Methods of handling security mode control procedure over new-generation network in mobile communications

WO2026166170A1PCT designated stage Publication Date: 2026-08-13MEDIATEK SINGAPORE PTE LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-12-05
Publication Date
2026-08-13

Smart Images

  • Figure CN2025140306_13082026_PF_FP_ABST
    Figure CN2025140306_13082026_PF_FP_ABST
Patent Text Reader

Abstract

Techniques pertaining to handling a security mode control procedure over a new-generation network in mobile communications are described. An apparatus (e.g., a network node of a network) receives, from a user equipment (UE), the UE's current-generation capability in a registration procedure over a new-generation network. The apparatus then initiates a security mode control procedure over the new-generation network to provide to the UE one or more non-access stratum (NAS) security algorithms for a current-generation network.
Need to check novelty before this filing date? Find Prior Art

Description

METHODS OF HANDLING SECURITY MODE CONTROL PROCEDURE OVER NEW-GENERATION NETWORK IN MOBILE COMMUNICATIONSCROSS REFERENCE TO RELATED PATENT APPLICATION (S)

[0001] The present disclosure claims the priority benefit of India Patent Application No. 202521009165, filed 04 February 2025, the content of which herein being incorporated by reference in its entirety.TECHNICAL FIELD

[0002] The present disclosure is generally related to mobile communications and, more particularly, to handling a security mode control procedure over a new-generation network in mobile communications.BACKGROUND

[0003] In wireless communications such as mobile communications under the current 3rd Generation Partnership Project (3GPP) specification, at the time of the present disclosure, network and user equipment (UE) behaviors regarding security mode control during intersystem transition from a current-generation network (e.g., 4th Generation (4G) or 5th Generation (5G) network) to a new-generation network (e.g., 6th Generation (6G) network) , or vice versa, are not yet defined. Therefore, there is a need for a solution of handling a security mode control procedure over a new-generation network in mobile communications.SUMMARY

[0004] The following summary is illustrative only and is not intended to be limiting in any way. That is, the following summary is provided to introduce concepts, highlights, benefits, and advantages of the novel and non-obvious techniques described herein. Select implementations are further described below in the detailed description. Thus, the following summary is not intended to identify essential features of the claimed subject matter, nor is it intended for use in determining the scope of the claimed subject matter.

[0005] An objective of the present disclosure is to propose solutions or schemes that address the issue (s) described herein. More specifically, various schemes proposed in the present disclosure are believed to provide solutions pertaining to handling a security mode control procedure over a new-generation network in mobile communications. It is believed that implementations of one or more of the schemes proposed herein may address or otherwise alleviate the issues described above.

[0006] In one aspect, a method may involve a UE indicating, to a network, the UE’s current-generation capability in a registration procedure over a new-generation network. The method may also involve the UE receiving, from the network, one or more non-access stratum (NAS) security algorithms for a current-generation network in a security mode control procedure initiated by the network over the new-generation network.

[0007] In another aspect, a method may involve a network receiving, from a UE, the UE’s current-generation capability in a registration procedure over a new-generation network. The method may also involve the network initiating a security mode control procedure over the new-generation network to provide to the UE one or more NAS security algorithms for a current-generation network.

[0008] It is noteworthy that, although the description provided herein may be in the context of certain radio access technologies, networks, and network topologies such as 5th Generation (5G) New Radio (NR)  / Beyond Fifth-Generation (B5G)  / 6th Generation (6G) mobile communications, the proposed concepts, schemes and any variation (s)  / derivative (s) thereof may be implemented in, for and by other types of radio access technologies, networks and network topologies such as, for example and without limitation, 4th Generation (4G)  / Long-Term Evolution (LTE) , LTE-Advanced, LTE-Advanced Pro, Internet-of-Things (IoT) , Narrow Band Internet of Things (NB-IoT) , Industrial Internet of Things (IIoT) , vehicle-to-everything (V2X) , and non-terrestrial network (NTN) communications. Thus, the scope of the present disclosure is not limited to the examples described herein.BRIEF DESCRIPTION OF THE DRAWINGS

[0009] The accompanying drawings are included to provide a further understanding of the disclosure and are incorporated in and constitute a part of the present disclosure. The drawings illustrate implementations of the disclosure and, together with the description, serve to explain the principles of the disclosure. It is appreciable that the drawings are not necessarily in scale as some components may be shown to be out of proportion than the size in actual implementation in order to clearly illustrate the concept of the present disclosure.

