Method and device for protecting information about access stratum key derivation in wireless communication system

The method encrypts and decrypts AS key derivation information within network nodes and terminals to secure key derivation processes in 5G and 6G wireless communication systems, addressing security challenges and ensuring data confidentiality.

WO2026155409A1PCT designated stage Publication Date: 2026-07-23LG ELECTRONICS INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
LG ELECTRONICS INC
Filing Date
2025-12-18
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

The challenge of protecting information related to access stratum (AS) key derivation in wireless communication systems, particularly in 5G and 6G networks, where security and integrity of key derivation processes are critical for ensuring data confidentiality and user privacy.

Method used

A method involving encryption and decryption of AS key derivation information within network nodes and terminals, where an upper layer entity encrypts the information and a lower layer decrypts it, enabling secure transmission and processing of user and control plane messages.

Benefits of technology

Enhances the security and integrity of AS key derivation processes, ensuring the confidentiality and integrity of communication data in wireless networks, particularly in 5G and 6G systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025022213_23072026_PF_FP_ABST
    Figure KR2025022213_23072026_PF_FP_ABST
Patent Text Reader

Abstract

A method and a device for protecting information about access stratum (AS) key derivation in a wireless communication system are disclosed. The method according to one embodiment of the present disclosure may comprise steps in which: a first network node receives, from a second network node, a first message including an updated value of the information about the access stratum (AS) key derivation; an upper stratum entity of the first network node provides an encrypted value of the information about the AS key derivation to a lower stratum entity of the first network node on the basis of the updated value of the information about the AS key derivation; and the first network node transmits, to a terminal, a second message including the encrypted value of the information about the AS key derivation.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for protecting information on access layer key derivation in a wireless communication system

[0001] The present disclosure relates to security in wireless communication systems, and more specifically to a method and apparatus for protecting information regarding access stratum (AS) key derivation.

[0002] The 5th generation (5G) wireless communication system is a successor technology to 4G LTE (long term evolution) and is a new clean-slate type mobile communication system with characteristics such as high performance, low latency, and high availability. In the case of 5G NR (New Radio), all available spectrum resources can be utilized, ranging from low-frequency bands below 1 GHz to intermediate frequency bands between 1 GHz and 10 GHz, and high-frequency (or millimeter wave) bands above 24 GHz. Based on the foundational technology of 5G wireless communication, 6G wireless communication systems are being developed.

[0003] 6G wireless communication systems are being developed with the goal of (i) very high data rates per device, (ii) a very large number of connected devices, (iii) global connectivity, (iv) very low latency, (v) reduced energy consumption of battery-free IoT (internet of things) devices, (vi) ultra-reliable connectivity, and (vii) connected intelligence with machine learning capabilities. The vision of 6G systems can be seen in four aspects: intelligent connectivity, deep connectivity, holographic connectivity, and ubiquitous connectivity. Various technologies are being researched in consideration of the requirements for 6G systems, such as a peak data rate of 1 Tbps per device, an end-to-end (E2E) latency of 1ms, a maximum spectrum efficiency of 100 bps / Hz, support for mobility of 1000 km / h, satellite integration, artificial intelligence (AI), autonomous vehicles, extended reality (XR), and haptic communication.

[0004] The technical problem of the present disclosure is to provide a method and apparatus for protecting information regarding access stratum (AS) key derivation in a wireless communication system.

[0005] The technical problems to be solved in this disclosure are not limited to those mentioned above, and other technical problems not mentioned will be clearly understood by those skilled in the art to which this disclosure belongs from the description below.

[0006] A method according to one aspect of the present disclosure may include: receiving a first message containing an updated value of information regarding an access layer (AS) key derivation from a second network node by a first network node; providing an encrypted value of information regarding an AS key derivation to a lower layer entity of the first network node by an upper layer entity of the first network node based on the updated value of information regarding the AS key derivation; and transmitting a second message containing the encrypted value of information regarding the AS key derivation to a terminal by the first network node.

[0007] A method according to a further aspect of the present disclosure may include: receiving a message containing an encrypted value of information regarding an access layer (AS) key derivation from a first network node by a terminal; receiving the encrypted value of the information regarding the AS key derivation from a lower layer of the terminal and decrypting it by an upper layer of the terminal; and encrypting or decrypting one or more of user plane data or control plane messages based on the decrypted information regarding the AS key derivation.

[0008] According to the present disclosure, a method and apparatus for protecting information regarding access stratum (AS) key derivation in a wireless communication system may be provided.

[0009] The effects obtainable from the present disclosure are not limited to those mentioned above, and other unmentioned effects will be clearly understood by those skilled in the art to which the present disclosure belongs from the description below.

[0010] The accompanying drawings, which are included as part of the detailed description to aid in understanding the present disclosure, provide embodiments of the present disclosure and explain the technical features of the present disclosure together with the detailed description.

[0011] FIG. 1 illustrates an exemplary flexible network topology to which some examples of the present disclosure may be applied.

[0012] FIG. 2 illustrates an exemplary communication system to which some examples of the present disclosure may be applied.

[0013] FIG. 3 illustrates an exemplary wireless device to which some examples of the present disclosure may be applied.

[0014] FIG. 4 illustrates an exemplary communication procedure between a first node and a second node to which some examples of the present disclosure may be applied.

[0015] FIG. 5 illustrates an exemplary functional framework for AI operations to which some examples of the present disclosure may be applied.

[0016] FIG. 6 illustrates an example of operations related to AI model training and AI model inference to which some examples of the present disclosure may be applied.

[0017] FIG. 7 illustrates another example of operations related to AI model training and AI model inference to which some examples of the present disclosure may be applied.

[0018] FIG. 8 illustrates another example of operations related to AI model training and AI model inference to which some examples of the present disclosure may be applied.

[0019] FIG. 9 shows an electromagnetic spectrum to which some examples of the present disclosure may be applied.

[0020] FIG. 10 illustrates an exemplary system information transmission / reception procedure to which some examples of the present disclosure may be applied.

[0021] FIG. 11 illustrates an exemplary beam management procedure to which some examples of the present disclosure may be applied.

[0022] FIGS. 12 and FIGS. 13 show examples of NTN scenarios to which some examples of the present disclosure may be applied.

[0023] FIG. 14 shows examples of sensing operations to which some examples of the present disclosure may be applied.

[0024] FIG. 15 shows an example of a 5G system structure to which the present disclosure can be applied.

[0025] FIGS. 16 and FIGS. 17 illustrate an example of a registration procedure to which the present disclosure may be applied.

[0026] FIG. 18 illustrates an example of an authentication procedure start and authentication method selection to which the present disclosure may be applied.

[0027] FIG. 19 is an example of a primary authentication procedure according to one embodiment of the present disclosure.

[0028] FIG. 20 illustrates an example of a 5GS key hierarchy generation to which the present disclosure can be applied.

[0029] FIG. 21 shows an example of a model for handover key chaining to which the present disclosure can be applied.

[0030] FIG. 22 illustrates an example of key handling based on a handover procedure to which the present disclosure may be applied.

[0031] FIG. 23 illustrates an example of a signaling procedure for an LTM to which the present disclosure may be applied.

[0032] FIG. 24 is a drawing for illustrating an example of a method performed by a first network node according to the present disclosure.

[0033] FIG. 25 is a drawing illustrating an example of a method performed by a measuring device according to the present disclosure.

[0034] FIGS. 26 to 28 are drawings illustrating an example of a CU-to-LTM procedure according to the present disclosure.

[0035] FIG. 29 is a diagram showing the operation of the CU and DU on the target base station side and the terminal side by layer according to the present disclosure.

[0036] Hereinafter, preferred embodiments according to the present disclosure will be described in detail with reference to the accompanying drawings. The detailed description disclosed below, together with the accompanying drawings, is intended to describe exemplary embodiments of the present disclosure and is not intended to represent the only embodiment in which the present disclosure may be practiced. The following detailed description includes specific details to provide a complete understanding of the present disclosure. However, those skilled in the art will know that the present disclosure may be practiced without such specific details.

[0037] In some cases, to avoid obscuring the concept of the present disclosure, known structures and devices may be omitted or illustrated in the form of a block diagram focusing on the core functions of each structure and device.

[0038] In the present disclosure, when a component is described as being “connected,” “combined,” or “joined” with another component, this may include not only a direct connection but also an indirect connection in which another component exists between them. Furthermore, in the present disclosure, the terms “comprising” or “having” specify the presence of the mentioned features, steps, actions, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, actions, elements, components, and / or groups thereof.

[0039] In the present disclosure, terms such as "first," "second," etc. are used solely for the purpose of distinguishing one component from another and are not used to limit the components, nor do they limit the order or importance of the components unless specifically stated otherwise. Accordingly, within the scope of the present disclosure, a first component in one embodiment may be referred to as a second component in another embodiment, and likewise, a second component in one embodiment may be referred to as a first component in another embodiment.

[0040] The terms used in this disclosure are for the description of specific embodiments and are not intended to limit the claims. As used in the description of embodiments and the appended claims, the singular form is intended to include the plural form unless the context clearly indicates otherwise.

[0041] In the present disclosure, "A or B" may mean "only A," "only B," or "both A and B." Alternatively, in the present disclosure, "A or B" may be interpreted as "A and / or B." For example, in the present disclosure, "A, B or C" may mean "only A," "only B," "only C," or "any combination of A, B and C."

[0042] A slash ( / ) or a comma used in the present disclosure may mean "and / or." For example, "A / B" may mean "A and / or B." Accordingly, "A / B" may mean "only A," "only B," or "both A and B." For example, "A, B, C" may mean "A, B or C."

[0043] In the present disclosure, "at least one of A and B" may mean "only A," "only B," or "both A and B." Additionally, in the present disclosure, the expressions "at least one of A or B" or "at least one of A and / or B" may be interpreted as synonymous with "at least one of A and B."

[0044] Additionally, in the present disclosure, "at least one of A, B and C" may mean "only A," "only B," "only C," or "any combination of A, B and C." Additionally, "at least one of A, B or C" or "at least one of A, B and / or C" may mean "at least one of A, B and C."

[0045] Additionally, parentheses used in this disclosure may mean "for example." Specifically, when indicated as "control information (PDCCH)," "PDCCH" may be described as an example of "control information." In other words, the "control information" of this disclosure is not limited to "PDCCH," and "PDCCH" may be described as an example of "control information." Furthermore, even when indicated as "control information (i.e., PDCCH)," "PDCCH" may be described as an example of "control information."

[0046] In the following explanation, '...when, if, in case of' can be replaced with '...based on'.

[0047] Technical features described individually within one drawing in this disclosure may be implemented individually or simultaneously.

[0048] In the present disclosure, a terminal or user equipment (UE) may be a portable device and may be a first node that receives a signal from a base station / second node / integrated access backhaul (IAB) node.

[0049] In the present disclosure, the base station (BS, Base Station) may be a second node / IAB node / Transmission-Reception Point (TRP).

[0050] In the present disclosure, a higher layer parameter may be a parameter configured, pre-configured, or pre-defined for a terminal. For example, a base station or network may transmit the higher layer parameter to the terminal. For example, the higher layer parameter may be transmitted via radio resource control (RRC) signaling or medium access control (MAC) signaling.

[0051] In the present disclosure, "set or defined" may be interpreted as being set to a device through predefined signaling (e.g., System Information Block (SIB), MAC, RRC) from a base station or network. In the present disclosure, "set or defined" may be interpreted as being set to a device through separate signaling or being predefined without separate signaling.

[0052] In the present disclosure, transmitting or receiving a channel includes the meaning of transmitting or receiving information or a signal through said channel. For example, transmitting a control channel means transmitting control information or a signal through the control channel. Similarly, transmitting a data channel means transmitting data information or a signal through the data channel.

[0053] The technology described in this disclosure can be used in various wireless communication systems such as CDMA (code division multiple access), FDMA (frequency division multiple access), TDMA (time division multiple access), OFDMA (orthogonal frequency division multiple access), and SC-FDMA (single carrier frequency division multiple access). CDMA can be implemented with wireless technologies such as UTRA (universal terrestrial radio access) or CDMA2000. TDMA can be implemented with wireless technologies such as GSM (global system for mobile communications), GPRS (general packet radio service), and EDGE (enhanced data rates for GSM evolution). OFDMA can be implemented with wireless technologies such as IEEE (institute of electrical and electronics engineers) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802-20, E-UTRA (evolved UTRA), LTE (long term evolution), and 5G NR.

[0054] The technology described in this disclosure can be implemented as 6G wireless technology and applied to various 6G systems. For example, 6G systems may have key factors such as eMBB (enhanced mobile broadband), URLLC (ultra-reliable low latency communications), mMTC (massive machine-type communication), AI (artificial intelligence) integrated communication, tactile internet, high throughput, high network capacity, high energy efficiency, low backhaul and access network congestion, and enhanced data security.

[0055] Network structure

[0056] FIG. 1 illustrates an exemplary flexible network topology to which some examples of the present disclosure may be applied.

[0057] To compensate for incomplete areas of network coverage, a network topology in which the split radio access network (RAN) is configured more flexibly and resiliently may be considered. To this end, various nodes such as integrated access backhaul (IAB) nodes, relays, and radio frequency (RF) repeaters, as exemplified in Fig. 1, may be applied, and a non-terrestrial network (NTN) may be integrated. For example, an IAB node may correspond to a node that provides wireless backhaul. For example, a relay may refer to any intermediate point, and in the case of a sidelink relay where a terminal functions as a relay, it may collectively refer to a terminal-to-network (U2N) relay and a terminal-to-terminal (U2U) relay. For example, an RF repeater may correspond to a node that performs simple signal amplification and forwarding functions, and in the case of a network-controlled repeater, it may adjust transmit / receive settings based on information provided by the network as well as signal amplification and forwarding. For example, NTN nodes can correspond to satellites or aircraft that provide NTN coverage that is difficult for terrestrial networks to provide. In addition to these examples, various intermediate points can be introduced to improve the network topology.

[0058] Referring to FIG. 1, a split RAN can support the division of a base station into one centralized unit (CU) and one or more distributed units (DU). The CU and DU may correspond to logical units. The CU may be further divided into a control plane (CP) portion and one or more user plane (UP) portions. Since a failure in the CU-CP affects not only the CU-UP but also the DU, various intermediate points may be introduced to compensate for this.

[0059] An intermediate point may correspond to a terminal or a base station depending on its relative relationship with other nodes. For example, an IAB node may include a mobile-termination (MT) portion and a DU. The MT may connect the IAB node to a donor node. The DU of the IAB node may serve other terminals or connect to other IAB nodes to provide multi-hop wireless backhaul to terminals. For example, an IAB node may correspond to a base station in its relative relationship with a user-side node and to a terminal in its relative relationship with a network-side node.

[0060] In some examples of the present disclosure, the description of a terminal may apply equally to an intermediate point corresponding to a terminal in relation to a network-side endpoint as well as to a user-side endpoint. Similarly, in some examples of the present disclosure, the description of a base station may apply equally to an intermediate point corresponding to a base station in relation to a user-side endpoint as well as to a network-side endpoint. In most cases where there is no additional description of the operation of three or more subjects, the communication subjects in the present disclosure are briefly described by the term terminal and / or base station (or first node and / or second node), wherein the term terminal and / or base station (or first node and / or second node) is interpreted to include or replace any endpoint or any intermediate point in relation to other nodes.

[0061] As such, in some examples of the present disclosure, for the sake of brevity of description, the subject of the operation may be referred to as a terminal and / or base station (or a first node and / or a second node). Additionally, the term terminal and / or base station (or a first node and / or a second node) may be interpreted or substituted as in the following examples: for example, the terminal (or first node) and the base station (or second node) may correspond to a first endpoint and a second endpoint, respectively; may correspond to an endpoint and an intermediate point, respectively; may correspond to an intermediate point and an endpoint, respectively; or may correspond to a first intermediate point and a second intermediate point, respectively.

[0062] In the present disclosure, there may be no intermediate points between the base station and the terminal, or there may be one or more. If intermediate points exist, the intermediate points may correspond to IAB nodes, relays, RF repeaters, NTN nodes, or nodes supporting other functions. The intermediate points may be nodes with a fixed location or nodes with an indefinite location.

