are different, the control unit 230 may include information indicating the NCC used to calculate the derived security key in the RRC reset message. Furthermore, if the NCC received from the core network device 300 is different from the NCC received from the UE 100 to be used for deriving the next security key, the control unit 230 may include information indicating the NCC received from the core network device 300 in the RRC reset message.

[0156] Furthermore, the control unit 230 may include the NCC information contained in the first update information in the RRC reset message. For example, if the RRC reset completion message contains information indicating that an NCC is not held, the control unit 230 may include NCC information for setting an unused NCC in the UE 100 in the RRC reset message. The control unit 230 may also include the first update information in the RRC reset message, or it may include the LTM configuration information containing the first update information in the RRC reset message. The LTM configuration information may be information for changing (i.e., resetting) at least a part of the LTM configuration information set in the UE 100. The first update information may include reset information used for executing the AS security key update process. The control unit 230 may include the reset information in the RRC reset message if the RRC reset completion message contains information indicating that an NCC is not held.

[0157] Furthermore, the control unit 230 may include instruction information indicating whether or not the UE 100 should include the second update information in the response message. The instruction information may, for example, indicate that the second update information should be included in the response message. The instruction information may, for example, indicate that the LTM should be continued. On the other hand, the instruction information may indicate that the second update information should not be included in the response message. The instruction information may also be information indicating the release of the settings for the LTM.

[0158] Step S270: As shown in Figure 7, the transmitting unit 211 of the base station 202 may transmit an RRC reset message from cell C2 to UE100. The receiving unit 112 of UE100 may receive an RRC reset message from the base station 202 (or cell C2).

[0159] The control unit 120 of UE100 may apply (or set) the information contained in the RRC reset message. For example, if the RRC reset message contains information indicating an NCC, the control unit 120 may derive a security key using the NCC indicated by that information. Also, if the RRC reset message contains information indicating an NCC to be used to derive the next security key, the control unit 120 may save the NCC indicated by that information. Also, if the RRC reset message contains first update information, the control unit 120 may perform processing based on the first update information as described above. Also, if the RRC reset message contains setting information for LTM, the control unit 120 may perform processing to apply the setting information for LTM.

[0160] Step S280: The transmitter 111 of UE100 may send an RRC reset completion message to base station 202 (cell C2). The receiver 212 of base station 202 may receive the RRC reset completion message from UE100 in cell C2.

[0161] The control unit 120 of the UE 100 may determine whether or not to include second update information in the RRC reset completion message, which is a response to the RRC reset message. For example, the control unit 120 may determine whether or not to include second update information in the RRC reset completion message based on whether or not the settings for LTM are saved. The control unit 120 may determine to include second update information in the RRC reset completion message if (a) the settings for LTM (i.e., LTM settings (e.g., LTM-Config)) are saved in the UE 100, or (b) one or more LTM candidate settings (e.g., ltm-CandidateConfig) are saved in the UE 100. The control unit 120 may store the LTM settings or one or more LTM candidate settings in the UE 100 based on the LTM setting information included in the RRC reset message in step S270, or it may store the LTM settings or one or more LTM candidate settings in the UE 100 based on the LTM setting information received in an RRC message received before step S270 (for example, in step S150). Therefore, the control unit 120 may determine to include the second update information in the RRC reset completion message while the LTM settings are set for the UE 100.

[0162] On the other hand, the control unit 120 may decide not to include the second update information in the RRC reset completion message if (a) the settings for LTM (i.e., LTM settings (e.g., LTM-Config)) are not stored in the UE 100, or (b) one or more LTM candidate settings (e.g., ltm-CandidateConfig) are not stored in the UE 100. The control unit 120 may also decide not to include the second update information in the RRC reset completion message if, for example, a process to release the settings for LTM is executed. The control unit 120 may execute a process to release the settings for LTM based on information instructing the release of the LTM settings information included in the RRC reset message in step S270. The instruction to release may be an existing information element or a newly defined information element. Furthermore, when the control unit 120 receives an RRC reset message, it does not need to automatically release information regarding the settings for LTM.

[0163] Furthermore, the control unit 120 may determine, based on the instruction information, whether or not to include the second update information in the RRC reset completion message. The control unit 120 may determine to include the second update information if the instruction information instructs to include the second update information, and / or to continue the LTM. On the other hand, the control unit 120 may determine not to include the second update information if the instruction information instructs not to include the second update information, and / or to not continue the LTM.

