Intra-cell handover using lower-layer triggered mobility (LTM) cell switch
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- NOKIA TECHNOLOGIES OY
- Filing Date
- 2026-01-16
- Publication Date
- 2026-08-06
Smart Images

Figure EP2026051001_06082026_PF_FP_ABST
Abstract
Description
INTRA-CELL HANDOVER USING LOWER-LAYER TRIGGERED MOBILITY (LTM) CELL SWITCH TECHNOLOGICAL FIELD
[0001] The present disclosure relates generally to telecommunications and, in particular, to lower-layer triggered mobility (LTM) of a user equipment (UE) in a telecommunications system.BACKGROUND
[0002] Telecommunications systems can be seen as facilities that enable communications between two or more entities such as between two user equipment, between a user equipment and a base station, between two base stations, a user equipment and a network function of a communication network and / or a base station and other nodes. A telecommunications system can include a communication network and one or more user equipment. The communication sessions may comprise, for example, communication of data for carrying communications such as voice, video, electronic mail (email), text message, multimedia and / or content data and so on. Non-limiting examples of services provided comprise two-way or multi-way calls, data communication or multimedia services and access to a data network system, such as the Internet.
[0003] In a telecommunications system that includes a wireless communication network, at least a part of a communication session between at least two stations occurs over a wireless link. Examples of wireless communication networks comprise public land mobile networks (PLMN), satellite based communication networks and different wireless local networks, for example wireless local area networks (WLAN). Some wireless communication networks can be divided into cells, and are therefore often referred to as cellular networks.
[0004] A user can access the telecommunications system by means of an appropriate communication device or terminal. A communication device of a user may be referred to as user equipment (UE) or user device. A communication device is provided with anappropriate signal receiving and transmitting apparatus for enabling communications, for example enabling access to a communication network or communications directly with other users. The communication device may access a carrier provided by, for example, a base station of a cell, and transmit and / or receive communications on the carrier.
[0005] Telecommunications systems have evolved through multiple generations, each bringing advancements in speed, capacity, and functionality. The Evolved Packet System (EPS) represents the 4G architecture, which includes Long-Term Evolution (LTE) and LTE-Advanced (LTE-A) as its radio access technologies. The 5G System (5GS) builds upon EPS, introducing 5G New Radio (5GNR) for enhanced mobile broadband, massive machine-type communications, and ultra-reliable low-latency communications. The future 6G System (6GS) is expected to further revolutionize telecommunications with even more advanced capabilities. These systems are interconnected, with 5GS designed to interwork with EPS for seamless service continuity. The 3rd Generation Partnership Project (3 GPP) plays a crucial role in developing and maintaining standards for these telecommunications systems, ensuring global interoperability and evolution from Universal Mobile Telecommunications System (UMTS) (3G) through to the ongoing development of 6G technologies.
[0006] In 3 GPP, mainstream mobility of a UE from a source cell to a target cell has been conducted using higher layer mobility. A more recent enhancement in 3 GPP is lower-layer triggered mobility (LTM), which involves moving execution of a ‘handover’ from the source cell to the target cell from a higher layer, such as the radio resource control (RRC) layer, to lower layers. Upon a handover from a source cell to a target cell, the target cell may receive new security context data associated with the UE. The target cell may initiate an intra-cell handover procedure with the UE to apply the new security context data, which as currently specified includes an RRC reconfiguration procedure. LTM, however, aims to avoid RRC signaling during handover, and the corresponding latency that comes with that RRC signaling.BRIEF SUMMARY
[0007] Example implementations of the present disclosure are directed to lower-layer triggered mobility (LTM) of a user equipment (UE) in a telecommunications system. The present disclosure includes, without limitation, the following example implementations.
[0008] Some example implementations provide an apparatus to implement a user equipment (UE), the apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least: perform a lower-layer triggered mobility (LTM) handover of the UE from a source cell to a target cell; receive, from the target cell, security context data associated with the UE; receive, from the target cell, an LTM cell switch command that includes an indication for an intra-cell LTM handover; and in response to the LTM cell switch command, perform the intra-cell LTM handover, including apply the security context data to a security context of the UE.
[0009] Some example implementations provide a method performed by a user equipment (UE), the method comprising: performing a lower-layer triggered mobility (LTM) handover of the UE from a source cell to a target cell; receiving, from the target cell, security context data associated with the UE; receiving, from the target cell, an LTM cell switch command that includes an indication for an intra-cell LTM handover; and in response to the LTM cell switch command, performing the intra-cell LTM handover, including applying the security context data to a security context of the UE.
[0010] Some example implementations provide an apparatus to implement a target cell, the apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least: perform a lower-layer triggered mobility (LTM) handover of the UE from a source cell to the target cell; receive security context data associated with the UE in a path switch procedure associated with the LTM handover; send, to the UE, the security context data; and send, to the UE, an LTM cell switch command that includes an indication for an intra-cell LTM handover for the UE to apply the security context data to the security context of the UE.
[0011] Some example implementations provide a method performed by a target cell, the method comprising: performing a lower-layer triggered mobility (LTM) handover ofthe UE from a source cell to the target cell; receiving security context data associated with the UE in a path switch procedure associated with the LTM handover; sending, to the UE, the security context data; and sending, to the UE, an LTM cell switch command that includes an indication for an intra-cell LTM handover for the UE to apply the security context data to the security context of the UE.
[0012] Some example implementations provide an apparatus to implement a user equipment (UE), the apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least: receive, from a source cell, a lower-layer triggered mobility (LTM) configuration and an intra-cell LTM configuration for a target cell, the intra-cell LTM configuration for the target cell including a configured uplink grant; perform an LTM handover to the target cell using the LTM configuration for the target cell; receive, from the target cell, security context data associated with the UE; receive, from the target cell, an LTM cell switch command that includes an indication for an intra-cell LTM handover; and in response to the LTM cell switch command, perform the intra-cell LTM handover using the intra-cell LTM configuration for the target cell, including: apply the security context data to a security context of the UE; and send a radio resource control (RRC) reconfiguration complete message to the target cell using the configured uplink grant from the intra-cell LTM configuration for the target cell.
[0013] Some example implementations provide a method performed by a user equipment (UE), the method comprising: receiving, from a source cell, a lower-layer triggered mobility (LTM) configuration and an intra-cell LTM configuration for a target cell, the intra-cell LTM configuration for the target cell including a configured uplink grant; performing an LTM handover to the target cell using the LTM configuration for the target cell; receiving, from the target cell, security context data associated with the UE; receiving, from the target cell, an LTM cell switch command that includes an indication for an intra-cell LTM handover; and in response to the LTM cell switch command, performing the intra-cell LTM handover using the intra-cell LTM configuration for the target cell, including: applying the security context data to a security context of the UE; and sending a radio resource control (RRC) reconfiguration complete message to thetarget cell using the configured uplink grant from the intra-cell LTM configuration for the target cell.
[0014] Some example implementations provide an apparatus to implement a target cell, the apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least: send, to a source cell, a lower-layer triggered mobility (LTM) configuration, and an intra-cell LTM handover configuration including a configured uplink grant; perform an LTM handover of a user equipment (UE) to the target cell using the LTM configuration; receive security context data associated with the UE in a path switch procedure associated with the LTM handover; send, to the UE, the security context data; send, to the UE, an LTM cell switch command that includes an indication for an intra-cell LTM handover for the UE to apply the security context data to the security context of the UE; and receive, from the UE, a radio resource control (RRC) reconfiguration complete message using the configured uplink grant from the intra-cell LTM configuration.
[0015] Some example implementations provide a method performed by a target cell, the method comprising: sending, to a source cell, a lower-layer triggered mobility (LTM) configuration, and an intra-cell LTM handover configuration including a configured uplink grant; performing an LTM handover of a user equipment (UE) to the target cell using the LTM configuration; receiving security context data associated with the UE in a path switch procedure associated with the LTM handover; sending, to the UE, the security context data; sending, to the UE, an LTM cell switch command that includes an indication for an intra-cell LTM handover for the UE to apply the security context data to the security context of the UE; and receiving, from the UE, a radio resource control (RRC) reconfiguration complete message using the configured uplink grant from the intra-cell LTM configuration.
[0016] These and other features, aspects, and advantages of the present disclosure will be apparent from a reading of the following detailed description together with the accompanying figures, which are briefly described below. The present disclosure includes any combination of two, three, four or more features or elements set forth in this disclosure, regardless of whether such features or elements are expressly combined orotherwise recited in a specific example implementation described herein. The present disclosure is intended to be read holistically such that any separable features or elements of the disclosure, in any of its aspects and example implementations, should be viewed as combinable unless the context of the disclosure clearly dictates otherwise.