[0010] FIG. 1 is a diagram of an example network environment in which various solutions and schemes in accordance with the present disclosure may be implemented.

[0011] FIG. 2 is a block diagram of an example communication system under a proposed scheme in accordance with the present disclosure.

[0012] FIG. 3 is a flowchart of an example process under a proposed scheme in accordance with the present disclosure.

[0013] FIG. 4 is a flowchart of an example process under a proposed scheme in accordance with the present disclosure. DETAILED DESCRIPTION OF PREFERRED IMPLEMENTATIONS

[0014] Detailed embodiments and implementations of the claimed subject matters are disclosed herein. However, it shall be understood that the disclosed embodiments and implementations are merely illustrative of the claimed subject matters which may be embodied in various forms. The present disclosure may, however, be embodied in many different forms and should not be construed as limited to the exemplary embodiments and implementations set forth herein. Rather, these exemplary embodiments and implementations are provided so that description of the present disclosure is thorough and complete and will fully convey the scope of the present disclosure to those skilled in the art. In the description below, details of well-known features and techniques may be omitted to avoid unnecessarily obscuring the presented embodiments and implementations. Overview

[0015] Implementations in accordance with the present disclosure relate to various techniques, methods, schemes and / or solutions pertaining to handling a security mode control procedure over a new-generation network in mobile communications. According to the present disclosure, a number of possible solutions may be implemented separately or jointly. That is, although these possible solutions may be described below separately, two or more of these possible solutions may be implemented in one combination or another.

[0016] FIG. 1 illustrates an example network environment 100 in which various solutions and schemes in accordance with the present disclosure may be implemented. FIG. 2 ~ FIG. 4 illustrate examples of implementation of various proposed schemes in network environment 100 in accordance with the present disclosure. The following description of various proposed schemes is provided with reference to FIG. 1 ~ FIG. 4.

[0017] Referring to FIG. 1, network environment 100 involves a UE 110 in wireless communication with a wireless network 120 (e.g., a mobile network including an NTN and a TN) via a terrestrial network node 125 (e.g., an evolved Node-B (eNB) , a Next Generation Node-B (gNB) , or a transmission / reception point (TRP) ) and / or a non-terrestrial network node 128 (e.g., a satellite) . For example, the terrestrial network node 125 and / or the non-terrestrial network node 128 may form a non-terrestrial network (NTN) serving cell for wireless communication with the UE 110. In some implementations, the UE 110 may be an IoT device such as an NB-IoT UE or an enhanced machine-type communication (eMTC) UE (e.g., a bandwidth reduced low complexity (BL) UE or a coverage enhancement (CE) UE) . In such communication environment, the UE 110, the network 120, the terrestrial network node 125, and the non-terrestrial network node 128 may implement various schemes pertaining to handling a security mode control procedure over a new-generation network in accordance with the present disclosure, as described below.

[0018] It is noteworthy that, while the various proposed schemes may be individually or separately described below, in actual implementations some or all of the proposed schemes may be utilized or otherwise implemented jointly. Of course, each of the proposed schemes may be utilized or otherwise implemented individually or separately. Moreover, as used herein, a lower layer may refer to a layer in the 5GMM protocol stack that is lower than the radio resource control (RRC) layer, such as a packet data convergence protocol (PDCP) layer, a radio control link (RLC) layer, a medium access control (MAC) layer, a physical (PHY) layer, or so forth.

