Key derivation during a mobility procedure
By deriving target communication keys based on source keys and mobility parameters, the method ensures secure and uninterrupted communication during transitions between 6G and other mobile communication technologies, addressing security gaps in existing systems.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- NOKIA TECHNOLOGIES OY
- Filing Date
- 2025-11-19
- Publication Date
- 2026-06-04
AI Technical Summary
The challenge of securely transitioning communication keys during mobility procedures between different generations of mobile communication technologies, such as from 6G to previous generations like 5G or 4G, is not adequately addressed in existing systems, leading to potential security gaps and disruptions in communication sessions.
A method and apparatus for deriving target communication keys based on source keys and mobility procedure parameters, including mobility type and communication technology, ensuring secure key association and continuity during handovers between network nodes.
Facilitates secure and seamless mobility procedures by associating and tracing keys effectively, maintaining communication security and continuity across different mobile communication technologies.
Smart Images

Figure 00000039_0000 
Figure 00000039_0001 
Figure 00000040_0000
Abstract
Description
KEY DERIVATION DURING A MOBILITY PROCEDUREFIELD
[0001] Various example embodiments of the present disclosure generally relate to the field of telecommunication and in particular, to methods, devices, apparatuses and computer readable storage medium for key derivation during a mobility procedure.BACKGROUND
[0002] With the development of communication technology, the further generation mobile communication technology (e.g., the 6th generation mobile communication technology (6G)) will come. When the 6G comes, the mobility procedure between the 6G and the previous generation mobile communication technology (e.g., the 2nd generation mobile communication technology (2G), the 3rd generation mobile communication technology mobile communication technology (3G), the 4th generation mobile communication technology (4G), or the 5th Generation mobile communication technology (5G)) needs to be considered.SUMMARY
[0003] In a first aspect of the present disclosure, there is provided an apparatus. The apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: obtain, during a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node; determine at least one parameter based on a mobility type of the mobility procedure; and derive a target key of the terminal device for communicating with the target network node based on the source key and the at least one parameter, wherein at least one of the source key or the target key comprises a key for a mobility management entity in the 6G communication system.
[0004] In a second aspect of the present disclosure, there is provided a method. The method comprises: obtaining, during a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node; determining at least one parameter based on a mobility type of the mobility procedure; and deriving a target key of the terminal device for communicating with the target network node based on the source key and the at least one parameter, wherein atleast one of the source key or the target key comprises a key for a mobility management entity in the 6G communication system.
[0005] In a third aspect of the present disclosure, there is provided an apparatus. The apparatus comprises means for obtaining, during a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node; means for determining at least one parameter based on a mobility type of the mobility procedure; and means for deriving a target key of the terminal device for communicating with the target network node based on the source key and the at least one parameter, wherein at least one of the source key or the target key comprises a key for a mobility management entity in the 6G communication system.
[0006] In a fourth aspect of the present disclosure, there is provided an apparatus. The apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: obtain, during a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node; determine at least one parameter associated with at least one of: a communication technology of the target network node, or a mobility type of the mobility procedure; and derive a target key of the terminal device for communicating with the target network node based on the source key and the at least one parameter, wherein at least one of the source key or the target key comprises a key for a mobility management entity in the 6G communication system.
[0007] In a fifth aspect of the present disclosure, there is provided a method. The method comprises: obtaining, during a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node; determining at least one parameter associated with at least one of: a communication technology of the target network node, or a mobility type of the mobility procedure; and deriving a target key of the terminal device for communicating with the target network node based on the source key and the at least one parameter, wherein at least one of the source key or the target key comprises a key for a mobility management entity in the 6G communication system.
[0008] In a sixth aspect of the present disclosure, there is provided an apparatus. The apparatus comprises means for obtaining, during a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node; means for determining at least one parameter associated with at least one of: a communication technology of the target network node, or amobility type of the mobility procedure; and means for deriving a target key of the terminal device for communicating with the target network node based on the source key and the at least one parameter, wherein at least one of the source key or the target key comprises a key for a mobility management entity in the 6G communication system.
[0009] In a seventh aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the second aspect.
[0010] In an eighth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the fifth aspect.
[0011] It is to be understood that the Summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description.BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Some example embodiments will now be described with reference to the accompanying drawings, where:
[0013] FIG. 1 illustrates an example communication environment in which example embodiments of the present disclosure can be implemented;
[0014] FIG. 2 illustrates a schematic diagram of a handover architecture between a 6G communication system and a 5G communication system;
[0015] FIG. 3 illustrates a schematic diagram of an architecture between a 6G communication system and a 5G communication system;
[0016] FIG. 4 illustrates a signaling chart of a process of key derivation during a mobility procedure according to example embodiments of the present disclosure;
[0017] FIG. 5 illustrates a signaling chart of a process of key derivation during a mobility procedure according to example embodiments of the present disclosure;
[0018] FIG. 6 is a schematic diagram of an example process of a handover of a UE from 5G to 6G;
[0019] FIG. 7 is a schematic diagram of an example process of a handover of a UE from 6G to 5G;
[0020] FIG. 8 illustrates a flowchart of a method implemented at an apparatus in accordance with some example embodiments of the present disclosure;
[0021] FIG. 9 illustrates a flowchart of a method implemented at an apparatus in accordance with some example embodiments of the present disclosure
[0022] FIG. 10 illustrates a simplified block diagram of a device that is suitable for implementing example embodiments of the present disclosure; and
[0023] FIG. 11 illustrates a block diagram of an example computer readable medium in accordance with some example embodiments of the present disclosure.
[0024] Throughout the drawings, the same or similar reference numerals represent the same or similar element.DETAILED DESCRIPTION
[0025] Principle of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. Embodiments described herein can be implemented in various manners other than the ones described below.
[0026] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0027] References in the present disclosure to “one embodiment,” “an embodiment,” “an example embodiment,” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
[0028] It shall be understood that although the terms “first,” “second,”..., etc. in front of noun(s) and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another and they do not limit the order of the noun(s). For example, a first elementcould be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.
[0029] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0030] As used herein, unless stated explicitly, performing a step “in response to A” does not indicate that the step is performed immediately after “A” occurs and one or more intervening steps may be included.
[0031] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises”, “comprising”, “has”, “having”, “includes” and / or “including”, when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0032] As used in this application, the term “circuitry” may refer to one or more or all of the following:(a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and(b) combinations of hardware circuits and software, such as (as applicable):(i) a combination of analog and / or digital hardware circuit(s) with software / firmware and(ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and(c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0033] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0034] As used herein, the term “communication network” refers to a network following any suitable communication standards, such as New Radio (NR), Long Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), Narrow Band Internet of Things (NB-IoT) and so on. Furthermore, the communications between a terminal device and a network device in the communication network may be performed according to any suitable generation communication protocols, including, but not limited to, the first generation (1G), the second generation (2G), 2.5G, 2.75G, the third generation (3G), the fourth generation (4G), 4.5G, the fifth generation (5G), 5.5G, the sixth generation (6G) communication protocols, and / or any other protocols either currently known or to be developed in the future. Embodiments of the present disclosure may be applied in various communication systems. Given the rapid development in communications, there will of course also be future type communication technologies and systems with which the present disclosure may be embodied. It should not be seen as limiting the scope of the present disclosure to only the aforementioned system.
