Communication method, user equipment, and network node

The integration of MAC PDUs and NCCs in LTM procedures addresses the inefficiencies of inter-CU handovers in 3GPP systems, enhancing mobility management by facilitating faster and more reliable cell switching across different gNBs.

WO2026100675A1PCT designated stage Publication Date: 2026-05-15KYOCERA CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
KYOCERA CORP
Filing Date
2025-11-07
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing 3GPP mobile communication systems face challenges in efficiently managing L1/L2-triggered mobility (LTM) procedures, particularly in inter-cell handovers, which can lead to increased mobility delays and inefficiencies due to the lack of support for inter-CU LTM operations.

Method used

The implementation of a communication method and network node that facilitates LTM by using MAC PDUs with MAC CEs and NCCs for deriving security keys, enabling seamless L1/L2-triggered mobility across different gNBs, thereby reducing handover delays and improving system efficiency.

Benefits of technology

This approach enhances the efficiency of LTM procedures by enabling faster and more reliable handovers between cells managed by different gNBs, reducing latency and maintaining communication integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025039089_15052026_PF_FP_ABST
    Figure JP2025039089_15052026_PF_FP_ABST
Patent Text Reader

Abstract

This communication method comprises: user equipment in an RRC connected state in a first cell receiving a MAC PDU from a network node that manages the first cell; and the user equipment deriving a security key to be used in communication with a second cell. The MAC PDU contains: a MAC CE to be used in LTM cell switching from the first cell to the second cell; an NCC to be used in deriving the security key; and at least one of an RRC message in which the NCC is arranged and a security token for confirming the integrity of the NCC.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, user equipment, and network node

[0001] This disclosure relates to a communication method, user equipment, and network node used in a communication system.

[0002] The 3GPP (3rd Generation Partnership Project) (registered trademark; hereinafter the same) defines the technical specifications for NR (New Radio), a fifth-generation (5G) wireless access technology. In 3GPP mobile communication systems, the switching of serving cells (serving cell change) of a user device in a Radio Resource Control (RRC) connected state is instructed by sending an RRC layer message (a so-called handover command) corresponding to Layer 3 (L3) from the network node to the user device.

[0003] Meanwhile, in 3GPP Release 18, the technical specification for LTM (L1 / L2-Triggered Mobility), a new procedure for serving cell switching, has been established. LTM is a procedure in which a network node receives a Layer 1 (L1) measurement report from a user device, and based on that, the network node signals a cell switching command to the user device via a Media Access Control (MAC) control element (CE), thereby changing the serving cell of the user device.

[0004] 3GPP Technical Specification "3GPP TS 38.300 V18.2.0"

[0005] This disclosure provides technology for improving LTM.

[0006] The first aspect of the communication method comprises: a user device in a Radio Resource Control (RRC) connected state in a first cell receiving a Medium Access Control (MAC) PDU (Protocol Data Unit) from a network node managing the first cell; and the user device deriving a security key to be used for communication with a second cell. The MAC PDU includes a MAC CE (Control Element) used for LTM (L1 / L2 Triggered Mobility) cell switching from the first cell to the second cell, an NCC (Next hop parameter Chaining Counter) used for deriving the security key, an RRC message in which the NCC is placed, and at least one of the security tokens for verifying the integrity of the NCC.

[0007] The user device according to the second embodiment includes a receiving unit that receives a MAC (Medium Access Control) PDU (Protocol Data Unit) from a network node managing the first cell when the first cell is in an RRC (Radio Resource Control) connected state, and a control unit that derives a security key to be used for communication with the second cell. The MAC PDU includes a MAC CE (Control Element) used for LTM (L1 / L2 Triggered Mobility) cell switching from the first cell to the second cell, an NCC (Next hop parameter Chaining Counter) used for deriving the security key, an RRC message in which the NCC is placed, and at least one of the security tokens for verifying the integrity of the NCC.

[0008] A network node according to the third embodiment has a transmitting unit that transmits a MAC (Medium Access Control) PDU (Protocol Data Unit) to a user device in the RRC (Radio Resource Control) connected state in the first cell. The MAC PDU includes a MAC CE (Control Element) used for LTM (L1 / L2 Triggered Mobility) cell switching from the first cell to the second cell, an NCC (Next hop parameter Chaining Counter) used for deriving a security key used for communication with the second cell, an RRC message in which the NCC is placed, and at least one of a security token for verifying the integrity of the NCC.

[0009] This figure shows an example configuration of a mobile communication system according to an embodiment. This figure shows an example configuration of a UE (User Equipment) according to an embodiment. This figure shows an example configuration of a gNB (Network Node) according to an embodiment. This figure shows the configuration of the protocol stack of the wireless interface of the user plane that handles data. This figure shows the configuration of the protocol stack of the wireless interface of the control plane that handles signaling (control signals). This figure is for explaining the overview of security in the mobile communication system according to an embodiment. This figure shows an example of a cell switching procedure by LTM in an intraCU (i.e., within the same gNB) according to an embodiment. This figure shows an example of LTM operation in an interCU (i.e., between different gNBs) according to an embodiment. This figure shows the operation of a UE according to the first embodiment. This figure is for explaining the MAC PDU according to the first embodiment of the first embodiment. This figure is for explaining the LTM cell switching command MAC CE according to the first embodiment of the first embodiment. This figure shows an example of operation of a mobile communication system according to the first embodiment of the first embodiment. This figure is for explaining the MAC PDU according to the second embodiment of the first embodiment. This figure is for explaining the MAC PDU according to the third embodiment of the first embodiment. This figure shows the operation of a UE according to the second embodiment. This figure shows an example of operation of a mobile communication system according to the second embodiment.

[0010] While referring to the drawings, a mobile communication system according to an embodiment will be described. In the description of the drawings, the same or similar parts are denoted by the same or similar reference numerals.

[0011] (1) First Embodiment The first embodiment will be described.

[0012] (1.1) Configuration of Mobile Communication System FIG. 1 is a diagram showing a configuration example of a mobile communication system 1 according to the present embodiment. The mobile communication system 1 complies with the 5th generation system (5GS: 5th Generation System) of the 3GPP standard. Hereinafter, the 5GS will be described as an example, but an LTE (Long Term Evolution) system may be at least partially applied to the mobile communication system. A 6th generation (6G) system may be at least partially applied to the mobile communication system.

[0013] The mobile communication system 1 includes a user equipment (UE: User Equipment) 100, a 5G radio access network (NG-RAN: Next Generation Radio Access Network) 10, and a 5G core network (5GC: 5G Core Network) 20. Hereinafter, the NG-RAN 10 may be simply referred to as the RAN 10. Also, the 5GC 20 may be simply referred to as the core network (CN) 20. The RAN 10 and the CN 20 constitute the network 5 of the mobile communication system 1.

[0014] The UE 100 is a movable wireless communication device. The UE 100 may be any device as long as it is a device used by a user. For example, the UE 100 is a mobile phone terminal (including a smartphone) and / or a tablet terminal, a notebook PC, a communication module (including a communication card or a chipset), a sensor or a device provided in the sensor, a vehicle or a device provided in the vehicle (Vehicle UE), an aircraft or a device provided in the aircraft (Aerial UE). The link in the transmission direction from the UE 100 to the network 5 is referred to as an uplink (UL), and the link in the transmission direction from the network 5 to the UE 100 is referred to as a downlink (DL).

[0015] NG-RAN10 includes a base station (referred to as "gNB" in a 5G system) 200, which is a type of network node. The gNBs 200 are interconnected via an Xn interface, which is an interface between base stations. The gNB 200 manages one or more cells. The gNB 200 performs wireless communication with the UE 100 that has established a connection with its own cell. The gNB 200 has a radio resource management (RRM) function, a routing function for user data (hereinafter simply referred to as "data"), a measurement control function for mobility control and scheduling, and the like. "Cell" is used as a term indicating the smallest unit of a wireless communication area. "Cell" is also used as a term indicating a function or resource for performing wireless communication with the UE 100. A "cell" is identified by a cell identifier (cell ID). One cell belongs to one carrier frequency (hereinafter simply referred to as "frequency").

[0016] Note that the gNB can also be connected to an EPC (Evolved Packet Core), which is an LTE core network. The LTE base station can also be connected to the 5GC. The LTE base station and the gNB can also be connected via an interface between base stations.

[0017] The 5GC 20 includes an AMF (Access and Mobility Management Function) and a UPF (User Plane Function) 300. The AMF performs various mobility controls for the UE 100. The AMF manages the mobility of the UE 100 by communicating with the UE 100 using NAS (Non-Access Stratum) signaling. The UPF performs transfer control of data. The AMF and the UPF are connected to the gNB 200 via an NG interface, which is an interface between the base station and the core network.

[0018] FIG. 2 is a diagram showing a configuration example of the UE 100 (user device) according to the present embodiment. The UE 100 includes a receiving unit 110, a transmitting unit 120, and a control unit 130. The receiving unit 110 and the transmitting unit 120 constitute a wireless communication unit 140 that performs wireless communication with the gNB 200.

