Ho completion with mac-security

The EnhancedHoCompletion MAC-CE addresses security and efficiency issues in handover procedures by enabling direct MAC layer processing, reducing delays and overhead in message exchanges, and ensuring secure handover completion in wireless communication systems.

WO2026104082A1PCT designated stage Publication Date: 2026-05-21NOKIA TECHNOLOGIES OY
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2025-08-27
Publication Date
2026-05-21

AI Technical Summary

Technical Problem

Existing handover procedures in wireless communication systems face security issues and inefficiencies, particularly in the handover completion phase, due to the lack of immediate validation and processing of MAC control elements (CEs) in the target cell, leading to delays and overhead in message exchanges between the distributed unit and central unit.

Method used

The introduction of an EnhancedHoCompletion MAC-CE, which is directly processed by the MAC layer of the target cell, allowing for secure and efficient transmission of critical information without the need for additional message exchanges between the distributed and central units, thereby reducing delay and overhead.

Benefits of technology

This approach enables secure and efficient handover completion by validating lower layer security at the target cell, reducing delays and overhead in message exchanges, and ensuring seamless communication between the UE and the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025074394_21052026_PF_FP_ABST
    Figure EP2025074394_21052026_PF_FP_ABST
Patent Text Reader

Abstract

A UE is to be handed over from a source cell to a target cell. The UE determines whether to send information that is protected and cannot be decoded by a DU of the target cell. The UE forms a message having a protected zone having a MAC CE that indicates that a handover from the source cell to the target cell is complete. The forming includes: adding the information into the MAC CE; or taking no action. The DU receives the message including a protected zone for a MAC layer and decodes to reveal a MAC CE that indicates at least that a handover from the source cell to the target cell is complete. If information is protected so that the information cannot be decoded by the DU, at least the information is forwarded from the DU to a CU. Otherwise, no action is taken for the information.
Need to check novelty before this filing date? Find Prior Art

Description

HO COMPLETION WITH MAC- SECURITYTECHNICAL FIELD

[0001] Examples of embodiments herein relate generally to wireless communications and, more specifically, relate to handover (HO) of a UE (user equipment) from a source cell to a target cell having a functional split.BACKGROUND

[0002] For communication between a UE (user equipment, a wireless and generally mobile device) and a network (NW), there are control command exchanges between the UE and network, which do not involve data traffic. Instead, control information is exchanged.

[0003] In LIE (long term evolution) and NR (new radio), a special type of communication is introduced that involves the MAC (medium access control) Layer, which is one layer in a protocol stack used in LIE or NR. In particular, there is a special MAC structure that carries control information. These special MAC structures carrying the control information are referred to as “MAC CEs”, which means “MAC Control Elements”.

[0004] This special MAC structure may be indicated via a special bit string in LCID (logical channel identification) (or eLCID, extended LCID) field of a MAC (sub)Header. For more information about MAC and MAC CEs, see 3GPP TS 38.321.

[0005] Handovers (HOs) are used to transfer a UE from one cell (e.g., a serving cell) to another cell (e.g., a target cell) when certain criteria are met, such as strength of the signal from the target cell being greater than (typically, by a threshold) the strength of the signal from the source cell. This ensures the UE is connected to a cell that has a relatively strong signal.

[0006] HO involves security for various layers. For instance, a UE sends a first (L3, layer 3) message to the target cell after connecting to the target cell. This message is ciphered (i.e., encrypted), and integrity protected using the target cell’s keys and algorithm. Thus, this very first message at the target cell is used to serve (at least) two purposes: 1) Indication of arrival of UE in the target cell; and 2) Secure entry is also validated during the arrival process itself. There are, however, security issues involving HO that can be addressed.BRIEF SUMMARY

[0007] This section is intended to include examples and is not intended to be limiting.

[0008] In an exemplary embodiment, a method is disclosed that includes in a distributed unit forming part of a target cell, receiving a message from a user equipment being handed over from a source cell to the target cell, wherein the message comprises a protected zone for a medium access control (MAC) layer; decoding the protected zone to reveal a MAC control element (CE) that indicates at least that a handover from the source cell to the target cell is complete; determining whether the MAC CE does or does not contain information that is protected so that the information cannot be decoded by the distributed unit; and performing one of the following: based on a determination the MAC CE does contain information that is protected so that the information cannot be decoded by the distributed unit, forwarding at least the information from the distributed unit to a central unit forming part of the target cell; or based on a determination the MAC CE does not contain information that is protected so that the information cannot be decoded by the distributed unit, taking no action by the distributed unit.

[0009] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.

[0010] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: in a distributed unit forming part of a target cell, receiving a message from a user equipment being handed over from a source cell to the target cell, wherein the message comprises a protected zone for a medium access control (MAC) layer; decoding the protected zone to reveal a MAC control element (CE) that indicates at least that a handover from the source cell to the target cell is complete; determining whether the MAC CE does or does not contain information that is protected so that the information cannot be decoded by the distributed unit; and performing one of the following: based on a determination the MAC CE does containinformation that is protected so that the information cannot be decoded by the distributed unit, forwarding at least the information from the distributed unit to a central unit forming part of the target cell; or based on a determination the MAC CE does not contain information that is protected so that the information cannot be decoded by the distributed unit, taking no action by the distributed unit.

[0011] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: in a distributed unit forming part of a target cell, receiving a message from a user equipment being handed over from a source cell to the target cell, wherein the message comprises a protected zone for a medium access control (MAC) layer; decoding the protected zone to reveal a MAC control element (CE) that indicates at least that a handover from the source cell to the target cell is complete; determining whether the MAC CE does or does not contain information that is protected so that the information cannot be decoded by the distributed unit; and performing one of the following: based on a determination the MAC CE does contain information that is protected so that the information cannot be decoded by the distributed unit, forwarding at least the information from the distributed unit to a central unit forming part of the target cell; or based on a determination the MAC CE does not contain information that is protected so that the information cannot be decoded by the distributed unit, taking no action by the distributed unit.

[0012] In another exemplary embodiment, an apparatus comprises means for: in a distributed unit forming part of a target cell, receiving a message from a user equipment being handed over from a source cell to the target cell, wherein the message comprises a protected zone for a medium access control (MAC) layer; decoding the protected zone to reveal a MAC control element (CE) that indicates at least that a handover from the source cell to the target cell is complete; determining whether the MAC CE does or does not contain information that is protected so that the information cannot be decoded by the distributed unit; and performing one of the following: based on a determination the MAC CE does contain information that is protected so that the information cannot be decoded by the distributed unit, forwarding at least the information from the distributed unit to a central unit forming part of the target cell; or basedon a determination the MAC CE does not contain information that is protected so that the information cannot be decoded by the distributed unit, taking no action by the distributed unit.

[0013] In an exemplary embodiment, a method is disclosed that includes determining, by a user equipment to be handed over from a source cell to a target cell and for a medium access control (MAC) control element (CE) to be sent in a message toward a distributed unit forming part of the target cell, whether to send information that is protected so that the information cannot be decoded by the distributed unit; forming, by the user equipment, a message comprising a protected zone, the protected zone comprising a MAC CE that indicates at least that a handover from the source cell to the target cell is complete, wherein the forming comprises one of the following: based on a determination the MAC CE is to contain the information that is protected so that the information cannot be decoded by the distributed unit, adding the information into the MAC CE; or based on a determination the MAC CE is not to contain the information that is protected so that the information cannot be decoded by the distributed unit, taking no action; and sending the message from the user equipment toward the target cell.

[0014] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.

[0015] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: determining, by a user equipment to be handed over from a source cell to a target cell and for a medium access control (MAC) control element (CE) to be sent in a message toward a distributed unit forming part of the target cell, whether to send information that is protected so that the information cannot be decoded by the distributed unit; forming, by the user equipment, a message comprising a protected zone, the protected zone comprising a MAC CE that indicates at least that a handover from the source cell to the target cell is complete, wherein the forming comprises one of the following: based on a determination the MAC CE is tocontain the information that is protected so that the information cannot be decoded by the distributed unit, adding the information into the MAC CE; or based on a determination the MAC CE is not to contain the information that is protected so that the information cannot be decoded by the distributed unit, taking no action; and sending the message from the user equipment toward the target cell.

[0016] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: determining, by a user equipment to be handed over from a source cell to a target cell and for a medium access control (MAC) control element (CE) to be sent in a message toward a distributed unit forming part of the target cell, whether to send information that is protected so that the information cannot be decoded by the distributed unit; forming, by the user equipment, a message comprising a protected zone, the protected zone comprising a MAC CE that indicates at least that a handover from the source cell to the target cell is complete, wherein the forming comprises one of the following: based on a determination the MAC CE is to contain the information that is protected so that the information cannot be decoded by the distributed unit, adding the information into the MAC CE; or based on a determination the MAC CE is not to contain the information that is protected so that the information cannot be decoded by the distributed unit, taking no action; and sending the message from the user equipment toward the target cell.

[0017] In another exemplary embodiment, an apparatus comprises means for: determining, by a user equipment to be handed over from a source cell to a target cell and for a medium access control (MAC) control element (CE) to be sent in a message toward a distributed unit forming part of the target cell, whether to send information that is protected so that the information cannot be decoded by the distributed unit; forming, by the user equipment, a message comprising a protected zone, the protected zone comprising a MAC CE that indicates at least that a handover from the source cell to the target cell is complete, wherein the forming comprises one of the following: based on a determination the MAC CE is to contain the information that is protected so that the information cannot be decoded by the distributed unit, adding the information into the MAC CE; or based on a determination the MAC CE is not to contain the information that is protected so that the information cannot be decoded by thedistributed unit, taking no action; and sending the message from the user equipment toward the target cell.BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The accompanying drawings use reference numerals, where the same reference numerals may be used to refer to like parts throughout, but parts having the same reference numeral can differ in operation and components. In the attached drawings:

[0019] FIG. 1 is a signaling diagram illustrating Layer 3 mobility;

[0020] FIG. 2 illustrates a normal and an enhanced MAC PDU for MAC security;

[0021] FIG. 3 is a MSC with lower layer security configuration;

[0022] FIG. 4 is an example of one possible proposed EnhancedHoCompletion MAC-CE;

[0023] FIG. 5, which is split over FIGS. 5A and 5B, is an MSC of handover completion with handover complete MAC-CE;

[0024] FIG. 6 is a flow diagram implemented by a target DU illustrating that the DU can make real-time decisions between at least Example 1 and Example 2;

[0025] FIG. 6A is a flow diagram implemented by a UE illustrating possible operations taken by the UE corresponding to FIG. 6; and

[0026] FIG. 7 is a block diagram of one possible and non-limiting exemplary system in which the exemplary embodiments may be practiced.DETAILED DESCRIPTION OF THE DRAWINGS

[0027] Abbreviations that may be found in the specification and / or the drawing figures are defined below, at the end of the detailed description section.