[0063] Systems applicable to the present disclosure

[0064] FIG. 2 illustrates an exemplary communication system to which some examples of the present disclosure may be applied.

[0065] The communication system (100) to which the present disclosure applies includes a wireless device (110), a network device (120), and a network (130). Here, the wireless device (110) refers to a device that performs communication using wireless access technology (e.g., LTE, LTE-A, LTE-A pro, NR, 5G, 5G-A, 6G) and may be referred to as a communication / wireless / 5G / 6G device. Although not limited thereto, the wireless device (110) may include a robot (110a), a vehicle (110b-1, 110b-2), an XR (extended reality) device (110c), a hand-held device (110d), a home appliance (110e), an IoT (Internet of Thing) device (110f), and an AI (artificial intelligence) device / server (110g). For example, the vehicle may include a vehicle equipped with wireless communication capabilities, an autonomous vehicle, a vehicle capable of performing inter-vehicle communication, etc. Here, the vehicle (110b-1, 110b-2) may include an unmanned aerial vehicle (UAV) (e.g., a drone). The XR device (110c) includes an augmented reality (AR) / virtual reality (VR) / mixed reality (MR) device and may be implemented in the form of a head-mounted device (HMD), a head-up display (HUD) equipped in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance, digital signage, a vehicle, a robot, etc. The portable device (110d) may include a smartphone, a smart pad, a wearable device (e.g., a smart watch, smart glasses), a computer (e.g., a laptop, etc.). The home appliance (110e) may include a TV, a refrigerator, a washing machine, etc. The IoT device (110f) may include a sensor, a smart meter, etc. The wireless device (110) may correspond to a terminal (or first node) or an intermediate point.The network device (120) may correspond to a base station (or a second node) or another intermediate point. For example, the network device (120) may also be implemented as a wireless device (110), and a specific wireless device (120a) may operate as a network device (120) to another wireless device (110).

[0066] Wireless devices (110a to 110f) can be connected to a network (130) through a network device (120). AI technology may be applied to the wireless devices (110a to 110f), and the wireless devices (110a to 110f) can be connected to an AI server (110g) through the network (130). The network (130) can be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR) network, or a 6G network. The wireless devices (110a to 110f) may communicate with each other through the network device (120) / network (130), but may also communicate directly (e.g., sidelink communication) without going through the network device (120) / network (130). For example, vehicles (110b-1, 110b-2) can communicate directly (e.g., V2V (vehicle to vehicle) / V2X (vehicle to everything) communication). Also, an IoT device (110f) (e.g., a sensor) can communicate directly with another IoT device (e.g., a sensor) or other wireless devices (110a to 110f).

[0067] Wireless communication / connection (150a, 150b, 150c) can be established between wireless devices (110a to 110f) / network devices (120) and between network devices (120). Here, wireless communication / connection can be established through various wireless access technologies such as uplink / downlink communication (150a), sidelink communication (150b) (or D2D communication), and communication between network devices (150c) (e.g., relay, IAB (integrated access backhaul)). Through wireless communication / connection (150a, 150b, 150c), wireless devices and network devices / wireless devices, and network devices and network devices can transmit / receive wireless signals to / from each other. For example, wireless communication / connection (150a, 150b, 150c) can transmit / receive signals through various physical channels. To this end, based on the various descriptions of the present disclosure, at least some of the following may be performed: a process for setting various configuration information for transmitting / receiving wireless signals, a process for various signal processing (e.g., channel encoding / decoding, modulation / demodulation, resource mapping / demapping, etc.), a resource allocation process, etc.

[0068] Devices applicable to the present disclosure

[0069] FIG. 3 illustrates an exemplary wireless device to which some examples of the present disclosure may be applied.

[0070] Referring to FIG. 3, the wireless device (200) can transmit and receive wireless signals through various wireless access technologies (e.g., LTE, LTE-A, LTE-A pro, NR, 5G, 5G-A, 6G). The wireless device (200) includes at least one processor (202) and at least one memory (204), and may additionally include at least one transceiver (206) and / or at least one antenna (208).

[0071] The processor (202) controls the memory (204) and / or the transceiver (206) and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or sequences of operation disclosed in this document. For example, the processor (202) may process information within the memory (204) to generate a first information / signal and then transmit a wireless signal containing the first information / signal through the transceiver (206). Additionally, the processor (202) may receive a wireless signal containing a second information / signal through the transceiver (206) and then store information obtained from the signal processing of the second information / signal in the memory (204). The memory (204) may be connected to the processor (202) and may store various information related to the operation of the processor (202). For example, memory (204) may store software code containing instructions for performing some or all of the processes controlled by the processor (202) or for performing the descriptions, functions, procedures, proposals, methods, and / or sequences of operation disclosed in this document. Here, the processor (202) and memory (204) may be part of a communication modem / circuit / chip designed to implement wireless communication technology. A transceiver (206) may be connected to the processor (202) and may transmit and / or receive wireless signals through at least one antenna (208). The transceiver (206) may include a transmitter and / or receiver. The transceiver (206) may be interchangeable with an RF (radio frequency) unit. In this disclosure, a wireless device may mean a communication modem / circuit / chip.

[0072] Hereinafter, hardware elements of the wireless device (200) will be described in more detail. Although not limited thereto, at least one protocol layer may be implemented by at least one processor (202). For example, at least one processor (202) may implement at least one layer (e.g., functional layers such as PHY (physical), MAC (media access control), RLC (radio link control), PDCP (packet data convergence protocol), RRC (radio resource control), and SDAP (service data adaptation protocol). At least one processor (202) may generate at least one PDU (Protocol Data Unit) and / or at least one SDU (service data unit) according to the descriptions, functions, procedures, proposals, methods and / or operation sequences disclosed in this document. At least one processor (202) may generate messages, control information, data, or information according to the descriptions, functions, procedures, proposals, methods and / or operation sequences disclosed in this document. At least one processor (202) may generate a signal (e.g., a baseband signal) including a PDU, SDU, message, control information, data, or information according to the functions, procedures, proposals, and / or methods disclosed in this document and provide it to at least one transceiver (206). At least one processor (202) may receive a signal (e.g., a baseband signal) from at least one transceiver (206) and may obtain a PDU, SDU, message, control information, data, or information according to the descriptions, functions, procedures, proposals, methods, and / or operation sequences disclosed in this document.

[0073] At least one processor (202) may be referred to as a controller, microcontroller, microprocessor, or microcomputer. At least one processor (202) may be implemented by hardware, firmware, software, or a combination thereof. For example, at least one application-specific integrated circuit (ASIC), at least one digital signal processor (DSP), at least one digital signal processing device (DSPD), at least one programmable logic device (PLD), or at least one field programmable gate array (FPGA) may be included in at least one processor (202). The descriptions, functions, procedures, proposals, methods, and / or operation sequences disclosed in this document may be implemented using firmware or software, and the firmware or software may be implemented to include modules, procedures, functions, etc. Firmware or software configured to perform the descriptions, functions, procedures, proposals, methods, and / or operation sequences disclosed in this document may be included in at least one processor (202) or stored in at least one memory (204) and driven by at least one processor (202). The descriptions, functions, procedures, proposals, methods, and / or flowcharts disclosed in this document may be implemented using firmware or software in the form of code, instructions, and / or sets of instructions.

[0074] At least one memory (204) may be connected to at least one processor (202) and may store various forms of data, signals, messages, information, programs, codes, instructions, and / or commands. At least one memory (204) may be composed of ROM (read-only memory), RAM (random access memory), EPROM (erasable programmable read-only memory), flash memory, hard drive, registers, cache memory, computer read storage media, and / or combinations thereof. At least one memory (204) may be located inside and / or outside of at least one processor (202). Additionally, at least one memory (204) may be connected to at least one processor (202) via various technologies, such as wired or wireless connections.

[0075] At least one transceiver (206) may transmit user data, control information, wireless signals / channels, etc., as mentioned in the methods and / or operation flowcharts, etc. of this document to at least one other device. At least one transceiver (206) may receive user data, control information, wireless signals / channels, etc., as mentioned in the descriptions, functions, procedures, proposals, methods and / or operation flowcharts, etc. disclosed in this document from at least one other device. For example, at least one transceiver (206) may be connected to at least one processor (202) and may transmit and receive wireless signals. For example, at least one processor (202) may control at least one transceiver (206) to transmit user data, control information, or wireless signals to at least one other device. Additionally, at least one processor (202) may control at least one transceiver (206) to receive user data, control information, or wireless signals from at least one other device. Additionally, at least one transceiver (206) may be connected to at least one antenna (208), and at least one transceiver (206) may be configured to transmit and receive user data, control information, wireless signals / channels, etc., as described in the descriptions, functions, procedures, proposals, methods, and / or operation sequence diagrams disclosed in this document through at least one antenna (208). In this document, at least one antenna may be a plurality of physical antennas or a plurality of logical antennas (e.g., antenna ports). At least one transceiver (206) may convert the received wireless signals / channels, etc., from RF band signals to baseband signals in order to process the received user data, control information, wireless signals / channels, etc., using at least one processor (202).At least one transceiver (206) can convert user data, control information, wireless signals / channels, etc. processed using at least one processor (202) from a baseband signal to an RF band signal. To this end, at least one transceiver (206) may include an (analog) oscillator and / or filter.

[0076] The components of the wireless device described with reference to FIG. 3 may be referred to by other terms in terms of their function. For example, the processor (202) may be referred to as the control unit, the transceiver (206) as the communication unit, and the memory (204) as the storage unit. In some cases, the communication unit may be used to mean at least a part of the processor (202) and the transceiver (206).

[0077] The structure of the wireless device described with reference to FIG. 3 can be understood as the structure of at least part of various devices. For example, the structure of the wireless device illustrated in FIG. 3 may be at least part of the various devices described with reference to FIG. 2 (e.g., robot (110a), vehicle (110b-1, 110b-2), XR device (110c), portable device (110d), home appliance (110e), IoT device (110f), AI device / server (110g)). Furthermore, according to various embodiments, the device may include other components in addition to the components illustrated in FIG. 3.

[0078] For example, the device may be a portable device such as a smartphone, smartpad, wearable device (e.g., smart watch, smart glasses), or portable computer (e.g., laptop, etc.). In this case, the device may further include at least one of a power supply unit that supplies power and includes a wired / wireless charging circuit, a battery, etc., an interface unit that includes at least one port for connection with another device (e.g., an audio input / output port, a video input / output port), and an input / output unit for inputting and outputting video information / signals, audio information / signals, data, and / or information input by a user.

[0079] For example, the device may be a mobile device such as a mobile robot, vehicle, train, manned / unmanned aerial vehicle (AV), or ship. In this case, the device may further include at least one of a drive unit comprising at least one of an engine, motor, power train, wheel, brake, and steering device of the device; a power supply unit that supplies power and includes a wired / wireless charging circuit, battery, etc.; a sensor unit that senses state information, environmental information, and user information of the device or its surroundings; an autonomous driving unit that performs functions such as path maintenance, speed control, and destination setting; and a position measurement unit that acquires position information of the moving body through a GPS (global positioning system) and various sensors.

[0080] For example, the device may be an XR device such as an HMD, a HUD (head-up display) equipped in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance, digital signage, a vehicle, a robot, etc. In this case, the device may further include at least one of a power supply unit that supplies power and includes a wired / wireless charging circuit, a battery, etc., an input / output unit that acquires control information, data, etc. from the outside and outputs a generated XR object, and a sensor unit that senses state information, environment information, and user information of the device or the surroundings of the device.

[0081] For example, the device may be a robot that can be classified into industrial, medical, household, military, etc., depending on the purpose or field of use. In this case, the device may further include at least one of a sensor unit that senses state information, environmental information, and user information of the device or its surroundings, and a drive unit that performs various physical actions, such as moving robot joints.

[0082] For example, the device may be an AI device such as a TV, projector, smartphone, PC, laptop, digital broadcasting terminal, tablet PC, wearable device, set-top box (STB), radio, washing machine, refrigerator, digital signage, robot, vehicle, etc. In this case, the device may further include at least one of an input unit that acquires various types of data from the outside, an output unit that generates output related to sight, hearing, or touch, a sensor unit that senses state information, environmental information, and user information of the device or its surroundings, and a training unit that learns a model composed of an artificial neural network using training data.

[0083] The structure of the wireless device illustrated in FIG. 3 may be understood as part of a terminal (or first node), or part of an intermediate point, or part of a base station (or second node). If the device illustrated in FIG. 3 is a base station (or second node), the device may further include a wired transceiver for front haul and / or back haul communication. If the front haul and / or back haul communication is based on wireless communication, at least one transceiver (206) illustrated in FIG. 3 is used for front haul and / or back haul communication, and a wired transceiver may not be included.

[0084] Communication procedures

[0085] FIG. 4 illustrates an exemplary communication procedure between a first node and a second node to which some examples of the present disclosure may be applied.

[0086] FIG. 4 illustrates the operation of a first node (110) (e.g., a terminal) and a second node (120) (e.g., a base station) transmitting and / or receiving data, and the operation performed prior to this.

[0087] In step S101, the first node (110) and the second node (120) can perform synchronization. For example, the terminal (110) performs an initial cell search operation. Specifically, the terminal (110) can detect at least one synchronization signal transmitted from the base station (120) according to a predefined rule. Here, the synchronization signal may include a plurality of synchronization signals (e.g., a primary synchronization signal, a secondary synchronization signal) classified according to structure or use. Through this, the terminal (110) can identify the boundaries of the frame, subframe, slot, and / or symbol of the base station (120) and obtain information about the base station (120) (e.g., a cell identifier).

[0088] In step S103, the first node (110) can obtain system information transmitted from the second node (120). For example, the system information is information related to the attributes, characteristics, and / or capabilities of the base station (120) required to connect to the base station (120) and use the service, and can be classified according to content (e.g., whether it is essential for connection), transmission structure (e.g., the channel used, whether it is provided on-demand), etc., and can be classified, for example, into a master information block (MIB) and a system information block (SIB). If necessary, the terminal (110) may transmit a signal requesting the system information prior to receiving the system information. Such request and provision of system information may be performed after a random access procedure described later.

[0089] In step S105, the first node (110) and the second node (120) can perform a random access procedure. For example, the terminal (110) can transmit and / or receive at least one message for a random access procedure (e.g., a random access preamble, a RAR (random access response) message, etc.) based on information related to the random access channel of the base station (120) obtained through system information (e.g., channel location, channel structure, structure of a supported preamble, etc.). For example, the terminal (110) may transmit a preamble (e.g., message 1 (MSG1)) through a random access channel, receive a random access response (RAR) message (e.g., message 2 (MSG2)), transmit a message (e.g., message 3 (MSG3)) containing information related to the terminal (110) (e.g., identification information) to the base station (120) using scheduling information included in the RAR message, and receive a message (e.g., message 4 (MSG4)) for contention resolution and / or connection establishment. As another example, MSG1 and MSG3 may be transmitted and received as a single message (e.g., message A (MSG A), or MSG2 and MSG4 may be transmitted and received as a single message (e.g., message B (MSG B).

[0090] In step S107, the first node (110) and the second node (120) can perform signaling of control information. For example, the control information may be defined in various layers, such as a layer that controls the connection (e.g., a radio resource control (RRC) layer), a layer that handles mapping between logical channels and transmission channels (e.g., a media access control (MAC) layer), and a layer that handles physical channels (e.g., a physical (PHY) layer). For example, the terminal (110) and the base station (120) may perform at least one of signaling to establish a connection, signaling to determine settings related to communication, and signaling to indicate allocated resources.

[0091] In step S109, the first node (110) and the second node (120) can transmit and / or receive data. For example, the terminal (110) and the base station (120) can process data based on the signaling of control information and transmit and / or receive data. For example, when transmitting data, the terminal (110) or the base station (120) can perform at least one of channel encoding, rate matching, scrambling, constellation mapping, layer mapping, waveform modulation, antenna mapping, and resource mapping on the information bits. For example, when receiving data, the terminal (110) or the base station (120) can perform at least one of extracting a signal from a resource, antenna-specific waveform demodulation, signal placement considering layer mapping, constellation demapping, descrambling, and channel decoding.