[0019] The receiving unit 110 performs various types of reception under the control of the control unit 130. The receiving unit 110 includes an antenna and a receiver. The receiver converts the radio signal received by the antenna into a baseband signal (received signal) and outputs it to the control unit 130.

[0020] The transmitting unit 120 performs various types of transmissions under the control of the control unit 130. The transmitting unit 120 includes an antenna and a transmitter. The transmitter converts the baseband signal (transmission signal) output by the control unit 130 into a wireless signal and transmits it from the antenna.

[0021] The control unit 130 performs various control and processing operations in the UE 100. Such processing includes processing in each layer described later. The operation of the UE 100 described above and later may also be controlled by the control unit 130. The control unit 130 includes at least one processor and at least one memory. The memory stores programs executed by the processor and information used for processing by the processor. The processor may include a baseband processor and a CPU (Central Processing Unit). The baseband processor performs modulation, demodulation, encoding, and decoding of baseband signals. The CPU executes programs stored in memory and performs various processing operations.

[0022] Figure 3 shows an example configuration of a gNB200 (network node) according to this embodiment. The gNB200 includes a transmitting unit 210, a receiving unit 220, a control unit 230, and a network communication unit 240. The transmitting unit 210 and the receiving unit 220 constitute a wireless communication unit 250 that performs wireless communication with the UE100. The network communication unit 240 includes a transmitting unit 241 that performs transmission and a receiving unit 242 that performs reception.

[0023] The transmitting unit 210 performs various types of transmissions under the control of the control unit 230. The transmitting unit 210 includes an antenna and a transmitter. The transmitter converts the baseband signal (transmission signal) output by the control unit 230 into a wireless signal and transmits it from the antenna.

[0024] The receiving unit 220 performs various types of reception under the control of the control unit 230. The receiving unit 220 includes an antenna and a receiver. The receiver converts the radio signal received by the antenna into a baseband signal (received signal) and outputs it to the control unit 230.

[0025] The control unit 230 performs various control and processing operations in the gNB 200. Such processing includes processing in each layer described later. The operation of the gNB 200 described above and later may also be controlled by the control unit 230. The control unit 230 includes at least one processor and at least one memory. The memory stores programs executed by the processor and information used for processing by the processor. The processor may include a baseband processor and a CPU. The baseband processor performs modulation, demodulation, encoding, decoding, etc. of the baseband signal. The CPU executes programs stored in memory and performs various processing operations.

[0026] The network communication unit 240 is connected to an adjacent base station via the Xn interface, which is an inter-base station interface. The network communication unit 240 is connected to the AMF / UPF 300 via the NG interface, which is an inter-base station-core network interface. The gNB 200 may consist of a central unit (CU) and a distributed unit (DU) (i.e., functionally divided), and the two units may be connected by the F1 interface, which is a front-haul interface. In this case, each of the gNB-DU and gNB-CU may have a functional block configuration similar to the one shown in Figure 3. However, the gNB-CU is assumed not to have a wireless communication unit 250.

[0027] Figure 4 shows the configuration of the protocol stack for the user plane's wireless interface that handles data.

[0028] The user plane radio interface protocol comprises a physical (PHY) layer, a MAC (Medium Access Control) layer, an RLC (Radio Link Control) layer, a PDCP (Packet Data Convergence Protocol) layer, and an SDAP (Service Data Adaptation Protocol) layer.

[0029] The PHY layer performs encoding / decoding, modulation / demodulation, antenna mapping / demapping, and resource mapping / demapping. Data and control information are transmitted between the PHY layer of UE100 and the PHY layer of gNB200 via a physical channel. The PHY layer of UE100 receives downlink control information (DCI) transmitted from gNB200 on the physical downlink control channel (PDCCH). Specifically, UE100 performs blind decoding of the PDCCH using a Radio Network Temporary Identifier (RNTI) and acquires the successfully decoded DCI as the DCI addressed to its own UE. The DCI transmitted from gNB200 has a CRC parity bit added, which is scrambled by the RNTI.

[0030] The MAC layer performs data priority control, retransmission processing using Hybrid ARQ (HARQ: Hybrid Automatic Repeat reQuest), and random access procedures. Data and control information are transmitted between the MAC layer of UE100 and the MAC layer of gNB200 via the transport channel. The MAC layer of gNB200 includes a scheduler. The scheduler determines the transport format for the up and down links (transport block size, modulation and coding scheme (MCS)) and the resource blocks to be allocated to UE100.

[0031] The RLC layer transmits data to the receiving RLC layer using the functions of the MAC layer and PHY layer. Data and control information are transmitted between the RLC layer of UE100 and the RLC layer of gNB200 via a logical channel.

[0032] The PDCP layer performs header compression / decompression, encryption / decryption, etc.

[0033] The SDAP layer maps IP flows, which are the units under which the core network performs QoS (Quality of Service) control, to wireless bearers, which are the units under which the AS (Access Stratum) performs QoS control. Note that if the RAN is connected to the EPC, the SDAP is not required.

[0034] Figure 5 shows the configuration of the protocol stack of the wireless interface of the control plane that handles signaling (control signals).

[0035] The protocol stack of the control plane's wireless interface includes an RRC (Radio Resource Control) layer and a NAS (Non-Access Stratum) layer, instead of the SDAP layer shown in Figure 4.

[0036] RRC signaling for various settings is transmitted between the RRC layer of the UE100 and the RRC layer of the gNB200. The RRC layer controls the logical channel, transport channel, and physical channel in response to the establishment, re-establishment, and release of the radio bearer. If there is a connection (RRC connection) between the RRC of the UE100 and the RRC of the gNB200, the UE100 is in the RRC connected state. If there is no connection (RRC connection) between the RRC of the UE100 and the RRC of the gNB200, the UE100 is in the RRC idle state. If the connection between the RRC of the UE100 and the RRC of the gNB200 is suspended, the UE100 is in the RRC inactive state.

[0037] The NAS layer (also simply referred to as "NAS"), located above the RRC layer, handles session management and mobility management, among other things. NAS signaling is transmitted between the NAS layer of the UE100 and the NAS layer of the AMF300A. The UE100 also has an application layer in addition to the wireless interface protocol. Furthermore, the layer below the NAS layer is called the AS layer (also simply referred to as "AS").

[0038] (1.2) Overview of Security Using Fig. 6, the overview of security in the mobile communication system 1 will be described.

[0039] In the case of user data (DRB: Data Radio Bearer), encryption provides the confidentiality of user data, and integrity protection provides the integrity of user data. In the case of RRC signaling (SRB: Signaling Radio Bearer), encryption provides the confidentiality of signaling data, and integrity protection provides the integrity of signaling data. Note that encryption and integrity protection are set as options, but integrity protection is always set in the case of RRC signaling. Encryption and integrity protection can be set for each DRB.

[0040] The security key (hereinafter, also simply referred to as "key") is configured and derived as follows.

[0041] Key of AMF 300: K AMF is a key derived by UE 100 and AMF 300 from K SEAF .

[0042] Key of NAS signaling: K NASint is a key derived by UE 100 and AMF 300 from K AMF and is used only for the protection of NAS signaling by a specific integrity algorithm. K NASenc is a key derived by UE 100 and AMF 300 from K AMF and is used only for the protection of NAS signaling by a specific encryption algorithm.

[0043] Key of gNB 200: K gNB is a key derived by UE 100 and AMF 300 from K AMF . K gNB is further derived by UE 100 and the source gNB 200 when performing horizontal or vertical key derivation.

[0044] Key of user plane (UP) traffic: K UPenc is a key derived by UE 100 and gNB 200 from K gNBThis key is derived from [the specified source] and is used solely for protecting UP traffic between UE100 and gNB200 using a specific encryption algorithm. UPint UE100 and gNB200 are K gNB This key is derived from [a specific algorithm] and is used solely for protecting UP traffic between UE100 and gNB200 using a particular integrity algorithm.

[0045] Key to RRC signaling: K RRCint UE100 and gNB200 are K gNB This is a key derived from and is used solely for protecting RRC signaling by a specific integrity algorithm. RRCenc UE100 and gNB200 are K gNB This is a key derived from [a specific cryptographic algorithm] and is used solely for protecting RRC signaling.

[0046] Intermediate key: NH is the key derived by UE100 and AMF300 to provide forward security. gNB* This is the key derived by UE100 and gNB200 when performing horizontal or vertical key derivation.

[0047] Primary authentication enables mutual authentication between UE100 and network 5, K SEAF An anchor key called K is provided. AMF is, K SEAF For example, it is created during primary authentication, or during NAS key re-key generation and key update events. NASint and K NASenc is, K AMF This is derived when the NAS SMC (Security Mode Command) procedure is executed successfully.