[0028] The word “exemplary” is used herein to mean “serving as an example, instance, or illustration.” Any embodiment described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments. All of the embodiments described in this Detailed Description are exemplary embodiments provided to enable persons skilled in the art to make or use the examples.

[0029] When more than one drawing reference numeral, word, or acronym is used within this description withand in general as used within this description, the “ / ” may be interpreted as “or”, “and”, or “both”. As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or,” mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0030] As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises”, “comprising”, “has”, “having”, “includes” and / or “including”, when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.

[0031] It is noted that capital and lowercase words or phrases are considered to be the same herein. For instance, the words Slice, slice, and SLICE are the same, as are the phrases Network Repository Function, network repository function, and NETWORK REPOSITORY FUNCTION.

[0032] Any flow diagram or signaling diagram herein is considered to be a logic flow diagram, and illustrates the operation of an exemplary method, results of execution of computer program instructions embodied on a computer readable memory, and / or functions performed by logic implemented in circuitry. For methods, flow diagrams, and signaling diagrams, the orders of method steps, blocks in the flow, or signaling are not critical and instead are examples.

[0033] Technical context is now provided for technical areas related to the understanding of the examples. These examples relate to mobility (e.g., the movement of UEs, user equipment, through a cellular network’s coverage area) and handover (HO) of those UEs, e.g., from source cells (formed by an access network supporting 5G, fifth generation, and / or LTE, long term evolution) to target cells (also formed by access networks), which occurs during mobility. In 5G, the access networks are commonly referred to as gNBs.

[0034] Network controlled mobility applies to UEs in the RRC CONNECTED state and is categorized into two types of mobility: cell-level mobility; and beam-level mobility. Celllevel is at that the level of cells, which are formed by access networks. Beam-level is at the levelof beams that are formed as part of cells, where there can be multiple beams per cell. Beam level mobility includes intra-cell beam level mobility (changing beams within the same cell) and intercell beam level mobility (changing beams between cells). The examples below are applicable at least to cell-level mobility.

[0035] Cell level mobility requires explicit RRC (radio resource control) signaling to be triggered, such as handover signaling. For inter-gNB handover, the signaling procedures include at least the following elemental components illustrated in FIG. 1 , which is a signaling diagram illustrating Layer 3 mobility. Layer 3 is a layer in a protocol stack, and relates to RRC. This is for a handover for the UE 10 from the source gNB 70-1 to the target gNB 70-2. The terms source cell and target cell will also be used, as the source gNB creates the source cell and the target gNB creates the target cell. The steps that are illustrated are as follows.

[0036] Step 1. The source gNB 70-1 initiates handover and issues a HANDOVER REQUEST message over the Xn interface.

[0037] Step 2. The target gNB 70-2 performs admission control and determines new RRC configuration.

[0038] Step 3. The target gNB 70-2 provides the new RRC configuration as part of the HANDOVER REQUEST ACKNOWLEDGE message.

[0039] Step 4. The source gNB 70-1 provides the RRC configuration to the UE by forwarding the RRCReconfiguration message received in the HANDOVER REQUEST ACKNOWLEDGE message. The RRCReconfiguration message includes at least cell ID (identification) and all other information required to access the target cell, e.g., so that the UE 10 can access the target cell without reading system information. For some cases, the information required for contention-based and contention-free random access can be included in the RRCReconfiguration message. The access information to the target cell may include beam specific information, if any.

[0040] Step 5. The UE 10 determines to switch to the new cell.

[0041] Step 6. The UE 10 moves the RRC connection to the target gNB 70-2 (e.g., as part of step 5 possibly) and replies with the RRCReconfigurationComplete message.

[0042] In terms of lower layer security, in 5G, security for control plane (CP) and user plane (UP) is performed by PDCP (Packet data convergence protocol). Controlcommunication on PDCP and lower layers are not protected. Attacks have been demonstrated exploiting lack of protection of MAC CEs (MAC, Medium Access Control, Control Elements). More procedures will be handled in the MAC layer only in 6G (sixth generation).

[0043] In terms of 6G and other generations, protection of lower layers is to be improved. Consider the following.

[0044] One technique being examined is to apply security for all of the CP on the MAC layer, thus protecting MAC CEs and all upper layer information up to the RRC. A present approach is to focus on protection for MAC CEs, providing the option to also protect RRC messages on the MAC layer. One idea with this option is that a “protected zone” can be included in the transport block that holds the sensitive MAC CEs and is cryptographically protected by the MAC layer. This means that not all of the lower-layer message would be lower-layer security protected. There would be specific types of messages which need to be secure at the lower layer.

[0045] That is, there would be specific types of messages which need to be secure at lower layer too. Below is the example of MAC-CEs which need to be secured as these MAC-CE’s carry information to actively alter the course of UE(s). A MAC-CE is a MAC control element that is used for control plane signaling at MAC level. The list of MAC CEs that can be relevant include the following:

[0046] 1 ) Timing Delta MAC CE;

[0047] 2) TCI (Transmission configuration indicator) States Activation / Deactivation for UE-specific PDSCH (physical downlink shared channel) MAC CE;

[0048] 3) TCI State Indication for UE-specific PDCCH (physical downlink control channel) MAC CE; and / or

[0049] 4) MAC-CE for a cell switch command.

[0050] FIG. 2 illustrates one set of proposed MAC-CEs enhancements to support lower layer (MAC) security. This is for example only, and other orders of header fields and MAC fields may be chosen, and other ways to specify the location of the protected zone may be chosen.

[0051] Reference 220 indicates that there are two possibilities: a normal MAC PDU (Protocol data unit) 215; and an enhanced MAC PDU 210. For the normal MAC PDU 215, thereis a field indicating that there is no protected zone (protected zone field 225, which has a value of “no”) and the MAC subPDUs 260 are not protected by the MAC.

[0052] The enhanced MAC PDU 210 is described as following. The following are description of the fields.

[0053] 1) The ‘Protected zone’ field 225 is added to indicate the presence of MAC security protected field in a MAC-CE. The enhanced MAC PDU 210 has a “yes” for the protected zone 225.

[0054] 2) The protected zone start 235 - indicates the starting position of MAC security protected field (it is noted that the complete MAC PDU is not lower layer security protected in this example).

[0055] 3) The protected zone start 235 indicates the start of the protected zone 250, and the protected zone size 240 indicates the size of the protected zone 250.

[0056] 3) MAC subPDUs 252 (Protected zone 250) - This is the field / part of mac PDU which is lower layer security protected.

[0057] 4) Counter 230 and MAC-I 255 - assistant information for lower layer security.

[0058] 5) The MAC subPDUs 251-1 are not protected by the MAC layer.

[0059] Upper part (MAC PDU 210) of the FIG. 2 depicts the MAC PDU with Protected zone field set to ‘Yes’, and other relevant fields including lower layer (mac) protected subPDUs 252. The lower part (MAC PDU 215) of FIG. 2 depicts the MAC PDU with Protected zone field 225 set to ‘No’. The MAC PDU 215 additionally contains MAC subPDUs 251-2 that are not protected by the MAC layer. SubPDUs 251-1 / 251-2 / 252 are smaller parts of the PDUs 210 / 215, and any subPDU 251 can contain a MAC CE.

[0060] In legacy HO (BHO, baseline handover), LTM (L1 / L2 Triggered Mobility, where LI = layer 1 and L2 = layer 2), CHO (conditional handover), rrcReconfigurationComplete is the first (L3, layer 3) message which UE sends to target cell after latching to the target cell. This message is ciphered (i.e., encrypted), and integrity protected using target cells keys and algorithm. Thus, this very first message at the target cell serves (at least) two purposes:

[0061] 1) Indication of arrival of UE in target cell; and

[0062] 2) Secure entry is also validated during the arrival process itself.

[0063] If the rrcReconfigurationComplete message failed to clear the ciphering and integrity, the target cell can take action as per specification such as the UE may be discarded (e.g., not allowed to connect to the target cell in subsequent attempts), or the target cell can reinitiate the authentication and security procedure.

[0064] With context to MAC security, the target cell provides MAC security-related configurations to the UE via the source cell during handover preparation (FIG. 3, described below, steps 4 and 5). MAC security is a procedure that is added on top of a legacy PDCP security, and it is recommended to secure only some of the MAC-CEs / MAC-PDUs. There are proposals that MAC-CEs should contain field(s) to indicate the MAC security applicability and related information.

[0065] Thus, the UE’s MAC security also needs to be validated, e.g., as the UE is arriving at the target cell. Otherwise, when the UE / NW (where NW = network) sends its first MAC-CE with mac security and if mac security fails, then corrective action could lead to delay.

[0066] More information regarding problems is described in relation to FIG. 3, which is a MSC (message signaling chart) with lower layer security configuration. This example uses a UE 10, a source cell 370-1, and a functional split of a target cell 370-2 into a target DU (distributed unit) 320 and target CU (central unit) 330. That is, the logical architecture of the target cell 370-2 (and its corresponding gNB) is separated into the target DU 320 and target CU 330, where there are often multiple target DUs 320 per single CU 330. The Fs interface 340 is split into Fs-C and Fs-U, which provide control plane and user plane connectivity, respectively, over the Fs interface 340. In this description of a legacy HO completion procedure, consider the following.

[0067] Step 1 : UE is in an rrc-connected state with source cell and data transmission / reception is ongoing.

[0068] Step 2: Depicts that the source cell 370-1 has provided measurement configurations to the UE 10 and the UE 10 has provided the measurement reports containing neighboring cell measurements.

[0069] Step 3: Based on measurement reports received at step 2, the source cell 370-1 has decided to handover the UE to the target cell 370-2, where the TargetDU 320 and TargetCU 330 are part of target cell 370-2, as previously described.

[0070] Steps 4 and 5: comprise the handover preparation stage.

[0071] In this stage, the source cell 370-1 sends the handover request to the target CU 330 with legacy contents and, in addition, mac security capabilities, to the target cell 370-2. Step 4 depicts the handover request message.