[0092] 6G System Core Technology

[0093] As core implementation technologies for 6G systems, technologies such as artificial intelligence (AI), THz (Terahertz) communication, optical wireless technology, free space optics (FSO) backhaul network, multiple input multiple output (MIMO) technology, blockchain, 3D networking, quantum communication, unmanned aerial vehicles, cell-free communication, wireless information and energy transfer (WIET), integration of sensing and communication, integration of access backhaul networks, holographic beamforming, big data analysis, and large intelligent surface (LIS) can be adopted.

[0094] artificial intelligence

[0095] The introduction of AI into communications can streamline and enhance real-time data transmission. AI can determine how complex target tasks are performed using numerous analyses. AI can increase efficiency and reduce processing latency. Time-consuming tasks such as handover, network selection, and resource scheduling can be performed instantly using AI. AI can also play a significant role in machine-to-machine (M2M), machine-to-human, and human-to-machine communication. Furthermore, AI can enable rapid communication in Brain-Computer Interfaces (BCI). AI-based communication systems can be supported by metamaterials, intelligent structures, intelligent networks, intelligent devices, intelligent cognitive radios, self-sustaining wireless networks, and machine learning.

[0096] FIG. 5 illustrates an exemplary functional framework for AI operations to which some examples of the present disclosure may be applied.

[0097] Below, to provide a more specific explanation of AI (or AI / ML (machine learning)), terms can be defined as follows.

[0098] - Data collection: Data collected from network nodes, management entities, or terminals, serving as a basis for AI model training, data analysis, and inference.

[0099] - AI model: A data-driven algorithm that applies AI technology to generate a set of outputs containing predictive information and / or decision parameters based on a set of inputs.

[0100] - AI / ML Training: An online or offline process of training an AI model by learning features and patterns that best represent data and acquire an AI / ML model trained for inference.

[0101] - AI / ML Inference: A process of making predictions or deriving decisions based on collected data and an AI model using a trained AI model.

[0102] Referring to FIG. 5, the data collection function (10) is a function that collects input data and provides processed input data to the model training function (20) and the model inference function (30).

[0103] Examples of input data may include measurements from terminals or other network entities, feedback from actors, and outputs from AI models.

[0104] The data collection function (10) performs data preparation based on input data and provides the input data processed through data preparation. Here, the data collection function (10) does not perform specific data preparation (e.g., data pre-processing and cleaning, forming and transformation) for each AI algorithm, and can perform data preparation common to AI algorithms.

[0105] After the data preparation process is performed, the data collection function (10) can provide training data (11) to the model training function (20) and provide inference data (12) to the model inference function (30). Here, the training data (11) corresponds to data required as input for the AI ​​model training function (20), and the inference data (12) corresponds to data required as input for the AI ​​model inference function (30).

[0106] The data collection function (10) may be performed by a single entity (e.g., terminal, RAN node, network node, etc.) but may also be performed by multiple entities. In this case, training data (11) and inference data (12) from multiple entities may be provided to the model training function (20) and the model inference function (30), respectively.

[0107] The model training function (20) may correspond to a function that performs AI model training, validation, and testing, which can generate model performance metrics as part of the AI ​​model testing procedure. If necessary, the model training function (20) may also be responsible for data preparation (e.g., data pre-processing and cleaning, formatting and transformation, etc.) based on training data (11) provided by the data collection function (10).

[0108] Here, model deployment / update (13) can be used to initially deploy a trained, validated, and tested AI model to the model inference function (30) or to provide an updated model to the model inference function (30).

[0109] The model inference function (30) may correspond to a function that provides an AI model inference output (16) (e.g., a prediction or a decision). The model inference function (30) may provide model performance feedback (14) to the model training function (20) where applicable. Additionally, the model inference function (30) may be responsible for data preparation (e.g., data pre-processing and cleaning, formatting and transformation, etc.) based on the inference data (12) provided by the data collection function (10) if necessary.

[0110] Here, output (16) refers to the inference output of an AI model generated by the model inference function (30), and the details of the inference output may vary depending on the use case.

[0111] Model performance feedback (14) can be used to monitor the performance of the AI ​​model if available, and this feedback may be omitted.

[0112] The actor function (40) is a function that receives an output (16) from the model inference function (30) and triggers or performs a corresponding operation / action. The actor function (40) can trigger an operation / action on another entity (e.g., one or more terminals, one or more RAN nodes, one or more network nodes, etc.) or on itself.

[0113] Feedback (15) can be used to derive training data (11) and inference data (12), or to monitor the performance of the AI ​​model, the impact on the network, etc.

[0114] Meanwhile, the definitions of training, validation, and testing in data sets used in AI / ML can be distinguished as follows.

[0115] - Training data: Refers to the dataset used to train a model.

[0116] - Validation data: This refers to a dataset used to validate a model that has already been trained. Validation data typically refers to a dataset used to prevent overfitting of the training dataset. Additionally, validation data can refer to a dataset used to select the best model among the various models trained during the learning process. Therefore, validation can be viewed as a type of training.

[0117] - Test data: Refers to the dataset for final evaluation. This data is unrelated to training.

[0118] For example, within the entire dataset, training data and validation data can be divided in a ratio of approximately 8:2 or 7:3. Alternatively, within the entire dataset, training data:validation data:test data can be divided in a ratio of 6:2:2.

[0119] Depending on whether the base station and the terminal possess the capability for AI / ML functions, the cooperation level can be defined as follows, and variations resulting from the combination of multiple levels below or the separation of any one level are also possible.

[0120] Category 0a: This corresponds to a no collaboration framework. In this case, the AI / ML algorithm is based on pure implementation and may not require changes to the wireless interface.

[0121] Category 0b: Corresponds to a framework that involves a wireless interface modified to fit efficient implementation-based AI / ML algorithms but lacks cooperation.

[0122] Category 1: This applies to cases involving inter-node support to improve the AI / ML algorithms of each node. For example, it applies when a terminal receives support from a base station (for training, adaptation, etc.), and vice versa. At this level, model exchange between network nodes is not required.

[0123] Category 2: This applies to cases where joint ML operations between a terminal and a base station can be performed. This level requires AI / ML model commands or exchanges between network nodes.

[0124] The functions exemplified in Figure 5 above may be implemented at RAN nodes (e.g., base station, TRP, base station CU, etc.), network nodes, network operator's OAM (operation administration maintenance), or terminals.

[0125] Alternatively, two or more entities among a RAN, a network node, a network operator's OAM, or a terminal may cooperate to implement the functions exemplified in FIG. 5. For example, one entity may perform some of the functions of FIG. 5, and another entity may perform the remaining functions. As such, some of the functions exemplified in FIG. 5 are performed by a single entity (e.g., a terminal, a RAN node, a network node, etc.), the transmission / provision of data / information between each function may be omitted. For example, if the model training function (20) and the model inference function (30) are performed by the same entity, the transmission / provision of model distribution / update (13) and model performance feedback (14) may be omitted.

[0126] Alternatively, any one of the functions exemplified in FIG. 5 may be performed by two or more entities among the RAN, network node, network operator's OAM, or terminal in collaboration. This may be referred to as a split AI operation.

[0127] FIG. 6 illustrates an example of operations related to AI model training and AI model inference to which some examples of the present disclosure may be applied.

[0128] For example, the AI ​​model training function can be performed by network nodes (e.g., core network nodes, network operator's OAM, etc.), and the AI ​​model inference function can be performed by RAN nodes (e.g., base station, TRP, base station's CU, etc.).

[0129] Step 1: RAN Node 1 and RAN Node 2 can transmit input data (e.g., training data) for training an AI model to a network node. Here, RAN Node 1 and RAN Node 2 can also transmit data collected from terminals to the network node (e.g., terminal measurements related to RSRP (reference signal received power), RSRQ (reference signal received quality), and SINR (signal to interference-plus-noise ratio) of the serving cell and neighboring cells, terminal location, speed, etc.).

[0130] Step 2: Network nodes can train AI models using the received training data.

[0131] Step 3: The network node can distribute / update the AI ​​model to RAN Node 1 and / or RAN Node 2. RAN Node 1 (and / or RAN Node 2) may also continue model training based on the received AI model.

[0132] For the sake of convenience of explanation, it is assumed that the AI ​​model was deployed / updated only to RAN Node 1.

[0133] Step 4: RAN Node 1 can receive input data (e.g., inference data) for AI model inference from the terminal and RAN Node 2.

[0134] Step 5: RAN Node 1 can perform AI model inference using the received inference data to generate output data (e.g., prediction or decision).

[0135] Step 6: If applicable, RAN node 1 can send model performance feedback to network nodes.

[0136] Step 7: RAN Node 1, RAN Node 2, and the terminal (or 'RAN Node 1 and the terminal', or 'RAN Node 1 and RAN Node 2') can perform an action based on the output data. For example, in the case of a load balancing action, the terminal may move from RAN Node 1 to RAN Node 2.

[0137] Step 8: RAN Node 1 and RAN Node 2 can transmit feedback information to network nodes.

[0138] FIG. 7 illustrates another example of operations related to AI model training and AI model inference to which some examples of the present disclosure may be applied.

[0139] For example, both AI model training and AI model inference functions can be performed by RAN nodes (e.g., base station, TRP, base station's CU, etc.).

[0140] Step 1: The terminal and RAN node 2 can transmit input data (e.g., training data) for training an AI model to RAN node 1.

[0141] Step 2: RAN Node 1 can train an AI model using the received training data.

[0142] Step 3: RAN Node 1 can receive input data (e.g., inference data) for AI model inference from the terminal and RAN Node 2.

[0143] Step 4: RAN Node 1 can perform AI model inference using the received inference data to generate output data (e.g., prediction or decision).

[0144] Step 5: RAN Node 1, RAN Node 2, and the terminal (or 'RAN Node 1 and the terminal', or 'RAN Node 1 and RAN Node 2') can perform an action based on the output data. For example, in the case of a load balancing action, the terminal may move from RAN Node 1 to RAN Node 2.

[0145] Step 6: RAN Node 2 can send feedback information to RAN Node 1.

[0146] FIG. 8 illustrates another example of operations related to AI model training and AI model inference to which some examples of the present disclosure may be applied.

[0147] For example, the AI ​​model training function may be performed by a RAN node (e.g., base station, TRP, base station CU, etc.), and the AI ​​model inference function may be performed by a terminal.

[0148] Step 1: A terminal can transmit input data (e.g., training data) for training an AI model to a RAN node. Here, the RAN node can collect data (e.g., terminal measurements related to RSRP, RSRQ, SINR of the serving cell and neighboring cells, terminal location, velocity, etc.) from various terminals and / or other RAN nodes.

[0149] Step 2: The RAN node can train an AI model using the received training data.

[0150] Step 3: The RAN node can distribute / update the AI ​​model to the terminal. The terminal may also continue model training based on the received AI model.

[0151] Step 4: Input data (e.g., inference data) for AI model inference can be received from terminals and RAN nodes (and / or other terminals).

[0152] Step 5: The terminal can perform AI model inference using the received inference data to generate output data (e.g., prediction or decision).

[0153] Step 6: If applicable, the terminal can transmit model performance feedback to the RAN node.

[0154] Step 7: The terminal and the RAN node can perform actions based on the output data.

[0155] Step 8: The terminal can transmit feedback information to the RAN node.

[0156] THz communication

[0157] Data transmission rates can be increased by expanding bandwidth. This can be achieved by using sub-THz communication with wide bandwidth and applying advanced large-scale MIMO technology. THz waves, also known as sub-millimeter radiation, generally refer to a frequency band between 0.1 THz and 10 THz with corresponding wavelengths ranging from 0.03 mm to 3 mm. The 100 GHz–300 GHz band range (sub-THz band) is considered the primary portion of the THz band for cellular communication. Adding the sub-THz band to the mmWave band increases 6G cellular communication capacity. Among the defined THz bands, the 300 GHz–3 THz band is located in the far-infrared (IR) frequency band. Although the 300 GHz–3 THz band is part of the broadband, it lies at the boundary of the broadband and immediately following the RF band. Therefore, this 300 GHz–3 THz band exhibits similarities to RF.

[0158] FIG. 9 shows an electromagnetic spectrum to which some examples of the present disclosure may be applied.

[0159] Key characteristics of THz communication include (i) widely available bandwidth to support very high data transmission rates, and (ii) high path loss occurring at high frequencies (highly directional antennas are indispensable). The narrow beam width generated by highly directional antennas reduces interference. The small wavelength of THz signals allows a much larger number of antenna elements to be integrated into devices and BSs operating in this band. This enables the use of advanced adaptive array technologies that can overcome range limitations.

[0160] When transmitting system information (e.g., MIB) of a cell in the THz frequency band, it can be inefficient because, in the case of high frequency bands, beam sweeping must be performed more frequently to cover the entire area of ​​the cell as the beam width becomes narrower. In particular, transmitting system information using this method is even more inefficient when there are not many users in the cell.

[0161] FIG. 10 illustrates an exemplary system information transmission / reception procedure to which some examples of the present disclosure may be applied.

[0162] The example of FIG. 10 is applicable not only to THz communication environments but also to 6G communication environments where THz communication is not applied. In addition, the procedure exemplified in FIG. 10 can be combined with various embodiments of the present disclosure described below. For example, embodiments described below can be performed based on system information obtained by the procedure exemplified in FIG. 10.

[0163] In step S1010, the second node (120) (e.g., a base station) can transmit system information of cell #1 through cell #2. For example, the base station provides at least two cells, cell #1 uses a THz frequency band, and cell #2 uses a frequency band other than the THz frequency band. Here, the system information may include at least one of a system frame number (SFN) generated at a higher layer, a PDCCH configuration for SIB1, cell barring, cell re-selection, and subcarrier spacing, and may include at least one of a synchronization signal / PBCH (physical broadcast channel) block index generated at a physical layer. To this end, as an example, cell #1 and cell #2 may have a secondary cell and primary cell relationship.

[0164] In step S1030, the first node (110) (e.g., a terminal) can acquire synchronization for cell #1. Synchronization can be acquired by detecting a synchronization signal. Generally, synchronization is acquired prior to receiving system information, but since the system information of cell #1 is received in cell #2, the acquisition of synchronization for cell #1 can be performed after receiving system information. For example, the terminal can acquire synchronization based on system information. Alternatively, the acquisition of synchronization may be performed prior to step S1010.

[0165] In step S1050, the first node (110) may transmit a signal to connect to cell #1. For example, the signal may include a random access preamble. The structure of such a signal and the resource for transmitting the signal (e.g., a channel) may be identified through system information. Subsequently, in step S1070, the first node (110) and the second node (120) may perform a connection procedure to cell #1 and perform communication.

[0166] The procedure described with reference to FIG. 10 may be performed when the first node (110) first connects to cell #1 of the second node (120). Alternatively, a similar procedure may be performed when the first node (110) handovers to cell #1 of the second node (120). However, in the case of a handover, the system information of cell #1 may be received from a cell of a different base station other than cell #2 of the second node (120).

[0167] Communication in the THz band is expected to experience severe path loss, and to overcome this, terminals and base stations may be required to use very sharp beams. The use of sharp beams implies that terminals and base stations must perform beam control in addition to beamforming, meaning that a very large number of beams are utilized. Consequently, aligning the transmit and receive beams between the base station and the terminal takes a very long time. Furthermore, if the beam alignment between the base station and the terminal is disrupted due to the movement of the terminal, time is frequently required to realign the beams, which may lead to link instability.

[0168] FIG. 11 illustrates an exemplary beam management procedure to which some examples of the present disclosure may be applied.

[0169] Figure 11 illustrates an example of a procedure for searching and / or selecting beams for THz communication, but this procedure is not limited to a THz environment and can also be applied in a 6G communication environment where THz communication is not applied.

[0170] Here, the term "beam" can be interpreted as other terms having equivalent technical meanings capable of distinguishing beams, such as "spatial domain filter," "spatial domain transmit filter," "spatial domain receive filter," reference signal (RS) resources for distinguishing beams, and SSB index.