[0048] Whenever it is necessary to establish an initial AS security context between UE100 and gNB200, AMF300 and UE100 shall, gNB And the next-hop parameter (NH) is derived. K gNB And NH is K AMF We derive it from this.

[0049] The NH Chaining Counter (NCC) is used for each K gNB and associated with the NH parameter. All K gNB It is associated with the NCC corresponding to the derived NH value. By default, K gNB is, K AMF It is directly derived from and associated with a virtual NH parameter with an NCC value of zero. By default, the derived NH value is associated with an NCC value of 1. In handover, the K used between UE100 and target gNB200 is... gNB K is the foundation gNB* The currently active K gNB Alternatively, it can be derived from the NH parameters. K gNB* K is currently active gNB If derived from , this is called a horizontal key derivation and is shown in UE100 with an unincreasing NCC. gNB* If it is derived from the NH parameter, this is called the vertical key derivation and is shown in UE100 as NCC increases. Finally, K RRCint _K RRCenc _K UPint , and K UPenc This is the new K gNB After K is derived, gNB It is derived based on this.

[0050] Through this key derivation, K, which is shared with UE100, is obtained. gNB The gNB200, which is known to be the same as the UE100, is used in the previous K gNB Since it cannot be calculated, back-end security is provided. Similarly, K shared with UE100 gNB Knowing this, gNB200 will be used between the same UE100 and another gNB200 after n or more handovers in the future. gNB It is not possible to predict this (because the NH parameters can only be calculated using UE100 and AMF300).

[0051] The AS SMC procedure aims to negotiate the RRC and UP security algorithms and activate RRC security. When establishing the AS security context on gNB200, AMF300 provides security information to gNB200. During handover, security information is provided from the source gNB to the target gNB.

[0052] The gNB200 selects the highest-priority encryption algorithm and the highest-priority integrity algorithm. The selected algorithms are shown in UE100 in the AS SMC.

[0053] RRC downlink encryption on the gNB200 begins after the AS SMC message is sent. RRC uplink decryption on the gNB200 begins after receiving and successfully verifying an integrity-protected AS security mode completion message from the UE100. The UE100 verifies the validity of the AS SMC message from the gNB200 by verifying the integrity of the received message.

[0054] RRC uplink encryption on the UE100 begins after the AS security mode completion message is sent. RRC downlink decryption on the UE100 begins after the AS SMC message is received and successfully verified. The RRC reconfiguration procedure used to add a DRB is executed only after RRC security has been activated as part of the AS SMC procedure.

[0055] A UE100 connected to a 5GC must support integrity-protected DRBs at any data rate, up to the highest data rate supported by the UE100, in both UL and DL. If the integrity check fails (i.e., MAC-I is faulty or missing), the relevant PDU is discarded by the receiving PDCP entity.

[0056] (1.3) Overview of LTM The mobile communication system 1 according to this embodiment supports LTM (L1 / L2-triggered mobility).

[0057] In a typical handover procedure, the serving cell switch is triggered by signaling at the higher layer, L3, specifically the RRC layer. This type of typical handover is also called an L3 handover. In an L3 handover, the UE100 sends an L3 measurement report message, which is an RRC message, to the gNB200. Based on this measurement report message, the gNB200 decides to hand over the UE100 and instructs the cell switch by sending a handover command (specifically, an RRC Reconfiguration message) from the gNB200 to the UE100.

[0058] On the other hand, LTM is a technique for reducing mobility delays (specifically, serving cell switching delays) compared to general handover procedures by triggering serving cell switching through signaling at the lower layers, Layer 1 (L1) and / or Layer 2 (L2). In LTM, the gNB200 receives an L1 measurement report from the UE100, and based on this, the gNB200 instructs the UE100 to switch serving cells by signaling a cell switching command via MAC CE.

[0059] Specifically, in LTM, firstly, gNB200 prepares an LTM candidate cell setting for the candidate cell to be switched to, and provides the LTM candidate cell setting to UE100 via RRC signaling.

[0060] Secondly, UE100 performs synchronization with LTM candidate cells through early synchronization.

[0061] Thirdly, the gNB200 receives the L1 measurement report from the UE100, decides to switch the serving cell to the target cell based on the L1 measurement report, and sends a Cell Switch Command indicating the target cell (LTM candidate cell setting) to the UE100 via the MAC control element (CE). The serving cell switching trigger is transmitted by the MAC CE, which includes at least the candidate setting index (setting ID) along with the beam indicator.

[0062] Fourthly, UE100 switches the serving cell in response to the LTM cell switching command MAC CE from gNB200 (source cell).

[0063] In this way, the gNB200 triggers a serving cell switch by selecting the LTM candidate cell configuration as the target configuration. The LTM candidate cell configuration can be added, modified, and released by the gNB200 via RRC signaling.

[0064] The following principles apply to LTM:

[0065] Each LTM candidate cell setting can be provided as a differential setting (delta setting) to a baseline setting used to form the complete LTM candidate cell setting.

[0066] - When the complete LTM candidate cell configuration is applied, the current UE configuration is replaced when the serving cell is switched. The reconfiguration procedure performs the replacement, but does not necessarily reset the MAC, RLC, or PDCP layers.

[0067] - The user plane will continue without resetting if configured with RRC signaling, in order to avoid additional delays in data recovery.

[0068] - Security updates are not provided in LTM versions.

[0069] - Subsequent LTMs (Subsequent LTMs) can be performed between subsequent LTM candidate cell settings without RRC reconfiguration. In other words, UE100 does not release other LTM candidate cell settings after an LTM is triggered.

[0070] Figure 7 shows an example of a cell switching procedure using LTM within an intraCU (i.e., within the same gNB200). In the illustrated example, UE100 performs an LTM-based serving cell switch (i.e., LTM cell switch) from the first cell to the second cell of the gNB200.

[0071] Here, the first cell and the second cell may be formed by different TRPs (Transmission and Reception Points). In the following description of the embodiments, the second cell will also be referred to as the "LTM candidate cell (or candidate cell)" until the LTM decides to switch the serving cell, and the second cell will also be referred to as the "target cell" after the LTM decides to switch the serving cell. The first cell will also be referred to as the "source cell" or the "(current) serving cell".

[0072] In step S1, UE100 is in an RRC connected state in the cell (first cell) of gNB200.

[0073] In step S2, UE100 sends a Measurement Report message, which is an RRC message, to gNB200 (first cell). The measurement report, which includes the L3 measurement result, is also called the L3 Measurement Report (L3 MR).

[0074] In step S3, gNB200 decides to use LTM based on the L3 measurement report and begins preparing LTM candidate cells.

[0075] In step S4, gNB200 (first cell) sends an LTM configuration, including the LTM Candidate Configuration / LTM Candidate for one or more LTM candidate cells, to UE100 in an RRC message, specifically an RRC Reconfiguration message. The LTM Candidate Configuration may include a Random Access Channel (RACH) configuration used for sending RA preambles to the corresponding LTM candidate cells, such as a Conflict-Free Random Access (CFRA) configuration. Such a RACH configuration may be referred to as an Early Ul Sync Configuration. CFRA is a random access procedure in which each UE100 is assigned dedicated RACH resources (e.g., dedicated preamble sequences and / or dedicated time and frequency resources), and no RACH contention occurs between UE100s.

[0076] In step S5, UE100 saves the LTM settings (LTM candidate cell settings) and sends an RRC Reconfiguration Complete message to gNB200 (first cell).

[0077] In step S6, UE100 may perform synchronization with the LTM candidate cell (second cell) before receiving the LTM cell switching command MAC CE from the first cell. Such synchronization may be called Early Sync. Here, UE100 may perform Downlink Synchronization (DL Synchronization) for the LTM candidate cell and then perform Early Timing Advance (TA) acquisition (i.e., UL Early Sync) for the LTM candidate cell requested by gNB200 (serving cell). This is performed by a CFRA triggered by a PDCCH order from the first cell. Note that if DCI Format 1_0 is used and all "Frequency domain resource assignment" fields in the DCI are set to "1", the DCI is treated as a PDCCH order. Furthermore, if Early Ul Sync Config is set on UE100, the PDCCH order may include a cell indicator that indicates the corresponding RACH transmission cell, i.e., which LTM candidate cell UE100 should send a random access preamble (RA preamble) to.

[0078] UE100 transmits an RA preamble to the designated LTM candidate cell (second cell). To minimize the interruption of serving cell communication by CFRA to the LTM candidate cell, during early synchronization, UE100 does not receive a Random Access Response (RAR) from the LTM candidate cell for the purpose of obtaining the TA value. The TA value of the LTM candidate cell (target cell) is indicated by the LTM cell switching command MAC CE in step S9. The TA value is used to adjust the uplink transmission timing of UE100.

[0079] In step S7, UE100 performs a Layer 1 (L1) measurement on the configured LTM candidate cell and transmits a measurement report (also referred to as "L1 measurement report (L1 MR)") including the L1 measurement result to gNB200 (first cell). The L1 measurement result may be, for example, L1-RSRP and / or L1-SINR.