[0017] It will therefore be appreciated that this Brief Summary is provided merely for purposes of summarizing some example implementations so as to provide a basic understanding of some aspects of the disclosure. Accordingly, it will be appreciated that the above described example implementations are merely examples and should not be construed to narrow the scope or spirit of the disclosure in any way. Other example implementations, aspects and advantages will become apparent from the following detailed description taken in conjunction with the accompanying figures which illustrate, by way of example, the principles of some described example implementations.BRIEF DESCRIPTION OF THE FIGURE(S)
[0018] Having thus described example implementations of the disclosure in general terms, reference will now be made to the accompanying figures, which are not necessarily drawn to scale, and wherein:
[0019] FIG. 1 illustrates a telecommunications system that includes one or more public land mobile networks (PLMNs) coupled to one or more external data networks, according to some example implementations of the present disclosure;
[0020] FIG. 2 illustrates a PLMN, according to some example implementations;
[0021] FIGS. 3Aand 3B illustrate a signaling chart for lower-layer triggered mobility (LTM), according to some example implementations;
[0022] FIGS. 4Aand 4B illustrate a signaling chart for LTM, according to some other example implementations;
[0023] FIG. 5 is a flowchart illustrating various steps in a method performed by a user equipment (UE), according to various example implementations;
[0024] FIG. 6 is a flowchart illustrating various steps in a method performed by a target cell, according to various example implementations;
[0025] FIG. 7 is a flowchart illustrating various steps in a method performed by a UE, according to various example implementations;
[0026] FIG. 8 is a flowchart illustrating various steps in a method performed by a target cell, according to various example implementations; and
[0027] FIG. 9 illustrates an apparatus according to some example implementations.DETAILED DESCRIPTION
[0028] Some implementations of the present disclosure will now be described more fully hereinafter with reference to the accompanying figures, in which some, but not all implementations of the disclosure are shown. Indeed, various implementations of the disclosure may be embodied in many different forms and should not be construed as limited to the implementations set forth herein; rather, these example implementations are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art. Like reference numerals refer to like elements throughout.
[0029] Unless specified otherwise or clear from context, references to first, second or the like should not be construed to imply a particular order. A feature described as being above another feature (unless specified otherwise or clear from context) may instead be below, and vice versa; and similarly, features described as being to the left of another feature else may instead be to the right, and vice versa. Also, while reference may be made herein to quantitative measures, values, geometric relationships or the like, unless otherwise stated, any one or more if not all of these may be absolute or approximate to account for acceptable variations that may occur, such as those due to engineering tolerances or the like.
[0030] As used herein, unless specified otherwise or clear from context, the “or” of a set of operands is the “inclusive or” and thereby true if and only if one or more of the operands is true, as opposed to the “exclusive or” which is false when all of the operands are true. Thus, for example, “[A] or [B]” is true if [A] is true, or if [B] is true, or if both [A] and [B] are true. Further, the articles “a” and “an” mean “one or more,” unless specified otherwise or clear from context to be directed to a singular form. Furthermore, it should be understood that unless otherwise specified, the terms “data,” “content,” “digital content,” “information,” and similar terms may be at times used interchangeably. The term “network” may refer to a group of interconnected computers including clientsand servers; and within a network, these computers may be interconnected directly or indirectly by various means including via one or more switches, routers, gateways, access points or the like.
[0031] The present disclosure discusses telecommunication systems and mobile or cellular networks and user equipment thereof, and while specific terms may be used, are broadly applicable across various technologies. For instance, while the present disclosure may reference radio access technologies such as 5G NR and 5G Advanced, the present disclosure is equally relevant to next generation radio access technologies, such as 6G. Example implementations of the present disclosure described herein also mention public land mobile networks (PLMNs) and mobile network operators (MNOs), but example implementations are similarly applicable to standalone non-public networks (SNPNs) . Furthermore, although some examples and figures focus on radio access networks (RANs) and in particular radio access networks that operate in accordance with the 3 GPP standard for 5G NR (generally referred to as 3 GPP access or 3 GPP access networks), example implementations are applicable to any type of access networks. This includes not only 3GPP access networks but also non-3GPP access networks, such as wireline access, untrusted non-3GPP access network, and trusted non-3GPP access network using wireless access gateway function (W-AGF), non-3GPP interworking function (N3IWF), or trusted non-3GPP gateway function (TNGF) to connect to a core network (e.g., a 5G core network (5GC) or a 6G core network (6GC)) of a mobile or cellular network.
[0032] Further, as used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry); (b) combinations of hardware circuits and software, such as (as applicable): (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions); or (c) hardware circuit(s) and / or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0033] The above definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0034] FIG. 1 illustrates a telecommunications system 100 according to various example implementations of the present disclosure. Examples of suitable telecommunications systems include UMTS, EPS and 5GS, as well as the future 6GS. The telecommunications system 100 (otherwise referred to as system 100) generally includes one or more mobile or cellular networks, and these mobile or cellular networks may interwork between telecommunications systems. As shown, for example, the system 100 includes one or more PLMNs 102 coupled to one or more other external data networks 104 - notably including a wide area network (WAN) such as the Internet. As will be appreciated, a PLMN may be a standalone PLMN that includes a 5GC, or may be a non-standalone PLMN that includes both an Evolved Packet Core (EPC) and a 5GC connected to a RAN.
[0035] Each of the PLMNs 102 includes a core network (CN) 106, such as the EPC, the 5GC, or a 6GC; and each CN is coupled to one or more RANs 108 that implement one or more radio access technologies (RATs). Examples of these RANs include the evolved UMTS terrestrial radio access network (E-UTRAN) of 4G LTE, the next generation (NG) radio access network (NG-RAN) of 5GNR, and the 6GRAN. As used herein, a “network device” refers to any suitable device of a RAN or a core network of a telecommunications system. Examples of suitable network devices are described in greater detail below.
[0036] Examples of RATs include 3GPP radio access technologies such as GSM, CDMA2000 IxEV-DO (HRPD), CDMA2000 lx (IxRTT), UTRA, E-UTRA, 5GNR, 5G Advanced, and 6G. Other examples of RATs include IEEE 802 technologies such as IEEE 802.11 (Wi-Fi), IEEE 802.15 (including 802.15.1 (WPAN / Bluetooth), 802.15.4(Zigbee) and 802.15.6 (WBAN)), Bluetooth, Bluetooth Low Energy (BLE), ultra wideband (UWB), and the like. Generally, a RAT may refer to any 2G, 3G, 4G, 5G, 6G or higher generation RAT and their different versions, as well as to any other RAT that may be arranged to interwork with such a RAT to provide access to the CN 106 of a MNO.
[0037] The telecommunications system 100 also includes one or more communication devices that may be varyingly known as user equipment (UE) 110, terminal device, terminal equipment, mobile station or the like. The UE is generally a device configured to communicate with a network device (e.g., an access node such as a RAN node of RAN 108) or a or a further UE in the telecommunications system. The UE may be a portable computer (e.g., laptop, notebook, tablet computer), mobile phone (e.g., cell phone, smartphone), wearable computer (e.g., smartwatch), or the like. In other examples, the UE may be an Internet of things (loT) device, an industrial loT (IIoT device), a vehicle equipped with a vehicle-to- everything (V2X) communication technology, or the like. In some examples, as referenced by 3 GPP, the UE may be a narrowband loT (NB-IoT) device, an enhanced machine-type communication (eMTC) device, a reduced capability (RedCap) device, an ambient loT device, or the like.
[0038] In operation, these UEs 110 may connect to one or more RAN nodes of the RANs 108 according to their particular RATs to thereby access a particular CN 106 of a PLMN 102, or to access one or more of the external data networks 104 (e.g., the Internet) or services provided by the PLMN. The external data network may provide Internet access, or 3rd party services. For example, the International Telecommunication Union (ITU) has classified 5G mobile network services (e.g., services provided by a 5G mobile network) into three categories: enhanced mobile broadband (eMBB), ultra-reliable and low-latency communications (URLLC), and massive machine type communications (mMTC) or massive internet of things (MIoT).