[0171] In step S1110, the second node (120) (e.g., base station) may set resources for beam management to the first node (110) (e.g., terminal). Here, the resources may include at least one of time-frequency resources, channels, and spatial resources (e.g., antenna ports). For example, the base station may utilize a beam search signal (BSS) that is transmitted spatially separated from the existing downlink signal / channel for beam search. Here, the BSS may be transmitted based on a dedicated port for beam search. The dedicated port may be a port different from the port used for transmitting the existing downlink signal / channel (e.g., SSB, PDSCH (physical downlink shared channel), etc.). BSS is a term defined for convenience of explanation, and the technical concept according to the present embodiment is not limited to the term BSS itself. For example, a signal transmitted based on a dedicated port defined / set for beam search may be included in the technical concept according to the present embodiment.

[0172] In step S1130, the second node (120) (e.g., a base station) transmits measurement signals using multiple transmission beams. For example, the measurement signals may include at least one of a reference signal and a synchronization signal. At this time, the measurement signals may be transmitted as many times as the number of beams requiring measurement, and may be transmitted using a multi-beam transmission method that forms multiple beams simultaneously to reduce sweeping time. Here, multi-beam transmission may be performed based on at least one of a multi-panel, a sub-array, or a true time delay (TTD).

[0173] In step S1050, the first node (110) (e.g., a terminal) may transmit a feedback signal to the second node (120) (e.g., a base station). The feedback signal may indicate at least one beam selected by the terminal. The terminal may select at least one preferred beam based on the measurement signals received in step S1030.

[0174] In step S1070, the first node (110) and the second node (120) can perform communication. For example, the second node (120) can perform transmission to the first node (110) using the receiving beam of the first node (110) selected in step S1050. If channel reciprocity is established, the transmission beam of the first node (110) can also be determined through steps S1030 and S1050, so the transmission operation from the first node (110) can also be performed using a beam that has a reciprocity relationship with the beam selected in step S1050. If channel reciprocity is not established, a procedure including the transmission of measurement signal(s) by the first node (110) and the transmission of feedback signal(s) by the second node (120) may be performed first to determine the transmission beam of the first node (110).

[0175] Non-terrestrial networks (NTN)

[0176] FIGS. 12 and FIGS. 13 show examples of NTN scenarios to which some examples of the present disclosure may be applied.

[0177] NTN can represent a network or network segment that uses RF (radio frequency) resources mounted on a satellite (or UAS (unmanned aerial system) platform).

[0178] Figure 12 shows an example of a typical scenario of an NTN based on a transparent payload, and Figure 13 shows an example of a typical scenario of an NTN based on a regenerative payload.

[0179] Referring to FIG. 12, the satellite (or UAS platform) can establish a service link with a terminal. The satellite (or UAS platform) can be connected to a gateway via a feeder link. The satellite can be connected to a data network via the gateway. A beam footprint may refer to an area where signals transmitted by the satellite can be received.

[0180] Referring to FIG. 13, a satellite (or UAS platform) can establish a service link with a terminal. The satellite (or UAS platform) connected to the terminal can be connected to another satellite (or UAS platform) via inter-satellite links (ISL). Another satellite (or UAS platform) can be connected to a gateway via a feeder link. Based on a regenerated payload, the satellite can be connected to a data network via another satellite and a gateway. If no ISL exists between the satellite and another satellite, a feeder link between the satellite and the gateway may be required.

[0181] FIGS. 12 and 13 are merely examples of NTN scenarios, and NTN can be implemented based on various scenarios. For example, a satellite (or UAS platform) can implement a transparent or regenerative (with on-board processing) payload. For example, a satellite (or UAS platform) can generate multiple beams across a designated service area depending on the field of view of the satellite (or UAS platform). For example, the field of view of the satellite (or UAS platform) may vary depending on the on-board antenna diagram and the minimum elevation angle.

[0182] For example, the transparent payload may include radio frequency filtering, frequency conversion, and amplification. Therefore, the waveform signal repeated by the payload may not be altered.

[0183] For example, the regeneration payload may include radio frequency filtering, frequency conversion and amplification, demodulation / decoding, switching and / or routing, and coding / modulation. For example, the regeneration payload may be substantially the same as carrying all or part of the base station functions on a satellite (or UAS platform).

[0184] Integrated Sensing and Communication (ISAC)

[0185] Wireless sensing is a technology that utilizes radio frequencies to determine the instantaneous linear velocity, angle, distance (or range) of an object, thereby obtaining information about the characteristics of the environment and / or objects within that environment. Since radio frequency sensing capabilities do not require connecting to objects via devices within a network, they can provide services for determining object locations without the need for devices. The ability to obtain range, velocity, and angle information from radio frequency signals can provide a wide range of new functions, such as various object detection and recognition (e.g., vehicles, humans, animals, UAVs), as well as high-precision localization, tracking, and activity recognition. Wireless sensing services can provide information to various industries (e.g., unmanned aerial vehicles, smart homes, V2X, factories, railways, public safety, etc.) that enable applications such as intruder detection, assisted vehicle steering and navigation, trajectory tracking, collision avoidance, traffic management, and health and traffic management. In some cases, wireless sensing may utilize non-3GPP type sensors (e.g., radar, cameras) to further support 3GPP-based sensing. For example, the operation of a wireless sensing service, such as sensing operations, may depend on the transmission, reflection, and scattering processing of wireless sensing signals. Therefore, wireless sensing can provide an opportunity to enhance existing communication systems from communication networks to wireless communication and sensing networks.

[0186] FIG. 14 shows examples of sensing operations to which some examples of the present disclosure may be applied.

[0187] Specifically, FIG. 14(a) illustrates an example of monostatic sensing operation using a sensing receiver and a sensing transmitter located at the same position. FIG. 14(b) illustrates an example of bistatic sensing operation using a sensing receiver and a sensing transmitter located at separate positions. A sensing receiver receives a signal that is reflected or scattered by a sensing object from a sensing signal transmitted from a sensing transmitter, and can extract or acquire sensing data based on the received signal. A sensing result can be generated or determined through appropriate processing of this sensing data. The sensing result can be provided to a trusted third-party entity or service outside the 3GPP system via an entity or service within the 3GPP system.

[0188] Network System Architecture

[0189] FIG. 15 shows an example of a 5G system structure to which the present disclosure can be applied.

[0190] The 5G system (5GS) structure may include one or more of the following network functions (NF).

[0191] - AUSF (Authentication Server Function)

[0192] -AMF (Access and Mobility Management Function)

[0193] - DN (Data Network), for example, operator services, internet access, or third-party services

[0194] - USDF (Unstructured Data Storage Function)

[0195] - NEF (Network Exposure Function)

[0196] - I-NEF (Intermediate NEF)

[0197] - NRF (Network Repository Function)

[0198] - NSSF (Network Slice Selection Function)

[0199] - PCF (Policy Control Function)

[0200] - SMF (Session Management Function)

[0201] - UDM (Unified Data Management)

[0202] - UDR (Unified Data Repository)

[0203] - UPF (User Plane Function)

[0204] - UCMF (UE radio Capability Management Function)

[0205] - AF (Application Function)

[0206] - UE (User Equipment)

[0207] - (R)AN ((Radio) Access Network)

[0208] - 5G-EIR (5G-Equipment Identity Register)

[0209] - NWDAF (Network Data Analytics Function)

[0210] - CHF (CHarging Function)

[0211] 또한, 5GS에서 다음과 같은 네트워크 기능이 더 고려될 수 있다.

[0212] - N3IWF (Non-3GPP InterWorking Function)

[0213] - TNGF (Trusted Non-3GPP Gateway Function)

[0214] - W-AGF (Wireline Access Gateway Function)

[0215] Figure 15 shows the 5G system structure in a non-roaming case using a reference point representation that shows how various network functions interact with each other.

[0216] In the example of Fig. 15, UDSF, NEF, and NRF are not shown, but all shown network functions can interact with UDSF, UDR, NEF, and NRF as needed.

[0217] For clarity, the connection between UDR and other NFs (e.g., PCF) is not shown in FIG. 15. For clarity, the connection between NWDAF and other NFs (e.g., PCF) is not shown in FIG. 15.

[0218] The 5G system architecture includes the following reference points.

[0219] - N1: Reference point between UE and AMF.

[0220] - N2: Reference point between (R)AN and AMF.

[0221] - N3: Reference point between (R)AN and UPF.

[0222] - N4: Reference point between SMF and UPF.

[0223] - N6: Reference point between UPF and the data network.

[0224] - N9: Reference point between two UPFs.

[0225] The following reference points show the interactions that exist between the NF services of NF.

[0226] - N5: Reference point between PCF and AF.

[0227] - N7: Reference point between SMF and PCF.

[0228] - N8: Reference point between UDM and AMF.

[0229] - N10: Reference point between UDM and SMF.

[0230] - N11: Reference point between AMF and SMF.

[0231] - N12: Reference point between AMF and AUSF.

[0232] - N13: Reference point between UDM and AUSF.

[0233] - N14: Reference point between two AMFs.

[0234] - N15: Reference point between PCF and AMF for non-roaming scenarios, reference point between PCF and AMF of the visited network for roaming scenarios.

[0235] - N16: Reference point between two SMFs (in the case of roaming, between the SMF of the visited network and the SMF of the home network)

[0236] - N22: Reference point between AMF and NSSF.

[0237] In some cases, two NFs may need to be connected to each other to service the UE.

[0238] Network registration procedure

[0239] FIGS. 16 and FIGS. 17 illustrate an example of a registration procedure to which the present disclosure may be applied.

[0240] A UE can register with a network to receive services, enable mobility tracking, and enable reachability. A UE can initiate the registration process using one of the following registration types.

[0241] - Initial registration for the 5GS; or

[0242] - Mobility registration update; or

[0243] - Periodic registration update; or

[0244] - Emergency registration

[0245] General registration procedures, such as the examples in FIGS. 16 and 17, can be applied to all of the aforementioned registration procedures. For example, in periodic registration updates, it may not be necessary to include all parameters used in other registration procedures.

[0246] A general registration procedure, such as the examples in FIGS. 16 and 17, may be used when a UE is registered to 3GPP access when it is already registered to non-3GPP access, and vice versa. To register to 3GPP access when a UE is already registered to a non-3GPP access scenario, an AMF change may be required.

[0247] First, the procedure illustrated in Fig. 16 will be explained.

[0248] (1) Step 1: The UE sends a registration request message to (R)AN. The registration request message corresponds to the AN message.

[0249] A registration request message may include AN parameters. For NG-RAN, AN parameters include, for example, 5G-S-TMSI (5G SAE temporary mobile subscriber identity) or GUAMI (globally unique AMF ID), a selected PLMN (public land mobile network) ID (or PLMN ID and NID (network identifier)), and requested NSSAI (Requested network slice selection assistance information). AN parameters also include an establishment cause. The establishment cause provides the reason for requesting the establishment of an RRC connection. Whether and how the UE includes the requested NSSAI as part of the AN parameters depends on the value of the access stratum connection establishment NSSAI inclusion mode parameter.

[0250] The registration request message may include a registration type. The registration type indicates whether the UE wants to perform an initial registration (e.g., the UE is in the RM-DEREGISTERED state), or a mobility registration update (e.g., the UE is in the RM-REGISTERED state and initiates the registration process because the UE moves, or the UE wants to update capability or protocol parameters, or requests a change to the set of network slices allowed for the UE to use), or a periodic registration update (e.g., the UE is in the RM-REGISTERED state and initiates the registration process due to the expiration of the periodic registration update timer), or an urgent registration (e.g., the UE is in the restricted service state).

[0251] When a UE performs initial registration, the UE specifies the UE ID in the registration request message as follows. The identification information below is listed in descending order of priority.

[0252] i) If the UE has a valid EPS (evolved packet system) GUTI (globally unique temporary identifier), the 5G-GUTI mapped from the EPS GUTI;

[0253] ii) Native 5G-GUTI assigned by the PLMN for which the UE is attempting to register (if available);

[0254] iii) Native 5G-GUTI assigned by a PLMN equivalent to the PLMN for which the UE is attempting to register;

[0255] iv) Native 5G-GUTI assigned by other PLMNs (if available);

[0256] v) Otherwise, the UE includes SUCI (subscriber concealed identifier) ​​in the registration request message.

[0257] If the UE performing the initial registration has both a valid EPS GUTI and a native 5G-GUTI, the UE also marks the native 5G-GUTI as an additional GUTI. If one or more native 5G-GUTIs are available, the UE selects a 5G-GUTI in descending order of priority from items (ii)-(iv) in the list above.

[0258] When the UE performs initial registration with native 5G-GUTI, the UE displays relevant GUAMI information in AN parameters. When the UE performs initial registration with SUCI, the UE does not display GUAMI information in AN parameters.

[0259] In the case of emergency registration, SUCI is included if the UE does not have a valid 5G-GUTI, and PEI is included if the UE does not have a SUPI (subscriber permanent identifier) ​​and does not have a valid 5G-GUTI. In other cases, a 5G-GUTI is included, which indicates the last serving AMF.

[0260] The registration request message may also include security parameters, PDU session status, etc. Security parameters are used for authentication and integrity protection. The PDU session status indicates a previously established PDU session in the UE. When the UE is connected to two AMFs belonging to different PLMNs via a 3GPP connection and a non-3GPP connection, the PDU session status indicates the established PDU session of the current PLMN in the UE.

[0261] (2) Step 2: (R)AN selects AMF.

[0262] If 5G-S-TMSI or GUAMI is not included, or if 5G-S-TMSI or GUAMI does not represent a valid AMF, (R)AN selects an AMF based on (R)AT and the requested NSSAI, where available.

[0263] If the UE is in the CM-CONNECTED state, (R)AN can send a registration request message to the AMF based on the UE's N2 connection.

[0264] If (R)AN cannot select a suitable AMF, (R)AN performs AMF selection by forwarding a registration request message to the AMF configured in (R)AN.

[0265] (3) Step 3: (R)AN sends a registration request message to the new AMF. The registration request message corresponds to the N2 message.

[0266] The registration request message may include all information and / or part of the information contained in the registration request message received from the UE described in Step 1.

[0267] The registration request message may include N2 parameters. When NG-RAN is used, the N2 parameters include the selected PLMN ID (or PLMN ID and NID), location information and cell ID associated with the cell where the UE is camping, and a UE context request indicating that a UE context including security information in NG-RAN must be established. When NG-RAN is used, the N2 parameters also include the cause for establishment.

[0268] If the registration type indicated by the UE is a periodic registration update, steps 4 through 19 described below may be omitted.

[0269] (4) Step 4: If the UE's 5G-GUTI is included in the registration request message and the serving AMF has changed since the last registration procedure, the new AMF may call the Namf_Communication_UEContextTransfer service operation on the previous AMF, including the full registration request NAS (non-access stratum) message to request the UE's SUPI and UE context.

[0270] (5) Step 5: The previous AMF can respond to the new AMF for the Namf_Communication_UEContextTransfer call, including the UE's SUPI and UE context.

[0271] (6) Step 6: If SUCI is not provided by the UE or is not retrieved from the previous AMF, the new AMF may initiate an Identity Request procedure by sending an Identity Request message to the UE to request SUCI.

[0272] (7) Step 7: The UE may respond with an Identity Response message containing SUCI. The UE derives SUCI using the provided public key of the home PLMN (HPLMN).

[0273] (8) Step 8: The new AMF may decide to call AUSF to initiate UE authentication. In this case, the new AMF selects AUSF based on SUPI or SUCI.

[0274] (9) Step 9: Authentication / security may be established by UE, new AMF, AUSF and / or UDM.

[0275] (10) Step 10: If the AMF is changed, the new AMF may call the Namf_Communication_RegistrationCompleteNotify service operation to notify the previous AMF that UE registration is complete for the new AMF. If the authentication / security procedure fails, registration is rejected and the new AMF may call the Namf_Communication_RegistrationCompleteNotify service operation with a reject indication reason code for the previous AMF. The previous AMF may continue as if no UE context passing service operation was received.