[0080] In step S8, the gNB200 decides to switch the serving cell to the target cell (second cell).

[0081] In step S9, gNB200 (first cell) sends an LTM cell switching command MAC CE to UE100, which includes the candidate setting index (setting ID) of the target cell. The LTM cell switching command MAC CE may include the TA value obtained by UL early synchronization (i.e., the TA value derived based on the RA preamble).

[0082] In step S10, UE100 switches to the settings for the target cell (second cell). Specifically, UE100 detaches from the first cell and applies the settings for the target cell (second cell).

[0083] In step S11, if the serving cell switch requires the execution of a random access procedure (for example, if the LTM cell switch command MAC CE does not contain a valid TA value), UE 100 executes a random access procedure on the target cell (RACH-based LTM cell switch). However, if UE 100 does not need to obtain the TA of the target cell during the serving cell switch (for example, if the LTM cell switch command MAC CE contains a valid TA value), the random access procedure can be skipped (RACH-less LTM cell switch).

[0084] In step S12, UE100 indicates that the serving cell switch to the target cell has been successfully completed by sending, for example, an RRC Reconfiguration Complete message to the target cell (second cell). Subsequently, UE100 may perform steps S6 to S12 multiple times for subsequent LTM serving cell switches based on the settings provided in step S4.

[0085] (1.4) Inter-CU LTM The LTM introduced in 3GPP Release 18 supports only intra-CUs and does not support inter-CU (i.e., between different gNB200s) LTM. In other words, with conventional LTM, it is possible to switch LTM cells between cells under the same CU (same gNB200), but it is not possible to switch LTM cells between cells under different CUs (different gNB200s).

[0086] On the other hand, 3GPP Release 19 will introduce InterCU LTM. In InterCU LTM, the UE100 will perform LTM cell switching from the first cell of one gNB200 to the second cell of another gNB200.

[0087] Based on the operation shown in Figure 7, an example of the operation of the InterCU LTM will be described. Figure 8 is a diagram showing an example of the operation of the InterCU LTM.

[0088] In step S101, UE100 sends an L3 (RRC) Measurement Report to gNB200a. gNB200a receives the L3 (RRC) Measurement Report.

[0089] In step S102, gNB200a decides to use inter-gNB (interCU) LTM based on the L3 (RRC) Measurement Report from step S101 and begins preparing the LTM candidate cell. Here, it is assumed that the second cell of gNB200b has been selected as the LTM candidate cell.

[0090] In step S103, gNB200a sends a request message (LTM HO Request) to gNB200b indicating that the serving cell change is due to LTM. gNB200b receives the request message (LTM HO Request). The request message (LTM HO Request) may include an LTM Indicator and may be a Handover Request message used in a general handover. Alternatively, the request message (LTM HO Request) may be a new message different from the Handover Request message, for example, an LTM Handover Request message. The request message (LTM HO Request) may include RRC configuration information for UE100 and a cell identifier indicating the second cell, similar to a typical handover.

[0091] In step S104, gNB200b decides whether to accept the request in step S103 (Admission control). Here, we will proceed assuming that the request in step S103 is accepted. In this case, gNB200b may set up a CFRA resource for early synchronization in the second cell. If the request in step S103 is rejected, gNB200b may send a rejection message to gNB200a. The rejection message may include information indicating that inter-gNB LTM is unavailable.

[0092] In step S105, gNB200b sends an acknowledgment message (LTM HO Request Ack) to gNB200a indicating acceptance of the request in step S103. gNB200a receives the acknowledgment message (LTM HO Request Ack). The acknowledgment message (LTM HO Request Ack) may include an LTM Indicator and may be a Handover Request Ack message used in general handovers. Alternatively, the acknowledgment message (LTM HO Request Ack) may be a new message different from the Handover Request Ack message, for example, an LTM Handover Request Ack message. The acknowledgment message (LTM HO Request Ack) may include information indicating the early synchronization CFRA resources (e.g., RA preamble and / or PRACH (Physical Random Access Channel) resources) configured by gNB200b for the second cell. The acknowledgment message (LTM HO Request Ack) may also include configuration information (LTM Candidate Configuration / LTM Candidate) such as RRC reconfiguration information (RRC Reconfiguration) for UE100 applied in the second cell. The acknowledgment message (LTM HO Request Ack) may include a notification that the second cell will send (reply to) a RAR in response to the RA preamble transmission, and / or information indicating the RAR reception window.

[0093] In step S106, gNB200a sends an RRC Reconfiguration message to UE100 that includes the LTM Candidate Configuration / LTM Candidate for the second cell. UE100 receives the RRC Reconfiguration message. The RRC Reconfiguration message may also include information indicating the early synchronization CFRA resources configured by gNB200b for the second cell. The RRC Reconfiguration message may also include a notification that the second cell will send (reply to) an RAR in response to the RA preamble transmission, and / or information indicating the RAR reception window.

[0094] In step S107, UE100 saves the LTM settings and sends an RRC Reconfiguration Complete message to gNB200a. gNB200a receives the RRC Reconfiguration Complete message.

[0095] In step S108, UE100 may send an L1 measurement report (or L3 measurement report) to gNB200a for gNB200a to determine about early synchronization. gNB200a may receive an L1 measurement report (or L3 measurement report).

[0096] In step S109, gNB200a may perform an early synchronization decision.

[0097] In step S110, gNB200a may send an Early sync CFRA Request message to gNB200b, which is a request message requesting the preparation of a CFRA resource for early synchronization, specifically, the configuration and / or activation of a CFRA resource for early synchronization. gNB200b may receive the request message (Early sync CFRA Request message). The request message (Early sync CFRA Request message) may include an identifier for identifying UE100 (Xn-AP UE ID) and / or an identifier for identifying the second cell (cell ID).

[0098] In step S111, gNB200b may prepare CFRA resources for early synchronization.

[0099] In step S112, gNB200b may send a notification message to gNB200a indicating that the CFRA resources for early synchronization are ready, for example, an Early sync CFRA Request Ack message. gNB200a may receive the notification message (Early sync CFRA Request Ack message).

[0100] In step S113, gNB200a may send a PDCCH order to UE100, instructing UE100 to perform a CFRA for early synchronization. UE100 receives the PDCCH order. The PDCCH order may include information for identifying the second cell as the target of the CFRA (Target cell indicator). The PDCCH order may also include a notification indicating that the second cell will send (reply with) a RAR in response to the RA preamble transmission, and / or information indicating the RAR reception window.

[0101] In step S114, UE100 may perform early synchronization of the downlink (DL) with the second cell. For example, UE100 may perform timing synchronization using the second cell's SSB (PSS / SSS). Note that UE100 may perform DL synchronization earlier than this point.

[0102] In step S115, UE100 transmits a CFRA, specifically an RA preamble on PRACH, to the second cell specified in the PDCCH order in order to perform early synchronization of the uplink (UL) with the second cell. gNB200b receives the RA preamble. UE100 identifies the CFRA resources (e.g., the RA preamble and / or PRACH resources) using information set in the SIB, etc., and information such as the "Random Access Preamble index" and "PRACH Mask Index" in the PDCCH order.

[0103] In step S116, gNB200b may send a RAR containing the TA value derived based on the RA preamble to UE100. UE100 may receive the RAR. Step S116 may be an optional step that is performed only if there is a setting from gNB200a (for example, the setting in step S106).

[0104] UE100 may send an Early Sync Complete notification to gNB200a indicating that UL early synchronization with the second cell is complete (step S117). The Early Sync Complete notification may include the TA value notified in RAR.

[0105] In step S118, gNB200b may send a notification message (Early Sync Complete) to gNB200a indicating that UL early synchronization with UE100 has been completed. gNB200a may receive the notification message (Early Sync Complete). The notification message (Early Sync Complete) may include the TA value derived based on the RA preamble in step S115.

[0106] In step S119, UE100 transmits the L1 measurement report to gNB200a. gNB200a receives the L1 measurement report.

[0107] In step S120, if gNB200a determines, for example, that the likelihood of LTM execution has increased based on the L1 measurement report in step S119, it may send a UL resource request message to gNB200b. gNB200b may receive the request message. The UL resource request may be a request for the preparation or activation of a CFRA resource. The UL resource request may be a request for the preparation or execution of a UL grant transmission to UE100. The UL resource request may be a request for the preparation or activation of a UL configured grant (CG) resource. Note that the transmission of the request message in step S120 may be simultaneous with the LTM execution decision in step S121. The transmission may also be after the LTM execution decision in step S121.

[0108] In step S121, gNB200a decides to perform LTM based on the L1 measurement report from step S119.

[0109] In step S122, gNB200a sends a cell switching command (MAC CE) to UE100 in response to the LTM execution decision. UE100 receives the cell switching command. The cell switching command may include the TA value notified to gNB200a in step S117 or S118.

[0110] In step S123, upon receiving a cell switching command, UE100 detaches from the first cell (source cell) and applies the LTM settings of the second cell (target cell).