[0039] In various examples, a RAN 108 may be configured to provide one or more macrocells, microcells, picocells, femtocells or the like. The RAN 108 may generally include one or more RAN nodes that interact with UEs 110. In various examples, a RAN node may be referred to as a base station (BS), access point (AP), base transceiver station (BTS). Examples of RAN nodes includes a Node B (NB), evolved NB (eNB), macro BS,NB (MNB) or eNB (MeNB), home BS, NB (HNB) or eNB (HeNB), next generation NB (gNB), enhanced gNB (en-gNB), next generation eNB (ng-eNB), 6G NB (6gNB), or the like. The term ‘gNB’ in 5G NR may correspond to the eNB in 4G LTE. Also, a NG-RAN node may refer to a gNB or a ng-eNB. And unless otherwise specified, a gNB in 5G NR or a 6gNB in 6G may at times be more generally referred to as a (6)gNB or more simply a gNB.
[0040] The RAN 108 may include some type of network controlling / governing entity responsible for control of the RAN nodes. The network controlling / governing entity and RAN node may be separate or integrated into a single apparatus. The network controlling / governing entity may include processing circuity configured to carry out various management functions for controlling RAN nodes of the RAN 108. The processing circuity may be associated with a memory, computer-readable storage medium or a data storage device comprising a database for maintaining information required in the various management functions.
[0041] FIG. 2 illustrates an example of a PLMN 102, such as 4G LTE, 5G NR or 6G PLMN that communicates with a UE 110 and an external data network 104 of the telecommunications system 100. As shown, the RAN 108 (e.g., E-UTRAN, NG-RAN, 6G RAN) includes one or more RAN nodes 202 configured to connect one or more UEs to the RAN to thereby access the CN 106 (e.g., EPC, 5GC, 6GC). In 4G LTE, the UE, E-UTRAN and EPC compose EPS. Similarly, in 5GNR, the UE, NG-RAN and 5GC compose the 5GS. And in 6G, the UE, 6GRAN and 6GC compose the 6GS.
[0042] In some implementations, operations of a gNB or other a RAN node may be distributed or functionally split into components including one or more remote radio head (RRHs) or radio units (RUs), and a baseband unit (BBU); and in some implementations, the BBU may be split into a central / centralized unit (CU) (central node) and a distributed unit (DU) (distributed node). The CU may be, for example, a server, host or node. In some implementations, the RRH / RU and DU may be collocated at a network device. It is also possible that operations of a gNB or RAN node may be distributed among a plurality of servers, hosts or nodes.
[0043] It should also be understood that the distribution of work between core network operations and RAN node operations may vary depending on implementation. A5G or 6G network architecture, for example, may be based on a so-called CU-DU split. One gNB-CU (a CU 204) may control one or more gNB-DUs (DUs 206). The gNB-CU may control a plurality of spatially separated gNB-DUs, acting at least as transmit / receive (Tx / Rx) nodes. In some example implementations, however, the gNB-DUs may include, for example, a radio link control (RLC), medium access control (MAC) layer and a physical (PHY) layer, whereas the gNB-CU may include the layers above the RLC layer, such as a packet data convergence protocol (PDCP) layer, a radio resource control (RRC), and an internet protocol (IP) layer. Other functional splits are also possible. It is considered that skilled person is familiar with the open systems interconnection (OSI) model and the functionalities within each layer.
[0044] In some example implementations, the server or CU 204 may generate a virtual network through which the server communicates with the radio node. In general, virtual networking may involve a process of combining hardware and software network resources and network functionality into a single, software-based administrative entity, a virtual network. Such virtual network may provide flexible distribution of operations between the server and the radio head / node. In practice, any digital signal processing task may be performed in either the CU or the DU 206, and the boundary where the responsibility is shifted between the CU and the DU may be selected according to implementation.
[0045] As also shown, CN 106 may include a number of network functions (NFs) divided between the control plane (CP) and the user plane (UP). In particular, for example, the CN may include, for example, a NF for access and mobility management (MM), such as a mobility management entity (MME) in the EPS, a 5G MM or access and mobility management function (AMF) 208 in the 5GS, or a 6G MM in the 6GS. The CN may include a NF for session management (SM), such as a serving gateway (SGW) control plane function (SGW-C) and / or packet data network gateway (PGW) control plane function (PGW-C) in the EPS, a 5G SM or session management function (SMF) 210 in the 5GS, or a 6G SM in the 6GS. The CN may also include a NF for reception and transmission of traffic (e.g., data), such as a SGW user plane function (SGW-U) and / or PGW user plane function (PGW-U) in the EPS, or a user plane function (UPF) 212 in 5GS / 6GS.
[0046] In 3 GPP, mainstream mobility has been conducted using higher layer (L3 or RRC controlled) mobility. In this regard, L3 handover based mobility is a well-known and proven method for ensuring a robust way of handing over the UE 110 from one serving cell (source cell) of a RAN node 202 to a new serving cell (target cell) of the same or another RAN node. The method has been used at least since GSM and is still in use in 5G NR. It is expected that L3 mobility (legacy handover) will also be commonly used in the future.
[0047] As the wireless generations evolve, however, so does the need for new and different solutions enabling more flexible, more efficient and sometimes faster procedures making the system seem more agile. One such enhancement includes moving the execution of the ‘handover’ from one cell to another from higher layers (L3), such as RRC, to lower layers. These lower layers may be either PHY (or LI) or MAC (or L2). This feature is currently referred to as L1 / L2- triggered mobility, or lower-layer triggered mobility (LTM), which may reduce latency, overhead and interruption time when compared to L3 handover based mobility. In a CU-DU split architecture, LTM may support one or more of intra-DU mobility, intra-CU inter-DU mobility, or inter-CU inter-DU mobility.
[0048] Upon an inter-CU handover of a UE 110 to a target cell (new serving cell) of a target (new serving) RAN node 202, the RAN node (CU 204) may send a path switch request to the AMF 208. The AMF may in turn send a path switch acknowledge message to the RAN node. In the path switch acknowledge message, the AMF may include or indicate (new) security context data associated with the UE. This security context data may include or indicate a new security policy or new security context (NewSecurityContextlnd). Upon receiving the security context data, the RAN node may initiate an intra-cell handover procedure with the UE, including an RRC reconfiguration with sync procedure, to apply the security context data. In this regard, an intra-cell handover is a handover in which the source cell and the target cell are the same cell.
[0049] More particularly, for example, if the target RAN node 202 receives UE’s UP security policy from the SMF 210 in the path switch acknowledge message, the target RAN node may update the UE’s UP security policy with the received UE’s UP security policy. If UE’s current UP confidentiality and / or UP integrity protection activation isdifferent from the received UE’s UP security policy, the target RAN node may initiate intra-cell handover procedure, which may include RRC reconfiguration to reconfigure data radio bearers (DRBs) to activate or deactivate the UP integrity / confidentiality as per the received policy from SMF.
[0050] In the case where the target RAN node receives both UE security capability and UP security policy, the target RAN node may initiate the intra-cell handover procedure which may include a selected algorithm and a next hop chaining counter (NCC) to the UE 110. Both the UE and the RAN node may derive (based on the selected algorithm and NCC) and use new UP keys.
[0051] As another more particular example, if the target RAN node 202 receives UE’s security capabilities from the AMF 208 in the path switch acknowledge message, the target RAN node may update the access stratum (AS) security context of the UE 110 with these security capabilities of the UE. The target RAN node may select an algorithm with highest priority from the security capabilities according to a locally-configured, prioritized list of algorithms, such as for both integrity and ciphering algorithms. If the algorithms selected by the target RAN node are different from the algorithms used at the source RAN node, the target RAN node may initiate an intra-cell handover procedure, which may include RRC reconfiguration indicating the selected algorithms and an NCC to the UE.
[0052] An intra-cell handover procedure with an RRC reconfiguration may therefore be used to apply new security context data at the UE 110 upon an inter-CU handover of the UE. LTM, however, aims to avoid RRC signaling during handover, and the corresponding latency that comes with that RRC signaling. Example implementations of the present disclosure therefore provide a solution in which an intra-cell handover may be initiated without RRC reconfiguration.
[0053] As described in greater detail below, in some example implementations of the present disclosure, the UE 110 may receive, from the target cell (e.g., from a target DU 206 of a target RAN node 202), an LTM cell switch command (CSC), such as a MAC control element (CE), from the target cell that includes an indication for the intra-cell LTM handover. The UE may also receive, from the target cell, security context data associated with the UE, such as via the LTM cell switch command or a separate RRCmessage. In response to the LTM cell switch command, the UE 110 may perform the intra-cell LTM handover, which may include the UE applying the security context data to a security context of the UE.