[0276] (11) Step 11: If the PEI is not provided by the UE or has not been retrieved from the previous AMF, the new AMF may initiate an identity request procedure by sending an identity request message to the UE to retrieve the PEI. The PEI is transmitted in encryption, except in cases where the UE cannot perform emergency registration and be authenticated.

[0277] (12) Step 12: Optionally, the new AMF can call the N5g-eir_EquipmentIdentityCheck_Get service operation to start ME ID checking.

[0278] Now, the procedure of Fig. 17 following the procedure of Fig. 16 is explained.

[0279] (13) Step 13: If you perform Step 14 below, the new AMF can select a UDM based on SUPI, and the UDM can select a UDR instance.

[0280] (14) Step 14: New AMFs can be registered with UDM.

[0281] (15) Step 15: The new AMF can select PCF.

[0282] (16) Step 16: The new AMF may optionally establish / modify AM policy associations.

[0283] (17) Step 17: The new AMF may send update / release SM context messages (e.g., Nsmf_PDUSession_UpdateSMContext and / or Nsmf_PDUSession_ReleaseSMContext) to the SMF.

[0284] (18) Step 18: If the new AMF and the previous AMF are in the same PLMN, the new AMF can send a request to modify the UE context to N3IWF / TNGF / W-AGF.

[0285] (19) Step 19: N3IWF / TNGF / W-AGF can send a UE context correction response to the new AMF.

[0286] (20) Step 20: After the new AMF receives a response message from N3IWF / TNGF / W-AGF in Step 19, the new AMF can register with UDM.

[0287] (21) Step 21: The new AMF sends a registration accept message to the UE.

[0288] The new AMF sends a registration acceptance message to the UE indicating that the registration request has been accepted. If the new AMF assigns a new 5G-GUTI, the 5G-GUTI is included. If the UE is already in the RM-REGISTERED state via another connection on the same PLMN, the UE uses the 5G-GUTI received in the registration acceptance message for both registrations. If the registration acceptance message does not include a 5G-GUTI, the UE uses the 5G-GUTI assigned to the existing registration for the new registration as well. If the new AMF assigns a new registration area, it sends the registration area to the UE via the registration acceptance message. If the registration acceptance message does not contain a registration area, the UE considers the previous registration area to be valid. Mobility restrictions are included when mobility restrictions apply to the UE and the registration type is not an urgent registration. The new AMF indicates the PDU session established for the UE in the PDU session state. The UE locally removes internal resources associated with PDU sessions that are not marked as established in the received PDU session state. When a UE connects to two AMFs belonging to different PLMNs via a 3GPP connection and a non-3GPP connection, the UE locally removes internal resources associated with the PDU session of the current PLMN that are not indicated as established in the received PDU session state. If PDU session state information is present in the registration acceptance message, the new AMF instructs the UE on the PDU session state.

[0289] The allowed NSSAI provided in the registration acceptance message is valid in the registration area and applies to all PLMNs having a tracking area included in the registration area. The mapping of allowed NSSAI is to map the HPLMN S-NSSAI to each S-NSSAI of the allowed NSSAI. The mapping of configured NSSAI is to map the HPLMN S-NSSAI to each S-NSSAI of the configured NSSAI for the serving PLMN.

[0290] Additionally, the new AMF optionally performs UE policy association establishment.

[0291] (22) Step 22: If the UE succeeds in updating itself, it can send a registration complete message to the new AMF.

[0292] The UE can send a registration completion message to the new AMF to check if a new 5G-GUTI has been assigned.

[0293] (23) Step 23: In the case of registration via a 3GPP connection, if the new AMF does not release the signaling connection, the new AMF may transmit RRC inactive assistance information to the NG-RAN. In the case of registration via a non-3GPP connection, if the UE is in a CM-CONTENED state on the 3GPP connection, the new AMF may transmit RRC inactive assistance information to the NG-RAN.

[0294] (24) Step 24: AMF can perform information updates on UDM.

[0295] (25) Step 25: The UE can execute network slice-specific authentication and authorization (NSSAA) procedures.

[0296] Security procedures between UE and 5G network functions

[0297] A UE, base station, or network performing mobile communication may use one example of the security procedure described below.

[0298] Examples of primary authentication and key agreement, as well as examples of authentication frameworks, are explained below.

[0299] The purpose of the first authentication and key consensus procedure is to enable mutual authentication between the UE and the network and to provide keying material that can be used between the UE and the serving network in subsequent security procedures. The keying material generated by the first authentication and key consensus procedure creates KSEAF, which is an anchor key provided by the AUSF of the home network to the SEAF of the serving network.

[0300] Keys for two or more security contexts can be derived from KSEAF without the need to execute new authentication. As a specific example, authentication executed over a 3GPP access network may provide a key that establishes security between a UE and an N3IWF used for untrusted non-3GPP access.

[0301] The anchor key KSEAF is derived from an intermediate key called KAUSF. KAUSF is established between the UE and the HN as a result of the primary authentication process. Depending on the home operator's policy regarding the use of the key, KAUSF can be securely stored in AUSF, for example, a control plane solution for roaming coordination or a UE parameter update procedure, or if AKMA (authentication and key management for applications) is supported by the HPLMN.

[0302] UE and serving networks support EAP-AKA and 5G AKA authentication methods.

[0303] The USIM can reside in the UICC. The UICC can be removable or non-removable.

[0304] If the terminal supports 3GPP access functions, for non-3GPP access networks, the credentials used for EAP-AKA and 5G AKA must reside in the UICC.

[0305] Once the 5G AKA first-level certification is successfully completed, the AMF can initiate the NAS security mode command procedure with the UE.

[0306] Next, an example of the EAP framework is explained.

[0307] The EAP framework is specified in RFC 3748. It defines the roles of peers, pass-through authenticators, and backend authentication servers. The backend authentication server acts as the EAP server that terminates the EAP authentication method with the peer. In 5G systems, the EAP framework is supported in the following ways:

[0308] - The UE can act as a peer.

[0309] - SEAF can act as a pass authenticator.

[0310] - AUSF can serve as a backend authentication server.

[0311] Explains an example of the granularity of anchor key binding to a serving network.

[0312] The primary authentication and key consensus procedure can bind KSEAF to the service network. Binding to the serving network prevents one serving network from claiming to be another serving network, and thus provides implicit serving network authentication to the UE.

[0313] Since this implicit serving network certification must be provided to the UE regardless of the access network technology, it applies to both 3GPP and non-3GPP access networks.

[0314] Additionally, the anchor key provided to the serving network may be specific to the authentication performed between the UE and the 5G core network. For example, it must be cryptographically separated from the KASME key transmitted from the home network to the serving network in previous mobile network generations.

[0315] Anchor key binding can be achieved by including a parameter called "serving network name" in the key derivation chain leading from the long-term subscriber key to the anchor key.

[0316] An example of the configuration of a serving network name is explained below.

[0317] The serving network name is used for anchor key derivation. This serves two purposes:

[0318] - The anchor key binds the anchor key to the serving network, including the serving network identifier (SN Id).

[0319] - Verify that the anchor key, including the service code set to "5G", is specific for authentication between the 5G core network and the UE.

[0320] In 5G AKA, serving network names have a similar purpose of binding RES* and XRES* to serving networks.

[0321] The serving network name is formed by connecting the service code and SN Id with the separator ":" so that the service code comes before the SN Id.

[0322] SN Id identifies the PLMN providing the service and is defined as an SNN-network identifier, except for standalone private networks.

[0323] This explains an example of configuring a serving network name by a UE.

[0324] The UE can configure the service network name as follows:

[0325] - Set the service code to "5G".

[0326] - Set the network identifier to the SN Id of the authenticating network.

[0327] - Connect the service code and SN ID with the separator ":".

[0328] This explains an example of configuring serving network names by SEAF.

[0329] SEAF configures the service network name as follows:

[0330] - Set the service code to "5G".

[0331] - Set the network identifier to the SN Id of the serving network to which AUSF transmits authentication data.

[0332] - Connect the service code and SN ID with the separator ":".

[0333] This shows an example of the procedure for starting authentication and selecting an authentication method.

[0334] FIG. 18 illustrates an example of an authentication procedure start and authentication method selection to which the present disclosure may be applied.

[0335] A UE may send an N1 message (e.g., including a registration request message) to a security anchor function (SEAF). For example, the SEAF may initiate authentication for the UE according to the SEAF's policy during the process of establishing a signaling association with the UE. The UE may use SUCI or 5G-GUTI in the registration request. For example, the registration request message may include SUCI or 5G-GUTI.

[0336] For example, SEAF can be a function responsible for the authentication function of a serving AMF. For instance, an AMF may include an entity named SEAF, or the AMF may perform operations related to SEAF.

[0337] SEAF can send an authentication request message (e.g., Nausf_UEAuthentication_Authentication_Request_Message) to the AUSF (authentication server function). Whenever SEAF wishes to initiate authentication, it can call the Nausf_UEAuthentication service by sending a Nausf_UEAuthentication_Authenticate request message to the AUSF.

[0338] Here, the Nausf_UEAuthenticate_authentication request message may include one of the following:

[0339] - SUCI, or

[0340] - SUPI.

[0341] If SEAF has a valid 5G-GUTI and re-authenticates the UE, SEAF may include SUPI in the Nausf_UEAuthentication_Authenticate request message. Otherwise, SUCI may be included in the Nausf_UEAuthentication_Authenticate Request.

[0342] The Nausf_UEAuthentication_Authenticate request may additionally include the serving network name.

[0343] The Nausf_UEAuthentication_Authenticate request may additionally include a disaster roaming service indication.

[0344] Upon receiving a Nausf_UEAuthentication_Authenticate request message, the AUSF can determine whether the SEAF requesting from the serving network is authorized to use the serving network name in the Nausf_UEAuthentication_Authenticate request by comparing it with the expected serving network name. The AUSF temporarily stores the received serving network name. If the serving network is not authorized to use the serving network name, the AUSF may respond with "Unauthorized serving network" in the Nausf_UEAuthentication_Authenticate response.

[0345] In the case of disaster roaming, AUSF can check local settings and, if allowed, send a Nudm_UEAuthentication_Get request to the UDM.

[0346] The Nudm_UEAuthentication_Get request sent from AUSF to UDM includes the following information:

[0347] - SUCI or SUPI;

[0348] - Serving network name;

[0349] - Disaster roaming service indication if received from SEAF.

[0350] The UDM that receives the Nudm_UEAuthentication_Get request calls SIDF when SUCI is received. SIDF obtains SUPI by unhiding SUCI before the UDM processes the request.

[0351] UDM / ARPF selects an authentication method based on SUPI.

[0352] In the case of disaster roaming, UDM checks the local configuration and, if allowed, proceeds with the selected authentication method.

[0353] Referring to the example in Fig. 19, an example of a primary authentication procedure triggered by a home network is described.

[0354] Support for Home Network Triggered Authentication is optional for the Home Network (HN) and Serving Network (SN). If both networks (HN and SN) support Home Network Triggered Primary Authentication, the following description applies.

[0355] Examples of security mechanisms are as follows.

[0356] UDM can also take local policies into account to initiate primary authentication for procedures initiated by the UE (e.g., UE registration in 5GC) or events of the UE (e.g., SoR / UPU) or other NFs.

[0357] The following drawings are made to illustrate a specific example of the present disclosure. The names of specific devices or specific signals / messages / fields described in the drawings are provided as examples, and therefore the technical features of the present disclosure are not limited to the specific names used in the following drawings.

[0358] FIG. 19 is an example of a primary authentication procedure according to one embodiment of the present disclosure.

[0359] Figure 19 is an example of a primary authentication procedure triggered by a home network.

[0360] Steps 0a and 0b are prerequisites for the entire procedure of Fig. 8.

[0361] 0a. To determine when to trigger the first authentication process, a carrier authentication policy can be pre-configured in the UDM.

[0362] 0b. A UE may register with a network. As part of the registration process, a serving AMF may register the UE with a UDM via Nudm_UECM_Registration according to a registration process such as the example in FIGS. 16 and FIGS. 17. To create an implicit subscription for potential home network-triggered re-authentication using the Nudm_UECM_Re-AuthenticationNotification service operation as in step 2, the UDM may provide a callback URI within the AMF registration.

[0363] 1a-c. Based on events or authentication policies, the UDM may decide on its own and perform home network trigger primary authentication as described in the following steps. For example, an NF such as AAnF may use the UDM service to send a Nudm_UECM_AuthTrigger request to the UDM for primary authentication. The NF may send a Nudm_UECM_AuthTrigger request message to the UDM along with the target UE's SUPI. The UDM may approve the request with a Nudm_UECM_AuthTrigger response to the NF.

[0364] If different AMFs are registered with the UDM for different accesses, the UDM can select one AMF to perform re-authentication. The criteria for selecting an AMF may vary depending on the local UDM authentication policy.

[0365] 2. UDM can send a Nudm_UECM_Re-AuthenticationNotification message to AMF / SEAF along with the UE's SUPI.

[0366] 3. After receiving the Nudm_UECM_Re-AuthenticationNotification message from the UDM, the AMF / SEAF may determine whether to execute the primary authentication procedure based on its own local authentication policy and the UE status (e.g., if the UE is in a handover or is already authenticated by the AMF before receiving the authentication notification from the UDM). If the AMF / SEAF determines that it cannot execute primary authentication as described in Step 4 (e.g., due to a local policy), the AMF / SEAF may send an authentication response message to the UDM indicating the cause of the failure; otherwise, it may approve the request. If the AMF / SEAF approves the request but cannot initiate primary authentication for the UE (e.g., if it cannot connect to the UE), the AMF / SEAF may set the authentication pending flag. Upon receiving a failure from the AMF, the UDM may check if another AMF is available through a different connection. If available, the UDM may select another AMF and retry Step 2.

[0367] When a UE reconnects to the same AMF or becomes able to connect, the AMF checks the authentication pending flag and can perform re-authentication if necessary. Once UE re-authentication is complete, the AMF can reset the authentication pending flag.

[0368] 4. As shown in the example below, AMF / SEAF can initiate the first certification process.

[0369] UDM can execute other procedures (e.g., SoR / UPU) depending on the reason for triggering the (re)authentication procedure in Step 1.

[0370] FIG. 20 illustrates an example of a 5GS key hierarchy generation to which the present disclosure can be applied.

[0371] Referring to the example in Fig. 20, an example of a key hierarchy, key derivation, and distribution scheme is described.

[0372] The keys associated with authentication include the following keys: K, CK / IK.

[0373] In the case of EAP-AKA' (extensible authentication protocol - authentication and key agreement), the keys CK' and IK' are keys derived from CK and IK as specified in Section 6.1.3.1 of TS 33.501 V18.5.0. For example, EAP-AKA' may be a technology based on RFC4187(EAP-AKA). For example, RFC4187(EAP-AKA) may be modified for 3GPP systems and enhanced to RFC5448(EAP-AKA').

[0374] The key hierarchy of FIG. 20 includes the following keys: KAUSF, KSEAF, KAMF, KNASint, KNASenc, KN3IWF, KgNB, KRRCint, KRRCenc, KUPint and KUPenc.

[0375] The key for AUSF in a home network (e.g., HPLMN in the example of Fig. 20) is as follows:

[0376] - KAUSF is a derived key:

[0377] - i) For example, in the EAP-AKA case, ME and AUSF derive KAUSF from CK' and IK'. Here, AUSF receives CK' and IK'. CK' and IK' are part of the AV (Authentication Vector) transformed by ARPF; or,

[0378] - ii) For example, in the 5G AKA case, ME and ARPF derive KAUSF from CK and IK. Here, AUSF can receive KAUSF. KAUSF is part of the 5G HE AV (Home Environment Authentication Vector) generated by ARPF.

[0379] KSEAF is an anchor key derived from KAUSF by ME and AUSF. KSEAF is provided by AUSF to the SEAF of the serving network.

[0380] The keys for AMF in network services are as follows:

[0381] - KAMF is a key derived from KSEAF by ME and SEAF. KAMF can be further derived by ME and source AMF when performing horizontal key derivation.