[0164] Furthermore, the control unit 120 may determine that if the RRC reset message includes NCC information, it will include the second update information in the RRC reset completion message. The control unit 120 may determine that if the RRC reset message does not include NCC information, it will not include the second update information in the RRC reset completion message.

[0165] If the control unit 120 determines that the second update information should be included in the RRC reset completion message, it includes the second update information in the RRC reset completion message. On the other hand, if the control unit 120 determines that the second update information should not be included in the RRC reset completion message, it controls the system so that the second update information is not included in the RRC reset completion message. In other words, the control unit 120 may generate an RRC reset message that does not include the second update information.

[0166] Furthermore, the control unit 120 may determine whether or not to include the NCC used to derive the next security key, i.e., the NCC to be used at the timing of the next LTM between different base stations (the next Inter-CU LTM) (hereinafter, the next NCC), in the RRC reconfiguration completion message. For example, the control unit 120 may determine to include the next NCC in the RRC reconfiguration completion message if (a) a setting for LTM (i.e., an LTM setting (e.g., LTM-Config)) is stored in the UE 100, or (b) one or more LTM candidate settings (e.g., ltm-CandidateConfig) are stored in the UE 100. The control unit 120 may also determine to always include the next NCC in the RRC reconfiguration completion message, regardless of whether or not there is an instruction from the base station 202.

[0167] Furthermore, the control unit 120 may determine whether or not to include the NCC used to update the security key when performing an LTM cell switch to cell C2 (hereinafter referred to as "used NCC") in the RRC reset completion message. The control unit 120 may decide to include the used NCC in the RRC reset completion message, or it may decide not to include it.

[0168] If the control unit 120 determines that the following NCC and / or NCC to be used should be included in the RRC reset completion message, it will include the following NCC and / or NCC to be used in the RRC reset completion message. On the other hand, if the control unit 120 determines that the second update information should not be included in the RRC reset completion message, it may control the system so that the following NCC and / or NCC to be used are not included in the RRC reset completion message.

[0169] Subsequently, UE100 may communicate with cell C2 of base station 202.

[0170] Steps S290 to S310: The same operations as in steps S180 to S200 may be performed. Base station 202 may perform the same operations as base station 201 described above, and base station 203 may perform the same operations as base station 202 described above. The control unit 120 of UE 100 may perform the security key update using the following NCC. The control unit 120 may, for example, use the following NCC included in the RRC reset completion message. The control unit 120 may also use the NCC (the following NCC) stored as a second variable.

[0171] Steps S320 to S370: The same operations as in steps S210 to S260 may be performed. Thus, UE100 may perform the same operations in the subsequent LTM as in the LTM described above. In step S370, based on the determination result, base station 203 may send an RRC reset message to UE100 in the same way as in step S270, or it may not send an RRC reset message to UE100. Based on the receipt of the RRC reset message, UE100 may send an RRC reset message completion message to cell C3 of base station 203 in the same way as in step S280.

[0172] As described above, the control unit 120 of UE 100 may update the security key when performing an LTM cell switch from cell C1 to cell C2. The transmission unit 111 may transmit a radio resource control (RRC) message to cell C2 that includes update information regarding the security key update, specifically, second update information. This allows the base station 202 of cell C2 to obtain information regarding the security key update based on the second update information from UE 100. The base station 202 can, for example, determine whether the security key is appropriate. In particular, in subsequent LTM, cell switching to another cell is possible based on the LTM settings received from the previous cell (base station 200) without receiving an RRC reset message from the base station 200 after the LTM cell switch. For this reason, UE 100 may not be able to properly perform security key updates in subsequent LTM. As shown in this example, by sending an RRC message containing the second update information to the target cell, the network can obtain information about the security key update and determine whether the security key is appropriate.

[0173] Furthermore, when the transmission unit 111 completes the execution of the LTM cell switch, it may send an RRC reset completion message, including the second update information, as an RRC message. This allows the base station 202 to obtain information regarding the security key update before a significant amount of time has elapsed since the completion of the LTM cell switch.

[0174] Furthermore, the control unit 120 may include in the RRC message second update information, which includes information indicating the NCC used to update the security key when performing an LTM cell switch to cell C2. This allows the base station 202 to know the NCC used to update the security key for communication with cell C2.