[0054] In some examples, the UE may receive an intra-cell LTM configuration for each of one or more LTM candidate target cells, including the target cell configuration. The intra-cell LTM configuration for each LTM candidate target cell may include, for example, a configured uplink grant (CG). In some of these examples, the UE may perform the intra-cell LTM handover using the intra-cell LTM configuration, such as by applying the security context data to the security context of the UE, and sending a RRC reconfiguration complete message to the target cell using the configured uplink grant.
[0055] Some example implementations will be described in the context of inter-CU LTM mobility in a CU-DU split architecture (a distributed architecture). It should be understood, however, that example implementations may equally apply to a monolithic architecture of the RAN node. In either case, example implementations may apply to LTM mobility from a source RAN node to a target RAN node, which in the case of a CU-DU split architecture, may be for inter-CU inter-DU mobility. In this case, the source RAN node may include a source CU (S-CU) and a source DU (S-DU), and the (candidate) target RAN node may include a (candidate) target CU (T-CU) and at least one (candidate) target DU (T-DU).
[0056] According to some example implementations, during LTM preparation for an inter-CU LTM, each of one or more candidate target cells (candidate target RAN nodes 202) may prepare an LTM configuration and an intra-cell LTM configuration. The intra-cell LTM configuration may include one or more parameters for an intra-cell LTM handover, such as a cell radio network temporary identifier (C-RNU) allocated to the UE. In some examples, the intra-cell LTM configuration is a delta configuration applied over the LTM configuration for the intra-cell LTM handover. In some examples without an intra-cell LTM configuration, the LTM configuration may be used for both LTM handover and intra-cell LTM handover.
[0057] Upon the inter-CU LTM handover to a target cell (target RAN node 202) among the candidate target cell(s), the target RAN node may perform a path switch procedure with the AMF 208. During the path switch procedure, the AMF may provide,to the target RAN node, security context data (e.g., new security policy, new security context, new security context indication) associated with the UE 110, such as in a path switch acknowledge message.
[0058] The T-CU (of the target RAN node 202) may indicate to the T-DU (of the target RAN node) to perform intra-cell LTM handover, such as by including an indication for intra-cell LTM handover in a UE context modification request message. The T-CU may also include the security context data in the UE context modification request message. In response, the T-DU may send an LTM cell switch command (e.g., MAC CE) to the UE 110. The LTM cell switch command may include an indication for an intra-cell LTM handover, and may also include the security context data. In some examples, the T-DU may send the LTM cell switch command when there is not active UP for the UE such as to minimize any impact to the UP caused by the intra-cell LTM handover. Upon receiving the LTM cell switch command, the UE may perform the intra-cell LTM handover during which the UE may apply the security context data to the security context of the UE, such as with the C-RNTI from the intra-cell LTM configuration.
[0059] According to some other example implementations, the intra-cell LTM configuration prepared during LTM preparation may include parameters such as a C-RNTI allocated to the UE, and a configured uplink grant. Similar to before, upon the inter-CU LTM handover to a target cell (target RAN node 202) among the candidate target cell(s), the target RAN node may perform a path switch procedure with the AMF 208. During the path switch procedure, the AMF may provide, to the target RAN node, security context data (e.g., new security policy, new security context) associated with the UE 110, such as in a path switch acknowledge message.
[0060] The target RAN node 202 (e.g., T-CU) may send the security context data to the UE 110, such as in an RRC message. The UE may store the security context data.
[0061] The T-CU (of the target RAN node 202) may indicate to the T-DU (of the target RAN node) to perform intra-cell LTM handover, such as by including an indication for intra-cell LTM handover in a UE context modification request message. In response, the T-DU may activate the configured uplink grant from the intra-cell LTM configuration. The T-DU may send an LTM cell switch command (e.g., MAC CE) to the UE 110, and the LTM cell switch command may include an indication for an intra-cell LTM handover.In some examples, the LTM cell switch command may include an identifier (ID) of the UE, such as a 3 GPP Release 19 ID allocated to the UE by the target cell (T-DU), and the ID may be set to a particular value (e.g., Rel 19 ID = 0) as the indication for the intra-cell LTM handover. In some other examples, the LTM cell switch command omits the ID of the UE, and omission of the ID is the indication for the intra-cell LTM handover.
[0062] Upon receiving the LTM cell switch command, the UE 110 may perform the intra-cell LTM handover. During the intra-cell LTM handover, the UE may apply the security context data (received in the RRC message) to the security context of the UE. In some examples, the security context data may be applied with the C-RNU (from the intra-cell LTM configuration), which may be used as a UE identifier used to transmit signaling or data between the UE and the target RAN node 202B. The UE may also perform a random access channel (RACH)-less access to the T-DU, such as by sending an RRC reconfiguration complete message to the target cell using the configured grant from the intra-cell LTM configuration.
[0063] To further illustrate some example implementations, FIGS. 3Aand 3B illustrate a signaling chart for an LTM procedure in a CU-DU split architecture, including a source RAN node 202A with a S-CU 204A and a S-DU 206A for a source (serving) cell, and a target RAN node 202B with T-CU 204B and a T-DU 206B for a (LTM candidate) target cell. Also shown is another candidate target RAN node 202C with a CU (CU3) 204C and a DU (DU3) 206C for another (LTM) candidate target cell.
[0064] As shown in FIG. 3A, at step 301, a UE 110 may be configured by the source RAN node 202A with measurement configurations for candidate target cells, including the (candidate) target cell provided by T-DU 206B and the other candidate target cell provided by DU3206C. The UE may perform L3 measurements on the candidate target cells, and the UE may at step 302 send, to the S-CU 204A, an L3 measurement report with measurement results of the L3 measurements on the candidate target cells. The S-CU may at step 303 decide to prepare LTM candidates based on the L3 measurement report.
[0065] The S-CU 204A may at steps 304, 305 send a handover request message to T-CU 204B and CU3204C to prepare LTM candidate target cells. Each of T-CU and CU3 prepares a LTM configuration (LTM candidate config) and an intra-cell LTMconfiguration. The intra-cell LTM configuration may include parameter(s) for an intracell LTM handover, such as a C-RNTI allocated to the UE. The T-CU and CU3 may at steps 306, 307 send handover request acknowledge messages to the S-CU, and the handover request acknowledge messages may include the LTM configurations and the intra-cell LTM configurations for the prepared LTM candidate target cells.
[0066] On receiving the LTM configurations and the intra-cell LTM configurations for the prepared LTM candidate target cells, the S-CU 204A may prepare an RRC reconfiguration message including the respective configurations. The S-CU may at step 308 send the RRC reconfiguration message to the UE 110. On receiving the RRC reconfiguration message, the UE may at steps 309, 310 store the respective configurations, and send an RRC reconfiguration complete message to the S-CU.
[0067] The UE 110 may perform LI measurements on the prepared LTM candidate target cells based on the LTM configurations, and the UE may at step 311 send, to the S-DU 206 A, an LI measurement report with measurement results of the LI measurements on the LTM candidate target cells. Based on the LI measurement report, the S-DU may at step 312 decide to initiate an LTM handover (cell switch) to the target cell provided by T-DU 206B of the target RAN node 202B. The S-DU may at steps 313, 314 send an LTM cell switch command (e.g., MAC CE) to the UE, and send a serving cell change notification to the S-CU 204A.
[0068] The UE 110 may perform the LTM handover to the target cell (T-DU 206B), and the UE may at step 315 send an RRC reconfiguration complete message to the T-CU 204B (via the T-DU); and as shown in FIG. 3B, the T-DU may at step 316 send an access notification to the T-CU. During the LTM handover, in some examples, the UE may apply a horizontal key derivation received by the UE in the LTM configuration for the target cell received by the UE at step 309.
[0069] Upon completion of the LTM handover to the target RAN node 202B, The T-CU 204B may at step 317 send a path switch request message towards the AMF 208 to initiate a path switch procedure. The AMF may at step 318 send a path switch acknowledge message to the T-CU. The path switch acknowledge message may include new security context data associated with the UE 110, such as a new security policy or new security context or NewSecurityContextlnd. In some more particular examples, thenew security context data may include a new NCC and / or next hop (NH) for the security context of the UE.