[0019] It is also noteworthy that, although in the examples provided in the present disclosure “current-generation” may refer to 4G and / or 5G and “new-generation” may refer to 6G, the scope of the present disclosure is not limited to the examples. That is, as future-generation access technologies are developed, the terms “current-generation” and “new-generation” may refer to different generations as suitable in actual implementations. For instance, in the future, “current-generation” may refer to 6G and “new-generation” may refer to a beyond-6G generation.

[0020] Under a proposed scheme in accordance with the present disclosure, a network (e.g., wireless network 120) may initiate a security mode control procedure over a 6G network to provide Selected Evolved Packet System (EPS) non-access stratum (NAS) security algorithms and / or Selected 5th Generation System (5GS) NAS security algorithms and / or new information element (IE)  / bit / set of bits in a security mode command message to inform a UE (e.g., UE 110) about the NAS security algorithms for 4G and / or 5G, in case that the UE has indicated its 4G (S1 mode) capability or 5G (N1 mode) capability to the network in a previous or ongoing registration procedure over the 6G network.

[0021] Under a proposed scheme in accordance with the present disclosure, during an intersystem change / transition from 4G to 6G and / or in case the UE or network supports interworking between 4G and 6G, then the UE may derive a mapped 6G security context from an EPS security context.

[0022] Under a proposed scheme in accordance with the present disclosure, during an intersystem change / transition from 6G to 4G and / or the UE or network supports interworking between 4G and 6G, then the UE may derive a mapped EPS security context from a 6G security context.

[0023] Under a proposed scheme in accordance with the present disclosure, during an intersystem change / transition from 5G to 6G and / or the UE or network supports interworking between 5G and 6G, then the UE may derive a mapped 6G security context from a 5GS security context.

[0024] Under a proposed scheme in accordance with the present disclosure, during an intersystem change / transition from 6G to 5G and / or the UE or network supports interworking between 5G and 6G, then the UE may derive a mapped 5GS security context from a 6G security context.

[0025] Under a proposed scheme in accordance with the present disclosure, when a new mapped 6G NAS security context or 6G NAS security context created using "null integrity protection algorithm" and "null ciphering algorithm" is taken into usage during an intersystem change from N1 mode to 6G mode or from S1 mode to 6G mode, a 6G core network (CN) and the UE may not delete (and, rather, may keep) a previously current native 6G NAS security context, if any. Instead, the previously current native 6G NAS security context may become a non-current native 6G NAS security context, and the Access and Mobility Management Function (AMF) of the network and the UE may delete any partial native 6G NAS security context.

[0026] Under a proposed scheme in accordance with the present disclosure, when the 6G CN and the UE derive a new mapped 6G NAS security context during an intersystem change / transition from S1 mode to 6G mode or from N1 mode to 6G mode, the 6G CN and the UE may delete any existing current mapped 6G NAS security context.

[0027] Under a proposed scheme in accordance with the present disclosure, when the UE performs an intersystem change / transition from S1 mode to 6G mode or from N1 mode to 6G mode in a 6G Mobility Management (6GMM) idle (6GMM-IDLE) mode, if the UE has a non-current full native 6G NAS security context, then the UE may treat or otherwise consider the non-current full native 6G NAS security context as the current native 6G NAS security context. Moreover, the UE may delete a mapped 6G NAS security context, if any.

[0028] Under a proposed scheme in accordance with the present disclosure, during an intersystem change / transition from S1 mode to 6G mode or from N1 mode to 6G mode in a 6GMM connected (6GMM-CONNECTED) mode, when a mapped 6G NAS security context is derived and taken into use, the 6G CN may set both the uplink (UL) and downlink (DL) NAS COUNT counters of this mapped 6G NAS security context to zero. Moreover, the UE may set both the uplink and downlink NAS COUNT counters of this 6G NAS security context to zero.