[0111] In step S124, if the cell switching command does not contain a TA value (a valid TA value), UE100 may execute a random access procedure on the second cell.

[0112] In step S125, UE100 sends an RRC Reconfiguration Complete message to the second cell. gNB200b receives the RRC Reconfiguration Complete message.

[0113] In step S126, gNB200b may transmit a DCI including a CRC (Cyclic Redundancy Code) scrambled with the C-RNTI assigned to UE100 to UE100 on the PDCCH, and transmit a Contention Resolution MAC CE to UE100 on the PDSCH assigned with the DCI. UE100 may receive the DCI and the Contention Resolution MAC CE.

[0114] In step S127, gNB200b may send a notification message (LTM HO Success) to gNB200a indicating that the inter-network node LTM to the second cell has been completed. gNB200a may receive the notification message (LTM HO Success).

[0115] (1.5) Security in InterCU LTM The operation according to this embodiment will be described. The operation according to this embodiment relates to security in InterCU LTM.

[0116] In the security processing of InterCU LTM, a method is being considered in which network 5 provides the NCC to UE100 via an RRC message each time an InterCU LTM cell switchover is performed. Specifically, similar to conventional handovers, after a cell switchover, a path switchover request is sent from target gNB200 to AMF300, and AMF300 generates a new NH and NCC and passes them to target gNB200. Target gNB200 sends the NCC to UE100 in an RRC Reconfiguration message, and UE100 generates an NH (new key) (i.e., vertical key derivation). With this method, similar to conventional handovers, it is necessary to perform RRC Reconfiguration again after a cell switchover.

[0117] On the other hand, in LTM cell switching, it is desirable to perform high-speed cell switching while minimizing the use of RRC signaling. Therefore, in the first embodiment, an operation is described in which the NCC can be notified to the UE100 at the MAC layer while ensuring security.

[0118] Figure 9 shows the operation of UE100 according to this embodiment.

[0119] In step S201, the UE100 in the RRC-connected state in the first cell receives a MAC PDU (Protocol Data Unit) from the gNB200 which manages the first cell. Specifically, the distributed unit (DU) of the gNB200 sends the MAC PDU to the UE100. The MAC PDU includes a MAC CE used for LTM cell switching from the first cell to the second cell, an NCC (Next hop parameter Chaining Counter) used for deriving security keys, an RRC message in which the NCC is located, and at least one of a security token for verifying the integrity of the NCC.

[0120] In step S202, UE100 uses NCC to derive a security key to be used for communication with the second cell.

[0121] According to this operation, the MAC PDU that UE100 receives from gNB200 includes at least one of the following: an RRC message in which the NCC is placed, and a security token for verifying the integrity of the NCC. By including the RRC message in which the NCC is placed in the MAC PDU, the RRC message includes a security key (e.g., K RRCenc Because it is encrypted by ), the NCC can be securely provided to UE100 in an encrypted state. By including the security token for verifying the integrity of the NCC in the MAC PDU, UE100 can perform an integrity check using that security token.

[0122] The UE 100 performing this operation has a receiving unit 110 that receives the above-mentioned MAC PDU from the gNB 200 which manages the first cell when the first cell is in an RRC connected state, and a control unit 130 that derives a security key to be used for communication with the second cell (see Figure 2). On the other hand, the gNB 200 has a transmitting unit 210 that transmits the above-mentioned MAC PDU to the UE 100 which is in an RRC connected state in the first cell (see Figure 3).

[0123] In this embodiment, the MAC CE included in the MAC PDU described above is the LTM cell switching command MAC CE. This allows the NCC to be securely provided to the UE100 along with the LTM cell switching command MAC CE.

[0124] (1.6) Examples Based on the above-described operation, the first to third embodiments of the first embodiment will be described. Note that two or more embodiments from the first to third embodiments may be combined and implemented.

[0125] (1.6.1) Figure 10 of the first embodiment is a diagram illustrating the MAC PDU according to the first embodiment of the first embodiment.

[0126] In this embodiment, gNB200(DU) transmits a MAC PDU to UE100 in which the LTM cell switching command MAC CE and the RRC message are multiplexed. UE100 receives the MAC PDU from gNB200(DU). By multiplexing the RRC message onto the MAC PDU carrying the LTM cell switching command MAC CE in this way, the NCC can be securely provided to UE100 simultaneously with the LTM cell switching command MAC CE. That is, the NCC can be provided from gNB200(DU) to UE100 while being protected by encryption. In this manner, gNB200(DU) multiplexes the LTM cell switching command MAC CE and the RRC message for NCC notification on the same MAC PDU and notifies UE100. In the illustrated example, the first half of the MAC PDU contains the LTM cell switching command MAC CE, while the second half of the MAC PDU contains the LTM cell switching command MAC CE including NCC.

[0127] Here, upon receiving the LTM cell switching command MAC CE, UE 100 can perform a cell switch and discard the source cell's RRC settings. Therefore, UE 100 recognizes the NCC received simultaneously with the LTM cell switching command MAC CE as part of the source cell settings and can discard the NCC upon cell switching. Thus, in this embodiment, gNB 200 (DU) includes information in the LTM cell switching command MAC CE indicating that the NCC (RRC message) used in the target cell is multiplexed. For example, the LTM cell switching command MAC CE may include information (NCC flag) to identify whether or not an RRC message (i.e., encrypted NCC) is multiplexed in the MAC PDU. That is, the MAC CE includes information (1-bit flag) indicating whether or not an RRC message for NCC notification is multiplexed in the same PDU.

[0128] The MAC layer of UE100 receives the MAC PDU from gNB200 (DU) and, in response to the fact that an RRC message is multiplexed in the received MAC PDU (i.e., the NCC flag indicates that an RRC message is multiplexed), provides the RRC message to the RRC layer of UE100. Here, the MAC layer of UE100 may also notify the RRC layer of UE100 of the RRC message (NCC) along with the LTM cell switching information.

[0129] The RRC layer of UE100 may retain the NCC contained in the RRC message for use in the second cell. For example, when the RRC of UE100 receives notification of such information, it may recognize the NCC contained in the RRC message as information to be used in the target cell, store it in its internal memory, and retain it even after cell switching.

[0130] The RRC layer of UE100 may generate a security key from the NCC contained in the RRC message and apply the generated security key to access the second cell (target cell). For example, when the RRC layer of UE100 is notified of such information, it may generate a security key (KgNB You may generate and apply NH and then access the target cell.

[0131] Figure 11 is a diagram illustrating the LTM cell switching command MAC CE according to this embodiment.

[0132] The LTM cell switching command MAC CE may include the reserved bit "R", the Target Configuration ID, Timing Advance Command, TCI state ID, UL TCI state ID, "C" indicating the presence of a field for a conflicting free random access resource, "S / U" indicating the UL carrier used for PRACH transmission of the conflicting free random access resource, the Random Access Preamble index, the SS / PBCH index, the PRACH Mask index, and the Repetition number. The LTM cell switching command MAC CE contains the reserved bit "R". Therefore, while maintaining the format of the LTM cell switching command MAC CE, the reserved bit "R" can be used to store the NCC flag.

[0133] Figure 12 shows an example of the operation of the mobile communication system 1 according to the first embodiment of the first embodiment.

[0134] In step S301, UE100 is in an RRC connected state in the cell of gNB200a.

[0135] In step S302, UE100 sends a measurement report message (L3 measurement result) to gNB200a.

[0136] In step S303, gNB200a decides to set up the LTM and begins preparing the LTM.

[0137] In step S304, gNB200a issues a HANDOVER REQUEST message to one or more LTM candidate cells belonging to one or more candidate gNB200b. The HANDOVER REQUEST message provides a transparent RRC container containing information necessary for preparation on the target side. This message may include an LTM indicator and other relevant LTM information.

[0138] In step S305, the gNB200b performs admission control.

[0139] In step S306, gNB200b prepares for the handover at L1 / L2 and sends an LTM response message (HANDOVER REQUEST ACKNOWLEDGE message) to gNB200a. This includes a transparent container that is sent to UE100 as an RRC message to perform the handover.

[0140] In step S307, gNB200a sends an RRC Reconfiguration message to UE100 that includes the LTM candidate cell settings. gNB may also include NCC in the message.

[0141] In step S308, UE100 saves the LTM candidate cell settings and the corresponding NCC, and sends an RRC Reconfiguration Complete message to gNB200a.

[0142] In steps S309 and S310, UE100 may perform DL and UL synchronization with LTM candidate cells by early synchronization.

[0143] In step S311, UE100 performs an L1 measurement on the configured LTM candidate cell and sends the L1 measurement report to gNB200a.

[0144] In step S312, gNB200a decides to perform LTM.

[0145] In step S313, gNB200a performs vertical key derivation, {K NG-RAN*The NCC pair is forwarded to gNB200b. gNB200b receives the K NG-RAN* K used in UE100 gNB It is used as follows. gNB200b receives the NCC value from gNB200a and uses K gNB To associate with.