[0072] Step 5: Target CU 330 prepares for the UE arrival and relevant configurations and sends the handover request acknowledgement related message (shown as HandoverRequestAck). This message contains HoCommand (e.g., rrcReconfiguration of target cell), see reference 301, piggybacked in the Handover Request Acknowledgement message. This has lower layer security configuration. The terms “piggybacking”, “piggybacked” and the like are terms where a set of information (in this case, a HoCommand message) is carried within another set of information (in this case, a Handover Request Acknowledgement message) in signaling. The HoCommand message is meant for the UE and not for the source cell 370-1.

[0073] Step 6: Source cell sends a HoCommand message to the UE by piggybacking in an rrcReconfiguration message.

[0074] Step 7: Depicts that the UE is synchronized with the target cell 370-2 and (optionally) performs a RACH (random access channel) procedure with the target DU 320. The RACH procedure is how the UE connects to the target DU 320. The UE will not perform the RACH procedure for RACH-less HO, TA=source TA, TA=0 or TA= UE estimated TA, where TA= Timing advance.

[0075] Step 8: UE sends an rrcReconfigurationComplete message (with PDCP security) to target cell. This is the first (L3) message UE sends to target cell and serves at least two purposes:

[0076] 1) It announces the UE’s arrival to target cell; and

[0077] 2) As this is integrity protected and ciphered with the target cell’s security keys, the target cell 370-2 verifies the integrity and deciphers the message, thus the UE's secure arrival is also validated.

[0078] In certain conditions (mentioned in 3GPP TS 38.331, third generation partnership project, technical specification) the UE optionally includes certain IES (information elements) in rrcReconfigurationComplete message like UplinkTxDirectCurrentList, needForGapsInfoNR, uplinkTxDirectCurrentTwoCarrierList or the like. Lower layer (PHY,physical layer, and MAC) of the Target DU 320 are the end users of information carried by these IES. But rrcReconfigurationComplete is layer 3 message and has to be integrity validated and deciphered at PDCP layer, then only the contents of rrcReconfigurationComplete have to be forwarded to a lower layer by means, e.g., of F1AP signaling messages. Fl AP is a communication protocol between CU and DU. 3GPP TS 38.473 defines the Fl AP protocol.

[0079] In the split architecture, the UE sends rrcReconfigurationComplete (optionally including above mentioned IEs) to the target DU 320 and the target DU 320 forwards this message to the target CU 330, piggybacking the message inside an UL RRC MESSAGE TRANSFER message, for instance.

[0080] Step 9: Depicts that the Target DU 320 sends an UL RRC MESSAGE TRANSFER message to the Target CU 330, by piggybacking the rrcReconfigurationComplete message.

[0081] If the rrcReconfigurationComplete message contains UplinkTxDirectCurrentList, needForGapsInfoNR, uplinkTxDirectCurrentTwoCarrierList or the like IEs, the target CU 330 (after integrity validation and deciphering) sends these IEs to the Target DU 320.

[0082] Steps 10 and 11 : These depict the signaling messages to send UplinkTxDirectCurrentList, needForGapsInfoNR, uplinkTxDirectCurrentTwoCarrierList or the like IEs to Target DU and Target DU acknowledge to CU.

[0083] At least steps 9, 10, and 11 are referred to herein as being a to-and-fro message exchange 315. This to-and-fro message exchange 315 may be problematic and cause delay.

[0084] Step 12: there is data transfer between the UE 10, the target DU 320, and the target CU 330.

[0085] Steps 7, 8, and 9 are the part of Handover completion (sub) procedures.Initially this procedure was defined for a classic / monolith architecture where complete protocol stacks was hosted inside one HW (hardware) element. That is, a single HW element hosted RRC, SDAP, PDCP, RLC, MAC, PHY layers of the protocol stack. When the UE sends rrcReconfigurationComplete message to the target cell (using a classic / monolith architecture) and a lower layer of target cell (internally) forwards the received rrcReconfigurationComplete torrc layer, and later the rrc layer forwards the contents which are being used by the lower layer, to lower layers using internal messaging.

[0086] The split architecture has divided the monolithic architecture into CU and DU. CU may host RRC, (SDAP) and PDCP layers, and DU may host RLC, MAC and PHY layers of the protocol stack. Thus, the monolithic HW stack implementation is now also split. In particular, according to 3GPP TS 38.401, the gNB-CU is a logical node hosting RRC (radio resource control), SDAP (Service Data Adaptation Protocol), and PDCP (Packet data convergence protocol) protocols of the gNB or RRC and PDCP protocols of the en-gNB that controls the operation of one or more gNB-DUs. The gNB-CU terminates the Fl interface connected with the gNB-DU. According to 3GPP TS 38.401, a gNB-DU is a logical node hosting RLC (radio link control), MAC (Medium Access Control) and PHY (physical) layers of the gNB or en-gNB, and its operation is partly controlled by gNB-CU. One gNB-DU supports one or multiple cells. One cell is supported by only one gNB-DU. The gNB-DU terminates the Fl interface connected with the gNB-CU. A gNB is a node providing NR user plane and control plane protocol terminations towards the UE, and connected via the NG interface to the 5GC. See 3GPP TS 38.300.

[0087] The above-mentioned Handover Complete procedure has not been evolved with split architecture, which means the UE sends the rrcReconfigruationComplete message to the Target DU 320, and the Target DU 320 forwards the message to the target CU 330 via an external interface (Fl interface). As rrcReconfigruationComplete is (PDCP) integrity and ciphered, the target DU has to send this message to CU because PDCP layer of CU can only validate the integrity and decipher the message. This message contains certain information like UplinkTxDirectCurrentList, needForGapsInfoNR, uplinkTxDirectCurrentTwoCarrierList or the like, though end users of these information includes lower layers (residing inside the target DU), this information was first sent to the target CU for integrity check and deciphering, then the target CU forwards this message to the target DU via the external interface (e.g., the Fs interface 340). This to-and-fro of the message exchange 315 (of FIG. 3) from target DU 320 to target CU 330 and again back to target DU is overhead and adds delay in having the lower layer related information be provided to DU during the handover completion procedure.

[0088] The examples herein address at least these problems, such as addressing how to simplify the handover completion procedure to perform one or more of the following:

[0089] 1) Avoid the overhead involve in to-and-fro message exchange 315 between the target DU and target CU;

[0090] 2) Reduce the delay involved in providing lower layer related information from the UE to the target DU via the target DU to target CU and then back to the target DU; and / or

[0091] 3) Validate the UE's lower layer security in response to the UE arriving in target cell without any overhead.

[0092] This document proposes efficient methods, in examples, to perform a handover completion procedure. One example proposes a new MAC-CE, e.g., EnhancedHoCompletion MAC-CE, which the UE can send to the target gNB as part of a handover completion procedure. This MAC-CE may carry information such as UplinkTxDirectCurrentList, needForGapsInfoNR, uplinkTxDirectCurrentTwoCarrierList or the like. EnhancedHoCompletion MAC-CE is destined for the MAC layer of the target cell (DU), So DU can get this information directly from UE. This will reduce the signaling overhead involved in a legacy HO procedure and the delay involved in sending this information to MAC / PHY layer of the target cell. Refer to the description above for signaling and delay overhead. Lower layer security could provide the secure transmission / reception of the Proposed EnhancedHoCompletion MAC-CE between UE and the NW (network).

[0093] Above, what was described was baseline handover (layer 3 based handover, e.g., as in FIG. 3) as an exemplary problem scenario, but proposed examples herein are valid and eligible for other handover procedures like - LTM, cell@mac, fast HO or the like. The term cell@mac is used to refer to different mobility at MAC level.

[0094] FIG. 4 depicts an exemplary structure of one proposed EnhancedHoCompletion MAC-CE 400 as one possible example. In this example, there are octets (oct) 1 through 2N+2.

[0095] Handover complete MAC-CE field descriptions are as follows in this example. These are provided in octets (oct), which are groups of 8 bits. The number line 410 is split into eight bits.

[0096] Oct 1..3 : UplinkTxDirectCurrentList / uplinkTxDirectCurrentTwoCarrierList: The formal definition of these two IES and their usage are mentioned above. The UplinkTxDirectCurrentList contains the Tx Direct Current locations for the configured serving cells and BWPs (bandwidth parts) if requested by the NW (see reportUplinkTxDirectCurrent in CellGroupConfig). The uplinkTxDirectCurrentTwoCarrierList contains the Tx Direct Current locations for the configured uplink intra-band CA with two carriers if requested by the NW (see reportUplinkTxDirectCurrentTwoCarrier-rl6 in CellGroupConfig). The target cell 370-2 sends only one of the IEs in, e.g., a FlAP:UeContextModification or a FlAP:UeContextSetup message to a lower layer to configure. So it is proposed in an example that the handoverComplete MAC-CE could contain only one of them. This example is not restricting the UE to send only one of the IE UplinkTxDirectCurrentList or uplinkTxDirectCurrentTwoCarrierList. Instead, the UE can send both the IEs in, e.g., handoverComplete MAC-CE in subsequent octets. Their usage at the lower layer is as mentioned in 3 GPP TS 38.473. These IEs could occupy more (or fewer) than the proposed octets.

[0097] Oct 4: needForGapsInfoNR : This field is used to indicate the measurement gap requirement information of the UE for NR target frequency bands.

[0098] Oct 2N+1 : scg-Response (Optional) : In case of NR-DC, new radio-dual connectivity, (nr-SCG-Response), this field includes the RRCReconfigurationComplete message. In case of NE-DC, new radio and Eutran for dual connectivity, (eutra-SCG-Response), this field includes the E-UTRA RRCConnectionReconfigurationComplete message as specified in 3 GPP TS 36.331. This field is not decodable by the DU (e.g., being at a higher layer than supported -at least for decoding - by the DU) and will be forwarded by the DU to the CU (which can decode the scg-Response).

[0099] Oct 2N+2: ue-MeasurementsAvailable (Optional): The IE UE-MeasurementsAvailable is used to indicate all relevant available indicators for UE measurements. The ue-MeasurementsAvailable is a known information element.

[0100] FIG. 5, which is split over FIGS. 5A and 5B, is an MSC of handover completion with handover complete MAC-CE. Two proposed main examples are disclosed. The first example (Example 1) combines both MAC and RRC signaling in one message from the UEto the target DU, while the second example (Example 2) splits the MAC and RRC signaling into multiple messages.