[0029] Under a proposed scheme in accordance with the present disclosure, during an intersystem change / transition from S1 mode to 6G mode in the 6GMM-CONNECTED mode, the 6G CN may increment the downlink NAS COUNT by one after the 6G CN has created an “S1 mode to 6G mode” NAS transparent container.

[0030] Under a proposed scheme in accordance with the present disclosure, during an intersystem change / transition from N1 mode to 6G mode in the 6GMM-CONNECTED mode, the 6G CN may increment the downlink NAS COUNT by one after the 6G CN has created an “N1 mode to 6G mode” NAS transparent container.

[0031] Under a proposed scheme in accordance with the present disclosure, during an intersystem change / transition from 6G mode to S1 mode in the 6GMM-CONNECTED mode, the 6G CN may increment the downlink NAS COUNT by one after the 6G CN has created a “6G mode to S1 mode” NAS transparent container.

[0032] Under a proposed scheme in accordance with the present disclosure, during an intersystem change / transition from 6G mode to N1 mode in the 6GMM-CONNECTED mode, the 6G CN may increment the downlink NAS COUNT by one after the 6G CN has created a “6G mode to N1 mode” NAS transparent container. Illustrative Implementations

[0033] FIG. 2 illustrates an example communication system 200 having at least an example apparatus 210 and an example apparatus 220 in accordance with an implementation of the present disclosure. Each of apparatus 210 and apparatus 220 may perform various functions to implement schemes, techniques, processes and methods described herein pertaining to handling a security mode control procedure over a new-generation network in mobile communications, including the various schemes described above with respect to various proposed designs, concepts, schemes, systems and methods described above, including network environment 100, as well as processes described below.

[0034] Each of apparatus 210 and apparatus 220 may be a part of an electronic apparatus, which may be a network apparatus or a UE (e.g., UE 110) , such as a portable or mobile apparatus, a wearable apparatus, a vehicular device or a vehicle, a wireless communication apparatus or a computing apparatus. For instance, each of apparatus 210 and apparatus 220 may be implemented in a smartphone, a smart watch, a personal digital assistant, an electronic control unit (ECU) in a vehicle, a digital camera, or a computing equipment such as a tablet computer, a laptop computer or a notebook computer. Each of apparatus 210 and apparatus 220 may also be a part of a machine type apparatus, which may be an IoT apparatus such as an immobile or a stationary apparatus, a home apparatus, a roadside unit (RSU) , a wire communication apparatus or a computing apparatus. For instance, each of apparatus 210 and apparatus 220 may be implemented in a smart thermostat, a smart fridge, a smart door lock, a wireless speaker or a home control center. When implemented in or as a network apparatus, apparatus 210 and / or apparatus 220 may be implemented in an eNB in an LTE, LTE-Advanced or LTE-Advanced Pro network or in a gNB or TRP in a 5G network, an NR network, or an IoT network.

[0035] In some implementations, each of apparatus 210 and apparatus 220 may be implemented in the form of one or more integrated-circuit (IC) chips such as, for example and without limitation, one or more single-core processors, one or more multi-core processors, one or more complex-instruction-set-computing (CISC) processors, or one or more reduced-instruction-set-computing (RISC) processors. In the various schemes described above, each of apparatus 210 and apparatus 220 may be implemented in or as a network apparatus or a UE. Each of apparatus 210 and apparatus 220 may include at least some of those components shown in FIG. 2 such as a processor 212 and a processor 222, respectively, for example. Each of apparatus 210 and apparatus 220 may further include one or more other components not pertinent to the proposed scheme of the present disclosure (e.g., internal power supply, display device and / or user interface device) , and, thus, such component (s) of apparatus 210 and apparatus 220 are neither shown in FIG. 2 nor described below in the interest of simplicity and brevity.