[0035] As used herein, the term “network device” refers to a node in a communication network via which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP), for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio header (RH), a remote radio head (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low power node such as a femto, a pico, a non-terrestrial network (NTN) or non-ground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, an aircraft network device, and so forth, depending on the applied terminology and technology. In some example embodiments, radio access network (RAN) split architecture comprises a Centralized Unit (CU) and a Distributed Unit (DU) at an IAB donor node. An IAB node comprises a Mobile Terminal (IAB-MT) part that behaves like a UE toward theparent node, and a DU part of an IAB node behaves like a base station toward the next-hop I AB node.
[0036] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), a Portable Subscriber Station, a Mobile Station (MS), or an Access Terminal (AT). The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, wireless customer-premises equipment (CPE), an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an IAB node (e.g., a relay node). In the following description, the terms “terminal device”, “communication device”, “terminal”, “user equipment” and “UE” may be used interchangeably.
[0037] As used herein, the term “resource,” “transmission resource,” “resource block,” “physical resource block” (PRB), “uplink resource,” or “downlink resource” may refer to any resource for performing a communication, for example, a communication between a terminal device and a network device, such as a resource in time domain, a resource in frequency domain, a resource in space domain, a resource in code domain, or any other combination of the time, frequency, space and / or code domain resource enabling a communication, and the like. In the following, unless explicitly stated, a resource in both frequency domain and time domain will be used as an example of a transmission resource for describing some example embodiments of the present disclosure. It is noted that example embodiments of the present disclosure are equally applicable to other resources in other domains.
[0038] A network function as described herein may be implemented as a core network entity that includes a combination of hardware processing circuit and software and / or firmwarecomprising machine-readable instructions, or software comprising machine-readable instructions that are executable by at least one processor of hardware processing circuit of an apparatus. The network function may be implemented at any suitable part, level or layer of the network, including but not limited to a core network, an application level, etc. A hardware processing circuit includes at least one processor and at least one memory storing machine-readable instructions that are executable by the at least one processor of the hardware processing circuit. A processor includes any or some combination of an accelerator, a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, a digital signal processor, a central processing unit, a graphic processing unit, a tensor processing unit. Memory includes any or some combination of volatile or non-volatile memory (e.g., a flash memory, cache, a randomaccess memory (RAM), and / or a read-only memory (ROM)). The memory stores the machine-readable instructions of the software and / or firmware for execution by the at least one processor of the hardware processing circuit. The machine-readable instructions are executable by the at least one processor of the hardware processing circuit cause the hardware processing circuit to perform the actions or operations of the methods described herein.
[0039] FIG. 1 illustrates an example communication environment 100 in which example embodiments of the present disclosure can be implemented. In the communication environment 100, the terminal device 110 (for example, a UE) is connected to a source network node 120. The source network node 120 may be associated with a source network function 130. While due to some reasons, such as the terminal device 110 moves away from the source network node 120, or the terminal device 110 moves rapidly and its relative position to the source network node 120 changes quickly, the terminal device 110 may need to perform mobility procedure, e.g., to communicate to a further network node, e.g., a target network node 140. The target network node 140 may be associated with a target network function 150. The source network node 120 and the target network node 140 may be random access network (RAN) nodes. The source network function 130 and the target network function 150 may be core network (CN) functions.
[0040] It is to be understood that the number of devices, functions and their connections shown in FIG. 1 are only for the purpose of illustration without suggesting any limitation. The communication environment 100 may include any suitable number of devices and functions configured to implementing example embodiments of the present disclosure. It is also to be noted that although the source network function 130 and the target networkfunction 150 are shown separately in FIG. 1, in some example embodiments, they may be the same.
[0041] Communications in the communication environment 100 may be implemented according to any proper communication protocol(s), comprising, but not limited to, cellular communication protocols, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.
[0042] It is also to be understood that the example environment 100 is shown only for purpose of illustration, without suggesting any limitation to the scope of the present disclosure. Embodiments of the present disclosure may also be applied to an environment with a different structure.
[0043] As briefly mentioned above, when the further generation mobile communication technology (such as 6G) comes, the mobility procedure between the further generation mobile communication technology and the previous generation mobile communication technology needs to be considered. The mobility procedure may include, e.g., handover. Handover, also known as handoff, is a process in mobile communication systems. It typically occurs when a terminal device moves out of a coverage area of one base station or access point and enters a coverage area of another. The handover ensures the continuity of the communication session without disruption. During handover, key derivation is crucial, it helps maintaining the security of the communication link.
[0044] FIG. 2 illustrates a schematic diagram of a handover architecture 200 between a 6G communication system and a 5G communication system.
[0045] As illustrated in FIG. 2, the handover architecture 200 involves the 5G specific part, the shared part, and the 6G specific part. The 5G specific part may involve 5G network functions (NFs), the network slice selection function (NSSF), the access and mobility management (AMF) function, etc. The shared part may involve the policy control function (PCF), the unified data management (UDM) function, the network repository function (NRF),the session management function (SMF), the user plane function (UPF), the authentication server function (AUSF), etc. The 6G specific part may involve 6G NFs, NSSF, mobility management (MM) function, etc. The handover architecture 100 depends on several aspects for 6G which may evolve in 6G comparison to 5G such as the interface between control and user plane nodes (the point A and the point B in FIG. 2), the interface between radio access network (RAN) and core network (CN) (the point C in FIG. 2), QoS framework and the evolution of non-access stratum (NAS) (the point D in FIG. 2).
[0046] FIG. 3 illustrates a schematic diagram of an architecture 300 between a 6G communication system and a 5G communication system. As illustrated in FIG. 3, the network functions between 5G and 6G may communicate through corresponding interfaces. For example, the AMF may communicate with UDM through the interface N8, the 6G MM may communicate with UDM through the interface N8-6G, etc.
[0047] In the present disclosure, it is noted that for the inter-radio access technology (inter- RAT) between 6G and the previous generation mobile communication technology (e.g., 5G), it is assumed that the architecture with combined network functions for session management, policy control function and user plane function may remain.
[0048] For the mobility procedure between the 6G and the previous generation mobile communication technology, it is expected and assumed that the key hierarchy may remain. For example, it is expected and assumed that the source key from a source generation mobile communication technology (e.g., 6G) may be used to derive the target key for a further generation mobile communication technology (e.g., 4G, 5G or 6G). In this case, there are some problems needs to be considered, for example, how is the key derivation for the target node derived in case of the mobile terminal moves from source 6G to target 4G or target 5G, or to target 6G or how is the key derivation for the target node derived in case of the mobile terminal moves from source 5G to target 6G or source 4G to target 6G.
[0049] Embodiments of the present disclosure provide a solution for key derivation during a mobility procedure. During a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node is obtained, and at least one parameter is determined based on a mobility type of the mobility procedure, and a target key of the terminal device for communicating with the target network node is derived based on the source key and the at least one parameter.
[0050] By determining the corresponding parameter based on the mobility type, the sourcekey is determined based on the source key and the corresponding parameter. Thus, the target key and the source key may be associated, it is easy to trace the keys, and the mobility of the mobile terminal may be performed securely.