[0070] The T-CU 204B may at step 319 send a UE context release message to the S-CU 204A. And on receiving the new security context data associated with the UE, the T-CU may at step 320 decide to initiate an intra-cell LTM handover at the UE to apply the new security context data, such as for a key refresh of security keys in the security context of the UE. The T-CU may at step 321 send a UE context modification request message to the T-DU 206B, and the UE context modification request message may include an indication to initiate intra-cell LTM handover. The UE context modification request may also include the new security context data. On receiving the UE context modification request message, the T-DU may at step 322 send an LTM cell switch command (e.g., MAC CE) to the UE. The LTM cell switch command may include an indication for an intra-cell LTM handover, as well as the new security context data. The T-DU may at step 323 send a UE context modification response to the T-CU.
[0071] On receiving the cell switch command, the UE 110 may at step 324 perform the intra-cell LTM handover procedure indicated in the cell switch command. During the intra-cell LTM handover procedure, the UE may apply the new security context data included in the cell switch command, such as using a C-RNU indicated in the intra-cell LTM configuration. In a more particular example, the UE may apply the new security context data for a key refresh of the security keys in the security context of the UE. When the new security context data includes a new NCC, the UE may perform a vertical key update. When the security context data includes the same NCC (in the UE’s security context) or no NCC, the UE may perform a horizontal key update.
[0072] The UE 110 may at steps 325, 326 send an RRC reconfiguration complete message to the T-CU 204B to complete the intra-cell LTM handover procedure. The RRC reconfiguration complete message may include, for example, information that indicates the application of the new security context data with the C-RNU such that the target RAN node 202B may start decoding messages form the UE through the new security context data.
[0073] FIGS. 4A and 4B illustrate a signaling chart for an LTM procedure in a CU-DU split architecture, according to some other example implementations. As shown inFIG. 4A, the LTM procedure includes steps 301 to 304 as described above, including the S-CU 204A deciding to prepare LTM candidates, and sending a handover request message T-CU 204B and CU3 204C to prepare LTM candidate target cells. Each of T-CU and CU3 prepares a LTM configuration (LTM candidate config) and an intra-cell LTM configuration. The intra-cell LTM configuration may include parameter(s) for an intra-cell LTM handover, such as a C-RNTI allocated to the UE, and a configured uplink grant (CG). The T-CU and CU3 may at steps 406, 407 send handover request acknowledge messages to the S-CU, and the handover request acknowledge messages may include the LTM configurations and the intra-cell LTM configurations (with CG) for the prepared LTM candidate target cells.
[0074] On receiving the LTM configurations and the intra-cell LTM configurations for the prepared LTM candidate target cells, the S-CU 204A may prepare an RRC reconfiguration message including the respective configurations. The S-CU may at step 408 send the RRC reconfiguration message to the UE 110. On receiving the RRC reconfiguration message, the UE may at step 409 store the respective configurations (including CG). As shown in FIGS. 4Aand 4B, the procedure may include steps 310 to 318 as described above, during which an LTM decision may be made, and the UE may perform an LTM handover to the target cell (T-DU 206B) of the target RAN node 202B. And upon completion of the LTM handover to the target RAN node, the T-CU 204B may receive new security context data associated with the UE 110 during a path switch procedure with the AMF 208.
[0075] The T-CU 204B may at step 419 send an RRC message to the UE 110, and the RRC message may include the new security context data. The UE may at steps 420, 421 send a message response to the T-CU, and store the new security context data (e.g., in a source RRC configuration).
[0076] The T-CU 204B may at step 422 send a UE context release message to the S-CU 204A. The T-CU may at step 423 send a UE context modification request message to the T-DU 206B, and the UE context modification request message may include an indication to initiate intra-cell LTM handover. On receiving the UE context modification request message, the T-DU may at step 424 activate the CG for the target RAN node 202B, and initiate a cell switch for intra-cell LTM handover.
[0077] The T-DU 206B may at step 425 send an LTM cell switch command (e.g., MAC CE) to the UE 110. The LTM cell switch command may include an indication for an intra-cell LTM handover. In some examples, the LTM cell switch command may include a 3 GPP Release 19 ID of the UE set to a particular value (e.g., Rel 19 ID = 0) as the indication for the intra-cell LTM handover. In some other examples, the LTM cell switch command may omit the ID of the UE as the indication for the intra-cell LTM handover. The T-DU may at step 426 send a UE context modification response to the T-CU 204A.
[0078] On receiving the cell switch command, the UE 110 may at step 427 perform the intra-cell LTM handover procedure indicated in the cell switch command. During the intra-cell LTM handover procedure, the UE may apply the new security context data received at step 420 and stored, such as using a C-RNU indicated in the intra-cell LTM configuration. In a more particular example, the UE may apply the new security context data for a key refresh of the security keys in the security context of the UE. The UE may at step 428 send an RRC reconfiguration complete message to the T-CU 204B using the configured uplink grant (CG). The RRC reconfiguration complete message may include, for example, information that indicates the application of the new security context data with the C-RNTI. At step 429, the intra-cell LTM handover procedure may be completed such that the target RAN node 202B may start decoding messages form the UE through the new security context data.
[0079] FIG. 5 is a flowchart illustrating various steps in a method 500 performed by a user equipment (UE), according to various example implementations. The method includes performing a lower-layer triggered mobility (LTM) handover of the UE from a source cell to a target cell, as shown at block 502. The method includes receiving, from the target cell, security context data associated with the UE, as shown at block 504. The method includes receiving, from the target cell, an LTM cell switch command that includes an indication for an intra-cell LTM handover, as shown at block 506. And the method includes, in response to the LTM cell switch command, performing the intra-cell LTM handover, including applying the security context data to a security context of the UE, as shown at block 508.
[0080] In some examples, the security context data is received at block 504 from the target cell via the LTM cell switch command or a separate radio resource control (RRC) message.
[0081] In some examples, the LTM cell switch command is a medium access control (MAC) control element (CE).
[0082] In some examples, the LTM cell switch command includes an identifier of the UE that is allocated by the target cell and set to a particular value as the indication for the intra-cell LTM handover.
[0083] In some examples, the LTM cell switch command omits an identifier of the UE, and omission of the identifier of the UE is the indication for the intra-cell LTM handover.
[0084] In some examples, the method 500 further includes receiving, from the source cell, an LTM configuration for each of one or more LTM candidate target cells including the target cell. In some of these examples, the LTM handover and the intra-cell LTM handover are performed at blocks 502, 508 using the LTM configuration for the target cell.
[0085] In some examples, the method 500 further includes receiving, from the source cell, an LTM configuration and an intra-cell LTM configuration for each of one or more LTM candidate target cells including the target cell. In some of these examples, the LTM handover is performed at block 502 using the LTM configuration for the target cell, and the intra-cell LTM handover is performed at block 508 using the intra-cell LTM configuration for the target cell.
[0086] In some examples, the intra-cell LTM configuration for the target cell is a delta configuration applied over the LTM configuration for the target cell for the intra-cell LTM handover.
[0087] In some examples, the intra-cell LTM configuration for the target cell includes a cell radio network temporary identifier (C-RNU) allocated to the UE. In some of these examples, the security context data is applied to the security context with the C-RNTI.
[0088] EIG. 6 is a flowchart illustrating various steps in a method 600 performed by a target cell, according to various example implementations. The method includes performing a lower-layer triggered mobility (LTM) handover of the UE from a source1cell to the target cell, as shown at block 602. The method includes receiving security context data associated with the UE in a path switch procedure associated with the LTM handover, as shown at block 604. The method includes sending, to the UE, the security context data, as shown at block 606. And the method includes sending, to the UE, an LTM cell switch command that includes an indication for an intra-cell LTM handover for the UE to apply the security context data to the security context of the UE, as shown at block 608.
[0089] In some examples, the security context data is sent at block 606 to the UE via the LTM cell switch command or a separate radio resource control (RRC) message.
[0090] In some examples, the LTM cell switch command is a medium access control (MAC) control element (CE).
[0091] In some examples, the LTM cell switch command includes an identifier of the UE that is allocated by the target cell and set to a particular value as the indication for the intra-cell LTM handover.
[0092] In some examples, the LTM cell switch command omits an identifier of the UE, and omission of the identifier of the UE is the indication for the intra-cell LTM handover.
[0093] In some examples, the method 600 further includes sending, to the source cell, an LTM configuration for the source cell to send to the UE for the LTM handover and the intra-cell LTM handover.
[0094] In some examples, the method 600 further includes sending, to the source cell, an LTM configuration and an intra-cell LTM configuration for the source cell to send to the UE for respectively the LTM handover and the intra-cell LTM handover.
[0095] In some examples, the intra-cell LTM configuration is a delta configuration applied over the LTM configuration for the intra-cell LTM handover.