[0382] The key for NAS signaling is as follows:

[0383] - KNASint is a key derived from KAMF by ME and AMF. KNASint can only be used to protect NAS signaling with a specific integrity algorithm.

[0384] - KNASenc is a key derived from KAMF by ME and AMF. KNASenc can be used to protect NAS signaling with a particular encryption algorithm.

[0385] The key for NG-RAN is as follows:

[0386] - KgNB is a key derived from KAMF by ME and AMF. When ME and source gNB perform horizontal key derivation or vertical key derivation, KgNB is additionally derived by ME and source gNB. KgNB can be used as a KeyNB between ME and ng-eNB.

[0387] The key for UP traffic is as follows:

[0388] - KUPenc is a key derived by ME and gNB from KgNB. KUPenc can only be used to protect UP traffic using a specific encryption algorithm.

[0389] - KUPint is a key derived from KgNB by ME and gNB. KUPint can be used to protect UP traffic between ME and gNB using a specific integrity algorithm.

[0390] The keys for RRC signaling are as follows:

[0391] - KRRCint is a key derived by ME and gNB from KgNB. For example, KRRCint can only be used for RRC signaling protection using a specific integrity algorithm.

[0392] - KRRCenc is a key derived by ME and gNB from KgNB. For example, KRRCenc can only be used for RRC signal protection using a specific encryption algorithm.

[0393] The middle keys are as follows:

[0394] - NH(next hop) is a key derived by ME and AMF to provide forward security.

[0395] - KNG-RAN* is a key derived by ME and NG-RAN (e.g., gNB or ng-eNB) when performing horizontal key derivation or vertical key derivation using KDF (key derivation function).

[0396] - KAMF’ is a key that ME and AMF can induce when a UE moves from one AMF to another AMF during an inter-AMF mobility-related procedure using KDF.

[0397] The key for non-3GPP access is as follows:

[0398] - KN3IWF is a key derived from KAMF by ME and AMF for non-3GPP access. KN3IWF is not forwarded between N3IWFs.

[0399] FIG. 21 shows an example of a model for handover key chaining to which the present disclosure can be applied.

[0400] The following describes examples of security handling related to mobility (e.g., key handling at the access layer in handover procedures).

[0401] The general principle of key processing for KNG-RAN* / NH during handover is illustrated in Fig. 21.

[0402] Explains an overview of the key processing model to clarify the intended structure of key derivation.

[0403] When an initial AS security context needs to be established between the UE and the gNB / ng-eNB, the AMF and the UE derive the KgNB and the parameter NH. The KgNB and NH are derived from the KAMF. The NH chaining counter (NCC) is associated with each KgNB and NH parameter. Every KgNB is associated with the NCC corresponding to the derived NH value. During initial setup, the KgNB is derived directly from the KAMF, and the KgNB is considered to be associated with a virtual NH parameter with an NCC value of 0. During initial setup, the derived NH value is associated with an NCC value of 1.

[0404] Whether the AMF sends the KgNB key or the {NH, NCC} pair to the serving gNB / ng-eNB is described in detail below in "Key Derivation for Context Modification Procedure" and "Key Derivation for Context Modification Procedure". The AMF does not send the NH value to the gNB / ng-eNB during initial connection setup. The gNB / ng-eNB initializes the NCC value to 0 after receiving the NGAP initial context setup request message.

[0405] The UE and the gNB / ng-eNB use a KgNB to secure communication between them. During handover and the transition from RRC_INACTIVE to RRC_CONNECTED, the reference for the KgNB to be used between the UE and the target gNB / ng-eNB is called KNG-RAN*, and KNG-RAN* is derived from the currently active KgNB or NH parameters. When KNG-RAN* is derived from the currently active KgNB, this is called horizontal key derivation (see Fig. 21). When KNG-RAN* is derived from NH parameters, this is called vertical key derivation (see Fig. 21).

[0406] NH parameters can be calculated only by the UE and the AMF. NH parameters can be arranged so that they are provided from the AMF to the gNB / ng-eNB in ​​a manner that achieves forward security.

[0407] In a handover with vertical key induction, NH can be used as KgNB in ​​the target gNB / ng-eNB after being additionally bound to the target PCI (physical cell identifier) ​​and the corresponding frequency ARFCN-DL. In a handover with horizontal key induction, the currently active KgNB can be used as KgNB in ​​the target gNB / ng-eNB after being additionally bound to the target PCI and the corresponding frequency ARFCN-DL.

[0408] Next, we will explain an example of key handling related to the NAS (non-access stratum).

[0409] NAS aspects to be considered during mobility-related procedures may include the possibility of KAMF change, the possibility of NAS algorithm change upon AMF change, and the possibility of the existence of parallel NAS connections. It is possible that the source AMF and the target AMF do not support the same set of NAS algorithms or have different priorities regarding the use of NAS algorithms. In this case, the target AMF uses the NAS algorithm ID and NAS algorithm type as inputs to the NAS key derivation function to re-derive the NAS key from the existing KAMF (if unchanged) or derive the NAS key from the new KAMF (if changed). If the KAMF is unchanged, all inputs, specifically all inputs except the NAS algorithm ID, are identical in the re-derivation. If the KAMF is changed, a new NAS key is derived regardless of changes to the NAS algorithm.

[0410] This explains examples of key derivations for context modification procedures.

[0411] Whenever a new KgNB is computed from KAMF, AMF may transmit the KgNB to the serving ng-eNB / gNB with a message modifying the security context of the ng-eNB / gNB. AMF and UE may compute a new KgNB. An NCC value of 0 is associated with the new KgNB. After composing a KNG-RAN* from the new KgNB, the ng-eNB / gNB and UE may use the computed KNG-RAN* as the KgNB / KeNB.

[0412] Explains examples of key derivations during handover.

[0413] For example, an example of key derivation during handover in gNB-CU handover and ng-eNB handover is explained.

[0414] A gNB may have a policy determining which intra-NB-CU handover allows the KgNB to be retained and which handover requires a new KgNB to be derived. During an intra-NB-CU handover, the gNB must inform the UE via an HO Command message whether to change or retain the current KgNB. Retaining the current KgNB can only be done during an intra-NB-CU handover.

[0415] If the current KgNB changes, the gNB / ng-eNB and the UE may derive KNG-RAN* using either NH or the current KgNB according to the target PCI, the corresponding frequency ARFCN-DL / EARFCN-DL, and the following criteria. If an unused {NH, NCC} pair is available in the gNB (referred to as vertical key derivation), the gNB may derive KNG-RAN* using the corresponding NH. Otherwise (referred to as horizontal key derivation), the gNB may derive KNG-RAN* from the current KgNB. The gNB may send an HO Command message to the UE containing the NCC used for the KNG-RAN* derivation. After the handover, the gNB / ng-eNB and the UE use the KNG-RAN* as the KgNB.

[0416] If the current KgNB needs to be maintained, the gNB and UE can continue to use the current KgNB even after the handover.

[0417] For example, an example of key derivation during a handover in Xn-handover is explained.

[0418] For horizontal key derivation, the source gNB / ng-eNB first calculates the KNG-RAN* from the target PCI, the corresponding frequency ARFCN-DL / EARFCN-DL, and the currently active KgNB. For vertical key derivation, the source gNB / ng-eNB first calculates the KNG-RAN* from the target PCI, the corresponding frequency ARFCN-DL / EARFCN-DL, and NH.

[0419] Next, the source gNB / ng-eNB transmits the {KNG-RAN*, NCC} pair to the target gNB / ng-eNB. The target gNB / ng-eNB directly uses the received KNG-RAN* as the KgNB to be used with the UE. The target gNB / ng-eNB can associate the NCC value received from the source gNB / ng-eNB with the KgNB. The target gNB / ng-eNB includes the received NCC in a prepared HO Command message, and this message is placed in a transparent container and sent back to the source gNB / ng-eNB, which then transmits it to the UE.

[0420] When the target gNB / ng-eNB completes handover signaling with the UE, the target gNB / ng-eNB can send an NGAP Path Switch Request message to the AMF. Upon receiving the NGAP Path Switch Request, the AMF can increment the locally stored NCC value by 1 and calculate a new NH from the stored data using a function. The AMF can use the KAMF of the currently active 5G NAS security context to calculate the new NH. Then, the AMF can send an NGAP Path Switch Request acknowledgment message containing the newly calculated {NH, NCC} pair to the target gNB / ng-eNB. The target gNB / ng-eNB stores the received {NH, NCC} pair for future handovers and removes any previously unused stored {NH, NCC} pairs.

[0421] The AMF may have activated a new 5G NAS security context using a new KAMF that is different from the 5G NAS security context underlying the currently active 5G AS security context. In this case, if the AMF has not yet successfully performed the UE context modification procedure, the transmitted NGAP route switch request acknowledgment message may additionally include an NSCI (New Security Context Indicator). In this case, the AMF may derive a new initial KgNB from the new KAMF and uplink NAS count of the most recent NAS security mode completion message. The AMF may associate the derived new initial KgNB with a new NCC value, such as 0. The AMF may then use the pair {derived new initial KgNB, new NCC value initialized to 0} as a newly calculated {NH, NCC} pair and transmit an NGAP route switch request acknowledgment message containing this. In this case, the gNB / ng-eNB may set the keySetChangeIndicator field value to true upon additional handover. In this case, the gNB / ng-eNB can immediately perform an intra-gNB-CU / intra-ng-eNB handover.

[0422] Explains an example of the KNG-RAN* guidance function for the target gNB.

[0423] For handover, and / or to transition from the RRC_INACTIVE state to the RRC_CONNECTED state, a KNG-RAN* may be derived from the current KgNB of the UE and NG-RAN, or a KNG-RAN* may be derived from a new NH and a target physical cell ID (PCI). In this case, the UE and NG-RAN may form an input S to the KDF using the following parameters.

[0424] - FC = 0x70

[0425] - P0 = PCI (Target PCI)

[0426] - L0 = Length of PCI (e.g., 0x00 0x02)

[0427] - P1 = ARFCN-DL (absolute frequency of the SSB of the target PCell (primary cell))

[0428] - L1 = Length of ARFCN-DL (e.g., 0x00 0x03)

[0429] The input key KEY becomes a 256-bit NH if the index NCC at the handover increases, otherwise it can be the current 256-bit KgNB (if the source is gNB) or KeNB (if the source is ng-eNB).

[0430] Explain examples of induction functions related to KgNB, KWAGF, KTNGF, KTWIF, and KN3IWF.

[0431] When deriving the keys KgNB, KWAGF, KTNGF, KTWIF, and KN3IWF from the KAMF and uplink NAS COUNT of UE and AMF, the input S to KDF can be formed using the following parameters.

[0432] - FC = 0x6E

[0433] - P0 = Uplink NAS Count

[0434] - L0 = Length of Uplink NAS Count (e.g., 0x00 0x04)

[0435] - P1 = Access type identifier

[0436] - L1 = Length of access type separator (e.g., 0x00 0x01)

[0437] The values ​​of the access type identifiers are defined in Table 1. The values ​​0x00 and 0x03 through 0xf0 are reserved for future use, and the values ​​0xf1 through 0xff are reserved for private use.

[0438] The access type identifier can be set to a 3GPP (0x01) value when deriving KgNB. When deriving KN3IWF, KWAGF, KTWIF, or KTNGF, the access type identifier can be set to a non-3GPP (0x02) value.

[0439] Access Type Separator Value 3GPP Access 0x01 Non-3GPP Access 0x02

[0440] The input key KEY can be a 256-bit KAMF. The induction function related to KgNB, KWAGF, KTNGF, KTWIF, and KN3IWF can be applied when a password-protected 5G radio bearer is established and a key change is performed on the fly.

[0441] FIG. 22 illustrates an example of key handling based on a handover procedure to which the present disclosure may be applied.

[0442] According to the example in Fig. 22, the UE can transmit a measurement report to the source base station (e.g., gNB / ng-eNB).

[0443] Source gNB / ng-eNB can determine Handover (HO).

[0444] A source gNB / ng-eNB can transmit a HandoverRequest message to a target base station (e.g., gNB / ng-eNB). For example, the source gNB / ng-eNB can transmit an XnAP-based message to the target base station (e.g., gNB / ng-eNB). The HandoverRequest message may include AS security information. For example, the AS security information may include KgNB* and NCC. For example, based on the KgNB held by the source base station, KgNB* and NCC values ​​generated using target PCI and DL ARFCN values ​​as input may be included in the HandoverRequest message.

[0445] The target gNB / ng-eNB can transmit a Handover Request Acknowledge message to the source base station. The Handover Request Acknowledge message may include a Handover Command. The Handover Command may include an NCC. For example, the target gNB / ng-eNB can create an RRC Container named HandoverCommand and transmit it to the source base station. At this time, the target gNB / ng-eNB may include the NCC value in the HandoverCommand and transmit it in order to inform the terminal of the NCC value received from the source base station.

[0446] The source gNB / ng-eNB can send an RRC reset message to the UE. The RRC reset message includes a handover command, and the handover command may include an NCC value.

[0447] The source gNB / ng-eNB can transmit SNStatusTransfer messages to the target base station.

[0448] The UE and the target gNB / ng-eNB can perform a random access channel (RACH) procedure. The UE can complete access to the target base station.

[0449] The UE can transmit an RRCReconfigurationComplete message to the target base station.

[0450] The target gNB / ng-eNB can send a PathSwitchRequest message to the AMF.

[0451] The AMF can transmit a route switch request acknowledgment message to the target base station. For example, the AMF can generate a new NH and increment the NCC value by one. The route switch request acknowledgment message may include the new NH and the incremented NCC.

[0452] The target gNB / ng-eNB can send a UEContextRelease message to the source base station. A UEContextRelease message can be sent to clear the UE context of the source base station.

[0453] L1 / L2 triggered mobility (LTM)

[0454] LTM may be a procedure that includes the following actions. For example, according to LTM, the gNB receives an L1 measurement report from the UE, and based on the measurement report, the gNB can change the UE's serving cell according to a cell switch command transmitted via MAC CE. The cell switch command may represent an LTM candidate setting previously prepared by the gNB and provided to the UE via RRC signaling. The UE can then switch to the target setting according to the cell switch command. The LTM procedure can be used to reduce mobility latency.

[0455] When the network establishes an LTM, the transmission configuration indicator (TCI) states of the current serving cell and one or more other cells may be enabled. For example, the TCI state of an LTM candidate cell may be enabled in advance before that cell becomes the serving cell. Accordingly, the UE can synchronize with the cell and switch to one of those cells more quickly when the cell switch is triggered. All enabled TCI states, except for those received in the cell switch command, may be disabled when the LTM cell switch is executed.

[0456] If the network has established an LTM, it may initiate the procedure to acquire a UL TA (timing advance) (e.g., referred to as an early TA) for the currently serving cell and one or more other cells. The cell's N TAis the same as the current serving cell or N TA If =0, the early TA acquisition procedure is not required. The network may request the UE to perform an early TA acquisition for the candidate cell prior to the cell switch. The early TA acquisition procedure may be triggered by a PDCCH order or realized based on a UE-based TA measurement as set by the RRC. In the former case, the gNB / gNB-DU to which the candidate cell belongs may calculate the TA value and transmit it via the gNB-CU to the gNB / gNB-DU to which the serving cell belongs. When the serving cell triggers the LTM cell switch, it may transmit an LTM cell switch command MAC CE (medium access control element) containing the TA value. In the latter case, the UE performs a TA measurement for the candidate cell after being set by the RRC, but the exact time at which the UE performs the TA measurement may vary depending on the UE implementation. If the UE does not contain a valid TA value upon receiving the cell switch command, it may apply a self-measured TA value and perform an LTM without RACH. The network may also transmit an LTM cell switch command MAC CE containing a TA value without early TA acquisition.

[0457] Based on the availability of valid TA values, the UE may perform RACH-free LTM or RACH-based LTM cell switching. If a valid TA value is included in the cell switch command, the UE may apply that TA value in accordance with network instructions. If UE-based TA measurement is established but a valid TA value is not provided in the cell switch command, the UE may apply a valid TA value on its own if available. If a valid TA value is available, the UE may perform RACH-free LTM cell switching upon receiving the cell switch command. If a valid TA value is not available, the UE may perform RACH-based LTM cell switching.