[0051]
[0052] Example embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0053] As described above, due to some reasons, the terminal device 110 may need to perform mobility procedure between different network nodes. In this case, the key for communicating with the network node to be communicated to (i.e. , the target network node) may need to be derived.
[0054] FIG. 4 illustrates a signaling chart of a process 400 for key derivation during a mobility procedure according to example embodiments of the present disclosure. The process 400 will be described with reference to FIG. 1. As illustrated in FIG. 4, the process 400 involves the network function 420, the source network function 410, and the target network function 430. In the example, the network function 420 may be responsible for key derivation for the terminal device 110. It is to be noted that although the network function 420 is shown independently relative to the source network function 410 and the target network function 430, in some example embodiments, the network function 420 may be the source network function 410, or the target network function 430.
[0055] In the case where the network function 420 is the target network function, during the mobility procedure of the terminal device 110 from the source network node to a target network node associated with the network function 420, the network function 420 may receive (412), from the source network function 410, the source key of the terminal device 110 for communicating with the source network node associated with the source network function 410. In other words, the network function 420 obtains (414) the source key. Then, the network function 420 may consider mobility type of the mobility procedure, and determine (416) the corresponding parameter. Based on the source key and the corresponding parameter, the network function 420 derives (418) the target key of the terminal device 110 for communicating with the target network node associated with the target network function 430.
[0056] In example embodiments of the present disclosure, the network function 420 may derive the target key with any key derivation function (KDF) or any key derivation method, embodiments of the present disclosure is not limited thereto.
[0057] In some example embodiments of the present disclosure, in the case where the network function 420 is the source network function, the network function 420 may transmit (422) the derived target key to the target network function 430. The target network function 430 may, for example, receive the target key from the network function 420, and use the received target key as the initial key (i.e., the source key) to perform corresponding key derivation.
[0058] In embodiments of the present disclosure, at least one of the source key or the target key includes a key for a mobility management entity in the 6G communication system. In the following, the key for the mobility management entity in the 6G communication system may be referred to as a key for mobility management, or Kmm. In the 6G communication system, Kmm may be related to mobility management for a terminal device. For example, Kmm may be used for a CN entity or function for the mobility management. The Kmmmay be considered as being equivalent to a key for AMF (also be referred to as KAMF) in the 5G communication system. In other words, Kmmmay play the same or at least partially the same role as that of KAMF in the 5G system. It is to be noted that in addition to the 6G system, Kmmmay be used in any future communication system.
[0059] In some example embodiments of the present disclosure, depending on the mobility type of the mobility procedure and the generation of the communication system, the corresponding parameter obtained by the network function 420 for deriving the target key may be different.
[0060] In some example embodiments, the terminal device 110 may communicate with the source network node in the 6G communication system. Due to some reasons, e.g., the terminal device 110 detects a decrease in signal quality of the current network, the terminal device 110 needs to perform mobility procedure from the source network node to the target network node in the 6G communication system, or the target network node in the 5G communication system.
[0061] In this case, the source key, received from the source network function associated with the source network node, of the terminal device 100 may be first key for the mobility management (also be referred to as KMM) in the 6G communication system, and the target key may be a second key for the mobility management in the 6G communication system (also be referred to as KMM’)), or may be a key for AMF (also be referred to as KAMF’). TO derive KMM’ or KAMF’, the network function 420 may determine parameters including at least one of: a predetermined value for function code, a direction, a length of the direction, a count, or a length of the count. For example, the network function 420 may determine the followingparameters:Function code (FC)=new value;PO = DIRECTION;LO = length of DIRECTION;Pl = COUNT;LI = length of COUNT.
[0062] In some example embodiments, depending on the mobility type of the mobility procedure, the value of the DIRECTION and the COUNT may be different.
[0063] In some example embodiments, the mobility type of the mobility procedure may include a handover. In this case, the value of the DIRECTION may be 0x01 and the value of COUNT may be a downlink count value, e.g., the downlink NAS COUNT of the 3GPP access.
[0064] In some example embodiments, the mobility type of the mobility procedure may include an idle mode mobility, e.g., the mobility registration update. In this case, the value of the DIRECTION may be 0x00 and the value of COUNT may be an uplink count value, e.g., the uplink NAS COUNT of the non-3GPP or 3GPP access used in the Registration Request.
[0065] Similar to the above mobility scenario, in some example embodiments, the terminal device 110 may communicate with the source network node in the 6G communication system, and need to perform mobility procedure from the source network node to the target network node in the 4G communication system.
[0066] In this case, the source key may be KMM, and the target key may be a key for ASME (also be referred to as KASME’). TO derive KASME’ , the network function 420 may further determine the mobility type of the mobility procedure.
[0067] In some example embodiments, if the network function 420 determines that the mobility type of the mobility procedure is the handover, the network function 420 may determine parameters including at least one of: a predetermined value for function code, a downlink count value, or a length of the downlink count value. For example, when deriving KASME’ from KMM during mapping of security context from 6G to evolved packet system (EPS) at handover, the following parameters may be used:FC = new value;PO = NAS Downlink COUNT value;LO = length of NAS Downlink COUNT value.
[0068] In some example embodiments, the length of NAS Downlink COUNT value may be 0x00 or 0x04.
[0069] In some example embodiments, if the network function 420 determines that the mobility type of the mobility procedure is the idle mode mobility, the network function 420 may determine parameters including at least one of: a predetermined value for function code, an uplink count value, or a length of the uplink count value. For example, when deriving KASME’ from KMM during mapping of security context from 6G to evolved packet system (EPS) at the idle mode mobility, the following parameters may be used:FC = new value;P0 = NAS Uplink COUNT value;L0 = length of NAS Uplink COUNT value.
[0070] In some example embodiments, the length of NAS Uplink COUNT value may be 0x00 or 0x04.
[0071] In some example embodiments, similar to the above mobility scenario, the terminal device 110 may communicate with the source network node in the 4G communication system or 5G, and need to perform mobility procedure from the source network node to the target network node in the 6G communication system.
[0072] In this case, the source key may be a key for ASME (also be referred to as KASME) or a key for AMF (also be referred to as KAMF), and the target key be KMM’ . TO derive the KMM’ , the network function 420 may further determine the mobility type of the mobility procedure.
[0073] In some example embodiments, if the network function 420 determines that the mobility type of the mobility procedure is the handover, the network function 420 may determine parameters including at least one of: a predetermined value for function code, a next hop (NH) value, and a length of the next hop value. For example, the network function 420 may determine the following parameters:FC = new value;PO = NH value;LO = length of NH value.
[0074] In some example embodiments, the length of NH value may be 0x00 or 0x20.
[0075] In some example embodiments, if the network function 420 determines that the mobility type of the mobility procedure is the idle mode mobility, the network function 420 may obtain parameters including at least one of: a predetermined value for function code, an uplink count value of a tracking area update (TAU) message, or a length of the uplink count value of the tracking area update message. For example, when deriving KMM’ from KASME or KAMF during mapping of security contexts from EPS to 6G, or 5G to 6G at the idle mode mobility, the following parameters may be used:FC = new value;P0 = NAS Uplink COUNT value of the TAU message included in the Registration Request message;L0 = length of NAS Uplink COUNT value of the TAU message included in the Registration Request message.