[0101] Step 1 to 7 are legacy procedure / messages and explained in relation to FIG. 3. The Example 1 510 comprises signaling in steps 8.1, 8.2 and potentially 8.3.

[0102] Step 8.1, an EnhancedHoCompletion MAC-CE is used as a message, which the UE sends to the target DU 320 of the target cell 370-2. The target cell 370-2 and the target DU 320 can determine whether the signaling received is from MAC or RRC. For example, the signaling in step 8.1 could use an LCID, logical channel ID, which is used to indicate at least MAC. More specifically, LCID is for a MAC PDU, and based on LCID, the MAC layer will send data to an appropriate RLC bearer / entity. The SRB, signaling radio bearer, may also be used determines which layer is sending the message.

[0103] EnhancedHoCompletion MAC-CE can contain information such as UplinkTxDirectCurrentList, needForGapsInfoNR, uplinkTxDirectCurrentTwoCarrierList and scg-Response (e.g., including any other higher-layer related information) or the like.

[0104] UplinkTxDirectCurrentList, needForGapsInfoNR, uplinkTxDirectCurrentTwoCarrierList are being used at MAC / PHY layer. As EnhancedHoCompletion MAC-CE is destined to be used by the MAC layer, MAC / PHY layer can get this information directly from the UE 10 without the to-and-fro signaling between the DU 320 to CU 330 to DU 320 again (as explained above with respect to steps 9-11 of FIG 3).

[0105] The scg-Response message is being used by CU / RRC layer. So the DU 320 can forward scg-Response of EnhancedHoCompletion MAC-CE, to the CU over UL RRC Message Transfer message as mentioned in step 8.3. That is, in step 8.2, the target DU 320 determines whether the EnhancedHoCompletion MAC-CE contains an scg-Response message (an RRC message), and, if so, executes step 8.3, where the target DU 320 sends an UL RRC message transfer message (comprising the scg-Response) to the target CU 330.

[0106] EnhancedHoCompletion MAC-CE could be the indication for HO completion at the target cell 370-2. Thus, the UE 10 need not to send the legacy rrcReconfigurationComplete message. After reception of EnhancedHoCompletion MAC-CE and UL data, the DU 320 can send the UL data to the CU 330 and that UL data could be the indication of HO completion at the higher layer of target CU.

[0107] Example 2520 is described as follows. In this example, the MAC and RRC are sent via both MAC and RRC signaling.

[0108] In step 8.4, the EnhancedHoCompletion MAC-CE can contain information such as UplinkTxDirectCurrentList, needForGapsInfoNR, uplinkTxDirectCurrentTwoCarrierList but if the UE 10 wants to send scg -Response (or any other higher layer related information), the UE 10 send these information over rrcReconfigurationComplete. See signaling in step 8.5, where the UE sends the rrcReconfigurationComplete message containing the scg-Response and potentially other higher-layer information (and the like).

[0109] The UplinkTxDirectCurrentList, needForGapsInfoNR, uplinkTxDirectCurrentTwoCarrierList are being used at MAC / PHY layer. As EnhancedHoCompletion MAC-CE is destined to be used by the MAC layer, MAC / PHY layer can get this information directly from UE without the to-and-fro signaling between the DU 320 to CU 330 to DU 320 again (as explained as a problem in steps 9-11 of FIG 3). Thus, in Step 8.5, the UE sends scg-Response and other higher layer related info over rrcReconfigurationComplete to target DU.

[0110] In Step 8.6, the scg-Response and other higher layer related information is being used by CU / RRC layer of the target CU 330. So the target DU 320 sends rrcReconfigurationComplete, containing scg-Response(or the like) piggybacked in UL RRC Message Transfer, to the target CU 330.

[0111] Thus, legacy rrcReconfigurationComplete (with scg-Response or the like) message could be the indication for HO Completion at the target cell 370-2 via the target CU 330.

[0112] In step 9, the UE 10 and target CU 330 have started data / signaling transmission / reception.

[0113] In step 10, the UE has successfully arrived at the target at step 8.1 for Example 1 510 or at step 8.4 for Example 2520, and the UE 10 indicates HO completion and secure entry of the UE is also validated.

[0114] In case the target cell 370-2 wants to take any action for the UE, such as refusing the entry or redirecting the UE to other cell, HO completion indication to the target DU320 or target CU 330 can be the triggering point to perform post-HO completion actions (like refusing, redirecting or the like).

[0115] As per lower layer security concepts (see FIG. 2) that not all lower layer messages would be lower layer security protected, some have proposed certain messages and format for MAC-PDU & MAC-CEs which can differentiate the lower layer security eligibility. So, if lower layer security configurations keys, algorithms, and the like are being exchanged at steps 4 & 5, it is needed that lower layer security should be validated as close to as soon as the UE arrives in the target cell as possible.

[0116] Step 10 illustrates the following:

[0117] 1) As lower layer security configuration keys, algorithms, and the like are exchanged during legacy handover procedure (steps 4 and 5), it is needed to validate the lower layer security of UE in response to the UE arriving at the target cell.

[0118] 2) As EnhancedHoCompletion MAC-CE could be lower layer security protected and validated at step at step 8.1 (Example 1) or 8.4 (Example 2), the UE’s secure entry is also validated by the target cell DU 320 in response to the UE arriving at Target cell.

[0119] This will enable the target cell and UE to send secured lower layer messages whenever there is need. If EnhancedHoCompletion MAC-CE is not sent or sent without lower layer security protection, lower layer security validation is skipped.

[0120] While Example 1 510 and Example 2520 are described separately, the target DU 320 may decide which one to pursue based on what is received and in real-time, or based on other configuration. Turning to FIG. 6, this figure is a flow diagram implemented by a target DU 320 illustrating that the DU can make real-time decisions between at least Example 1 510 and Example 2520, and describes other options too. This flow diagram is performed by the target DU 320. In block 605, the target DU 605 receives a handover message using MAC-CE(s). In block 610, the DU 320 decodes information that is protected in (see FIG. 2) a protected zone(s) 250 (e.g., protected MAC subPDUs 251) that carry the MAC CE(s) to reveal the decoded information. Block 610 would be performed after step 8.1 or 8.4 in FIG. 5. In block 615, the DU performs operation(s) based on (at least) the decoded information.

[0121] In block 620, the DU determines whether the revealed HO complete message (in a MAC CE) contains the scg-Response (e.g., information that cannot be decoded by thedistributed unit). If so (block 620 = Yes), the flow proceeds to block 625, where the DU performs step 8.3 to pass higher layer information (e.g., at least the scg-Response) to the target CU. If not (block 620 = No), in block 630, the DU determines whether information for the scg-Response is received via RRC signaling (such as in step 8.5). If so (block 630 = Yes), the DU performs step 8.6 to pass higher layer information (including the scg-Response) to the target CU. See block 635. If not (block 630 = No), the method proceeds to block 640, where higher layer information will not be passed to the target CU and no action is taken.

[0122] In one example, the structure of a proposed EnhancedHoCompletion MAC-CE 400 is used for block 620, and the EnhancedHoCompletion MAC-CE 400 is tested to see if it contains the scg-Response or the like (e.g., information that is not decodable by the DU 320 but is instead decodable by the CU 330). This is one possibility, and can be applied to both steps 8.1 and 8.4. Another example is indicated by block 621, where, for step 8.1, the HO complete message in MAC CE has structure to contain scg-Response or the like. This example assumes that only Example 1 810 is valid and only steps 8.1, 8.2, and 8.3 would be performed (and steps 8.4, 8.5, and 8.6 would not be performed). That is, if there is no scg-Response or the like in the EnhancedHoCompletion MAC-CE 400, then the scg-Response would not be sent another way. An alternate example is illustrated in block 622, where, for step 8.4, the HO complete message in MAC CE 400 does not have a structure to contain scg-Response or the like. This causes the scg-Response or the like to be sent (if it will be sent) via step 8.5. This example assumes that only Example 2820 is valid and only steps 8.4, 8.5, and 8.6 would be performed (and steps 8.1, 8.2, and 8.3 would not be performed).

[0123] Referring to FIG. 6A, this figure is a flow diagram implemented by a UE illustrating possible operations taken by the UE corresponding to FIG. 6. In block 645, the UE 10 forms a MAC PDU 210 indicating a handover complete message using MAC-CE(s) (e.g., MAC subPDU(s) 252251-1, to be protected). In block 650, the UE encodes information that is protected in a protected zone(s) (e.g., protected MAC subPDUs 252) that carry the MAC CE(s). This is information that is protected at the MAC layer and decodable by the DU (e.g., and is not decodable by the CU, as the CU does not implement the MAC layer). Note that it is also possible to protect this information first, then add the protected information to the protected zone(s).

[0124] In block 655, the UE determines whether scg-Response (or other protected and higher layer information) is to be in the HO complete message. This higher layer information is encoded at the PDCP layer and is not decodable by the DU (as the DU does not implement the PDCP layer) but is decodable by the CU (as the CU implements the PDCP layer). The UE, in block 660, determines whether the HO complete message (in a MAC CE) is to contain the scg-Response. As indicated by blocks 661 and 662, there are two possibilities: in block 661, for step 8.1, the HO complete message in MAC CE has structure to contain scg-Response or the like; or in block 662, for step 8.4, the HO complete message in MAC CE does not have a structure to contain scg-Response or the like. These two possibilities have been described above already, but it is possible for the UE to perform one of step 8.1 with or without the scg-Response or the like, or steps 8.4 and (if used) step 8.5, or choose between the two. FIG.6A shows all the blocks for all three options.

[0125] If block 660 = Yes, in block 670, the UE adds (step 8.1) higher layer information to the HO complete message to be passed to the target CU via the target DU. If block 660 = NO, then in block 675, the UE determines whether the information for scg-Response (or other higher level information) is to be sent via RRC signaling. If so (block 675 = yes), the UE performs step 8.5 to send higher layer information to the target CU via the target DU, in block 680. If not (block 675 = No), the higher layer information will not be passed to the target CU via the DU (e.g., no action taken with respect to the higher layer information). See block 685.

[0126] Additional examples of embodiments are as follows.

[0127] Embodiment 1 : UE sends EnhancedHoCompletion MAC-CE with lower layer related information to target cell.

[0128] a) In one of the example cases, the UE can send lower layer related formation like UplinkTxDirectCurrentList, needForGapsInfoNR, uplinkTxDirectCurrentTwoCarrierList or the like.