[0175] Furthermore, when the control unit 120 performs an LTM cell switch to cell C2, after updating the security key, it may include in the RRC message a second update information that indicates the NCC used to derive the next security key. This allows the base station 202 to determine whether the next security key derived in the LTM (or subsequent LTM) is appropriate.

[0176] Furthermore, the control unit 120 may perform control to include the second update information in the RRC message if the security key is updated when performing the LTM cell switch. The control unit 120 may perform control to not include the second update information in the RRC message if the security key is not updated when performing the LTM cell switch. This allows the UE 100 to avoid using unnecessary wireless resources by omitting the transmission of update information when the security key has not been updated.

[0177] Furthermore, the receiving unit 112 of the UE 100 may receive RRC reset messages from the network (for example, base station 202 (cell C2)). The control unit 120 may, if LTM settings are saved, perform control to include update information in the RRC reset completion message, which is a response to the RRC reset message. The control unit 120 may, if LTM settings are not saved, perform control to exclude update information from the RRC reset completion message. This allows the UE 100 to avoid sending update information even when LTM is not being performed.

[0178] Furthermore, if the control unit 120 does not have information indicating an unused NCC used to derive the security key when executing an LTM cell switch, it may include information indicating that it does not have an unused NCC in the RRC message. This allows the base station 202 to determine whether or not the UE 100 has an unused NCC.

[0179] (Other Embodiments) In the embodiments described above, the cell switch command may include first update information. The cell switch command may include NCC information as the first update information. The NCC information may include, for example, one parameter (i.e., one NCC). Alternatively, the NCC information may include an identifier (e.g., an NCC identifier) ​​that specifies one of the one or more NCCs included in the list of NCCs. If the control unit 230 has a list of NCCs for each base station 200, it may, for example, select an NCC corresponding to the NCC identifier from among the NCCs included in the list of NCCs associated with the determination identifier. The control unit 230 of the UE 100 may perform derivation (or update) of a security key based on the NCC included in the cell switch command. The control unit 230 of the UE 100 may perform derivation (or update) of a security key based on the NCC specified by the NCC identifier.

[0180] Furthermore, the control unit 120 of the UE100 may include the NCC information included in the cell switch command as second update information in the RRC message. Alternatively, the control unit 120 may update the NCC based on the NCC included in the cell switch command. The control unit 120 may also include the updated NCC as second update information in the RRC message.

[0181] Furthermore, if the NCC specified or indicated based on the cell switch command is different from the NCC included in the handover request message, the control unit 230 of the base station 201 may include information indicating the NCC specified or indicated based on the cell switch command in the cell switch notification message.

[0182] Furthermore, although the above embodiments have described the operation in LTM, the operation is not limited thereto. The control unit 120 of UE 100 may, for example, perform the operations in steps S270 and S280 when it receives an RRC reconfiguration message including a handover command when performing a handover (specifically, a handover at Layer 3 (L3)). If a setting for LTM (i.e., an LTM setting (e.g., LTM-Config)) is stored in UE 100, or (b) if one or more LTM candidate settings (e.g., ltm-CandidateConfig) are stored in UE 100, the control unit 120 may include information indicating a second update and / or the next NCC in the RRC reconfiguration completion message, which is a response to the RRC reconfiguration message including the handover command. The control unit 120 may autonomously decide whether or not to include second update information and / or information indicating the next NCC in the RRC reset completion message, or it may decide based on the information included in the RRC reset message (for example, the instruction information described above).

[0183] Furthermore, although the above embodiment describes a case in which the RRC reset completion message includes second update information, it is not limited to this. The control unit 120 of the UE 100 may include the second update information, for example, (a) in an RRC Resume Complete message used to confirm the successful completion of RRC connection resume when an RRC resume message is received, (b) in an RRC Setup Complete message used to confirm the successful completion of RRC connection establishment when an RRC setup message is received, or (c) in a UE Assistance Information message used to indicate UE assistance information to the network.

[0184] In the above embodiment, the LTM configuration information may be divided into a list of LTM candidate settings that require security key updates and a list of LTM candidate settings that do not require security key updates. Each of the LTM candidate settings that require security key updates may include first update information, or the first update information may be included separately from the LTM candidate settings.