[0146] In step S314, gNB200b sends a key update acknowledgment to gNB200a.

[0147] In step S315, gNB200a sends an LTM cell switching command MAC CE to UE100 that triggers cell switching by including the candidate configuration index of the target cell. Here, gNB200a multiplexes an RRC message including NCC with the MAC CE (includes it in the same MAC PDU). gNB200a sets a flag in the MAC CE indicating that a multiplexed RRC message exists.

[0148] UE100 receives the MAC PDU. If the flag is set, the MAC layer of UE100 notifies the higher layer (UE100's RRC layer) that it received the RRC message in the same PDU (that it was multiplexed) or that the RRC message is information to be applied in the target cell (NCC).

[0149] The RRC layer of UE100 may store the information (NCC) in its internal memory when it receives the RRC message.

[0150] When UE100 receives an NCC, it compares it to the NCC it holds. If the received NCC is smaller than the NCC it holds, it indicates that the message may have been tampered with and that the handover should be canceled. Subsequently, UE100 initiates the RRC re-establishment procedure.

[0151] Currently active K gNBIf UE100 receives an NCC greater than the NCC associated with it, UE100 first iteratively synchronizes the locally held NH parameters and increments the NCC until it matches the received NCC. Once the NCCs match, UE100 takes the synchronized NH parameters and K NG-RAN* Calculate.

[0152] Currently active K gNB If UE100 receives the same NCC as the NCC associated with, UE100 will use the current NH parameter to K NG-RAN* Calculate.

[0153] In step S316, UE100 switches to the target cell and applies the configuration indicated by the candidate configuration index.

[0154] In step S317, if UE100 does not have a valid TA for the target cell, it executes a random access procedure on the target cell.

[0155] In step S318, UE100 completes the LTM cell switching procedure by sending an RRC Reconfiguration Complete message to the target cell. If UE100 executed a random access procedure in step S317, UE100 considers the LTM cell switching to have been successfully completed when the random access procedure is successfully completed. In the case of RACH-less LTM, UE100 considers the LTM cell switching to have been successfully completed when it determines that network 5 has successfully received the first UL data.

[0156] (1.6.2) Figure 13 of the second embodiment of the first embodiment is a diagram illustrating the MAC PDU according to the second embodiment of the first embodiment.

[0157] In this embodiment, gNB200(DU) sends a MAC PDU containing an RRC message in the RRC container within MAC CE to UE100. UE100 receives the MAC PDU. That is, gNB200(DU) notifies UE100 that it has included an NCC notification RRC message in the RRC container provided in the LTM cell switching command MAC CE. In this way, an RRC container is provided within the LTM cell switching command MAC CE, enabling secure notification of NCC to UE100.

[0158] An LTM cell switching command MAC CE that includes an NCC in the RRC container may be a new LTM cell switching command MAC CE that is different from a conventional (i.e., one that does not include an NCC) LTM cell switching command MAC CE. This new LTM cell switching command MAC CE may be defined in a different LCID and / or a different MAC CE format than the conventional LTM cell switching command MAC CE.

[0159] An LTM cell switching command MAC CE that includes an NCC in an RRC container may include an identifier, such as a version indicator, that indicates that the NCC area (RRC container area) is allocated to the MAC CE. This identifier may be set in the reserved bit "R" field of the LTM cell switching command MAC CE. If "1" is set in this field, the NCC area (RRC container area) may be allocated to the LTM cell switching command MAC CE.

[0160] Furthermore, when the MAC layer of UE100 receives the MAC CE, it acquires the NCC area (RRC container area) of the MAC CE and passes the acquired RRC message (MAC SDU) to SRB1 (or its corresponding LCID).

[0161] An example of the operation of the mobile communication system 1 according to this embodiment will be explained using Figure 12. The operation of this embodiment differs from that of the first embodiment only in step S315 in Figure 12, so only the differences in the operation of step S315 will be explained.

[0162] In this embodiment, in step S315, gNB200a sends an LTM cell switching command MAC CE to UE100 that triggers cell switching by including a candidate configuration index of the target cell. Here, gNB200a includes an RRC message containing NCC in the RRC container of the MAC CE. UE100 receives the MAC PDU.

[0163] If the container is set, the MAC layer of UE100 notifies the upper layer (UE100's RRC) that it has received the RRC message in the same PDU (i.e., it has been multiplexed) or that the RRC message is information to be applied in the target cell (NCC).

[0164] The MAC layer of UE100 retrieves the RRC message from the RRC container of the received MAC CE and passes it to SRB1 (or its corresponding LCID).

[0165] Other operations are the same as in the first embodiment described above.

[0166] (1.6.3) Figure 14 of the third embodiment of the first embodiment is a diagram illustrating the MAC PDU according to the third embodiment of the first embodiment.

[0167] In this embodiment, gNB200 transmits a MAC PDU to UE100 that contains a MAC CE including the NCC and a security token, MAC-I. UE100 receives the MAC PDU from gNB200. For example, gNB200 (DU) stores the NCC in plain text (i.e., unencrypted) in the LTM cell switching command MAC CE and notifies UE100 that the corresponding security token (MAC-I) is included in the LTM cell switching command MAC CE. This allows UE100 to verify the integrity of the NCC using the security token (MAC-I).

[0168] An example of the operation of the mobile communication system 1 according to this embodiment will be explained using Figure 12. The operation of this embodiment differs from that of the first embodiment only in step S315 in Figure 12, so only the differences in the operation of step S315 will be explained.

[0169] In this embodiment, in step S315, gNB200a sends an LTM cell switching command MAC CE to UE100 that triggers cell switching by including the candidate configuration index of the target cell. Here, gNB200a sends the LTM cell switching command MAC CE to UE100 including the LTM candidate configuration index of the target cell. gNB200a includes the NCC in plain text and the corresponding security token (MAC-I) in the message. UE100 receives the MAC CE and checks whether the NCC has been tampered with (i.e., its integrity) based on the MAC-I. If it has not been tampered with, UE100 immediately compares the NCC value with the NCC it holds. Other operations are the same as in the first embodiment described above.

[0170] (1.7) Modification of the First Embodiment In the first embodiment described above, the MAC CE transmitted together with the NCC is the LTM cell switching command MAC CE. That is, in the first embodiment described above, an example was described in which the NCC is transmitted to the UE100 together with the LTM cell switching command MAC CE.

[0171] However, in the case of conditional LTM cell switching described later, the LTM cell switching command MAC CE is not transmitted or received. Therefore, instead of the LTM cell switching command MAC CE, the NCC may be transmitted to the UE100 along with other MAC signaling.

[0172] For example, when gNB200 sends a random access response (MAC RAR) to UE100 during early synchronization, NCC may be transmitted to UE100 along with the random access response. In this case, the LTM cell switching command MAC CE in the first embodiment described above may be replaced with the random access response.

[0173] Alternatively, if a new MAC CE for providing Timing Advance (TA) (e.g., an Early TA MAC CE) is introduced instead of such a random access response, the NCC may be transmitted to the UE 100 along with the new MAC CE. In this case, the LTM cell switching command MAC CE in the first embodiment described above may be replaced with the MAC CE for providing Timing Advance (TA).

[0174] (2) Second Embodiment The second embodiment will be described mainly in terms of the differences from the first embodiment described above.

[0175] In the second embodiment, the scenario primarily assumes that the LTM cell switching of the interCU is performed by conditional LTM cell switching. The operation according to the second embodiment may be performed in combination with the operation according to the first embodiment.

[0176] In conditional LTM, for example, the RRC Reconfiguration message in step S4 of Figure 7 includes information indicating the execution conditions for LTM cell switching (e.g., wireless quality conditions) for each LTM candidate cell. Instead of receiving the cell switching command MAC from the gNB200, the UE100 performs LTM cell switching for LTM candidate cells that meet the set execution conditions (wireless quality conditions). This eliminates the need to send and receive L1 measurement reports and cell switching command MACs, enabling faster LTM cell switching.

[0177] Furthermore, as described above, after UE100 first performs an LTM cell switch, subsequent LTMs (Subsequent LTMs) between LTM candidate cell settings can be performed without RRC signaling (RRC reconfiguration). Specifically, UE100 can perform the subsequent LTM cell switch executions in steps S6 to S12 multiple times using the multiple LTM candidate cell settings (i.e., setting information for multiple LTM candidate cells) provided in step S4 of Figure 7. Here, even after performing an LTM cell switch, UE100 retains the multiple LTM candidate cell settings provided in step S4 of Figure 7 and uses the retained LTM candidate cell settings for the Subsequent LTM.

[0178] When UE100 performs an LTM cell switchover of the interCU via a conditional LTM cell switchover, network 5 is unaware of which target cell UE100 has selected until the cell switchover is executed. In particular, there is a concern that gNB200a may not be able to properly update the security key because the subsequent LTM cell switchover (Subsequent LTM) is performed without RRC signaling (RRC reconfiguration).