[0129] b) In another example case, the UE can optionally send scg-Response and other higher layer related information in EnhancedHoCompletion MAC-CE.1

[0130] c) In another example case, if the UE sends scg-Response and other higher layer related information in EnhancedHoCompletion MAC-CE, the target DU can forward this information to the CU using, e.g., the FA1 AP messages.

[0131] 4) In another example case, the target CU can reply to reception of a message sent at above bullet point (c) for Embodiment 1.

[0132] Embodiment 2: UE sends rrcReconfigurationComplete message only with higher layer related information to CU.

[0133] 1) In one of the example cases, the UE sends rrcReconfigurationComplete with higher layer related information like scg-Response or the like to the target.

[0134] 2) In another example case, the UE can send scg-Response in EnhancedHoCompletion MAC-CE(Embodiment l.c) and send rrcReconfigurationComplete to indicate the HO completion to higher layer of target.

[0135] Embodiment 4: UE sends only EnhancedHoCompletion MAC-CE with all information to the target.

[0136] a) In one of the example cases, the UE sends EnhancedHoCompletion MAC-CE as completion of the handover procedure and hence the UE does not send legacy rrcReconfigurationComplete to the target.

[0137] b) In another example case, when the DU sends the UL message to the CU, the first UL message arrival at the CU could be an (L3) indication to CU for HO completion.

[0138] Embodiment 5: EnhancedHoCompletion MAC-CE could be an indication of HO completion for other HO procedure.

[0139] 1) In one of the example cases, during the LTM, cell@mac, e.g., fast HO, the UE can send a proposed EnhancedHoCompletion MAC-CE as the indication of HO completion instead of legacy rrcReconfigurationComplete message.

[0140] b) In another example case, the UE can chose to send EnhancedHoCompletion MAC-CE with the contains as mentioned in above embodiments of legacy HO procedure.

[0141] Turning to FIG. 7, this figure shows a block diagram of one possible and nonlimiting example of a cellular network 1 that is connected to a user equipment (UE) 10. A number of network elements are shown in the cellular network of FIG. 7: an access network (e.g., gNB) 70; and a core network 90.

[0142] In FIG. 7, a user equipment (UE) 10 is in wireless communication via radio link 11 with an access network 70 of the cellular network 1. A UE 10 is a wireless communication device, such as a mobile device, that is configured to access a cellular network. The UE 10 is illustrated with one or more antennas 28. The ellipses 2 indicate there could be multiple UEs 10 in wireless communication via radio links with the access network 70. The UE 10 includes one or more processors 13, one or more memories 15, and other circuitry 16. The other circuitry 16 includes one or more receivers (Rx(s)) 17 and one or more transmitters (Tx(s)) 18. Instructions 12 (such as from a program or other software) are used to cause the UE 10 to perform the operations described herein. For a UE 10, the other circuitry 16 could include circuitry such as for user interface elements (not shown) like a display. The instructions 12 may be stored in memory / memories 15 and executed by processor(s) 13, or executed by circuitry such being implemented as part of the processor(s) or other circuitry elements, or both.

[0143] The access network 70, as a network element of the cellular network 1, provides the UE 10 access to cellular network 1 and to the data network 91 via the core network 90 (e.g., via a user plane function (UPF) of the core network 90). The access network 70 controls source cells 370-1 or target cells 370-2, e.g., using corresponding DUs 42 and CUs 43, depending on whether the access network 70 is the source or the target. The access network 70 may be monolithic, meaning that all the functionality is performed by one hardware element and the functionality is not split into multiple entities. The access network 70 may instead have a functional split into a central unit (CU) 43 and one or more distributed units (DUs) 42 (of which only one is shown), and this is the example that is used herein. That is, the access network comprises the CU and (one or more) DU(s). The Fs interface 44 connects the DU 42 and CU 43.

[0144] The access network 70 may be considered to be an access node, such as a base station, which provides access by UE(s) 10 to the cellular network 1. The access network 70 is illustrated as having one or more antennas 58. If the split functionality is used, these antennas and other radio functions may be controlled by the DU 42. In general, the access network 70 may be referred to as RAN node, although many will make reference to this as a gNB (gNode B, a base station for NR, new radio) instead. There are, however, many other examples of RAN nodes including an eNB (evolved Node B) or TRP (Transmission-Reception Point). The access network 70 may have the ability to use both gNB and LTE protocols. The access network 70includes one or more processors 73, one or more memories 75, and other circuitry 76. The other circuitry 76 includes one or more receivers (Rx(s)) 77 and one or more transmitters (Tx(s)) 78. Instructions 72 are used to cause the access network 70 to perform the operations described herein. Instructions 72 (such as from a program or other software) may be stored in memory / memories 75 and executed by processor(s) 73, or executed by circuitry such being implemented as part of the processor(s) or other circuitry elements, or both. If the functionality split is used, the DU 42 and CU 43, which may be referred to as logical elements, are implemented using the circuitry of the processors 73, the memories 75, and potentially other circuitry 76.

[0145] Two or more access networks 70 communicate using, e.g., link(s) 79. The link(s) 79 may be wired or wireless or both and may implement, e.g., an Xn interface for 5G (fifth generation), an X2 interface for LTE (Long Term Evolution), or other suitable interface for other standards.

[0146] The cellular network 1 may include a core network 90, as a second network element or elements, that may include core network functionality, and which provide connectivity via a link or links 81 with a data network 91, such as a telephone network and / or a data communications network (e.g., the Internet). The core network 90 includes one or more processors 93, one or more memories 95, and other circuitry 96. The other circuitry 96 includes one or more receivers (Rx(s)) 97 and one or more transmitters (Tx(s)) 98. Instructions 92 (such as from a program or other software) are used to cause the core network 90 to perform the operations described herein. The instructions 92 may be stored in memory / memories 95 and executed by processor(s) 93, or executed by circuitry such being implemented as part of the processor(s) or other circuitry elements, or both.

[0147] The core network 90 could be a 5GC (5G core network). The core network 90 can implement or comprise multiple network functions (NF(s)) 99, and the instructions 92 may comprise one or more of the NFs 99. A 5G core network may use circuitry such as memory and processors, which may implement a virtualization layer. It could be a single standalone computing system, a distributed computing system, or a cloud computing system. The NFs 99, as network elements, of the core network could be containers or virtual machines running on the circuitry of the computing system(s) making up the core network 90.

[0148] Core network functionality for 5G may include access and mobility management functionality that is provided by a network function 99 such as an access and mobility management function (AMF), session management functionality that is provided by a network function such as a session management function (SMF). Core network functionality for access and mobility management in an LTE (Long Term Evolution) network may be provided by an MME (Mobility Management Entity) and / or SGW (Serving Gateway) functionality, which routes data to the data network. Many others are possible, as illustrated by the examples in FIG.7: AMF; SMF; MME; SGW; GMLC (Gateway Mobile Location Center); LMF (Location Management Function); UDM (Unified Data Management) / UDR (Unified Data Repository); NRF (Network Repository Function); and / or E-SMLC (Evolved Serving Mobile Location Center). These are merely exemplary core network functionality that may be provided by the core network 90, and note that both 5G and LTE core network functionality might be provided by the core network 90. The access network 70 is coupled via a backhaul link 31 to the core network 90. The access network 70 and the core network 90 may include an NG (Next Generation) interface for 5 G, or an SI interface for LTE, or other suitable interface for other radio access technologies for communicating via the backhaul link 31.

[0149] In the data network 91, there are instructions 94 stored in a computer-readable storage medium 4-1, which could be circuitry such as long-term memory such as a hard drive or a solid-state drive, a short-term memory such as dynamic random-access memory, or a combination of both (e.g., reading from long-term memory for temporary placement into shortterm memory and subsequent downloading). The computer-readable medium 4-1 contains instructions 94 that, when downloaded and installed into the instructions 12, 72, and 92 and / or memories 15, 75, or 95 of the corresponding UE 10, access network 70, and / or core network element(s) 90, and executed by processor(s) 13, 73, or 93, cause the respective device to perform corresponding actions described herein. The computer-readable storage medium 4 may be implemented in other forms, such as via instructions 94 on a compact disc (as a computer-readable storage medium 4-2) or a memory stick.

[0150] The instructions 12, 72, and 92 stored by corresponding one or more memories 15, 75, or 95. These instructions, when executed by the corresponding one or more processors 13, 73, or 93, cause the corresponding apparatus 10, 70, or 90, to perform theoperations described herein. The computer readable memories 15, 75, or 95 are circuitry and may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, flash memory, firmware, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The processors 13, 73, and 93, are circuitry and may be of any type suitable to the local technical environment. For example, these processors may include one or more of general-purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), processors based on a multi-core processor architecture, and may also include specialized circuits such as field-programmable gate arrays (FPGAs), application specific circuits (ASICs), signal processing devices and other devices, or combinations of these devices, as non-limiting examples. The processors 13, 73, and 93 are circuitry that can be programmed to perform functions via software, firmware or the like (including microcode), but are not solely software.

[0151] The receivers 17, 77, and 97, and the transmitters 18, 78, and 98 may implement wired or wireless interfaces. The receivers and transmitters may be grouped together as transceivers.

[0152] The cellular network 1 may implement network virtualization, which is the process of combining circuitry and software network resources and network functionality into a single, software-based administrative entity, a virtual network. Network virtualization involves platform virtualization, often combined with resource virtualization. Network virtualization is categorized as either external, combining many networks, or parts of networks, into a virtual unit, or internal, providing network-like functionality to software containers on a single system. Note that the virtualized entities (such as network functions 99) that result from the network virtualization are still implemented, at some level, using circuitry such as processors 73 and / or 93 and memories 75 and / or 95, and also such virtualized entities create technical effects.

[0153] It is noted that a common way to view “cells” in a cellular system is as a 360-degree oval. However, antennas typically do not radiate over 360 degrees, and therefore a common technique is to have the 360 degrees subdivided into multiple sections. That is, there can be multiple cells per base station. For instance, there could be three cells for a single carrier frequency and associated bandwidth, each cell covering one-third of a 360-degree area so thatthe single base station’s coverage area covers an approximate oval. Furthermore, each cell can correspond to a single carrier and a base station may use multiple carriers. So, if there are three 120-degree cells per carrier and two carriers, then the base station has a total of six cells. While the description herein may indicate that “cells” perform functions, it should be apparent that the base station that forms the cell will perform the functions.