[0096] In some examples, the intra-cell LTM configuration includes a cell radio network temporary identifier (C-RNU) allocated to the UE for the UE to apply the security context data to the security context with the C-RNTI.
[0097] FIG. 7 is a flowchart illustrating various steps in a method 700 performed by a user equipment (UE), according to various example implementations. The method includes receiving, from a source cell, a lower-layer triggered mobility (LTM)configuration and an intra-cell LTM configuration for a target cell, the intra-cell LTM configuration forthe target cell including a configured uplink grant, as shown at block 702. The method includes performing an LTM handover to the target cell using the LTM configuration for the target cell, as shown at block 704. The method includes receiving, from the target cell, security context data associated with the UE, as shown at block 706. The method includes receiving, from the target cell, an LTM cell switch command that includes an indication for an intra-cell LTM handover, as shown at block 708.
[0098] The method 700 includes in response to the LTM cell switch command, performing the intra-cell LTM handover using the intra-cell LTM configuration for the target cell, as shown at block 710. Performing the intra-cell LTM handover includes applying the security context data to a security context of the UE, as shown at block 712. And performing the intra-cell LTM handover includes sending a radio resource control (RRC) reconfiguration complete message to the target cell using the configured uplink grant from the intra-cell LTM configuration for the target cell, as shown at block 714.
[0099] In some examples, the security context data is received at block 706 from the target cell via a RRC message.
[0100] In some examples, the LTM cell switch command is a medium access control (MAC) control element (CE).
[0101] In some examples, the LTM cell switch command includes an identifier of the UE that is allocated by the target cell and set to a particular value as the indication for the intra-cell LTM handover.
[0102] In some examples, the LTM cell switch command omits an identifier of the UE, and omission of the identifier of the UE is the indication for the intra-cell LTM handover.
[0103] In some examples, the intra-cell LTM configuration for the target cell is a delta configuration applied over the LTM configuration for the target cell for the intra-cell LTM handover.
[0104] In some examples, the intra-cell LTM configuration for the target cell also includes a cell radio network temporary identifier (C-RNTI) allocated to the UE. In some of these examples, the security context data is applied at block 712 to the security context with the C-RNTI.
[0105] FIG. 8 is a flowchart illustrating various steps in a method 800 performed by a target cell, according to various example implementations. The method includes sending, to a source cell, a lower-layer triggered mobility (LTM) configuration, and an intra-cell LTM handover configuration including a configured uplink grant, as shown at block 802. The method includes performing an LTM handover of a user equipment (UE) to the target cell using the LTM configuration, as shown at block 804. The method includes receiving security context data associated with the UE in a path switch procedure associated with the LTM handover, as shown at block 806. The method includes sending, to the UE, the security context data, as shown at block 808. The method includes sending, to the UE, an LTM cell switch command that includes an indication for an intra-cell LTM handover for the UE to apply the security context data to the security context of the UE, as shown at block 810. And the method includes receiving, from the UE, a radio resource control (RRC) reconfiguration complete message using the configured uplink grant from the intra-cell LTM configuration, as shown at block 812.
[0106] In some examples, the security context data is sent at block 808 to the UE via a RRC message.
[0107] In some examples, the LTM cell switch command is a medium access control (MAC) control element (CE).
[0108] In some examples, the LTM cell switch command includes an identifier of the UE that is allocated by the target cell and set to a particular value as the indication for the intra-cell LTM handover.
[0109] In some examples, the LTM cell switch command omits an identifier of the UE, and omission of the identifier of the UE is the indication for the intra-cell LTM handover.
[0110] In some examples, the intra-cell LTM configuration is a delta configuration applied over the LTM configuration for the intra-cell LTM handover.
[0111] In some examples, the intra-cell LTM configuration also includes a cell radio network temporary identifier (C-RNTI) allocated to the UE for the UE to apply the security context data to the security context with the C-RNTI.
[0112] According to example implementations of the present disclosure, a telecommunications system 100 or PLMN 102, and its components such as a UE 110, CN106, RAN 108, RAN node 202, CU 204 and / or DU 206, may be implemented by various means. Means for implementing the system and its components may include hardware, firmware, software, or combinations thereof In some examples, one or more apparatuses may be configured to function as or otherwise implement the system and its components shown and described herein. In examples involving more than one apparatus, the respective apparatuses may be connected to or otherwise in communication with one another in a number of different manners, such as directly or indirectly via a wired or wireless network or the like.
[0113] According to some example implementations, at least some of the methods 500, 600 described with respect to FIG. 5 and FIG. 6 may be carried out by apparatuses comprising means for performing functions corresponding steps of the respective methods. Similarly, at least some of the methods 700, 800 described with respect to FIG.7 and FIG. 8 may be carried out by apparatuses comprising means for performing functions corresponding steps of the respective methods. Examples of a suitable apparatus may include a user equipment, user device, user terminal or the like. Other examples of a suitable apparatus may include a RAN node (e.g., ng-eNB, gNB, gNB-DU, gNB-CU) or any suitable apparatus, such as a server, host or node.
[0114] FIG. 9 illustrates an apparatus 900 in which means for performing various operations includes hardware, alone or under direction of one or more computer programs from a computer-readable storage medium or other memory, such as computer memory, according to some example implementations of the present disclosure. The apparatus may include one or more of each of a number of components such as, for example, processing circuitry 902 connected to computer-readable storage medium or other memory 904.
[0115] The processing circuitry 902 may be composed of one or more processors alone or in combination with one or more computer-readable storage media. The processing circuitry is generally any piece of computer hardware that is capable of processing information such as, for example, data, computer programs, computer code and / or other suitable electronic information. The processing circuitry is composed of a collection of electronic circuits some of which may be packaged as an integrated circuit or multiple interconnected integrated circuits (an integrated circuit at times morecommonly referred to as a “chip”). The processing circuitry may be configured to execute computer programs, which may be stored onboard the processing circuitry or otherwise stored in the memory 904 (of the same or another apparatus).
[0116] The processing circuitry 902 may comprise a number of processors, a multicore processor or some other type of processor, such as a central processing unit, a graphics processing unit, a tensor processing, unit, or an accelerator, depending on the particular implementation. Further, the processing circuitry may be implemented using a number of heterogeneous processor systems in which a main processor is present with one or more secondary processors on a single chip. As another illustrative example, the processing circuitry may be a symmetric multi-processor system containing multiple processors of the same type. In yet another example, the processing circuitry may be embodied as or otherwise include one or more application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or the like. Thus, although the processing circuitry may be capable of executing a computer program to perform one or more functions, the processing circuitry of various examples may be capable of performing one or more functions without the aid of a computer program. In either instance, the processing circuitry may be appropriately programmed to perform functions or operations according to example implementations of the present disclosure.
[0117] The memory 904 is generally any piece of computer hardware that is capable of storing information such as, for example, data, computer programs, instructions 906 (e.g., computer-readable program code) and / or other suitable information either on a temporary basis and / or a permanent basis. The memory may include volatile and / or nonvolatile memory, and may be fixed or removable. Examples of suitable memory include recording media, random access memory (RAM), read-only memory (ROM), a hard drive, a flash memory, a thumb drive, a removable computer diskette, an optical disk or some combination thereof.
[0118] The memory 904 is a non-transitory device capable of storing information. One example of a suitable memory is a computer-readable storage medium, which is distinguishable from a computer-readable transmission medium capable of carrying information from one location to another. Examples of suitable computer-readable transmission media comprise electronic carrier signals, telecommunications signals, orsome combination thereof. As used herein, the term “non-transitory” is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM versus ROM). A computer-readable medium as described herein generally refers to a computer-readable storage medium or computer-readable transmission medium. A computer-readable medium is any entity or device capable in which information, such as one or more computer programs or portions thereof, may be stored and carried.
[0119] In addition to the memory 904 (e.g., computer-readable storage medium), the processing circuitry 902 may also be connected to one or more interfaces for displaying, transmitting and / or receiving information. The interfaces may include a communications interface 908 and / or one or more user interfaces. The communications interface may be configured to transmit and / or receive information, such as to and / or from other apparatus(es), network(s) or the like. The communications interface may be configured to transmit and / or receive information by physical (wired) and / or wireless communications links. Examples of suitable communication interfaces include a network interface controller (NIC), wireless NIC (WNIC) or the like.