[0458] Regardless of whether terminal-based TA measurement for a specific candidate cell is configured, the terminal follows a PDCCH order to perform a random access procedure to one or more cells. This also applies to candidate cells for terminals capable of deriving TA values ​​themselves. Additionally, if the network has configured terminal-based measurement, the terminal follows the terminal-based measurement configuration regardless of whether it has initiated random access to candidate cells. In the case of LTM without RACH, the UE can access the target cell using a configured grant or a dynamic grant. A configured grant is provided in the LTM candidate configuration, and the UE can select a configured grant opportunity associated with the beam indicated in the cell switch command. Once the LTM cell switch for the target cell is initiated, the UE can begin monitoring the target cell's PDCCH for dynamic scheduling. If there are no valid PUCCH resources for a scheduling request (SR) triggered before the LTM without RACH procedure is completed, the UE may not trigger the random access procedure.

[0459] The following principles apply to LTM:

[0460] - The security key is retained during the LTM cell switch;

[0461] - Subsequent LTM is supported.

[0462] LTM supports both intra-gNB-DU mobility and inter-gNB-DU mobility within the same gNB-CU. LTM supports both intra-frequency and inter-frequency mobility, including mobility to inter-frequency cells that are not the current serving cell. LTM can be supported for licensed spectrum. The following scenarios are supported:

[0463] - PCell changes in non-CA scenarios and non-DC (dual connectivity) scenarios;

[0464] - Changes in PCell and SCell (secondary cell) in CA scenarios;

[0465] - DC Scenario: Includes PCell changes and MCG (master cell group) SCell changes, and intra-SN (secondary node) PSCell (primary SCell) and SCG (secondary cell group) SCell changes without intervention from the MN (master node). Simultaneous changes to PCell and PSCell may not be supported.

[0466] While the UE saves the LTM candidate settings, the UE may execute all L3 handovers except for DAPS (dual active protocol stack) handovers. In the RRC messages applied by the UE for all L3 handovers (excluding DAPS), the LTM candidate settings may be added / modified / unset by the target cell.

[0467] Explains examples of control plane handling related to LTM procedures.

[0468] The cell switch command may be included in a MAC CE containing information necessary to perform an LTM cell switch.

[0469] Subsequent LTMs can be performed by repeating the initial synchronization, LTM cell switch execution, and LTM cell switch completion steps after each LTM cell switch is completed, without releasing other LTM candidate settings. Standard procedures via the wireless interface can be applied to SCG LTMs.

[0470] FIG. 23 illustrates an example of a signaling procedure for an LTM to which the present disclosure may be applied.

[0471] The UE can be in the RRC_CONNECTED state.

[0472] 1. The UE can transmit measurement reports to the gNB.

[0473] For example, the UE can send a MeasurementReport message to the gNB. The gNB can determine the LTM settings and start LTM preparation.

[0474] gNB can prepare LTM candidates.

[0475] 2. The gNB may send an RRC reset message to the UE. The RRC reset message may include LTM candidate settings.

[0476] For example, the gNB can send an RRC reconfiguration message (RRCReconfiguration) containing LTM candidate settings to the UE.

[0477] 3. The UE can send an RRC reset complete message to the gNB.

[0478] For example, the UE can save the LTM candidate settings and send an RRC reconfiguration completion message (RRCReconfigurationComplete) to the gNB.

[0479] 4a. Downlink (DL) synchronization between the LTM candidate cell and the UE can be performed.

[0480] For example, the UE can perform DL synchronization with the LTM candidate cell before receiving a cell switch command. The UE can enable and disable the TCI status of the LTM candidate cell as triggered by the gNB.

[0481] 4b. Uplink (UL) synchronization between the LTM candidate cell and the UE can be performed.

[0482] For example, the UE can perform UL synchronization with the LTM candidate cell before receiving the cell switch command. For example, the UE can perform UL synchronization with the LTM candidate cell by using a UE-based TA measurement (if configured) or by sending a preamble toward the candidate cell as triggered by the gNB. If a UE-based TA measurement is configured, the UE can obtain the TA value of the candidate cell through the measurement. The UE can perform an early TA acquisition for the candidate cell requested by the network before receiving the cell switch command. This is done via a contention-free random access (CFRA) triggered by the source cell's PDCCH order, after which the UE can send a preamble to the designated candidate cell. To minimize data interruption of the source cell caused by the CFRA for the candidate cell, the UE does not receive a random access response from the network for the purpose of obtaining the TA value, and the candidate cell's TA value can be indicated in the cell switch command. The UE does not maintain a TA timer for candidate cells and may rely on the network implementation to guarantee TA validity.

[0483] 5. The UE can transmit L1 measurement reports to the gNB.

[0484] For example, the UE can perform an L1 measurement on a configured LTM candidate cell and transmit the L1 measurement report to the gNB. The L1 measurement can be performed only when the RRC reset (step 2) is applied.

[0485] gNB can determine LTM.

[0486] 6. The gNB can send LTM cell switch command messages (including MAC CE) to the UE.

[0487] The gNB may decide to execute a cell switch for the target cell and transmit an LTM cell switch command MAC CE that triggers the cell switch. For example, the MAC CE may include a target setup ID indicating the index of the candidate setup of the target cell, a beam indicating the TCI status or a beam indicating the DL TCI status and UL TCI status, and, if possible, a timing pre-command for the target cell.

[0488] The UE can detach from the source and apply the target settings. For example, the UE can switch to the target cell and apply the candidate settings indicated by the target setting ID.

[0489] 7. The UE and the target cell can perform the RACH procedure.

[0490] The UE can perform a random access procedure to the target cell if there is no valid TA for the target cell.

[0491] 8. The LTM cell switch can be completed.

[0492] For example, the UE can complete the LTM cell switch procedure by sending an RRC ReconfigurationComplete message to the target cell. If the UE performed the RA procedure in Step 7, the UE considers the LTM cell switch execution to be successfully completed when the random access procedure is successfully completed. In the case of LTM without RACH, the UE considers the LTM cell switch execution to be successfully completed when it determines that the network has successfully received the first UL data.

[0493] For subsequent LTM cell switch execution, steps 4 through 8 may be performed multiple times using the LTM candidate configuration provided in step 2.

[0494] The procedure through the wireless interface described in Fig. 23 can be applied to both intra-NB-DU LTM and inter-NB-DU LTM.

[0495] Examples of user plane handling are as follows.

[0496] After receiving the LTM cell switch command MAC CE, the UE can perform a MAC reset. Whether the UE performs an RLC reset and PDCP data recovery during the cell switch can be explicitly controlled by the network via the RRC signal.

[0497] Examples of RACH-less handovers are as follows.

[0498] RACH-less handover can be configured for a UE during the Intra-NB Handover (HO) procedure. The RACH-less handover procedure can apply the following features:

[0499] - The UE can use the same timing advance value as the source cell in the target cell or a timing advance value of 0.

[0500] - A handover command for the UE may include a beam identifier for the beam that the UE will use in the target cell. The beam may be determined based on UE measurement reports and / or gNB implementations. For example, gNB implementations may include using the target cell's knowledge of the beam that the UE uses in a co-located source cell, etc.

[0501] - The handover command may include a configured UL grant. If there is no configured valid UL grant, the UE may fall back to RACH. Alternatively, a UL grant may be dynamically signaled by the target cell.

[0502] - Based on a configured UL grant or a dynamically signaled UL grant, the UE may send an RRCReconfigurationComplete message. If the UL data is successfully received at the target cell, the RACH-free handover execution may be terminated.

[0503] Protection of specific information in CU-to-CU LTM procedures

[0504] The following describes a method for protecting specific information in inter-CU LTM procedures. The specific information may correspond to information provided from a base station to a terminal via (unprotected) MAC CE messages in inter-CU LTM procedures. For example, the specific information may be information regarding access layer (AS) key derivation. For example, information regarding AS key derivation may include a next-hop chaining counter (NCC). One example of the present disclosure includes a novel method for protecting NCC information transmitted to a terminal via (unprotected) MAC CE in inter-CU LTM procedures.

[0505] The LTM between CUs to which the examples of the present disclosure apply corresponds to an example of a handover that supports the mobility of a terminal, and the application of security technology is essential even in handover. As the terminal moves from the serving node (or source node) currently being accessed to the target node, it is necessary to generate and apply a new security key to protect the signaling between the terminal and the base station at the newly accessed target node as well. As described above, for the generation of a new security key, the AMF and the terminal can generate a KgNB and an NH (next hop) based on the KAMF. Here, all KgNBs and NHs can be used in association with an NCC (NH chaining counter). For example, the information for key generation may include a pair of NH and NCC, and if the NH value changes, a new NCC value may be generated.

[0506] LTM can support faster mobility by improving existing handover procedures. To this end, in the LTM procedure, information (e.g., context) of nearby target base station / cell candidate(s) can be provided to or configured to the terminal in advance. Accordingly, if the terminal's measurement report provided to the current serving (or source) base station / cell satisfies specific conditions, a handover can be performed immediately without additional signaling between the source base station / cell and the target base station / cell.

[0507] For such LTM, the context information regarding the target base station / cell, which is provided to or configured in advance by the terminal, may include security information. For example, during the path switching procedure between the target base station / cell candidate and the AMF, the NCC value required for generating a new security key may be updated. If a handover / LTM to the corresponding target base station / cell candidate is performed, the updated NCC value must be provided to the terminal in advance so that the same security key can be generated at the terminal without separate signaling.

[0508] To provide NCC values ​​to the terminal, the target base station / cell may use L3 RRC signaling / messages or L2 MAC CE signaling / messages. Since RRC signaling involves an RRC reset procedure, it requires significant time and resources to execute. While MAC CE signaling is faster and requires fewer resources compared to RRC signaling, it does not apply the same security measures, meaning the NCC values ​​included in MAC CE signaling may not be protected. Therefore, a new method needs to be defined to protect NCC values ​​transmitted via MAC CE.

[0509] To this end, the present disclosure provides a method for applying encryption to specific information (e.g., an updated NCC value) regarding AS key derivation when such information is provided through an unprotected message (e.g., MAC CE) in a CU-to-CU LTM procedure. For example, such encryption may be performed using RRC security keys (e.g., an RRC encryption key, and / or an RRC integrity key).

[0510] As described with reference to FIGS. 20 and 21, an RRC encryption key (e.g., KRRCenc) may correspond to a key for encrypting plaintext. An RRC integrity key (e.g., KRRCintc) may correspond to a key for message protection, such as a message authentication code (MAC). The RRC encryption key and / or RRC integrity key may be generated based on KgNB and NH. The feature of the embodiments of the present disclosure is that specific information regarding AS key derivation (e.g., updated NCC value) is encrypted at an upper layer (e.g., PDCP layer), and the method of encrypting specific information regarding AS key derivation (e.g., updated NCC value) in the embodiments of the present disclosure is not limited to a specific method.

[0511] Hereinafter, examples of procedures and examples of layers are described in order regarding a method for encrypting an NCC value using an RRC encryption key and / or an RRC integrity key and signaling it via MAC CE, which corresponds to a representative embodiment of the present disclosure.

[0512] FIG. 24 is a drawing for illustrating an example of a method performed by a first network node according to the present disclosure.

[0513] The example of FIG. 24 can be performed in connection with a terminal handover or an inter-centralized unit LTM procedure based on L1 / L2 (layer 1 / layer 2) measurement reports.

[0514] In step S2410, the first network node may receive a first message from the second network node containing an updated value of information regarding access layer (AS) key derivation.

[0515] In some examples, information for AS key derivation may include the NCC (next hop chaining counter).

[0516] In some examples, the first message may correspond to a new generation application protocol (NGAP) path switch request acknowledge message.

[0517] In some examples, the first network node may be a candidate for the LTM target base station or a candidate for the LTM target CU. The first network node, which is the target base station / CU, may become the serving base station / CU when the terminal's initial access (e.g., random access) is completed during the LTM process, and may become the source base station / CU in another LTM or handover that may occur later. The term base station may correspond to a gNB or to a network node of a different name in a 6G system.

[0518] In some examples, the second network node may correspond to an AMF, or to a mobility management node / function / entity of a different name in a 6G core network.

[0519] In step S2420, the first network node may provide the encrypted value of the information regarding AS key derivation to the lower layer entity of the first network node by the upper layer entity of the first network node, based on the updated value of the information regarding AS key derivation.

[0520] In some examples, the upper-level entity may provide the encrypted value of the information regarding AS key derivation to the lower-level entity (in advance) without a request from the lower-level entity.

[0521] In some examples, the upper-level entity may provide the encrypted value of the information regarding the AS key derivation to the lower-level entity (in advance) after the first network node receives the first message.

[0522] In some examples, the upper-level entity may provide the encrypted value of the information regarding the AS key derivation to the lower-level entity in response to the lower-level entity's request.

[0523] In some examples, information regarding AS key derivation may be encrypted based on a higher-level key. For example, the higher-level key may include a radio resource control (RRC) encryption key and / or an RRC integrity key.

[0524] In some examples, the upper layer may be the PDCP (packet data convergence protocol) layer.

[0525] In some examples, the lower layer may be the MAC (medium access control) layer.

[0526] In step S2430, the first network node may transmit a second message containing an encrypted value of information regarding AS key derivation to the terminal.

[0527] In some examples, the second message may be an unprotected message (or a message that is not secure). For example, the second message may include a layer 1 / layer 2 triggered mobility (LTM) cell switch command, a medium access control (MAC), and a control element (CE).

[0528] The method described in the example of FIG. 24 may be performed by the wireless device (200) of FIG. 3 corresponding to the second node (120) of FIG. 2 described above. For example, the processor (202) of the wireless device (200) of FIG. 3 may be configured to receive a first message containing an updated value of information regarding AS key derivation from another network node through one or more transceivers (206), provide an encrypted value of information regarding AS key derivation to a lower-level entity by an upper-level entity based on the updated value of information regarding AS key derivation, and transmit a second message containing an encrypted value of information regarding AS key derivation to a first node (e.g., a terminal) through one or more transceivers (206). Furthermore, one or more memories (204) of the wireless device (200) may store instructions for performing the method described in the example of FIG. 24 or the examples described below when executed by one or more processors (202).

[0529] FIG. 25 is a drawing illustrating an example of a method performed by a measuring device according to the present disclosure.

[0530] In step S2510, the terminal can receive a message from the first network node containing an encrypted value of information regarding AS key derivation.

[0531] In step S2520, the terminal can receive the encrypted value of the information regarding AS key derivation from the lower layer of the terminal and decrypt it by the upper layer of the terminal.

[0532] In step S2530, the terminal can encrypt or decrypt user plane data and / or control plane messages based on information regarding the decrypted AS key derivation.

[0533] For example, the terminal can generate a new base station key (e.g., KgNB) based on information regarding the decrypted AS key derivation (e.g., NCC). The terminal can generate other keys (e.g., KRRCenc, KUPenc, etc.) based on the base station key (e.g., KgNB). The terminal can use the other keys (e.g., KRRCenc, KUPenc, etc.) for encryption / decryption of RRC messages, user data, etc.

[0534] In the example of FIG. 25, the specific characteristics of the information regarding AS key derivation, the encrypted value of the information regarding AS key derivation, the message including the encrypted value of the information regarding AS key derivation, the first network node, the lower layer, and the upper layer are the same as those described with reference to the example of FIG. 24, so redundant descriptions are omitted.

[0535] The method described in the example of FIG. 25 may be performed by the wireless device (200) of FIG. 3 corresponding to the first node (110) of FIG. 2 described above. For example, the processor (202) of the wireless device (200) of FIG. 3 may be configured to receive a message containing an encrypted value of information regarding AS key derivation from a first network node through one or more transceivers (206), receive the encrypted value of information regarding AS key derivation from a lower layer of the terminal and decrypt it by an upper layer of the terminal; and encrypt or decrypt user plane data and / or control plane messages based on the decrypted information regarding AS key derivation. Furthermore, one or more memories (204) of the wireless device (200) may store instructions for performing the method described in the example of FIG. 25 or the examples described below when executed by one or more processors (202).