[0154] In general, the various embodiments of the user equipment 10 can include, but are not limited to, devices implementing cellular technologies (such as smart phones, mobile phones, cellular phones, voice over Internet Protocol (IP) (VoIP) phones, and / or wireless local loop phones), tablets, portable computers, vehicles or vehicle-mounted devices for, e.g., wireless V2X (vehicle-to-everything) communication, image capture devices such as digital cameras, gaming devices, music storage and playback appliances, Internet appliances (including Internet of Things, loT, devices), loT devices with sensors and / or actuators for, e.g., automation applications, as well as portable units or terminals that incorporate combinations of such functions, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), Universal Serial Bus (USB) dongles, smart devices, wireless customer-premises equipment (CPE), an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. That is, the UE 10 could be any end device that may be capable of wireless communication. By way of example rather than limitation, the UE may also be referred to as a communication device, terminal device (MT), a Subscriber Station (SS), a Portable Subscriber Station, a Mobile Station (MS), or an Access Terminal (AT).

[0155] Without in any way limiting the scope, interpretation, or application of the claims appearing below, a technical effect and / or advantage of one or more of the example embodiments disclosed herein is the techniques will align the handover (e.g., completion) procedure with evolving split architecture. Legacy handover (e.g., completion) procedure was defined for classic / monolith architecture where all protocol stack / layers reside inside one HW, so the UE sends HO complete (layer3) message to the target and the target’s higher layer (afterlayer3 security clearance) can send the contains to lower layer with internal messaging. Another technical effect and / or advantage of one or more of the example embodiments disclosed herein is techniques will reduce the signaling and delay overhead involve in legacy handover completion procedure (as explained in reference to FIG. 3).

[0156] The following are additional examples.

[0157] Example 1. A method, comprising: in a distributed unit forming part of a target cell, receiving a message from a user equipment being handed over from a source cell to the target cell, wherein the message comprises a protected zone for a medium access control (MAC) layer; decoding the protected zone to reveal a MAC control element (CE) that indicates at least that a handover from the source cell to the target cell is complete; determining whether the MAC CE does or does not contain information that is protected so that the information cannot be decoded by the distributed unit; and performing one of the following: based on a determination the MAC CE does contain information that is protected so that the information cannot be decoded by the distributed unit, forwarding at least the information from the distributed unit to a central unit forming part of the target cell; or based on a determination the MAC CE does not contain information that is protected so that the information cannot be decoded by the distributed unit, taking no action by the distributed unit.

[0158] Example 2. The method according to example 1, wherein: the MAC CE contains the information that is protected so that the information cannot be decoded by the distributed unit; and the forwarding at least the information from the distributed unit to a central unit forming part of the target cell is performed, wherein the central unit is able to decode the information.

[0159] Example 3. The method according to example 2, wherein the information cannot be decoded at a level of the MAC layer, and instead is protected at a level of a packet data convergence protocol (PDCP) layer.

[0160] Example 4. The method according to example 2 or 3, wherein the information indicates that a radio resource control (RRC) reconfiguration has been completed by the user equipment.

[0161] Example 5. The method according to any of examples 2 to 4, wherein the distributed unit that implements first layers including the MAC layer from the target cell butdoes not implement the PDCP layer from the target cell, and wherein the central unit implements different second layers including a PDCP layer of the target cell, but does not implement the MAC layer from the target cell.

[0162] Example 6. The method according to any of examples 1 to 5, wherein the MAC CE comprises one or more of the following: one or more entries for information for one or both of UplinkTxDirectCurrentList or uplinkTxDirectCurrentTwoCarrierList; one or more entries used to indicate measurement gap requirement information of the UE for one or more target frequency bands; for information that is protected so that the information cannot be decoded by the distributed unit, one or more entries indicating reconfiguration is complete for RRC; or one or more entries used to indicate available indicators for UE measurements.

[0163] Example 7. The method according to any of examples 1 to 6, further comprising: determining, by the distributed unit, that the user equipment has successfully arrived at the target cell; and validating, by the distributed unit, secure entry of the user equipment, based on the determination that the user equipment has successfully arrived at the target cell.

[0164] Example 8. A method, comprising: determining, by a user equipment to be handed over from a source cell to a target cell and for a medium access control (MAC) control element (CE) to be sent in a message toward a distributed unit forming part of the target cell, whether to send information that is protected so that the information cannot be decoded by the distributed unit; forming, by the user equipment, a message comprising a protected zone, the protected zone comprising a MAC CE that indicates at least that a handover from the source cell to the target cell is complete, wherein the forming comprises one of the following: based on a determination the MAC CE is to contain the information that is protected so that the information cannot be decoded by the distributed unit, adding the information into the MAC CE; or based on a determination the MAC CE is not to contain the information that is protected so that the information cannot be decoded by the distributed unit, taking no action; and sending the message from the user equipment toward the target cell.

[0165] Example 9. The method according to example 8, wherein: the message comprises the information that is protected so that the information cannot be decoded by the distributed unit, but is instead decodable by a central unit forming part of the target cell.

[0166] Example 10. The method according to example 9, wherein the information cannot be decoded at a level of a MAC layer, and instead is protected at a level of a packet data convergence protocol (PDCP) layer.

[0167] Example 11. The method according to example 8 or 9, wherein the information indicates that a radio resource control (RRC) reconfiguration has been completed by the user equipment.

[0168] Example 12. The method according to any of examples 8 to 12, wherein the MAC CE comprises one or more of the following: one or more entries for information for one or both of UplinkTxDirectCurrentList or uplinkTxDirectCurrentTwoCarrierList; one or more entries used to indicate measurement gap requirement information of the UE for one or more target frequency bands; for information that is protected so that the information cannot be decoded by the distributed unit, one or more entries indicating reconfiguration is complete for RRC; or one or more entries used to indicate available indicators for UE measurements.

[0169] Example 13. An apparatus, comprising means for: in a distributed unit forming part of a target cell, receiving a message from a user equipment being handed over from a source cell to the target cell, wherein the message comprises a protected zone for a medium access control (MAC) layer; decoding the protected zone to reveal a MAC control element (CE) that indicates at least that a handover from the source cell to the target cell is complete; determining whether the MAC CE does or does not contain information that is protected so that the information cannot be decoded by the distributed unit; and performing one of the following: based on a determination the MAC CE does contain information that is protected so that the information cannot be decoded by the distributed unit, forwarding at least the information from the distributed unit to a central unit forming part of the target cell; or based on a determination the MAC CE does not contain information that is protected so that the information cannot be decoded by the distributed unit, taking no action by the distributed unit.

[0170] Example 14. The apparatus according to example 13, wherein: the MAC CE contains the information that is protected so that the information cannot be decoded by the distributed unit; and the forwarding at least the information from the distributed unit to a central unit forming part of the target cell is performed, wherein the central unit is able to decode the information.

[0171] Example 15. The apparatus according to example 14, wherein the information cannot be decoded at a level of the MAC layer, and instead is protected at a level of a packet data convergence protocol (PDCP) layer.

[0172] Example 16. The apparatus according to example 14 or 15, wherein the information indicates that a radio resource control (RRC) reconfiguration has been completed by the user equipment.

[0173] Example 17. The apparatus according to any of examples 14 to 16, wherein the distributed unit that implements first layers including the MAC layer from the target cell but does not implement the PDCP layer from the target cell, and wherein the central unit implements different second layers including a PDCP layer of the target cell, but does not implement the MAC layer from the target cell.

[0174] Example 18. The apparatus according to any of examples 13 to 17, wherein the MAC CE comprises one or more of the following: one or more entries for information for one or both of UplinkTxDirectCurrentList or uplinkTxDirectCurrentTwoCarrierList; one or more entries used to indicate measurement gap requirement information of the UE for one or more target frequency bands; for information that is protected so that the information cannot be decoded by the distributed unit, one or more entries indicating reconfiguration is complete for RRC; or one or more entries used to indicate available indicators for UE measurements.

[0175] Example 19. The apparatus according to any of examples 13 to 18, wherein the means are further configured for: determining, by the distributed unit, that the user equipment has successfully arrived at the target cell; and validating, by the distributed unit, secure entry of the user equipment, based on the determination that the user equipment has successfully arrived at the target cell.

[0176] Example 20. An apparatus, comprising means for: determining, by a user equipment to be handed over from a source cell to a target cell and for a medium access control (MAC) control element (CE) to be sent in a message toward a distributed unit forming part of the target cell, whether to send information that is protected so that the information cannot be decoded by the distributed unit; forming, by the user equipment, a message comprising a protected zone, the protected zone comprising a MAC CE that indicates at least that a handover from the source cell to the target cell is complete, wherein the forming comprises one of thefollowing: based on a determination the MAC CE is to contain the information that is protected so that the information cannot be decoded by the distributed unit, adding the information into the MAC CE; or based on a determination the MAC CE is not to contain the information that is protected so that the information cannot be decoded by the distributed unit, taking no action; and sending the message from the user equipment toward the target cell.

[0177] Example 21. The apparatus according to example 20, wherein: the message comprises the information that is protected so that the information cannot be decoded by the distributed unit, but is instead decodable by a central unit forming part of the target cell.

[0178] Example 22. The apparatus according to example 21, wherein the information cannot be decoded at a level of a MAC layer, and instead is protected at a level of a packet data convergence protocol (PDCP) layer.

[0179] Example 23. The apparatus according to example 20 or 21, wherein the information indicates that a radio resource control (RRC) reconfiguration has been completed by the user equipment.

[0180] Example 24. The apparatus according to any of examples 20 to 24, wherein the MAC CE comprises one or more of the following: one or more entries for information for one or both of UplinkTxDirectCurrentList or uplinkTxDirectCurrentTwoCarrierList; one or more entries used to indicate measurement gap requirement information of the UE for one or more target frequency bands; for information that is protected so that the information cannot be decoded by the distributed unit, one or more entries indicating reconfiguration is complete for RRC; or one or more entries used to indicate available indicators for UE measurements.

[0181] Example 25. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: in a distributed unit forming part of a target cell, receiving a message from a user equipment being handed over from a source cell to the target cell, wherein the message comprises a protected zone for a medium access control (MAC) layer; decoding the protected zone to reveal a MAC control element (CE) that indicates at least that a handover from the source cell to the target cell is complete; determining whether the MAC CE does or does not contain information that is protected so that the information cannot be decoded by the distributed unit; and performing one of the following: based on a determination the MAC CE does containinformation that is protected so that the information cannot be decoded by the distributed unit, forwarding at least the information from the distributed unit to a central unit forming part of the target cell; or based on a determination the MAC CE does not contain information that is protected so that the information cannot be decoded by the distributed unit, taking no action by the distributed unit.