[0179] In this embodiment, we will describe an operation that enables the security key to be properly updated even when the LTM cell switching of the interCU is performed by conditional LTM cell switching.

[0180] Figure 15 shows the operation of UE100 according to this embodiment.

[0181] In step S401, the UE100 in the first cell, which is in an RRC connected state, holds the setting information for conditional LTM cell switching.

[0182] In step S402, UE100 evaluates whether the conditions for executing the LTM cell switch to the second cell have been met, based on the setting information for the conditional LTM cell switch.

[0183] In step S403, UE100 sends a notification to gNB200, which manages the first cell, in response to the conditions for executing the LTM cell switch to the second cell being met. This notification may be a MAC CE or RRC message. The notification includes an identifier for the second cell, for example, a candidate configuration index (configuration ID) and / or a physical cell identifier (PCI) for the second cell. The notification may further include information indicating the frequency of the second cell.

[0184] In step S404, UE100 performs an LTM cell switch to the second cell after sending the notification.

[0185] With this operation, the gNB200 (gNB200a) managing the first cell can identify the target cell for conditional LTM cell switching based on the notification from UE100, and therefore can update the security key appropriately.

[0186] The UE 100 that performs this operation has a control unit 130 that, when the first cell is in an RRC connected state, holds setting information for conditional LTM cell switching and evaluates whether the execution conditions for LTM cell switching to the second cell have been met based on the setting information, and a transmission unit 120 that, when the execution conditions have been met, sends a notification to the gNB 200 that manages the first cell, which includes an identifier for the second cell and is used by the gNB 200 for security key update processing (see Figure 2).

[0187] On the other hand, the gNB200a that manages the first cell has a control unit 230 that identifies the second cell, which is the target cell of the UE100 that holds the setting information for conditional LTM cell switching, and derives a security key to be used for communication between the UE100 and the second cell from the information of the second cell, and a transmission unit 241 that transmits the derived security key to another gNB200b that manages the second cell (see Figure 3).

[0188] In this embodiment, the LTM cell switching shown in Figure 15 is a subsequent LTM cell switching (Subsequent LTM) performed without RRC reconfiguration after the UE 100 performs the first LTM cell switching using configuration information notified from the network 5 via RRC signaling. The UE 100 sends the notification in step S403 before executing the subsequent LTM cell switching, depending on whether the execution conditions are met. Thus, the UE 100 sends the notification in step S403 when performing a subsequent LTM cell switching (Subsequent LTM) by conditional LTM.

[0189] In this embodiment, the LTM cell switching shown in Figure 15 is an interCU LTM cell switching from a first cell under the CU of gNB200a to a second cell under a different CU. UE100 sends the notification in step S403 before executing the subsequent LTM cell switching when the execution conditions are met. Thus, UE100 sends the notification in step S403 when performing an interCU LTM cell switching by conditional LTM.

[0190] Upon receiving the notification from UE100 in step S403, gNB200a derives a security key based on the notification and transmits the derived security key to gNB200b. For example, gNB200a uses the identifier for the target cell notified by UE100 to derive the intermediate key (K NG-RAN* ) is generated and the intermediate key (and NCC) is notified to gNB200b.

[0191] Figure 16 shows an example of the operation of the mobile communication system 1 according to the second embodiment.

[0192] In step S501, the UE100 in the RRC connected state in the gNB200a cell sends a measurement report message (L3 measurement result) to the gNB200a.

[0193] In step S502, gNB200a decides to set a conditional LTM and begins preparing the conditional LTM.

[0194] In step S503, gNB200a sends a HANDOVER REQUEST message to candidate gNB200b for each LTM candidate cell, requesting LTM configuration. This message may include conditional LTM indicators and other relevant LTM information.

[0195] In step S504, the NB200b performs admission control.

[0196] In step S505, gNB200b sends an LTM response message (HANDOVER REQUEST ACKNOWLEDGE) to gNB200a, which includes the setting of LTM candidate cells (multiple cells are possible).

[0197] In step S506, gNB200a sends an RRCReconfiguration message to UE100 that includes the LTM candidate cell settings.

[0198] In step S507, UE100 saves the LTM candidate cell settings and sends the RRCReconfigurationComplete message to gNB200a.

[0199] In step S508, UE100 may perform DL and UL synchronization with LTM candidate cells by early synchronization.

[0200] In step S509, gNB200b may transfer the TA value and related information to gNB200a via XnAP signaling.

[0201] In step S510, UE100 sends a notification (CELL SWITCH NOTIFICATION) containing an identifier for the LTM candidate cell (target cell) to gNB200a in response to the execution conditions for LTM cell switching to the configured LTM candidate cell being met. UE100 may send this notification only when executing Subsequent LTM (second or subsequent LTM cell switching executions). UE100 may also send this notification only when executing InterCU conditional LTM cell switching LTM. UE100 may also send this notification as a MAC CE or RRC message.

[0202] In step S511, gNB200a identifies the target cell based on the notification from UE100. gNB200a identifies the physical cell identifier (PCI) of the target cell, the frequency (ARFCN) of the target cell, and the currently active K gNB Or based on NH, K NG-RAN* The following is derived. gNB200a performs vertical key derivation if there are unused {NH,NCC} pairs.

[0203] In steps S512 and S513, data transfer from gNB200a to gNB200b may occur.

[0204] In step S514, gNB200a sends a CELL SWITCH NOTIFICATION message to gNB200b via XnAP signaling. gNB200a then sends the generated {K NG-RAN* Send the NCC pair to gNB200b.

[0205] In step S515, UE100 accesses the target cell. gNB200b detects the access by UE100. gNB200b receives K from gNB200a. NG-RAN* Upon receiving, the received K NG-RAN* K used in UE100 gNB It is applied directly as follows: gNB200b receives the NCC value from gNB200a and converts it to K gNB To associate with.

[0206] In step S516, UE100 sends an RRC Reconfiguration Complete message to gNB200b.

[0207] In step S517, gNB200b sends a HANDOVER SUCCESS message to gNB200a to notify UE100 that it has successfully accessed the target cell.

[0208] In step S518, gNB200a sends an SN STATUS TRANSFER message for data transfer to gNB200b.

[0209] In step S519, gNB200b sends a PATH SWITCH REQUEST message to 5GC20 (AMF300).

[0210] (2.1) Modification Examples A modification example of the second embodiment will be described. In the second embodiment described above, gNB200a identified the target cell for conditional LTM cell switching based on a notification from UE100. This notification is sent in UE100 when the conditions for executing LTM cell switching are met.

[0211] However, when gNB200a sends a PDCCH order to UE100 for early synchronization (step S508 in Figure 16), it may identify the cell specified in the PDCCH order as the target cell. Alternatively, when gNB200a receives a TA INFORMATION TRANSFER from gNB200b (step S509 in Figure 16), it may identify the cell indicated in the TA INFORMATION TRANSFER as the target cell.

[0212] (3) Other Embodiments The above-described operation flows are not limited to being performed separately and independently, but can also be performed by combining two or more operation flows. For example, some steps of one operation flow may be added to another operation flow, or some steps of one operation flow may be replaced with some steps of another operation flow. It is not necessary to perform all steps in each flow, and only some steps may be performed. In addition, the order of steps in each flow may be changed as appropriate.

[0213] In the embodiments and examples described above, an example in which the base station is an NR base station (gNB) was described, but the base station may also be an LTE base station (eNB) or a 6G base station. Furthermore, the base station may also be a relay node such as an IAB (Integrated Access and Backhaul) node. The base station may also be a DU of an IAB node. Furthermore, UE100 may be an MT (Mobile Termination) of an IAB node. That is, UE100 may be a terminal function unit (a type of communication module) for the base station to control a relay device that performs signal relay. Such a terminal function unit is referred to as an MT. Examples of multi-transmission architectures (MTs) include IAB-MT, NCR (Network Controlled Repeater)-MT, and RIS (Reconfigurable Intelligent Surface)-MT.

[0214] Furthermore, the term "network node" primarily refers to a base station, but may also refer to a core network device or a part of a base station (CU, DU, or RU). Additionally, a network node may consist of a combination of at least a part of the core network device and at least a part of a base station.

[0215] A program may be provided that causes a computer to execute each process performed by the UE100 or gNB200. The program may be recorded on a computer-readable medium. Using a computer-readable medium, it is possible to install the program on a computer. Here, the computer-readable medium on which the program is recorded may be a non-transient recording medium. The non-transient recording medium is not particularly limited, but may be a recording medium such as a CD-ROM and / or DVD-ROM. Alternatively, the circuits that execute each process performed by the UE100 or gNB200 may be integrated, and at least a part of the UE100 or gNB200 may be configured as a semiconductor integrated circuit (chipset, SoC: System on a chip).