[0036] In one aspect, each of processor 212 and processor 222 may be implemented in the form of one or more single-core processors, one or more multi-core processors, or one or more CISC or RISC processors. That is, even though a singular term “a processor” is used herein to refer to processor 212 and processor 222, each of processor 212 and processor 222 may include multiple processors in some implementations and a single processor in other implementations in accordance with the present disclosure. In another aspect, each of processor 212 and processor 222 may be implemented in the form of hardware (and, optionally, firmware) with electronic components including, for example and without limitation, one or more transistors, one or more diodes, one or more capacitors, one or more resistors, one or more inductors, one or more memristors and / or one or more varactors that are configured and arranged to achieve specific purposes in accordance with the present disclosure. In other words, in at least some implementations, each of processor 212 and processor 222 is a special-purpose machine specifically designed, arranged, and configured to perform specific tasks including those pertaining to handling a security mode control procedure over a new-generation network in mobile communications in accordance with various implementations of the present disclosure.

[0037] In some implementations, apparatus 210 may also include a transceiver 216 coupled to processor 212. Transceiver 216 may be capable of wirelessly transmitting and receiving data. In some implementations, transceiver 216 may be capable of wirelessly communicating with different types of wireless networks of different radio access technologies (RATs) . In some implementations, transceiver 216 may be equipped with a plurality of antenna ports (not shown) such as, for example, four antenna ports. That is, transceiver 216 may be equipped with multiple transmit antennas and multiple receive antennas for multiple-input multiple-output (MIMO) wireless communications. In some implementations, apparatus 220 may also include a transceiver 226 coupled to processor 222. Transceiver 226 may include a transceiver capable of wirelessly transmitting and receiving data. In some implementations, transceiver 226 may be capable of wirelessly communicating with different types of UEs / wireless networks of different RATs. In some implementations, transceiver 226 may be equipped with a plurality of antenna ports (not shown) such as, for example, four antenna ports. That is, transceiver 226 may be equipped with multiple transmit antennas and multiple receive antennas for MIMO wireless communications.

[0038] In some implementations, apparatus 210 may further include a memory 214 coupled to processor 212 and capable of being accessed by processor 212 and storing data therein. In some implementations, apparatus 220 may further include a memory 224 coupled to processor 222 and capable of being accessed by processor 222 and storing data therein. Each of memory 214 and memory 224 may include a type of random-access memory (RAM) such as dynamic RAM (DRAM) , static RAM (SRAM) , thyristor RAM (T-RAM) and / or zero-capacitor RAM (Z-RAM) . Alternatively, or additionally, each of memory 214 and memory 224 may include a type of read-only memory (ROM) such as mask ROM, programmable ROM (PROM) , erasable programmable ROM (EPROM) and / or electrically erasable programmable ROM (EEPROM) . Alternatively, or additionally, each of memory 214 and memory 224 may include a type of non-volatile random-access memory (NVRAM) such as flash memory, solid-state memory, ferroelectric RAM (FeRAM) , magnetoresistive RAM (MRAM) and / or phase-change memory.

[0039] Each of apparatus 210 and apparatus 220 may be a communication entity capable of communicating with each other using various proposed schemes in accordance with the present disclosure. For illustrative purposes and without limitation, a description of capabilities of apparatus 210, as a UE (e.g., UE 110) , and apparatus 220, as a network node (e.g., network node 125) of a network (e.g., wireless network 120 as a 5G / NR mobile network) , is provided below in the context of example processes 300 and 400. Illustrative Processes

[0040] FIG. 3 illustrates an example process 300 in accordance with an implementation of the present disclosure. Process 300 may represent an aspect of implementing various proposed designs, concepts, schemes, systems and methods described above. More specifically, process 300 may represent an aspect of the proposed concepts and schemes pertaining to handling a security mode control procedure over a new-generation network in mobile communications in accordance with the present disclosure. Process 300 may include one or more operations, actions, or functions as illustrated by one or more blocks. Although illustrated as discrete blocks, various blocks of process 300 may be divided into additional blocks, combined into fewer blocks, or eliminated, depending on the desired implementation. Moreover, the blocks / sub-blocks of process 300 may be executed in the order shown in FIG. 3 or, alternatively, in a different order. Furthermore, one or more of the blocks / sub-blocks of process 300 may be executed repeatedly or iteratively. Process 300 may be implemented by or in apparatus 210 and apparatus 220 as well as any variations thereof. Solely for illustrative purposes and without limiting the scope, process 300 is described below in the context of apparatus 210 as a UE (e.g., UE 110) and apparatus 220 as a communication entity such as a network node (e.g., non-terrestrial network node 128 or terrestrial network node 125) of a network (e.g., wireless network 120) . Process 300 may begin at block 310.