[0076] In some example embodiments, the length of NAS Uplink COUNT value of the TAU message included in the Registration Request message may be 0x00 or 0x04.
[0077] Some example embodiments regarding key derivation are described above with reference to FIG. 4.
[0078] In another aspect, some example embodiments of the present disclosure further provide a solution for key derivation during a mobility procedure. During a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node is obtained, at least one parameter associated with at least one of: a communication technology of the target network node, or a mobility type of the mobility procedure is determined, and a target key of the terminal device for communicating with the target network node is derived based on the source key and the at least one parameter.
[0079] By considering the communication technology and / or the mobility type, the corresponding parameter associated with the communication technology and / or the mobility type is determined, and the source key is determined based on the source key and the corresponding parameter. Thus, the target key and the source key may be associated, it is easy to trace the keys, and the mobility of the mobile terminal may be performed securely.
[0080] FIG. 5 illustrates a signaling chart of a process 500 for key derivation during a mobility procedure according to example embodiments of the present disclosure. The process 500 will be described with reference to FIG. 1. As illustrated in FIG. 5, the process 400 involves the network function 520, the source network function 510, and the target network function 530. In the example, the network function 520 may be responsible for key derivation for the terminal device 110. It is to be noted that although the network function 520 is shown independently relative to the source network function 510 and the target network function 530, in some example embodiments, the network function 520 may be the source network function 510, or the target network function 530.
[0081] In embodiments of the present disclosure, in the case where the network function 520 is the target network function, during the mobility procedure of the terminal device 110 from the source network node to a target network node associated with the network function 520, the network function 520 may receive (512), from the source network function 510, the source key of the terminal device 110 for communicating with the source network node associated with the source network function 510. In other words, the network function 520 obtains (514) the source key. Then, the network function 520 may determine (516) corresponding parameter associated with a mobility type of the mobility procedure and / or a communication technology of the target network node. Based on the source key and the corresponding parameter, the network function 520 derives (518) the target key of the terminal device 110 for communicating with the target network node associated with the target network function 530.
[0082] In embodiments of the present disclosure, the network function 420 may derive the target key with any KDF or any key derivation method, embodiments of the present disclosure is not limited thereto.
[0083] In embodiments of the present disclosure, in the case where the network function 520 is the source network function, the network function 520 may transmit (522) the derived target key to the target network function 530. The target network function 530 may, for example, receive the target key from the network function 520, and use the received target key as the initial key (i.e., the source key) to perform corresponding key derivation.
[0084] In embodiments of the present disclosure, at least one of the source key or the target key includes a key for a mobility management entity in the 6G communication system. In the following, the key for the mobility management entity in the 6G communication system may be referred to as a key for mobility management, or Kmm. In the 6G communication system, Kmm may be related to mobility management for a terminal device. For example,Kmm may be used for a CN entity or function for the mobility management. The Kmm may be considered as being equivalent to a key for AMF (also be referred to as KAMF) in the 5G communication system. In other words, Kmm may play the same or at least partially the same role as that of KAMF in the 5G system. It is to be noted that in addition to the 6G system, Kmm may be used in any future communication system.
[0085] In some example embodiments of the present disclosure, depending on the mobility type of the mobility procedure, the communication technology, and the generation of the communication system, the corresponding parameter obtained by the network function 520 for deriving the target key may be different.
[0086] In some example embodiments, the terminal device 110 may communicate with the source network node in the 6G communication system. Due to some reasons, e.g., the terminal device 110 detects a decrease in signal quality of the current network, the terminal device 110 needs to perform mobility procedure from the source network node to the target network node in the 4G communication system, 5G communication system, or 6G communication system.
[0087] In this case, the source key of the terminal device 100 may be a first key for the mobility management (also be referred to as KMM) in the 6G communication system. The target key may be, for example, a second key for the mobility management in the 6G communication system (also be referred to as KMM’)) when the target network node is in the 6G communication system, a key for AMF (also be referred to as KAMF’) when the target network node is in the 5G communication system, or a key for ASME (also be referred to as KASME’) when the target network node is in the 4G communication system.
[0088] To derive KMM’, KAMF’ , or KASME’ , the network function 520 may first determine the communication technology of the target network node, and determine the corresponding parameter associated with the communication technology of the target network node. In some example embodiments, in addition to the communication technology, the network function 520 may determine other parameters to drive the target key.
[0089] In some example embodiments, the network function 520 may further determine parameters including at least one of: a predetermined value for function code, a direction, a length of the direction, a count, a length of the count, or a length of the communication technology. For example, during derivation of KMM’ , KAMF’, or KASME’ from KMM, the following parameters may be used:FC = new valuePO = DIRECTION;LO = length of DIRECTION;Pl = COUNT;LI = length of COUNT;P2 = Target Technology;L2 = length of Target Technology.
[0090] In some example embodiments, the length of the DIRECTION may be 0x00 or 0x01. The length of the COUNT may be 0x00 or 0x04. The length of Target Technology may be 0x00 or 0x04.
[0091] In some example embodiments, depending on the generation of the communication technology, the value of the communication technology may be different, and depending on the generation of the communication technology, the value of the Target Technology may be different. For example, when the Target Technology is the global system for mobile communication (GSM), the value of the Target Technology may be 0. When the Target Technology is universal mobile telecommunications system (UTRAN), the value of the Target Technology may be 1. When the Target Technology is long term evolution (LTE), the value of the Target Technology may be 2. When the Target Technology is 5G, the value of the Target Technology may be 3. When the Target Technology is 6G, the value of the Target Technology may be 4.
[0092] In some example embodiments, depending on the mobility type of the mobility procedure, the value of the DIRECTION and the COUNT may be different. In some example embodiments, the mobility type of the mobility procedure may include a handover. In this case, the value of the DIRECTION may be 0x01 and the value of COUNT may be a downlink count value, e.g., a downlink NAS COUNT of the 3GPP access. In some example embodiments, the mobility type of the mobility procedure may include an idle mode mobility, e.g., the mobility registration update. In this case, the value of the DIRECTION may be 0x00 and the value of COUNT may be an uplink count value, e.g., the uplink NAS COUNT of the 3GPP access used in the Registration Request.
[0093] Similar to the above mobility scenario, the terminal device 110 may communicate with the source network node in the 4G communication system or 5G, and need to perform mobility procedure from the source network node to the target network node in the 6G communication system due to some reasons.
[0094] In this case, the source key may be a key for ASME (also be referred to as KASME) or a key for AMF (also be referred to as KAMF), and target key may be a key for the mobility management in the communication system (also be referred to as KMM’). TO derive KMM’, the network function 520 may further determine the mobility type of the mobility procedure and then determine the corresponding parameter associated with mobility type of the mobility procedure. The corresponding parameter may include at least one of: a predetermined value for function code, an uplink count value of a tracking area update message or a next hop value, a length of the uplink count value of the tracking area update message or the next hop value, or a length of the mobility type. For example, when deriving KMM’ from KASME or KAMF during mapping of security contexts from 4G to 6G, or from 5G to 6G at the idle mode mobility and the handover, the following parameters may be used:FC = new value;P0 = NAS Uplink COUNT value of the TAU message included in the Registration Request message or NH value;E0 = length of NAS Uplink COUNT value of the TAU message included in the Registration Request message or NH value;Pl = Mobility Type;El = Eength of Mobility type.