[0182] Example 26. The apparatus according to example 25, wherein: the MAC CE contains the information that is protected so that the information cannot be decoded by the distributed unit; and the forwarding at least the information from the distributed unit to a central unit forming part of the target cell is performed, wherein the central unit is able to decode the information.

[0183] Example 27. The apparatus according to example 26, wherein the information cannot be decoded at a level of the MAC layer, and instead is protected at a level of a packet data convergence protocol (PDCP) layer.

[0184] Example 28. The apparatus according to example 26 or 27, wherein the information indicates that a radio resource control (RRC) reconfiguration has been completed by the user equipment.

[0185] Example 29. The apparatus according to any of examples 26 to 28, wherein the distributed unit that implements first layers including the MAC layer from the target cell but does not implement the PDCP layer from the target cell, and wherein the central unit implements different second layers including a PDCP layer of the target cell, but does not implement the MAC layer from the target cell.

[0186] Example 30. The apparatus according to any of examples 25 to 29, wherein the MAC CE comprises one or more of the following: one or more entries for information for one or both of UplinkTxDirectCurrentList or uplinkTxDirectCurrentTwoCarrierList; one or more entries used to indicate measurement gap requirement information of the UE for one or more target frequency bands; for information that is protected so that the information cannot be decoded by the distributed unit, one or more entries indicating reconfiguration is complete for RRC; or one or more entries used to indicate available indicators for UE measurements.

[0187] Example 31. The apparatus according to any of examples 25 to 30, wherein the one or more memories further store instructions that, when executed by the one or moreprocessors, cause the apparatus at least to perform: determining, by the distributed unit, that the user equipment has successfully arrived at the target cell; and validating, by the distributed unit, secure entry of the user equipment, based on the determination that the user equipment has successfully arrived at the target cell.

[0188] Example 32. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: determining, by a user equipment to be handed over from a source cell to a target cell and for a medium access control (MAC) control element (CE) to be sent in a message toward a distributed unit forming part of the target cell, whether to send information that is protected so that the information cannot be decoded by the distributed unit; forming, by the user equipment, a message comprising a protected zone, the protected zone comprising a MAC CE that indicates at least that a handover from the source cell to the target cell is complete, wherein the forming comprises one of the following: based on a determination the MAC CE is to contain the information that is protected so that the information cannot be decoded by the distributed unit, adding the information into the MAC CE; or based on a determination the MAC CE is not to contain the information that is protected so that the information cannot be decoded by the distributed unit, taking no action; and sending the message from the user equipment toward the target cell.

[0189] Example 33. The apparatus according to example 32, wherein: the message comprises the information that is protected so that the information cannot be decoded by the distributed unit, but is instead decodable by a central unit forming part of the target cell.

[0190] Example 34. The apparatus according to example 33, wherein the information cannot be decoded at a level of a MAC layer, and instead is protected at a level of a packet data convergence protocol (PDCP) layer.

[0191] Example 35. The apparatus according to example 32 or 33, wherein the information indicates that a radio resource control (RRC) reconfiguration has been completed by the user equipment.

[0192] Example 36. The apparatus according to any of examples 32 to 36, wherein the MAC CE comprises one or more of the following: one or more entries for information for one or both of UplinkTxDirectCurrentList or uplinkTxDirectCurrentTwoCarrierList; one ormore entries used to indicate measurement gap requirement information of the UE for one or more target frequency bands; for information that is protected so that the information cannot be decoded by the distributed unit, one or more entries indicating reconfiguration is complete for RRC; or one or more entries used to indicate available indicators for UE measurements.

[0193] Example 37. A computer program, comprising instructions which, when the program is executed by an apparatus, cause the apparatus to carry out the methods of any of examples 1 to 12.

[0194] Example 38. The computer program according to example 37, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus.

[0195] Example 39. The computer program according to example 37, wherein the computer program is directly loadable into an internal memory of the apparatus.

[0196] As used in this application, the term “circuitry” may refer to one or more or all of the following:

[0197] (a) hardware-only circuit implementations (such as implementations in analog, digital, and / or quantum circuitry) and

[0198] (b) combinations of hardware circuits and software such as (as applicable): (i) a combination of analog, digital, and / or quantum hardware circuit(s) with software / firmware and (ii) any or all portions of hardware processor(s) (including digital and / or quantum processor(s)) with software, and memory(ies) that work together to cause an apparatus, such as a mobile device, computing device, or server, to perform various functions) and

[0199] (c) any or all portions of hardware circuit(s), such as microprocessor(s), processor(s) and / or quantum processors, that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.

[0200] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or asimilar integrated circuit in server, a cellular network device, or other computing or network device.

[0201] In an example embodiment, software (e.g., application logic, an instruction set) as used herein is maintained on any one of various conventional computer-readable media. In the context of this document, a “computer-readable medium” may be any media or means that can contain, store, communicate, propagate or transport the instructions for use by or in connection with an instruction execution system, apparatus, or device, such as a computer, with one example of a computer described and depicted, e.g., in FIG. 7. A computer-readable medium may comprise a computer-readable storage medium (e.g., memories 15, 75, and 95 or other device) that may be any media or means that can contain, store, and / or transport the instructions for use by or in connection with an instruction execution system, apparatus, or device, such as a computer. A computer-readable storage medium does not comprise propagating signals, and therefore may be considered to be non-transitory. The term “non-transitory”, as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM, random access memory, versus ROM, read-only memory).

[0202] If desired, the different functions discussed herein may be performed in a different order and / or concurrently with each other. Furthermore, if desired, one or more of the above-described functions may be optional or may be combined.

[0203] Although various aspects of the invention are set out in the independent claims, other aspects of the invention comprise other combinations of features from the described embodiments and / or the dependent claims with the features of the independent claims, and not solely the combinations explicitly set out in the claims.

[0204] It is also noted herein that while the above describes example embodiments of the invention, these descriptions should not be viewed in a limiting sense. Rather, there are several variations and modifications which may be made without departing from the scope of the present invention as defined in the appended claims.

[0205] The following abbreviations that may be found in the specification and / or the drawing figures are defined as follows:

[0206] 3 GPP third generation partnership project

[0207] 5G fifth generation

[0208] 6G sixth generation

[0209] AMF access and mobility management function

[0210] BHO baseline handover

[0211] CE control element

[0212] CP control plane

[0213] CU central unit

[0214] DU distributed unit

[0215] E-SMLC evolved serving mobile location center

[0216] Eutran Evolved UMTS Terrestrial Radio Access Network

[0217] eLCID extended LCID

[0218] eNB (or eNodeB) evolved Node B (e.g., an LTE base station)

[0219] GMLC Gateway Mobile Location Center

[0220] gNB (or gNodeB) base station for 5G / NR

[0221] HO handover

[0222] HW hardware

[0223] ID identification

[0224] IE information element

[0225] I / F interface

[0226] LI layer 1

[0227] L2 layer 2

[0228] L3 layer 3

[0229] LCID logical channel identification

[0230] LMF Location Management Function

[0231] LTE long term evolution

[0232] LTM L1 / L2 Triggered Mobility

[0233] MAC Medium Access Control

[0234] MSC Message sequence chart

[0235] MME mobility management entity

[0236] NE-DC New radio and Eutran for dual connectivity

[0237] NF network function

[0238] ng or NG next generation

[0239] NR new radio

[0240] NR-DC new radio - dual connectivity

[0241] NRF Network Repository Function

[0242] N / W or NW network

[0243] PDCCH physical downlink control channel

[0244] PDSCH physical downlink shared channel

[0245] PDU protocol data unit

[0246] PDCP packet data convergence protocol

[0247] PHY physical or physical layer

[0248] RACH random access channel procedure

[0249] RAN radio access network

[0250] RLC radio link control

[0251] RRC radio resource control

[0252] Rx receiver

[0253] SDAP Service Data Adaptation Protocol

[0254] SGW serving gateway

[0255] SMF session management function

[0256] SRB signaling radio bearer

[0257] TA timing advance

[0258] TCI Transmission configuration indicator

[0259] TRP transmission-reception point

[0260] TS technical specification

[0261] Tx transmitter

[0262] UDM unified data management

[0263] UDR unified data repository

[0264] UE user equipment (e.g., a wireless, typically mobile device)

[0265] UP user plane

[0266] UPF user plane function

Claims

39We Claim:

1. A method, comprising:in a distributed unit forming part of a target cell, receiving a message from a user equipment being handed over from a source cell to the target cell, wherein the message comprises a protected zone for a medium access control (MAC) layer; decoding the protected zone to reveal a MAC control element (CE) that indicates at least that a handover from the source cell to the target cell is complete; determining whether the MAC CE does or does not contain information that is protected so that the information cannot be decoded by the distributed unit; and performing one of the following:based on a determination the MAC CE does contain information that is protected so that the information cannot be decoded by the distributed unit, forwarding at least the information from the distributed unit to a central unit forming part of the target cell; orbased on a determination the MAC CE does not contain information that is protected so that the information cannot be decoded by the distributed unit, taking no action by the distributed unit.

2. The method according to claim 1, wherein:the MAC CE contains the information that is protected so that the information cannot be decoded by the distributed unit; andthe forwarding at least the information from the distributed unit to a central unit forming part of the target cell is performed, wherein the central unit is able to decode the information.

3. The method according to claim 2, wherein the information cannot be decoded at a level of the MAC layer, and instead is protected at a level of a packet data convergence protocol (PDCP) layer.

404. The method according to claim 2 or 3, wherein the information indicates that a radio resource control (RRC) reconfiguration has been completed by the user equipment.

5. The method according to any of claims 2 to 4, wherein the distributed unit that implements first layers including the MAC layer from the target cell but does not implement the PDCP layer from the target cell, and wherein the central unit implements different second layers including a PDCP layer of the target cell, but does not implement the MAC layer from the target cell.

6. The method according to any of claims 1 to 5, wherein the MAC CE comprises one or more of the following:one or more entries for information for one or both of UplinkTxDirectCurrentList or uplinkTxDirectCurrentTwoCarrierList;one or more entries used to indicate measurement gap requirement information of the UE for one or more target frequency bands;for information that is protected so that the information cannot be decoded by the distributed unit, one or more entries indicating reconfiguration is complete for RRC; orone or more entries used to indicate available indicators for UE measurements.