[0185] In the embodiments described above, a mobile communication system based on NR was used as an example for the mobile communication system 1. However, the mobile communication system 1 is not limited to this example. The mobile communication system 1 may be a system compliant with a TS of either LTE (Long Term Evolution) or another generation system of the 3GPP standard (e.g., 6th generation). The base station 200 may be an eNB that provides E-UTRA user plane and control plane protocol terminations directed to UE100 in LTE. The mobile communication system 1 may be a system compliant with a TS of a standard other than the 3GPP standard. The base station 200 may be an IAB (Integrated Access and Backhaul) donor or IAB node.

[0186] In the embodiments described above, a mobile communication system based on NR was used as an example for the mobile communication system 1. However, the mobile communication system 1 is not limited to this example. The mobile communication system 1 may be a system compliant with a TS of either LTE or another generation system of the 3GPP standard (e.g., 6th generation). The base station 200 may be an eNB that provides E-UTRA user plane and control plane protocol terminations directed to UE100 in LTE. The mobile communication system 1 may be a system compliant with a TS of a standard other than the 3GPP standard.

[0187] The steps in the operation of the above-described embodiment do not necessarily have to be executed chronologically in the order described in the flowchart or sequence diagram. For example, the steps in the operation may be executed in a different order than that described in the flowchart or sequence diagram, or they may be executed in parallel. Also, some steps in the operation may be deleted, or further steps may be added to the process. Furthermore, each of the above-described operation flows can be implemented not only separately and independently, but also by combining two or more operation flows. For example, some steps of one operation flow may be added to another operation flow, or some steps of one operation flow may be replaced with some steps of another operation flow.

[0188] A program may be provided that causes a computer to execute each process performed by the UE 100 or base station 200. The program may be recorded on a computer-readable medium. Using a computer-readable medium, it is possible to install the program on a computer. Here, the computer-readable medium on which the program is recorded may be a non-transient recording medium. The non-transient recording medium is not particularly limited, but may be a recording medium such as a CD-ROM or DVD-ROM. Alternatively, the circuits that execute each process performed by the UE 100 or base station 200 may be integrated, and at least a part of the UE 100 or base station 200 may be configured as a semiconductor integrated circuit (chipset, SoC).

[0189] In the embodiments described above, "transmit" may mean processing at least one layer in the protocol stack used for transmission, or it may mean physically transmitting a signal wirelessly or via a wire. Alternatively, "transmit" may mean a combination of processing at least one layer and physically transmitting a signal wirelessly or via a wire. Similarly, "receive" may mean processing at least one layer in the protocol stack used for reception, or it may mean physically receiving a signal wirelessly or via a wire. Alternatively, "receive" may mean a combination of processing at least one layer and physically receiving a signal wirelessly or via a wire. Similarly, "obtain / acquire" may mean obtaining information from stored information, obtaining information from information received from another node, or obtaining information by generating it. Similarly, the phrases “based on” and “depending on / in response to” do not mean “based solely on” or “in response to” unless otherwise specified. The phrase “based on” means both “based solely on” and “at least partially on.” Similarly, the phrase “in response” means both “at least partially on” and “in at least partially on.” Similarly, “include” and “comprise” do not mean “include only the listed items,” but rather “may include only the listed items,” or “may include additional items in addition to the listed items.” Similarly, in this disclosure, “or” does not mean exclusive OR, but rather logical OR. Furthermore, any reference to elements using designations such as “first,” “second,” etc., as used in this disclosure does not limit the quantity or order of those elements in general. These designations may be used in this disclosure as a convenient way to distinguish between two or more elements.Therefore, references to the first and second elements do not imply that only two elements may be adopted therein, or that the first element must precede the second element in any way. In this disclosure, where articles are added by translation, such as a, an, and the in English, these articles shall be plural unless it is clearly indicated from the context that they are not.

[0190] This disclosure is described in accordance with the embodiments, but it is understood that this disclosure is not limited to such embodiments or structures. This disclosure also includes various modifications and variations within the equivalence. In addition, various combinations and forms, as well as other combinations and forms that include only one, more, or fewer of those elements, fall within the scope and concept of this disclosure.

[0191] (Note) The features of the above-described embodiment are noted below.

[0192] (Note 1) A communication device comprising: a control unit that updates a security key to a Layer 1 / Layer 2 triggered mobility (LTM) cell switch from a first cell to a second cell; and a transmission unit that transmits a radio resource control (RRC) message to the second cell that includes update information regarding the update of the security key to the LTM cell switch.