[0095] In example some example embodiments, the length of NAS Uplink COUNT value of the TAU message included in the Registration Request message or NH value may be 0x00 or 0x04. In some example embodiments, depending on the mobility type of the mobility procedure, the value of the Mobility Type may be different.
[0096] In some example embodiments, when the KMM’ is derived during the mapping of security contexts from 4G or 5G to 6G at the idle mode mobility, the value of the Mobility Type is 0. When the KMM’ is derived during the mapping of security contexts from 4G or 5G to 6G at the handover, the value of the Mobility Type is 1.
[0097] In some example embodiments, when the terminal device 110 is communicated with the source network node in the 6G communication system, the network function 520 may further determine, from the key for mobility management (i.e., the KMM), a NH parameter based on one or more parameters associated with an access type instance for the terminal device 110.
[0098] In some example embodiments, the one or more parameters comprise at least one of:a value for the access type instance, or a length of the access type instance. For example, when deriving the NH parameter from the KMM, the following parameters may be used:FC = 0 X 6F;PO = SYNC-input;LO = length of SYNC-input (i.e. 0x00 0x20);Pl= Access type instance;LI = length of Access type instance.
[0099] In some example embodiments, the length of SYNC-input may be 0x00, or 0x20, and the length of Access type instance may be 0x000x20. For different access type instances, the value of Access type instance may be different. For example, for first 3GPP access (e.g., terrestrial) instance, the value of Access type instance may be 1, for second 3GPP access (e.g., satellite on board has gNB) instance, the value of Access type instance may be 2, etc.
[0100] In some example embodiments, the SYNC-input parameter may be the newly derived KgNB for the initial NH derivation, and the previous NH for all subsequent derivations. This results in a NH chain, where the next NH is always fresh and derived from the previous NH. If the AMF supports more than one 3GPP access types, then each RAN nodes represents each instance. In some example embodiments, the KM may be the 256-bit KMM.
[0101] To better understand the embodiments of the present disclosure, some example processes are described with reference to FIG. 6 and FIG. 7. FIG. 6 is a schematic diagram of an example process 600 of a handover of a UE from 5G to 6G. In the example process 600, the UE 650, the source gNB 610, the source AMF 630, the target gNB 620 and the target MM 640 are involved. As illustrated in FIG. 6, during the mobility procedure of the UE 650 from the 5G communication system to the 6G communication system, the source gNB 610 may transmit (612) a HANDOVER REQUIRED message to the source AMF 630. In some example embodiments, the HANDOVER REQUIRED message may include information such as related information of the UE 650, and the reason of handover, etc.
[0102] The source AMF 630 may receive the HANDOVER REQUIRED message from the source gNB 610. The source AMF 630 may use its local policy to determine whether to perform horizontal KAMF derivation on a current key KAMF. If it is determined to perform the horizontal KAMF derivation, a Nmm_Communication_CreateUEContext Request may contain an indication that a new source key KAMF has been calculated. Then the source AMF 630 may transmit (614) a Nmm_Communication_CreateUEContext Request message to thetarget MM 640. The Nmm_Communication_CreateUEContext Request message includes a {NH, NH chaining count (NCC)} pair and the new source key KAMF.
[0103] The target MM 640 may receive the Nmm_Communication_CreateUEContext Request message from the source AMF 630. Based on the new source key KAMF in the Nmm_Communication_CreateUEContext Request message, the target MM 640 may generate (616) the target key KMM. In some example embodiments, the target MM 640 may generate the target key KMM according to the manner as described with reference to FIG. 4. In some other example embodiments, the target MM 640 may generate the target key KMM according to the manner as described with reference to FIG. 5.
[0104] For example, the target MM 640 may first determine the mobility type of the mobility procedure, and then determine corresponding parameters, and derive or generate the target key KMM based on the corresponding parameters and the new source key KAMF. In some example embodiments, if the mobility type of the mobility procedure is handover, the target MM 640 may determine parameters such as a predetermined value for function code, a NH value, or a length of the NH value. For example, the length of the NH value may be 0x00, or 0x20. Then, the target MM 640 may derive the target key KMM based on the predetermined value for function code, the NH value, the length of the NH value, and the new source key KAMF. If the mobility type of the mobility procedure is the idle mode mobility, the target MM 640 may determine parameters such as a predetermined value for function code, an uplink count value of a TAU message (e.g., NAS uplink COUNT value of the TAU message included in the Registration Request message), and a length of the uplink count value of the TAU message. For example, the length of the uplink count value of the TAU message may be 0x00, or 0x04. Then, the target MM 640 may derive the target key KMM based on the predetermined value for function code, the uplink count value of the TAU message, the length of the uplink count value of the TAU message, and the new source key KAMF.
[0105] In some example embodiments, the target MM 640 may determine parameters such as the mobility type and a length of the mobility type. For example, if the mobility type of the mobility procedure is handover, the value of the mobility type may be 1, and if the mobility type of the mobility procedure is the idle mode mobility, the value of the mobility type may be 0. Then, based on the predetermined value for function code, the uplink count value of the TAU message, the length of the uplink count value of the TAU message, the mobility type, the length of the mobility type, and the new source key KAMF, the target MM 640 may derive the target key KMM. Alternatively, based on the predetermined value forfunction code, the NH value, the length of the NH value, the mobility type, the length of the mobility type, and the new source key KAMF, the target MM 640 may derive the target key KMM.
[0106] The target MM 640 may transmit (618) a HANDOVER REQUEST message to the target gNB 620. The HANDOVER REQUEST message may include information such as the {NH, NH chaining count (NCC)} pair, the NAS Container (NASC), and UE security capabilities. The NASC may be, e.g., the 6G key set identifier (6gKSI). The target gNB 620 may receive the HANDOVER REQUEST message from the target MM 640, and check whether its resources may support the UE to be accessed. If the target gNB 620 determines that there are sufficient resources, it may transmit (622) a HANDOVER REQUEST ACK message to target MM 640. The HANDOVER REQUEST ACK message may include information such as HO command (NCC, NASC(6gKSI)).
[0107] The target MM 640 may receive the HANDOVER REQUEST ACK message from the target gNB 620, and then transmit (624) a Nmm_Communication_CreateUEContext Response message to the source AMF 630. The Nmm_Communication_CreateUEContext Response message may include information such as HO command (NCC, NASC(6gKSI)).The source AMF 630 may receive the Nmm_Communication_CreateUEContext Response message from the target MM 640, and transmit (626) a HANDOVER REQUIRED ACK message to the source gNB 610. The source gNB 610 may receive the HANDOVER REQUIRED ACK message from the source AMF 630. Then, the source gNB 610 may transmit (628) a HO command (NCC, NASC(6gKSI)) message to the UE 650. The UE 650 may receive the HO command (NCC, NASC(6gKSI)) message from the source gNB 610. The UE 650 may generate (632) the 6G security context, and transmit (634) a handover confirm message to the target gNB 620, to request to access the target gNB 620. After successful access, the target gNB 620 may transmit (636) a handover notify message to the target MM 640, to notify that the access is complete.