[0120] The user interfaces may include a display 910 and / or one or more user input interfaces 912. The display may be configured to present or otherwise display information to a user, suitable examples of which include a liquid crystal display (LCD), light-emitting diode (LED) display, organic LED (OLED) display, active-matrix OLED (AMOLED) or the like. The user input interfaces may be wired or wireless, and may be configured to receive information from a user into the apparatus, such as for processing, storage and / or display. Suitable examples of user input interfaces include a microphone, image or video capture device, keyboard or keypad, joystick, touch-sensitive surface (separate from or integrated into a touchscreen), biometric sensor or the like. The user interfaces may further include one or more interfaces for communicating with peripherals such as printers, scanners or the like.
[0121] Execution of the instructions 906 by the processing circuitry 902, or storage of the instructions in the memory 904, supports combinations of operations for implementing example implementations of the present disclosure. In this manner, an apparatus 900 may comprise at least one processing circuitry and at least one memorycoupled to the at least one processing circuitry, where the at least one processing circuitry is configured to execute instructions stored in the at least one memory. It will also be understood that one or more functions, and combinations of functions, may be implemented by special purpose hardware-based computer systems and / or processing circuitry which perform the specified functions, or combinations of special purpose hardware and program code instructions.
[0122] Some example implementations of the present disclosure may also be carried out in the form of a computer process defined by one or more computer programs or portions thereof. Example implementations of the present disclosure may be carried out by executing at least one portion of a computer program comprising instructions. The computer program may be in source code form, object code form, or in some intermediate form. The computer program may be stored in a computer-readable medium that is readable by a computer, processing circuitry or other suitable apparatus. As indicated above, for example, the computer program may be stored in a memory, such as a computer-readable storage medium. Additionally or alternatively, for example, the computer program may be stored in a computer-readable transmission medium. The coding of software for carrying out example implementations of the present disclosure is well within the scope of a person of ordinary skill in the art.
[0123] As will be appreciated, any suitable instructions may be loaded onto a computer, a processing circuitry or other programmable apparatus from a memory or a computer-readable medium (e.g., computer-readable storage medium, computer-readable transmission medium) to produce a particular machine, such that the particular machine becomes a means for implementing the functions specified herein. The instructions may also be stored in a computer-readable medium that can direct a computer, a processing circuitry or other programmable apparatus to function in a particular manner to thereby generate a particular machine or particular article of manufacture. In some examples, the instructions stored in the computer-readable medium may produce an article of manufacture, where the article of manufacture becomes a means for implementing functions described herein. The instructions may be retrieved from a computer-readable medium and loaded into a computer, processing circuitry or other programmable apparatus to configure the computer, processing circuitry or other programmableapparatus to execute operations to be performed on or by the computer, processing circuitry or other programmable apparatus.
[0124] Retrieval, loading and execution of instructions comprising program code instructions may be performed sequentially such that one instruction is retrieved, loaded and executed at a time. In some example implementations, retrieval, loading and / or execution may be performed in parallel such that multiple instructions are retrieved, loaded, and / or executed together. Execution of the program code instructions may produce a computer-implemented process such that the instructions executed by the computer, processing circuitry or other programmable apparatus provide operations for implementing functions described herein.
[0125] As explained above and reiterated below, the present disclosure includes, without limitation, the following example implementations.
[0126] Clause 1. A method performed by a user equipment (UE), the method comprising: performing a lower-layer triggered mobility (LTM) handover of the UE from a source cell to a target cell; receiving, from the target cell, security context data associated with the UE; receiving, from the target cell, an LTM cell switch command that includes an indication for an intra-cell LTM handover; and in response to the LTM cell switch command, performing the intra-cell LTM handover, including applying the security context data to a security context of the UE.
[0127] Clause 2. The method of clause 1 , wherein the security context data is received from the target cell via the LTM cell switch command or a separate radio resource control (RRC) message.
[0128] Clause 3. The method of clause 1 or clause 2, wherein the LTM cell switch command is a medium access control (MAC) control element (CE).
[0129] Clause 4. The method of any of clauses 1 to 3, wherein the LTM cell switch command includes an identifier of the UE that is allocated by the target cell and set to a particular value as the indication for the intra-cell LTM handover.
[0130] Clause 5. The method of any of clauses 1 to 4, wherein the LTM cell switch command omits an identifier of the UE, and omission of the identifier of the UE is the indication for the intra-cell LTM handover.
[0131] Clause 6. The method of any of clauses 1 to 5, wherein the method further comprises receiving, from the source cell, an LTM configuration for each of one or more LTM candidate target cells including the target cell, and wherein the LTM handover and the intra-cell LTM handover are performed using the LTM configuration for the target cell.
[0132] Clause 7. The method of any of clauses 1 to 6, wherein the method further comprises receiving, from the source cell, an LTM configuration and an intra-cell LTM configuration for each of one or more LTM candidate target cells including the target cell, and wherein the LTM handover is performed using the LTM configuration for the target cell, and the intra-cell LTM handover is performed using the intra-cell LTM configuration for the target cell.
[0133] Clause 8. The method of clause 7, wherein the intra-cell LTM configuration for the target cell is a delta configuration applied over the LTM configuration for the target cell for the intra-cell LTM handover.
[0134] Clause 9. The method of clause 7 or clause 8, wherein the intra-cell LTM configuration for the target cell includes a cell radio network temporary identifier (C-RNTI) allocated to the UE, and wherein the security context data is applied to the security context with the C-RNTI.
[0135] Clause 10. An apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to perform the method of any of clauses 1 to 9.
[0136] Clause 11. An apparatus comprising means for performing the method of any of clauses 1 to 9.
[0137] Clause 12. A computer-readable medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 1 to 9.
[0138] Clause 13. A computer-readable storage medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 1 to 9.
[0139] Clause 14. A computer program comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 1 to 9.
[0140] Clause 15. A method performed by a target cell, the method comprising: performing a lower-layer triggered mobility (LTM) handover of the UE from a source cell to the target cell; receiving security context data associated with the UE in a path switch procedure associated with the LTM handover; sending, to the UE, the security context data; and sending, to the UE, an LTM cell switch command that includes an indication for an intra-cell LTM handover for the UE to apply the security context data to the security context of the UE.
[0141] Clause 16. The method of clause 15, wherein the security context data is sent to the UE via the LTM cell switch command or a separate radio resource control (RRC) message.
[0142] Clause 17. The method of clause 15 or clause 16, wherein the LTM cell switch command is a medium access control (MAC) control element (CE).
[0143] Clause 18. The method of any of clauses 15 to 17, wherein the LTM cell switch command includes an identifier of the UE that is allocated by the target cell and set to a particular value as the indication for the intra-cell LTM handover.
[0144] Clause 19. The method of any of clauses 15 to 18, wherein the LTM cell switch command omits an identifier of the UE, and omission of the identifier of the UE is the indication for the intra-cell LTM handover.
[0145] Clause 20. The method of any of clauses 15 to 19, wherein the method further comprises sending, to the source cell, an LTM configuration for the source cell to send to the UE for the LTM handover and the intra-cell LTM handover.
[0146] Clause 21. The method of any of clauses 15 to 20, wherein the method further comprises sending, to the source cell, an LTM configuration and an intra-cell LTM configuration for the source cell to send to the UE for respectively the LTM handover and the intra-cell LTM handover.
[0147] Clause 22. The method of clause 21, wherein the intra-cell LTM configuration is a delta configuration applied over the LTM configuration for the intra-cell LTM handover.
[0148] Clause 23. The method of clause 21 or clause 22, wherein the intra-cell LTM configuration includes a cell radio network temporary identifier (C-RNTI) allocated to the UE for the UE to apply the security context data to the security context with the C-RNTI.
[0149] Clause 24. An apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to perform the method of any of clauses 15 to 23.
[0150] Clause 25. An apparatus comprising means for performing the method of any of clauses 15 to 23.
[0151] Clause 26. A computer-readable medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 15 to 23.
[0152] Clause 27. A computer-readable storage medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 15 to 23.
[0153] Clause 28. A computer program comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 15 to 23.
[0154] Clause 29. A method performed by a user equipment (UE), the method comprising: receiving, from a source cell, a lower-layer triggered mobility (LTM) configuration and an intra-cell LTM configuration for a target cell, the intra-cell LTM configuration for the target cell including a configured uplink grant; performing an LTM handover to the target cell using the LTM configuration for the target cell; receiving, from the target cell, security context data associated with the UE; receiving, from the target cell, an LTM cell switch command that includes an indication for an intra-cell LTM handover; and in response to the LTM cell switch command, performing the intra-cell LTM handover using the intra-cell LTM configuration for the target cell, including: applying the security context data to a security context of the UE; and sending a radio resource control (RRC) reconfiguration complete message to the target cell using the configured uplink grant from the intra-cell LTM configuration for the target cell.