7. The method according to any of claims 1 to 6, further comprising:determining, by the distributed unit, that the user equipment has successfully arrived at the target cell; andvalidating, by the distributed unit, secure entry of the user equipment, based on the determination that the user equipment has successfully arrived at the target cell.

8. A method, comprising:determining, by a user equipment to be handed over from a source cell to a target cell and for a medium access control (MAC) control element (CE) to be sent in a message toward a distributed unit forming part of the target cell, whether to send41information that is protected so that the information cannot be decoded by the distributed unit;forming, by the user equipment, a message comprising a protected zone, the protected zone comprising a MAC CE that indicates at least that a handover from the source cell to the target cell is complete, wherein the forming comprises one of the following:based on a determination the MAC CE is to contain the information that is protected so that the information cannot be decoded by the distributed unit, adding the information into the MAC CE; orbased on a determination the MAC CE is not to contain the information that is protected so that the information cannot be decoded by the distributed unit, taking no action; andsending the message from the user equipment toward the target cell.

9. The method according to claim 8, wherein:the message comprises the information that is protected so that the information cannot be decoded by the distributed unit, but is instead decodable by a central unit forming part of the target cell.

10. The method according to claim 9, wherein the information cannot be decoded at a level of a MAC layer, and instead is protected at a level of a packet data convergence protocol (PDCP) layer.

11. The method according to claim 8 or 9, wherein the information indicates that a radio resource control (RRC) reconfiguration has been completed by the user equipment.

12. The method according to any of claims 8 to 11, wherein the MAC CE comprises one or more of the following:one or more entries for information for one or both of UplinkTxDirectCurrentList or uplinkTxDirectCurrentTwoCarrierList;one or more entries used to indicate measurement gap requirement information of the UE for one or more target frequency bands;for information that is protected so that the information cannot be decoded by the distributed unit, one or more entries indicating reconfiguration is complete for RRC; orone or more entries used to indicate available indicators for UE measurements.

13. An apparatus, comprising means for:in a distributed unit forming part of a target cell, receiving a message from a user equipment being handed over from a source cell to the target cell, wherein the message comprises a protected zone for a medium access control (MAC) layer; decoding the protected zone to reveal a MAC control element (CE) that indicates at least that a handover from the source cell to the target cell is complete; determining whether the MAC CE does or does not contain information that is protected so that the information cannot be decoded by the distributed unit; and performing one of the following:based on a determination the MAC CE does contain information that is protected so that the information cannot be decoded by the distributed unit, forwarding at least the information from the distributed unit to a central unit forming part of the target cell; orbased on a determination the MAC CE does not contain information that is protected so that the information cannot be decoded by the distributed unit, taking no action by the distributed unit.

14. The apparatus according to claim 13, wherein:the MAC CE contains the information that is protected so that the information cannot be decoded by the distributed unit; andthe forwarding at least the information from the distributed unit to a central unit forming part of the target cell is performed, wherein the central unit is able to decode the information.

15. The apparatus according to claim 14, wherein the information cannot be decoded at a level of the MAC layer, and instead is protected at a level of a packet data convergence protocol (PDCP) layer.

16. The apparatus according to claim 14 or 15, wherein the information indicates that a radio resource control (RRC) reconfiguration has been completed by the user equipment.

17. The apparatus according to any of claims 14 to 16, wherein the distributed unit that implements first layers including the MAC layer from the target cell but does not implement the PDCP layer from the target cell, and wherein the central unit implements different second layers including a PDCP layer of the target cell, but does not implement the MAC layer from the target cell.

18. The apparatus according to any of claims 13 to 17, wherein the MAC CE comprises one or more of the following:one or more entries for information for one or both of UplinkTxDirectCurrentList or uplinkTxDirectCurrentTwoCarrierList;one or more entries used to indicate measurement gap requirement information of the UE for one or more target frequency bands;for information that is protected so that the information cannot be decoded by the distributed unit, one or more entries indicating reconfiguration is complete for RRC; orone or more entries used to indicate available indicators for UE measurements.

19. The apparatus according to any of claims 13 to 18, wherein the means are further configured for:determining, by the distributed unit, that the user equipment has successfully arrived at the target cell; and44validating, by the distributed unit, secure entry of the user equipment, based on the determination that the user equipment has successfully arrived at the target cell.

20. An apparatus, comprising means for:determining, by a user equipment to be handed over from a source cell to a target cell and for a medium access control (MAC) control element (CE) to be sent in a message toward a distributed unit forming part of the target cell, whether to send information that is protected so that the information cannot be decoded by the distributed unit;forming, by the user equipment, a message comprising a protected zone, the protected zone comprising a MAC CE that indicates at least that a handover from the source cell to the target cell is complete, wherein the forming comprises one of the following:based on a determination the MAC CE is to contain the information that is protected so that the information cannot be decoded by the distributed unit, adding the information into the MAC CE; orbased on a determination the MAC CE is not to contain the information that is protected so that the information cannot be decoded by the distributed unit, taking no action; andsending the message from the user equipment toward the target cell.

21. The apparatus according to claim 20, wherein:the message comprises the information that is protected so that the information cannot be decoded by the distributed unit, but is instead decodable by a central unit forming part of the target cell.

22. The apparatus according to claim 21, wherein the information cannot be decoded at a level of a MAC layer, and instead is protected at a level of a packet data convergence protocol (PDCP) layer.4523. The apparatus according to claim 20 or 21, wherein the information indicates that a radio resource control (RRC) reconfiguration has been completed by the user equipment.

24. The apparatus according to any of claims 20 to 23, wherein the MAC CE comprises one or more of the following:one or more entries for information for one or both of UplinkTxDirectCurrentList or uplinkTxDirectCurrentTwoCarrierList;one or more entries used to indicate measurement gap requirement information of the UE for one or more target frequency bands;for information that is protected so that the information cannot be decoded by the distributed unit, one or more entries indicating reconfiguration is complete for RRC; orone or more entries used to indicate available indicators for UE measurements.

25. An apparatus, comprising:one or more processors; andone or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform:in a distributed unit forming part of a target cell, receiving a message from a user equipment being handed over from a source cell to the target cell, wherein the message comprises a protected zone for a medium access control (MAC) layer; decoding the protected zone to reveal a MAC control element (CE) that indicates at least that a handover from the source cell to the target cell is complete; determining whether the MAC CE does or does not contain information that is protected so that the information cannot be decoded by the distributed unit; and performing one of the following:based on a determination the MAC CE does contain information that is protected so that the information cannot be decoded by the distributed unit, forwarding at least the information from the distributed unit to a central unit forming part of the target cell; or46based on a determination the MAC CE does not contain information that is protected so that the information cannot be decoded by the distributed unit, taking no action by the distributed unit.

26. The apparatus according to claim 25, wherein:the MAC CE contains the information that is protected so that the information cannot be decoded by the distributed unit; andthe forwarding at least the information from the distributed unit to a central unit forming part of the target cell is performed, wherein the central unit is able to decode the information.

27. The apparatus according to claim 26, wherein the information cannot be decoded at a level of the MAC layer, and instead is protected at a level of a packet data convergence protocol (PDCP) layer.

28. The apparatus according to claim 26 or 27, wherein the information indicates that a radio resource control (RRC) reconfiguration has been completed by the user equipment.

29. The apparatus according to any of claims 26 to 28, wherein the distributed unit that implements first layers including the MAC layer from the target cell but does not implement the PDCP layer from the target cell, and wherein the central unit implements different second layers including a PDCP layer of the target cell, but does not implement the MAC layer from the target cell.

30. The apparatus according to any of claims 25 to 29, wherein the MAC CE comprises one or more of the following:one or more entries for information for one or both of UplinkTxDirectCurrentList or uplinkTxDirectCurrentTwoCarrierList;one or more entries used to indicate measurement gap requirement information of the UE for one or more target frequency bands;47for information that is protected so that the information cannot be decoded by the distributed unit, one or more entries indicating reconfiguration is complete for RRC; orone or more entries used to indicate available indicators for UE measurements.

31. The apparatus according to any of claims 25 to 30, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform:determining, by the distributed unit, that the user equipment has successfully arrived at the target cell; andvalidating, by the distributed unit, secure entry of the user equipment, based on the determination that the user equipment has successfully arrived at the target cell.

32. An apparatus, comprising:one or more processors; andone or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform:determining, by a user equipment to be handed over from a source cell to a target cell and for a medium access control (MAC) control element (CE) to be sent in a message toward a distributed unit forming part of the target cell, whether to send information that is protected so that the information cannot be decoded by the distributed unit;forming, by the user equipment, a message comprising a protected zone, the protected zone comprising a MAC CE that indicates at least that a handover from the source cell to the target cell is complete, wherein the forming comprises one of the following:based on a determination the MAC CE is to contain the information that is protected so that the information cannot be decoded by the distributed unit, adding the information into the MAC CE; or48based on a determination the MAC CE is not to contain the information that is protected so that the information cannot be decoded by the distributed unit, taking no action; andsending the message from the user equipment toward the target cell.

33. The apparatus according to claim 32, wherein:the message comprises the information that is protected so that the information cannot be decoded by the distributed unit, but is instead decodable by a central unit forming part of the target cell.

34. The apparatus according to claim 33, wherein the information cannot be decoded at a level of a MAC layer, and instead is protected at a level of a packet data convergence protocol (PDCP) layer.

35. The apparatus according to claim 32 or 33, wherein the information indicates that a radio resource control (RRC) reconfiguration has been completed by the user equipment.

36. The apparatus according to any of claims 32 to 35, wherein the MAC CE comprises one or more of the following:one or more entries for information for one or both of UplinkTxDirectCurrentList or uplinkTxDirectCurrentTwoCarrierList;one or more entries used to indicate measurement gap requirement information of the UE for one or more target frequency bands;for information that is protected so that the information cannot be decoded by the distributed unit, one or more entries indicating reconfiguration is complete for RRC; orone or more entries used to indicate available indicators for UE measurements.4937. A computer program, comprising instructions which, when the program is executed by an apparatus, cause the apparatus to carry out the methods of any of claims 1 to 12.

38. The computer program according to claim 37, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus.

39. The computer program according to claim 37, wherein the computer program is directly loadable into an internal memory of the apparatus.