[0108] FIG. 7 is a schematic diagram of an example process 700 of a handover of a UE from 6G to 5G. In the example process 700, the UE 750, the source gNB 710, the source AMF 730, the target gNB 720 and the target MM 740 are involved. As illustrated in FIG. 7, during the mobility procedure of the UE 750 from the 6G communication system to the 5G communication system, the source gNB 710 may transmit (712) a HANDOVER REQUIRED message to the target MM 740. In some example embodiments, the HANDOVER REQUIRED message may include information such as related information of the UE 750, and the reason of handover, etc.
[0109] The target MM 740 may receive the HANDOVER REQUIRED message from the source gNB 710, and generate (714) the target key KAMF. In some example embodiments, the target MM 740 may generate the target key KAMF according to the manner as described with reference to FIG. 4. In some other example embodiments, the target MM 740 may generate the target key KAMF according to the manner as described with reference to FIG. 5. Details are not repeated here. After generation of the target key KAMF, the target MM 740 may transmit (716) a Namf_Communication_CreateUEContext Response message to the source AMF 730. The Namf_Communication_CreateUEContext Response message includes information such as the {NH, NCC} pair, the target key KAMF and ngKSI.
[0110] The source AMF 730 may receive the Namf_Communication_CreateUEContext Response message from the target MM 740, and transmit (718) a HANDOVER REQUEST message to the target gNB 720. The HANDOVER REQUEST message may include information such as the {NH, NCC] pair, the NASC (ngKSI), and the UE security capabilities. The target gNB 720 may receive the HANDOVER REQUEST message from the source AMF 730, and check whether its resources may support the UE to be accessed. If the target gNB 720 determines that there are sufficient resources, it may transmit (722) a HANDOVER REQUEST ACK message to source AMF 730. The HANDOVER REQUEST ACK message may include information such as HO command (NCC, NASC(ngKSI)).
[0111] The source AMF 730 may receive the HANDOVER REQUEST ACK message from the target gNB 720, and then transmit (724) a Nmm_Communication_CreateUEContext Response message to the target MM 740. The Nmm_Communication_CreateUEContext Response message may include information such as HO command (NCC, NASC(ngKSI)). The target MM 740 may receive the Nmm_Communication_CreateUEContext Response message from the source AMF 730, and transmit (726) a HANDOVER REQUIRED ACK message to the source gNB 710. The source gNB 710 may receive the HANDOVER REQUIRED ACK message from the target MM 740.
[0112] Then, the source gNB 710 may transmit (728) a HO command (NCC, NASC(ngKSI)) message to the UE 750. The UE 750 may receive the HO command (NCC, NASC(ngKSI)) message from the source gNB 710. The UE 750 may generate (732) the 5G security context, and transmit (734) a handover confirm message to the target gNB 720, to request to access the target gNB 720. After successful access, the target gNB 720 may transmit (736) a handover notify message to the target MM 740, to notify that the access is complete.
[0113] FIG. 8 shows a flowchart of an example method 800 implemented at an apparatus in accordance with some example embodiments of the present disclosure.
[0114] At block 810, during a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node is obtained.
[0115] At block 820, at least one parameter is determined based on a mobility type of the mobility procedure.
[0116] At block 830, a target key of the terminal device for communicating with the target network node is derived based on the source key and the at least one parameter. At least one of the source key or the target key comprises a key for a mobility management entity in the 6G communication system.
[0117] In some example embodiments, the source key comprises a first key for the mobility management in the communication system, and the target key comprises a second key for the mobility management in the communication system or a key for an access and mobility management function, and the at least one parameter comprises at least one of: a predetermined value for function code, a direction, a length of the direction, a count, or a length of the count.
[0118] In some example embodiments, the apparatus is caused to determine the at least one parameter based on the mobility type of the mobility procedure by: in accordance with a determination that the mobility type of the mobility procedure comprises a handover, determining a first value for the direction and a downlink count value for the count.
[0119] In some example embodiments, the apparatus is caused to determine the at least one parameter based on the mobility type of the mobility procedure by: in accordance with a determination that the mobility type of a mobility procedure comprises an idle mode mobility, determining a second value for the direction and an uplink count value for the count.
[0120] In some example embodiments, the source key comprises a key for an access and mobility management function or a key for an access security management entity, and the target key comprises a second key for the mobility management in the communication system, and wherein the apparatus is caused to determine the at least one parameter based on the mobility type of the mobility procedure by: in accordance with a determination that the mobility type of the mobility procedure comprises a handover, determining at least one of: a predetermined value for function code, a next hop value, or a length of the next hop value.
[0121] In some example embodiments, the source key comprises a key for an access and mobility management function or a key for an access security management entity, and thetarget key comprises a second key for the mobility management in the communication system, and wherein the apparatus is caused to determine the at least one parameter based on the mobility type of the mobility procedure by: in accordance with a determination that the mobility type of the mobility procedure comprises an idle mode mobility, determining at least one of: a predetermined value for function code, an uplink count value of a tracking area update message, or a length of the uplink count value of the tracking area update message.
[0122] In some example embodiments, the source key comprises a first key for the mobility management in the communication system, and the target key comprises a key for an access security management entity, and wherein the apparatus is caused to determine the at least one parameter based on the mobility type of the mobility procedure by: in accordance with a determination that the mobility type of the mobility procedure comprises a handover, determining at least one of: a predetermined value for function code, a downlink count value, or a length of the downlink count value.
[0123] In some example embodiments, the source key comprises a first key for the mobility management in the communication system, and the target key comprises a key for an access security management entity, and wherein the apparatus is caused to determine the at least one parameter based on the mobility type of the mobility procedure by: in accordance with a determination that the mobility type of the mobility procedure comprises an idle mode mobility, determining at least one of: a predetermined value for function code, an uplink count value, or a length of the downlink count value.
[0124] In some example embodiments, the method 800 further comprises: transmitting the target key to a target network function associated with the target network node.
[0125] In some example embodiments, the method 800 further comprises: receiving the source key from a source network function associated with the source network node.
[0126] In some example embodiments, an apparatus capable of performing any of the method 800may comprise means for performing the respective operations of the method 800. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0127] In some example embodiments, the apparatus comprises means for obtaining, during a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node; means for determining at least one parameter based on a mobility type of the mobilityprocedure; and means for deriving a target key of the terminal device for communicating with the target network node based on the source key and the at least one parameter, wherein at least one of the source key or the target key comprises a key for a mobility management entity in the 6G communication system.
[0128] In some example embodiments, the source key comprises a first key for the mobility management in the communication system, and the target key comprises a second key for the mobility management in the communication system or a key for an access and mobility management function, and the at least one parameter comprises at least one of: a predetermined value for function code, a direction, a length of the direction, a count, or a length of the count.
[0129] In some example embodiments, the apparatus is caused to determine the at least one parameter based on the mobility type of the mobility procedure by: in accordance with a determination that the mobility type of the mobility procedure comprises a handover, determining a first value for the direction and a downlink count value for the count.
[0130] In some example embodiments, the apparatus is caused to determine the at least one parameter based on the mobility type of the mobility procedure by: in accordance with a determination that the mobility type of a mobility procedure comprises an idle mode mobility, determining a second value for the direction and an uplink count value for the count.