[0041] At 310, process 300 may involve processor 212 of apparatus 210, as UE 110, indicating, via transceiver 216, to a network (e.g., wireless network 120 via apparatus 220 as non-terrestrial network node 128 or terrestrial network node 125) the UE’s current-generation capability in a registration procedure over a new-generation network. Process 300 may proceed from 310 to 320.

[0042] At 320, process 300 may involve processor 212 receiving, via transceiver 216, from the network one or more non-access stratum (NAS) security algorithms for a current-generation network in a security mode control procedure initiated by the network over the new-generation network.

[0043] In some implementations, the current-generation network may include a 4G network including an EPS network or a 5G network. Additionally, the current-generation capability may include an S1 mode capability or N1 mode capability. Moreover, the new-generation network may include a 6G network. Furthermore, the security mode control procedure may provide to the UE selected EPS NAS security algorithms or selected 5GS NAS security algorithms or new IE or bits in a security mode command message.

[0044] In some implementations, process 300 may further involve processor 212 deriving, during an intersystem transition from a current-generation system to a new-generation system, a new-generation security context from a current-generation security context. Additionally, process 300 may further involve processor 212 deleting any existing current mapped new-generation NAS security context. In some implementations, the current-generation system may include a 4GS which is an EPS or a 5GS, and the current-generation security context may include an EPS security context or 5GS security context. Moreover, the new-generation system may include a 6GS, and the new-generation security context may include a 6G security context.

[0045] In some implementations, process 300 may further involve processor 212 deriving, during an intersystem transition from a new-generation system to a current-generation system, a current-generation security context from a new-generation security context. In some implementations, the current-generation system may include a 4GS or 5GS, and the current-generation security context may include an EPS security context or 5GS security context. Moreover, the new-generation system may include a 6GS, and the new-generation security context may include a 6G security context.

[0046] In some implementations, process 300 may further involve processor 212 keeping a previously current native new-generation NAS security context as a non-current native new-generation NAS security context responsive to a new mapped new-generation NAS security context or new-generation NAS security context created using a null integrity protection algorithm and a null ciphering algorithm being taken into use during an intersystem transition from a current-generation system to a new-generation system. Moreover, process 300 may further involve processor 212 deleting any partial native new-generation NAS security context.

[0047] In some implementations, process 300 may further involve processor 212 performing, via transceiver 216, an intersystem transition from a current-generation system to a new-generation system in a new-generation mobility management idle mode. Additionally, process 300 may further involve processor 212 treating a non-current full native new-generation NAS security context as a current native new-generation NAS security context. Moreover, process 300 may further involve processor 212 deleting a mapped new-generation NAS security context, if any.

[0048] In some implementations, process 300 may further involve processor 212 performing, via transceiver 216, an intersystem transition from a current-generation system to a new-generation system in a new-generation mobility management connected mode. Furthermore, process 300 may further involve processor 212 setting both uplink and downlink NAS count counters of a new-generation NAS security context to zero responsive to the new-generation NAS security context having been derived and taken into use.