[0216] The functions realized by UE100 or gNB200 may be implemented in a circuit or processing circuit, including a general-purpose processor, application processor, integrated circuit, ASICs (Application Specific Integrated Circuits), CPU (a Central Processing Unit), conventional circuitry, and / or a combination thereof, programmed to realize the described functions. A processor is considered a circuit or processing circuit, including transistors and / or other circuitry. A processor may be a programmed processor that executes a program stored in memory. In this specification, circuitry, unit, and means are hardware programmed to realize or execute the described functions. The hardware may be any hardware disclosed herein, or any hardware known to be programmed to perform or execute the functions described herein. If the hardware is a processor that is considered to be of the type of circuit, the circuit, means, or unit is a combination of hardware and software used to constitute the hardware and / or processor.

[0217] The phrases “based on” and “depending on / in response to” as used in this disclosure do not mean “based solely on” or “in response solely” unless otherwise specified. “Based on” means both “based solely on” and “at least partially on.” Similarly, “depending” means both “at least partially on” and “in at least partially on.” The terms “include,” “comprise,” and variations thereof do not mean that only the listed items are included, but that they may include only the listed items or may include additional items in addition to the listed items. Furthermore, the term “or” as used in this disclosure is not intended to mean exclusive OR. Moreover, any reference to elements using designations such as “first,” “second,” etc., as used in this disclosure does not generally limit the quantity or order of those elements. These designations may be used herein as a convenient way to distinguish between two or more elements. Therefore, references to the first and second elements do not imply that only two elements may be adopted therein, or that the first element must precede the second element in any way. In this disclosure, where articles are added by translation, such as a, an, and the in English, these articles shall be plural unless it is clearly indicated from the context that they are not.

[0218] Although the embodiments have been described in detail above with reference to the drawings, the specific configuration is not limited to those described above, and various design changes can be made without departing from the gist of the invention.

[0219] This application claims priority to Japanese Patent Application No. 2024-194916 (filed November 7, 2024), the entirety of which is incorporated into the specification of this application.

[0220] (4) Additional notes: Features of the above-described embodiments are noted below.

[0221] - Note 1 A user device in the first cell that is RRC (Radio Resource Control) connected receives a MAC (Medium Access Control) PDU (Protocol Data Unit) from the network node managing the first cell, and the user device derives a security key to be used for communication with the second cell, wherein the MAC PDU includes a MAC CE (Control Element) used for LTM (L1 / L2 Triggered Mobility) cell switching from the first cell to the second cell, and an NCC (Next hop parameter Chaining Counter) used for deriving the security key, A communication method comprising at least one of the following: an RRC message on which the NCC is located, and a security token for verifying the integrity of the NCC.

[0222] - Note 2: The MAC CE is the LTM cell switching command MAC CE, as described in Note 1.

[0223] - Appendix 3: The communication method according to Appendix 1 or 2, further comprising the distributed unit of the network node transmitting the MAC PDU to the user device.

[0224] - Appendix 4 The communication method according to Appendix 1 or 2, wherein the user device receives the MAC PDU, which is a multiplexed MAC CE and RRC message, from the network node.

[0225] - Appendix 5 The MAC CE is the communication method described in Appendix 4, which includes information for determining whether or not the RRC message is multiplexed in the MAC PDU.

[0226] - Appendix 6 The communication method according to Appendix 4 or 5, wherein the MAC layer of the user device receives the MAC PDU from the network node and provides the RRC message to the RRC layer of the user device in accordance with the fact that the RRC message is multiplexed on the received MAC PDU.

[0227] - Appendix 7 The communication method according to Appendix 6, wherein the RRC layer of the user device holds the NCC included in the RRC message for use in the second cell.

[0228] - Appendix 8 The communication method described in Appendix 6, wherein the RRC layer of the user device generates the security key from the NCC included in the RRC message and applies the generated security key to access the second cell.

[0229] - Appendix 9 The communication method according to Appendix 1 or 2, wherein the user device receives the MAC PDU, in which the RRC message is stored in the RRC container within the MAC CE, from the network node.

[0230] - Appendix 10 The communication method according to Appendix 1 or 2, wherein the user device receives the MAC PDU, which stores the MAC CE including the NCC and the security token MAC-I, from the network node.

[0231] - Appendix 11 The communication method according to Appendix 1, wherein the MAC CE is a MAC CE for providing a timing advance to the user device in a procedure for conditional LTM cell switching.

[0232] - Appendix 12 When the first cell is in an RRC (Radio Resource Control) connected state, it has a receiving unit that receives a MAC (Medium Access Control) PDU (Protocol Data Unit) from the network node managing the first cell, and a control unit that derives a security key to be used for communication with the second cell, wherein the MAC PDU includes a MAC CE (Control Element) used for LTM (L1 / L2 Triggered Mobility) cell switching from the first cell to the second cell, and an NCC (Next hop parameter Chaining Counter) used for deriving the security key, A user device comprising at least one of the following: an RRC message on which the NCC is located, and a security token for verifying the integrity of the NCC.

[0233] - Appendix 13 A network node having a transmission unit that transmits a MAC (Medium Access Control) PDU (Protocol Data Unit) to a user device in an RRC (Radio Resource Control) connected state in the first cell, wherein the MAC PDU includes a MAC CE (Control Element) used for LTM (L1 / L2 Triggered Mobility) cell switching from the first cell to the second cell, an NCC (Next hop parameter Chaining Counter) used for deriving a security key used for communication with the second cell, and at least one of the following: an RRC message in which the NCC is located, and a security token for verifying the integrity of the NCC.

[0234] 1: Mobile communication system 5: Network 10: RAN 20: CN 100: UE 110: Receiving unit 120: Transmitting unit 130: Control unit 140: Wireless communication unit 200: gNB 210: Transmitting unit 220: Receiving unit 230: Control unit 240: Network communication unit 241: Transmitting unit 242: Receiving unit 250: Wireless communication unit 300: AMF / UPF

Claims

1. A user device in a Radio Resource Control (RRC) connected state in the first cell receives a Medium Access Control (MAC) PDU (Protocol Data Unit) from a network node managing the first cell, and the user device derives a security key to be used for communication with the second cell, wherein the MAC PDU includes a Control Element (MAC CE) used for LTM (L1 / L2 Triggered Mobility) cell switching from the first cell to the second cell, and an Next Hop Parameter Chaining Counter (NCC) used for deriving the security key. A communication method comprising at least one of the following: an RRC message on which the NCC is located, and a security token for verifying the integrity of the NCC.

2. The communication method according to claim 1, wherein the MAC CE is an LTM cell switching command MAC CE.

3. The communication method according to claim 1 or 2, further comprising the distributed unit of the network node transmitting the MAC PDU to the user device.

4. The communication method according to claim 1 or 2, wherein the user device receives the MAC PDU, which is a multiplexed MAC CE and RRC message, from the network node.

5. The communication method according to claim 4, wherein the MAC CE includes information for determining whether or not the RRC message is multiplexed in the MAC PDU.

6. The communication method according to claim 4, wherein the MAC layer of the user device receives the MAC PDU from the network node and provides the RRC message to the RRC layer of the user device in accordance with the fact that the RRC message is multiplexed on the received MAC PDU.

7. The communication method according to claim 6, wherein the RRC layer of the user device holds the NCC included in the RRC message for use in the second cell.

8. The communication method according to claim 6, wherein the RRC layer of the user device generates the security key from the NCC included in the RRC message and applies the generated security key to access the second cell.

9. The communication method according to claim 1 or 2, wherein the user device receives the MAC PDU, in which the RRC message is stored in the RRC container within the MAC CE, from the network node.

10. The communication method according to claim 1 or 2, wherein the user device receives the MAC PDU, which stores the MAC CE including the NCC and the security token MAC-I, from the network node.

11. The communication method according to claim 1, wherein the MAC CE is a MAC CE for providing a timing advance to the user device in a procedure for conditional LTM cell switching.

12. The first cell has a receiving unit that receives a MAC (Medium Access Control) PDU (Protocol Data Unit) from a network node managing the first cell when the first cell is in an RRC (Radio Resource Control) connected state, and a control unit that derives a security key to be used for communication with the second cell, wherein the MAC PDU includes a MAC CE (Control Element) used for LTM (L1 / L2 Triggered Mobility) cell switching from the first cell to the second cell, and an NCC (Next hop parameter Chaining Counter) used for deriving the security key, A user device comprising at least one of the following: an RRC message on which the NCC is located, and a security token for verifying the integrity of the NCC.

13. A network node having a transmitting unit that transmits a MAC (Medium Access Control) PDU (Protocol Data Unit) to a user device in an RRC (Radio Resource Control) connected state in the first cell, wherein the MAC PDU includes a MAC CE (Control Element) used for LTM (L1 / L2 Triggered Mobility) cell switching from the first cell to the second cell, an NCC (Next hop parameter Chaining Counter) used for deriving a security key used for communication with the second cell, and at least one of the following: an RRC message on which the NCC is located, and a security token for verifying the integrity of the NCC.