[0131] In some example embodiments, the source key comprises a key for an access and mobility management function or a key for an access security management entity, and the target key comprises a second key for the mobility management in the communication system, and wherein the apparatus is caused to determine the at least one parameter based on the mobility type of the mobility procedure by: in accordance with a determination that the mobility type of the mobility procedure comprises a handover, determining at least one of: a predetermined value for function code, a next hop value, or a length of the next hop value.
[0132] In some example embodiments, the source key comprises a key for an access and mobility management function or a key for an access security management entity, and the target key comprises a second key for the mobility management in the communication system, and wherein the apparatus is caused to determine the at least one parameter based on the mobility type of the mobility procedure by: in accordance with a determination that the mobility type of the mobility procedure comprises an idle mode mobility, determining at least one of: a predetermined value for function code, an uplink count value of a tracking area update message, or a length of the uplink count value of the tracking area updatemessage.
[0133] In some example embodiments, the source key comprises a first key for the mobility management in the communication system, and the target key comprises a key for an access security management entity, and wherein the apparatus is caused to determine the at least one parameter based on the mobility type of the mobility procedure by: in accordance with a determination that the mobility type of the mobility procedure comprises a handover, determining at least one of: a predetermined value for function code, a downlink count value, or a length of the downlink count value.
[0134] In some example embodiments, the source key comprises a first key for the mobility management in the communication system, and the target key comprises a key for an access security management entity, and wherein the apparatus is caused to determine the at least one parameter based on the mobility type of the mobility procedure by: in accordance with a determination that the mobility type of the mobility procedure comprises an idle mode mobility, determining at least one of: a predetermined value for function code, an uplink count value, or a length of the downlink count value.
[0135] In some example embodiments, the apparatus further comprises: means for transmitting the target key to a target network function associated with the target network node.
[0136] In some example embodiments, the apparatus further comprises: means for receiving the source key from a source network function associated with the source network node.
[0137] FIG. 9 shows a flowchart of an example method 900 implemented at an apparatus in accordance with some example embodiments of the present disclosure.
[0138] At block 910, during a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node is obtained.
[0139] At block 920, at least one parameter is determined. The at least one parameter is associated with at least one of: a communication technology of the target network node, or a mobility type of the mobility procedure.
[0140] At block 930, a target key of the terminal device for communicating with the target network node is derived based on the source key and the at least one parameter. At least one of the source key or the target key comprises a key for a mobility management entity in the 6G communication system.
[0141] In some example embodiments, the source key comprises a first key for the mobility management in the communication system, and the target key comprises at least one of: a second key for the mobility management in the communication system, a key for an access security management entity, or a key for an access and mobility management function, and wherein the at least one parameter is associated with the communication technology of the target network node, and the at least one parameter further comprises at least one of: a predetermined value for function code, a direction, a length of the direction, a count, or a length of the count.
[0142] In some example embodiments, the apparatus is caused to determine the at least one parameter by: in accordance with a determination that the mobility type of the mobility procedure comprises a handover, determining a first value for the direction and a downlink count value for the count.
[0143] In some example embodiments, the apparatus is caused to determine the at least one parameter by: in accordance with a determination that the mobility type of the mobility procedure comprises an idle mode mobility, determining a second value for the direction and an uplink count value for the count.
[0144] In some example embodiments, a value of the communication technology is determined based on a generation of the communication technology.
[0145] In some example embodiments, the source key comprises a key for an access and mobility management function or a key for an access security management entity, and the target key comprises a second key for the mobility management in the communication system, and wherein the at least one parameter is associated with the mobility type of the mobility procedure, and the at least one parameter further comprises at least one of: a predetermined value for function code, an uplink count value of a tracking area update message or a next hop value, a length of the uplink count value of the tracking area update message or the next hop value, or a length of the mobility type.
[0146] In some example embodiments, the apparatus is caused to determine the at least one parameter by: in accordance with a determination that the mobility type of the mobility procedure comprises a handover, determining a first value for the mobility type; and in accordance with a determination that the mobility type of the mobility procedure comprises an idle mode mobility, determining a second value for the mobility type.
[0147] In some example embodiments, the method 900 further comprises: determining, from the key for mobility management, a next hop parameter based on one or moreparameters associated with an access type instance for the terminal device.
[0148] In some example embodiments, the one or more parameters comprise at least one of: a value for the access type instance, or a length of the access type instance.
[0149] In some example embodiments, the method 900 further comprises: transmitting the target key to a target network function associated with the target network node.
[0150] In some example embodiments, the method 900 further comprises: receiving the source key from a source network function associated with the source network node.
[0151] In some example embodiments, an apparatus capable of performing any of the method 900 may comprise means for performing the respective operations of the method 900. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
[0152] In some example embodiments, the apparatus comprises means for obtaining, during a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node; means for determining at least one parameter associated with at least one of: a communication technology of the target network node, or a mobility type of the mobility procedure; and means for deriving a target key of the terminal device for communicating with the target network node based on the source key and the at least one parameter, wherein at least one of the source key or the target key comprises a key for a mobility management entity in the 6G communication system.
[0153] In some example embodiments, the source key comprises a first key for the mobility management in the communication system, and the target key comprises at least one of: a second key for the mobility management in the communication system, a key for an access security management entity, or a key for an access and mobility management function, and wherein the at least one parameter is associated with the communication technology of the target network node, and the at least one parameter further comprises at least one of: a predetermined value for function code, a direction, a length of the direction, a count, or a length of the count.
[0154] In some example embodiments, the apparatus is caused to determine the at least one parameter by: in accordance with a determination that the mobility type of the mobility procedure comprises a handover, determining a first value for the direction and a downlink count value for the count.
[0155] In some example embodiments, the apparatus is caused to determine the at least one parameter by: in accordance with a determination that the mobility type of the mobility procedure comprises an idle mode mobility, determining a second value for the direction and an uplink count value for the count.
[0156] In some example embodiments, a value of the communication technology is determined based on a generation of the communication technology.
[0157] In some example embodiments, the source key comprises a key for an access and mobility management function or a key for an access security management entity, and the target key comprises a second key for the mobility management in the communication system, and wherein the at least one parameter is associated with the mobility type of the mobility procedure, and the at least one parameter further comprises at least one of: a predetermined value for function code, an uplink count value of a tracking area update message or a next hop value, a length of the uplink count value of the tracking area update message or the next hop value, or a length of the mobility type.
[0158] In some example embodiments, the apparatus is caused to determine the at least one parameter by: in accordance with a determination that the mobility type of the mobility procedure comprises a handover, determining a first value for the mobility type; and in accordance with a determination that the mobility type of the mobility procedure comprises an idle mode mobility, determining a second value for the mobility type.
[0159] In some example embodiments, the apparatus further comprises: means for determining, from the key for mobility management, a next hop parameter based on one or more parameters associated with an access type instance for the terminal device.
[0160] In some example embodiments, the one or more parameters comprise at least one of: a value for the access type instance, or a length of the access type instance.
[0161] In some example embodiments, the apparatus further comprises: means for transmitting the target key to a target network function associated with the target network node.
[0162] In some example embodiments, the apparatus further comprises: means for receiving the source key from a source network function associated with the source network node.