[0536] Specific examples of the present disclosure regarding methods for protecting information (e.g., NCC) for AS key derivation are described below. First, the process in which an NCC value is updated during an LTM procedure and the updated NCC value is encrypted and transmitted to a terminal is described.

[0537] FIGS. 26 to 28 are drawings illustrating an example of a CU-to-LTM procedure according to the present disclosure.

[0538] In the examples of FIGS. 26 to 28, the UE corresponds to a terminal, the source gNB corresponds to the source base station of the LTM, the target gNB corresponds to one target base station among the candidate target base stations of the LTM where the LTM is actually performed, and the other gNB may correspond to another one among the candidate target base stations of the LTM.

[0539] Steps 0 to 6 correspond to the LTM preparation process, steps 7 to 14 correspond to the LTM execution process, and steps 15 to 17 may correspond to the subsequent LTM process following the initial LTM execution.

[0540] In step 0, the state of the terminal can be assumed to be RRC_CONNECTED.

[0541] In step 1, the terminal can transmit a measurement report message to the source base station (e.g., source gNB).

[0542] For example, before the LTM procedure between CUs is performed, if a preset or preset condition for the measurement result value is satisfied, the terminal may transmit the measurement report to the source base station.

[0543] In step 2, the source base station can derive new security information for each of the candidate cell(s) within the target base station.

[0544] For example, the source base station may decide whether to initiate the LTM procedure. If it decides to initiate the LTM procedure, the source base station may generate a security key for the candidate cell(s) of the surrounding target base station(s) (e.g., a KgNB* corresponding to a candidate KgNB derived from KAMF).

[0545] In step 3, the source base station may transmit a handover request message to the target base station(s). For example, the handover request message may be a handover request message for an LTM. In step 3, the target base station may correspond to a target candidate base station that can become the target base station.

[0546] For example, the source base station can include the newly generated KgNB* and NCC values ​​in a handover request message and transmit it to the target candidate base station(s).

[0547] In step 4, the target base station may send a handover request acknowledgment (ACK) message to the source base station. For example, the handover request ACK message may be a handover request ACK message for LTM.

[0548] For example, the target base station can send a handover request ACK message to the source base station, including the NCC value received from the source base station.

[0549] In step 5, the source base station can send an RRC reconfiguration message to the terminal.

[0550] For example, the terminal receives an RRC reset message and can store / configure configuration information for the received candidate cell(s) for future access (e.g., future access to a target base station).

[0551] In step 6, the terminal can transmit an RRC reconfiguration complete message to the source base station.

[0552] Accordingly, the LTM preparation process is completed, and subsequently, the LTM execution process can be performed.

[0553] In step 7, the terminal can transmit the measurement report to the source base station.

[0554] Based on the measurement report from the terminal, the source base station can determine whether LTM is available.

[0555] In step 8, the source base station may transmit an LTM cell switch command to the terminal via MAC CE. The terminal may create a new KgNB for the candidate cell(s) of the target base station(s).

[0556] For example, KgNB** may also be referred to as the new KgNB*. In this disclosure, the new KgNB* and KgNB** may be used as terms with the same meaning.

[0557] In step 9, the source base station may transmit a cell switch notification or cell change notification message to the target base station.

[0558] In step 10, the terminal can access a specific cell of the target base station by performing a RACH procedure. Alternatively, the terminal may access a specific cell of the target base station without a RACH procedure.

[0559] If the cell switch is successful, in step 11, the terminal can send an RRC reset complete message to the target base station.

[0560] In step 12, the target base station can send a path switch request message to the AMF.

[0561] For example, the target base station can send an NGAP path switch request message to the AMF.

[0562] In step 13, the target base station may receive a first message from the AMF (e.g., an NGAP path switch request ACK (acknowledgement) message).

[0563] The first message provided by the AMF may include an NGAP-encrypted NCC. The target base station may obtain the plaintext NCC through NGAP decryption. The target base station may determine whether the obtained NCC contains the same value as the existing one or an updated value. If the serving base station / cell changes through a handover procedure such as an LTM, the NH changes, and the NCC value may be updated accordingly. If the NCC contains an updated value, the target base station may encrypt the NCC based on a higher-layer key. For example, the PDCP layer entity of the target base station may encrypt the NCC information containing the updated value using an RRC encryption key (e.g., KRRCenc) and / or an RRC integrity key (e.g., KRRCint).

[0564] The PDCP layer entity of the target base station may provide encrypted NCC information to the MAC layer entity in advance. Alternatively, if the encrypted NCC information is not delivered to the MAC layer entity after receiving the path switch request ACK message of step 13, the encrypted NCC information may be delivered to the MAC layer entity in response to a request from the MAC layer entity in step 16 described later.

[0565] Through the LTM procedure, a target base station for which LTM will be performed can be identified from among the target base station candidates, and the identified target base station can operate as a source base station after the LTM procedure is completed. This target base station (e.g., a base station identified as a new source base station) can generate new KgNB* for candidate cell(s) of surrounding target base station candidate(s).

[0566] In step 14, such a target base station (e.g., a base station designated as a new source base station) can transmit the newly generated KgNB* and NCC (the updated value of the NCC obtained from the AMF in step 13) to the target base station candidate(s).

[0567] In step 15, if a preset or preset condition for the measurement result value is satisfied, the terminal may transmit the measurement report to a target base station (e.g., a base station specified as a new source base station).

[0568] In step 16, the target base station (e.g., the base station designated as the new source base station) can transmit a second message (e.g., an LTM cell switch command) to the terminal.

[0569] For example, the second message may correspond to a MAC CE message. For example, the second message may correspond to an unprotected (or unencrypted) MAC CE.

[0570] For example, the second message may include NCC information. For example, the NCC information included in the second message may correspond to encrypted NCC information. For example, after receiving the first message in step 13, the PDCP layer entity of the target base station (e.g., the base station designated as the new source base station) may perform encryption on the NCC information (of the updated value) and provide the encrypted NCC information to the MAC layer entity in advance. Alternatively, if the MAC layer entity intending to transmit the second message in step 16 does not possess the NCC information provided in advance, the encrypted NCC information may be provided to the MAC layer entity from the PDCP layer entity in response to the request of the MAC layer entity. Accordingly, the target base station (e.g., the base station designated as the new source base station) may transmit the second message containing the encrypted NCC information to the terminal.

[0571] In step 17, the terminal and the target base station (e.g., the base station designated as the new source base station) can perform the rest of the LTM process. For example, the terminal may perform RACH to the target base station (e.g., the base station designated as the new source base station) to obtain TA, or perform the cell switch procedure using previously obtained TA information without RACH.

[0572] FIG. 29 is a diagram showing the operation of the CU and DU on the target base station side and the terminal side by layer according to the present disclosure.

[0573] The example in FIG. 29 may correspond to a detailed example of a layered operation related to step 16 of FIG. 28. The target base station (e.g., a base station specified as a new source base station) is illustrated by dividing the CU and DU.

[0574] Step 1 may not be performed if the encrypted NCC is provided in advance without a request from the MAC layer entity of the DU. If the MAC layer entity does not have the encrypted NCC information, it may request the (encrypted) NCC from the PDCP layer entity to generate a MAC CE message to be transmitted to the terminal.

[0575] In Step 2, the PDCP layer entity of the CU may transmit the encrypted NCC to the MAC layer entity in response to a request from the MAC layer entity, or after obtaining updated NCC information. For example, the PDCP layer entity may encrypt the NCC using an RRC encryption key and / or an RRC integrity key.

[0576] The MAC layer entity of the DU can generate a MAC CE containing an encrypted NCC.

[0577] In step 3, the MAC CE generated by the MAC layer of the DU can be transmitted through the physical channel (e.g., PDSCH) of the DU's PHY. The UE's PHY can decode PDSCH to obtain the MAC CE and pass it to the MAC layer.

[0578] In step 4, the UE's MAC layer entity can parse the encrypted NCC contained in the MAC CE and pass it to the UE's PDCP layer entity to request NCC decryption.

[0579] The NCC decrypted from the PDCP layer entity can be used to generate a new security key (e.g., AS key derivation) for additional handovers such as subsequent LTMs.

[0580] As such, according to the examples of the present disclosure, information regarding AS key derivation in a handover procedure such as an existing LTM can be transmitted while encrypted / protected. Therefore, even if information regarding AS key derivation is provided to a terminal through an unprotected message such as MAC CE, the security of said information regarding AS key derivation can be maintained, and a faster and more reliable handover procedure can be performed.

[0581] The embodiments described above are combinations of the components and features of the present disclosure in a specific form. Each component or feature should be considered optional unless otherwise explicitly stated. Each component or feature may be implemented in a form not combined with other components or features. Additionally, it is possible to construct embodiments of the present disclosure by combining some components and / or features. The order of operations described in the embodiments of the present disclosure may be changed. Some components or features of one embodiment may be included in another embodiment, or may be replaced with corresponding components or features of another embodiment. It is obvious that embodiments may be constructed by combining claims that are not explicitly related in the claims, or that they may be included as new claims by amendment after filing.

[0582] It is obvious to those skilled in the art that the present disclosure may be embodied in other specific forms without departing from the essential features of the present disclosure. Accordingly, the foregoing detailed description should not be interpreted restrictively in all respects and should be considered exemplary. The scope of the present disclosure shall be determined by a reasonable interpretation of the appended claims, and all modifications within the equivalent scope of the present disclosure are included within the scope of the present disclosure.

[0583] The scope of the present disclosure includes software or machine-executable instructions (e.g., operating systems, applications, firmware, programs, etc.) that enable operations according to the methods of various embodiments to be executed on a device or computer, and a non-transitory computer-readable medium on which such software or instructions, etc. are stored and executable on a device or computer. Instructions that may be used to program a processing system to perform the features described in the present disclosure may be stored on or within a storage medium or a computer-readable storage medium, and the features described in the present disclosure may be implemented using a computer program product comprising such a storage medium. The storage medium may include, but is not limited to, high-speed random access memory such as DRAM, SRAM, DDR RAM, or other random access solid-state memory devices, and may include non-volatile memory such as one or more magnetic disk storage devices, optical disk storage devices, flash memory devices, or other non-volatile solid-state storage devices. The memory may optionally include one or more storage devices located remotely from the processor(s). Memory or alternatively, non-volatile memory device(s) within memory comprises a non-transient computer-readable storage medium. The features described in this disclosure may be stored in any one of the machine-readable media and integrated into software and / or firmware that can control the hardware of a processing system and allow the processing system to interact with other mechanisms utilizing results according to the embodiments of this disclosure. Such software or firmware may include, but is not limited to, application code, device drivers, operating systems, and execution environments / containers.

[0584] Here, the wireless communication technology implemented in the device of the present disclosure may include LTE, NR, and 6G, as well as Narrowband Internet of Things for low-power communication. In this case, for example, NB-IoT technology may be an example of LPWAN (Low Power Wide Area Network) technology and may be implemented according to standards such as LTE Cat NB1 and / or LTE Cat NB2, but is not limited to the aforementioned names. Additionally or generally, the wireless communication technology implemented in the device of the present disclosure may perform communication based on LTE-M technology. In this case, for example, LTE-M technology may be an example of LPWAN technology and may be referred to by various names such as eMTC (enhanced Machine Type Communication). For example, LTE-M technology may be implemented in at least one of various standards such as 1) LTE CAT 0, 2) LTE Cat M1, 3) LTE Cat M2, 4) LTE non-BL (non-Bandwidth Limited), 5) LTE-MTC, 6) LTE Machine Type Communication, and / or 7) LTE M, and is not limited to the aforementioned names. Additionally or generally, wireless communication technology implemented in the device (100, 200) of the present disclosure may include at least one of ZigBee, Bluetooth, and Low Power Wide Area Network (LPWAN) for low-power communication, and is not limited to the aforementioned names. As an example, ZigBee technology may create personal area networks (PANs) related to small / low-power digital communication based on various standards such as IEEE 802.15.4, and may be referred to by various names.

[0585] Although the method proposed in this disclosure has been described with an example applied to 3GPP LTE / LTE-A, 5G, and 6G systems, it is possible to apply it to quantum-based communication in various wireless communication systems in addition to 3GPP LTE / LTE-A, 5G, and 6G systems.

Claims

1. A step of receiving a first message containing an updated value of information regarding an access layer (AS) key derivation from a second network node by a first network node; Based on the updated value of the information regarding the AS key derivation, the step of providing the encrypted value of the information regarding the AS key derivation to the lower layer entity of the first network node by the upper layer entity of the first network node; and A method comprising the step of transmitting a second message containing the encrypted value of the information regarding the AS key derivation to a terminal by the first network node.

2. In Paragraph 1, A method in which the upper layer entity provides the encrypted value of the information regarding the AS key derivation to the lower layer entity without a request from the lower layer entity, or after the first network node receives the first message.

3. In Paragraph 1, A method in which the upper layer entity provides the encrypted value of the information regarding the AS key derivation to the lower layer entity in response to a request from the lower layer entity.

4. In Paragraph 1, The information regarding the above AS key derivation is a method that is encrypted based on a higher-level key.

5. In Paragraph 4, A method in which the upper layer key comprises one or more of an RRC (radio resource control) encryption key or an RRC integrity key.

6. In Paragraph 1, A method comprising an NCC (next hop chaining counter) for information regarding the AS key derivation above.

7. In Paragraph 1, A method in which the first message above is a new generation application protocol (NGAP) path switch request acknowledge message.

8. In Paragraph 1, The above second message is an unprotected message, 9. In Paragraph 1, The above second message comprises a layer 1 / layer 2 triggered mobility (LTM) cell switch command, a medium access control (MAC), and a control element (CE), in a method.

10. In Paragraph 1, The above method is a method performed in connection with an inter-centralized unit LTM procedure based on L1 / L2 (layer 1 / layer 2) measurement reports of the terminal.

11. In Paragraph 1, The above-mentioned first network node is a method corresponding to a target base station or target CU of an LTM procedure.

12. In Paragraph 1, The above-mentioned second network node is an AMF (access and mobility management function), a method.

13. In Paragraph 1, The above upper layer is the PDCP (packet data convergence protocol) layer, and The above lower layer is a MAC (medium access control) layer, a method.

14. One or more transceivers; and It includes one or more processors connected to the above one or more transmitters and receivers, and The above one or more processors are: A step of receiving a first message containing an updated value of information regarding access layer (AS) key derivation from a second network node through one or more transceivers of a first network node; Based on the updated value of the information regarding the AS key derivation, the encrypted value of the information regarding the AS key derivation is provided to the lower-level entity of the first network node by the upper-level entity of the first network node; and A first network node configured to transmit a second message containing the encrypted value of the information regarding the AS key derivation to a terminal through one or more transceivers of the first network node.

15. A step of receiving a message containing an encrypted value of information regarding an access layer (AS) key derivation from a first network node by a terminal; A step of receiving the encrypted value of the information regarding the AS key derivation from the lower layer of the terminal and decrypting it by the upper layer of the terminal; and A method comprising the step of encrypting or decrypting one or more of user plane data or control plane messages based on information regarding the decrypted AS key derivation.

16. One or more transceivers; and It includes one or more processors connected to the above one or more transmitters and receivers, and The above one or more processors are: Receiving a message containing an encrypted value of information regarding access layer (AS) key derivation from a first network node through one or more transceivers of the terminal; A step of receiving the encrypted value of the information regarding the AS key derivation from the lower layer of the terminal and decrypting it by the upper layer of the terminal; and A terminal configured to encrypt or decrypt one or more of user plane data or control plane messages based on information regarding the decrypted AS key derivation.

17. One or more processors; and A processing device comprising one or more computer memories that are operably connected to one or more processors and store instructions for performing a method according to any one of claims 1 to 13 based on execution by one or more processors.

18. One or more non-transitory computer-readable media storing one or more instructions that are executed by one or more processors to control the execution of a method according to any one of claims 1 through 13.