[0193] (Note 2) The communication device according to Note 1, wherein the transmitting unit transmits an RRC reset completion message including the update information as the RRC message when it completes the execution of the LTM cell switch.

[0194] (Note 3) The communication device according to Note 1 or 2, wherein the control unit includes in the RRC message the update information, which includes information indicating the NCC used to update the security key when performing the LTM cell switch to the second cell.

[0195] (Note 4) The communication device according to any one of Notes 1 to 3, wherein the control unit updates the security key when performing the LTM cell switch to the second cell, and then includes the update information, which includes information indicating the NCC used to derive the next security key, in the RRC message.

[0196] (Note 5) The communication device according to any one of Notes 1 to 4, wherein the control unit performs control to include the update information in the RRC message when the security key is updated when the LTM cell switch is executed, and performs control to not include the update information in the RRC message when the security key is not updated when the LTM cell switch is executed.

[0197] (Note 6) A communication device according to any one of Notes 1 to 5, comprising a receiving unit that receives RRC reset messages from a network, wherein the control unit, if LTM settings are saved, performs control to include the update information in the RRC reset completion message which is a response to the RRC reset message, and if LTM settings are not saved, performs control to not include the update information in the RRC reset completion message.

[0198] (Note 7) The communication device according to any one of Notes 1 to 6, wherein the control unit does not have information indicating an unused NCC used to derive the security key when executing the LTM cell switch, and includes information indicating that it does not have an unused NCC in the RRC message.

[0199] (Note 8) A base station comprising a receiving unit that receives a radio resource control (RRC) message containing update information relating to the update of the security key for a Layer 1 / Layer 2 triggered mobility (LTM) cell switch from a communication device that updates the security key for the LTM cell switch.

[0200] (Note 9) A communication method performed by a communication device, comprising the steps of: updating a security key for a Layer 1 / Layer 2 triggered mobility (LTM) cell switch from a first cell to a second cell; and transmitting a radio resource control (RRC) message to the second cell that includes update information relating to the update of the security key for the LTM cell switch.

Claims

1. A communication device (100) comprising: a control unit (120) that updates a security key to a Layer 1 / Layer 2 triggered mobility (LTM) cell switch from a first cell (C1) to a second cell (C2); and a transmission unit (111) that transmits a radio resource control (RRC) message to the second cell that includes update information regarding the update of the security key to the LTM cell switch.

2. The communication device according to claim 1, wherein the transmitting unit transmits an RRC reset completion message including the update information as the RRC message when it completes the execution of the LTM cell switch.

3. The communication device according to claim 1 or 2, wherein the control unit includes in the RRC message the update information, which includes information indicating the NCC used to update the security key when performing the LTM cell switch to the second cell.

4. The communication device according to claim 1 or 2, wherein the control unit updates the security key when performing the LTM cell switch to the second cell, and then includes the update information, which includes information indicating the NCC used to derive the next security key, in the RRC message.

5. The communication device according to claim 1 or 2, wherein the control unit performs control to include the update information in the RRC message when the security key is updated when the LTM cell switch is executed, and performs control to not include the update information in the RRC message when the security key is not updated when the LTM cell switch is executed.

6. A communication device according to claim 1 or 2, comprising a receiving unit that receives RRC reset messages from a network, wherein the control unit, when LTM settings are saved, performs control to include the update information in the RRC reset completion message which is a response to the RRC reset message, and when LTM settings are not saved, performs control to not include the update information in the RRC reset completion message.

7. The communication device according to claim 1 or 2, wherein the control unit does not have information indicating an unused NCC used to derive the security key when executing the LTM cell switch, and includes information indicating that it does not have an unused NCC in the RRC message.

8. A base station (200, 202) comprising a receiving unit (212) that receives a radio resource control (RRC) message containing update information regarding the update of the security key for a Layer 1 / Layer 2 triggered mobility (LTM) cell switch from a communication device (100) that updates the security key for the LTM cell switch.

9. A communication method performed by a communication device (100), comprising the steps of: updating a security key for a Layer 1 / Layer 2 triggered mobility (LTM) cell switch from a first cell (C1) to a second cell (C2); and transmitting a radio resource control (RRC) message to the second cell that includes update information relating to the update of the security key for the LTM cell switch.