[0163] FIG. 10 is a simplified block diagram of a device 1000 that is suitable for implementing example embodiments of the present disclosure. The device 1000 may be provided to implement a communication device. As shown, the device 1000 includes one ormore processors 1010, one or more memories 1020 coupled to the processor 1010, and one or more communication modules 1040 coupled to the processor 1010.
[0164] The communication module 1040 is for bidirectional communications. The communication module 1040 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interfaces may represent any interface that is necessary for communication with other network elements. In some example embodiments, the communication module 1040 may include at least one antenna.
[0165] The processor 1010 may be of any type suitable to the local technical network and may include one or more of the following: general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 1000 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.
[0166] The memory 1020 may include one or more non-volatile memories and one or more volatile memories. Examples of the non-volatile memories include, but are not limited to, a Read Only Memory (ROM) 1024, an electrically programmable read only memory (EPROM), a flash memory, a hard disk, a compact disc (CD), a digital video disk (DVD), an optical disk, a laser disk, and other magnetic storage and / or optical storage. Examples of the volatile memories include, but are not limited to, a random-access memory (RAM) 1022 and other volatile memories that will not last in the power-down duration.
[0167] A computer program 1030 includes computer executable instructions that are executed by the associated processor 1010. The instructions of the program 1030 may include instructions for performing operations / acts of some example embodiments of the present disclosure. The program 1030 may be stored in the memory, e.g., the ROM 1024. The processor 1010 may perform any suitable actions and processing by loading the program 1030 into the RAM 1022.
[0168] The example embodiments of the present disclosure may be implemented by means of the program 1030 so that the device 1000 may perform any process of the disclosure as discussed with reference to FIG. 4 or FIG. 5. The example embodiments of the present disclosure may be implemented by hardware or by a combination of software and hardware.
[0169] In some example embodiments, the program 1030 may be tangibly contained in a computer readable medium which may be included in the device 1000 (such as in the memory1020) or other storage devices that are accessible by the device 1000. The device 1000 may load the program 1030 from the computer readable medium to the RAM 1022 for execution. In some example embodiments, the computer readable medium may include any types of non-transitory storage medium, such as ROM, EPROM, a flash memory, a hard disk, CD, DVD, and the like. The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e. , tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).
[0170] FIG. 11 shows an example of the computer readable medium 1100 which may be in form of CD, DVD or other optical storage disk. The computer readable medium 1100 has the program 1030 stored thereon.
[0171] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, and other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. Although various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representations, it is to be understood that the block, apparatus, system, technique or method described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[0172] Some example embodiments of the present disclosure also provide at least one computer program product tangibly stored on a computer readable medium, such as a non- transitory computer readable medium. The computer program product includes computerexecutable instructions, such as those included in program modules, being executed in a device on a target physical or virtual processor, to carry out any of the methods as described above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.
[0173] Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general-purpose computer, special purpose computer, orother programmable data processing apparatus, such that the program code, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0174] In the context of the present disclosure, the computer program code or related data may be carried by any suitable carrier to enable the device, apparatus or processor to perform various processes and operations as described above. Examples of the carrier include a signal, computer readable medium, and the like.
[0175] The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random-access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0176] Further, although operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, although several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Unless explicitly stated, certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated, various features that are described in the context of a single embodiment may also be implemented in a plurality of embodiments separately or in any suitable sub-combination.
[0177] Although the present disclosure has been described in languages specific to structural features and / or methodological acts, it is to be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific featuresor acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.
Claims
35We claim:
1. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: obtain, during a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node; determine at least one parameter associated with at least one of: a communication technology of the target network node, or a mobility type of the mobility procedure; and derive a target key of the terminal device for communicating with the target network node based on the source key and the at least one parameter, wherein at least one of the source key or the target key comprises a key for a mobility management entity in a 6 generation, 6G, communication system.
2. The apparatus of claim 1, wherein the source key comprises a first key for the mobility management entity in the 6G communication system, and the target key comprises at least one of: a second key for the mobility management entity in the 6G communication system, a key for an access security management entity, or a key for an access and mobility management function, and wherein the at least one parameter is associated with the communication technology of the target network node, and the at least one parameter further comprises at least one of: a predetermined value for function code, a direction, a length of the direction, a count, a length of the count, or a length of the communication technology.
3. The apparatus of claim 2, wherein the apparatus is caused to determine the at least one parameter by: in accordance with a determination that the mobility type of the mobility procedure comprises a handover, determining a first value for the direction and a downlink count value for the count.
4. The apparatus of claim 2, wherein the apparatus is caused to determine the at least one parameter by: in accordance with a determination that the mobility type of the mobility procedure comprises an idle mode mobility, determining a second value for the direction and an uplink count value for the count.
5. The apparatus of claim 2, wherein a value of the communication technology is determined based on a generation of the communication technology.
6. The apparatus of claim 1, wherein the source key comprises a key for an access and mobility management function or a key for an access security management entity, and the target key comprises a second key for the mobility management entity in the 6G communication system, and wherein the at least one parameter is associated with the mobility type of the mobility procedure, and the at least one parameter further comprises at least one of: a predetermined value for function code, an uplink count value of a tracking area update message or a next hop value, a length of the uplink count value of the tracking area update message or the next hop value, or a length of the mobility type.
7. The apparatus of claim 6, wherein the apparatus is caused to determine the at least one parameter by: in accordance with a determination that the mobility type of the mobility procedure comprises a handover, determining a first value for the mobility type; and in accordance with a determination that the mobility type of the mobility procedure comprises an idle mode mobility, determining a second value for the mobility type.
8. The first apparatus of claim 1, wherein the apparatus is further caused to: determine, from the key for the mobility management entity in the 6G communication system, a next hop parameter based on one or more parameters associated with an access type instance for the terminal device.
9. The apparatus of claim 9, wherein the one or more parameters comprise at least one of:a value for the access type instance, or a length of the access type instance.
10. The apparatus of claim 1, wherein the apparatus comprises or is comprised in a source network function associated with the source network node, and the apparatus is further caused to: transmit the target key to a target network function associated with the target network node.
11. The apparatus of claim 1, wherein the apparatus comprises or is comprised in a target network function associated with the target network node, and the apparatus is further caused to: receive the source key from a source network function associated with the source network node.
12. A method comprising: obtaining, during a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node; determining at least one parameter associated with at least one of: a communication technology of the target network node, or a mobility type of the mobility procedure; and deriving a target key of the terminal device for communicating with the target network node based on the source key and the at least one parameter, wherein at least one of the source key or the target key comprises a key for a mobility management entity in a 6 generation, 6G, communication system.
13. A apparatus comprising: means for obtaining, during a mobility procedure of a terminal device from a source network node to a target network node, a source key of the terminal device for communicating with the source network node; means for determining at least one parameter associated with at least one of: a communication technology of the target network node, or a mobility type of the mobility procedure; and means for deriving a target key of the terminal device for communicating with the target network node based on the source key and the at least one parameter, wherein at least one of the source key or the target key comprises a key for a mobility management entity in a 6 generation, 6G, communication system.
14. A computer readable medium comprising instructions stored thereon for causing an apparatus at least to perform the method of claim 12.