[0155] Clause 30. The method of clause 29, wherein the security context data is received from the target cell via a RRC message.
[0156] Clause 31. The method of clause 29 or clause 30, wherein the LTM cell switch command is a medium access control (MAC) control element (CE).
[0157] Clause 32. The method of any of clauses 29 to 31, wherein the LTM cell switch command includes an identifier of the UE that is allocated by the target cell and set to a particular value as the indication for the intra-cell LTM handover.
[0158] Clause 33. The method of any of clauses 29 to 32, wherein the LTM cell switch command omits an identifier of the UE, and omission of the identifier of the UE is the indication for the intra-cell LTM handover.
[0159] Clause 34. The method of any of clauses 29 to 33, wherein the intra-cell LTM configuration for the target cell is a delta configuration applied over the LTM configuration for the target cell for the intra-cell LTM handover.
[0160] Clause 35. The method of any of clauses 29 to 34, wherein the intra-cell LTM configuration for the target cell also includes a cell radio network temporary identifier (C-RNTI) allocated to the UE, and wherein the security context data is applied to the security context with the C-RNTI.
[0161] Clause 36. An apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to perform the method of any of clauses 29 to 35.
[0162] Clause 37. An apparatus comprising means for performing the method of any of clauses 29 to 35.
[0163] Clause 38. A computer-readable medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 29 to 35.
[0164] Clause 39. A computer-readable storage medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 29 to 35.
[0165] Clause 40. A computer program comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 29 to 35.
[0166] Clause 41. A method performed by a target cell, the method comprising: sending, to a source cell, a lower-layer triggered mobility (LTM) configuration, and an intra-cell LTM handover configuration including a configured uplink grant; performing an LTM handover of a user equipment (UE) to the target cell using the LTM configuration; receiving security context data associated with the UE in a path switch procedure associated with the LTM handover; sending, to the UE, the security context data; sending, to the UE, an LTM cell switch command that includes an indication for an intra-cell LTM handover for the UE to apply the security context data to the security context of the UE; and receiving, from the UE, a radio resource control (RRC) reconfiguration complete message using the configured uplink grant from the intra-cell LTM configuration.
[0167] Clause 42. The method of clause 41, wherein the security context data is sent to the UE via a RRC message.
[0168] Clause 43. The method of clause 41 or clause 42, wherein the LTM cell switch command is a medium access control (MAC) control element (CE).
[0169] Clause 44. The method of any of clauses 41 to 43, wherein the LTM cell switch command includes an identifier of the UE that is allocated by the target cell and set to a particular value as the indication for the intra-cell LTM handover.
[0170] Clause 45. The method of any of clauses 41 to 44, wherein the LTM cell switch command omits an identifier of the UE, and omission of the identifier of the UE is the indication for the intra-cell LTM handover.
[0171] Clause 46. The method of any of clauses 41 to 45, wherein the intra-cell LTM configuration is a delta configuration applied over the LTM configuration for the intra-cell LTM handover.
[0172] Clause 47. The method of any of clauses 41 to 46, wherein the intra-cell LTM configuration also includes a cell radio network temporary identifier (C-RNTI) allocated to the UE for the UE to apply the security context data to the security context with the C-RNTI.
[0173] Clause 48. An apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to perform the method of any of clauses 41 to 47.
[0174] Clause 49. An apparatus comprising means for performing the method of any of clauses 41 to 47.
[0175] Clause 50. A computer-readable medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 41 to 47.
[0176] Clause 51. A computer-readable storage medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 41 to 47.
[0177] Clause 52. A computer program comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 41 to 47.
[0178] Many modifications and other implementations of the disclosure set forth herein will come to mind to one skilled in the art to which the disclosure pertains having the benefit of the teachings presented in the foregoing description and the associated figures. Therefore, it is to be understood that the disclosure is not to be limited to the specific implementations disclosed and that modifications and other implementations are intended to be included within the scope of the appended claims. Moreover, although the foregoing description and the associated figures describe example implementations in the context of certain example combinations of elements and / or functions, it should be appreciated that different combinations of elements and / or functions may be provided by alternative implementations without departing from the scope of the appended claims. In this regard, for example, different combinations of elements and / or functions than those explicitly described above are also contemplated as may be set forth in some of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.
Claims
WHAT IS CLAIMED IS:
1. An apparatus to implement a user equipment (UE), the apparatus comprising:at least one memory configured to store instructions; andat least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least:perform a lower-layer triggered mobility (LTM) handover of the UE from a source cell to a target cell;receive, from the target cell, security context data associated with the UE; receive, from the target cell, an LTM cell switch command that includes an indication for an intra-cell LTM handover; andin response to the LTM cell switch command, perform the intra-cell LTM handover, including apply the security context data to a security context of the UE.
2. The apparatus of claim 1, wherein the security context data is received from the target cell via the LTM cell switch command or a separate radio resource control (RRC) message.
3. The apparatus of claim 1 or claim 2, wherein the LTM cell switch command is a medium access control (MAC) control element (CE).
4. The apparatus of any of claims 1 to 3, wherein the LTM cell switch command includes an identifier of the UE that is allocated by the target cell and set to a particular value as the indication for the intra-cell LTM handover.
5. The apparatus of any of claims 1 to 4, wherein the LTM cell switch command omits an identifier of the UE, and omission of the identifier of the UE is the indication for the intra-cell LTM handover.
6. The apparatus of any of claims 1 to 5, wherein the at least one processing circuitry is configured to execute the instructions to cause the apparatus to furtherreceive, from the source cell, an LTM configuration for each of one or more LTM candidate target cells including the target cell, andwherein the LTM handover and the intra-cell LTM handover are performed using the LTM configuration for the target cell.
7. The apparatus of any of claims 1 to 6, wherein the at least one processing circuitry is configured to execute the instructions to cause the apparatus to further receive, from the source cell, an LTM configuration and an intra-cell LTM configuration for each of one or more LTM candidate target cells including the target cell, and wherein the LTM handover is performed using the LTM configuration for the target cell, and the intra-cell LTM handover is performed using the intra-cell LTM configuration for the target cell.
8. The apparatus of claim 7, wherein the intra-cell LTM configuration for the target cell is a delta configuration applied over the LTM configuration for the target cell for the intra-cell LTM handover.
9. The apparatus of claim 7 or claim 8, wherein the intra-cell LTM configuration for the target cell includes a cell radio network temporary identifier (C-RNTI) allocated to the UE, and wherein the security context data is applied to the security context with the C-RNTI.
10. An apparatus to implement a target cell, the apparatus comprising: at least one memory configured to store instructions; andat least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least:perform a lower-layer triggered mobility (LTM) handover of the UE from a source cell to the target cell;receive security context data associated with the UE in a path switch procedure associated with the LTM handover;send, to the UE, the security context data; and38send, to the UE, an LTM cell switch command that includes an indication for an intra-cell LTM handover for the UE to apply the security context data to the security context of the UE.
11. The apparatus of claim 10, wherein the security context data is sent to the UE via the LTM cell switch command or a separate radio resource control (RRC) message.
12. The apparatus of claim 10 or claim 11, wherein the LTM cell switch command is a medium access control (MAC) control element (CE).
13. The apparatus of any of claims 10 to 12, wherein the LTM cell switch command includes an identifier of the UE that is allocated by the target cell and set to a particular value as the indication for the intra-cell LTM handover.
14. The apparatus of any of claims 10 to 13, wherein the LTM cell switch command omits an identifier of the UE, and omission of the identifier of the UE is the indication for the intra-cell LTM handover.
15. The apparatus of any of claims 10 to 14, wherein the at least one processing circuitry is configured to execute the instructions to cause the apparatus to further send, to the source cell, an LTM configuration for the source cell to send to the UE for the LTM handover and the intra-cell LTM handover.
16. The apparatus of any of claims 10 to 15, wherein the at least one processing circuitry is configured to execute the instructions to cause the apparatus to further send, to the source cell, an LTM configuration and an intra-cell LTM configuration for the source cell to send to the UE for respectively the LTM handover and the intra-cell LTM handover.
17. The apparatus of claim 16, wherein the intra-cell LTM configuration is a delta configuration applied over the LTM configuration for the intra-cell LTM handover.
18. The apparatus of claim 16 or claim 17, wherein the intra-cell LTM configuration includes a cell radio network temporary identifier (C-RNU) allocated to the UE for the UE to apply the security context data to the security context with the C-RNTI.