[0049] FIG. 4 illustrates an example process 400 in accordance with an implementation of the present disclosure. Process 400 may represent an aspect of implementing various proposed designs, concepts, schemes, systems and methods described above. More specifically, process 400 may represent an aspect of the proposed concepts and schemes pertaining to handling a security mode control procedure over a new-generation network in mobile communications in accordance with the present disclosure. Process 400 may include one or more operations, actions, or functions as illustrated by one or more blocks. Although illustrated as discrete blocks, various blocks of process 400 may be divided into additional blocks, combined into fewer blocks, or eliminated, depending on the desired implementation. Moreover, the blocks / sub-blocks of process 400 may be executed in the order shown in FIG. 4 or, alternatively, in a different order. Furthermore, one or more of the blocks / sub-blocks of process 400 may be executed repeatedly or iteratively. Process 400 may be implemented by or in apparatus 210 and apparatus 220 as well as any variations thereof. Solely for illustrative purposes and without limiting the scope, process 400 is described below in the context of apparatus 210 as a UE (e.g., UE 110) and apparatus 220 as a communication entity such as a network node (e.g., non-terrestrial network node 128 or terrestrial network node 125) of a network (e.g., wireless network 120) . Process 400 may begin at block 410.

[0050] At 410, process 400 may involve processor 222 of apparatus 220, as non-terrestrial network node 128 or terrestrial network node 125, receiving, via transceiver 226, from a UE (e.g., apparatus 210 as UE 110) the UE’s current-generation capability in a registration procedure over a new-generation network. Process 400 may proceed from 410 to 420.

[0051] At 420, process 400 may involve processor 222 initiating, via transceiver 226, a security mode control procedure over the new-generation network to provide to the UE one or more NAS security algorithms for a current-generation network.

[0052] In some implementations, the current-generation network may include a 4G network including an EPS network or a 5G network. Additionally, the current-generation capability may include an S1 mode capability or N1 mode capability. Moreover, the new-generation network may include a 6G network. Furthermore, the security mode control procedure may provide to the UE selected EPS NAS security algorithms or selected 5GS NAS security algorithms or new IE or bits in a security mode command message.

[0053] In some implementations, process 400 may further involve processor 222 keeping a previously current native new-generation NAS security context as a non-current native new-generation NAS security context responsive to a new mapped new-generation NAS security context or new-generation NAS security context created using a null integrity protection algorithm and a null ciphering algorithm being taken into use during an intersystem transition from a current-generation system to a new-generation system. Moreover, process 400 may further involve processor 222 deleting any partial native new-generation NAS security context.

[0054] In some implementations, process 400 may further involve processor 222 deriving, during an intersystem transition from a current-generation system to a new-generation system, a new-generation security context from a current-generation security context. Additionally, In some implementations, process 400 may further involve processor 222 deleting any existing current mapped new-generation NAS security context. In some implementations, the current-generation system may include a 4GS which is an EPS or a 5GS, and the current-generation security context may include an EPS security context or 5GS security context. Moreover, the new-generation system may include a 6GS, and the new-generation security context may include a 6G security context.

[0055] In some implementations, process 400 may further involve processor 222 performing, via transceiver 226, an intersystem transition from a current-generation system to a new-generation system in a new-generation mobility management connected mode. Moreover, process 400 may further involve processor 222 setting both uplink and downlink NAS count counters of a new-generation NAS security context to zero responsive to the new-generation NAS security context having been derived and taken into use.

[0056] In some implementations, process 400 may further involve processor 222 incrementing, during an intersystem transition from a current-generation mode to a new-generation mode in a new-generation mobility management connected mode, a downlink NAS count by one after the network has created a “current-generation mode to new-generation mode” NAS transparent container. In some implementations, the current-generation mode may include an S1 mode or N1 mode. Moreover, the new-generation mode may include a 6G mode, and the new-generation mobility management connected mode may include a 6GMM-CONNECTED mode.

[0057] In some implementations, process 400 may further involve processor 222 incrementing, during an intersystem transition from a current-generation mode to a new-generation mode in a new-generation mobility management connected mode, a downlink NAS count by one after the network has created a “new-generation mode to current-generation mode” NAS transparent container. In some implementations, the current-generation mode may include an S1 mode or N1 mode. Moreover, the new-generation mode may include a 6G mode, and the new-generation mobility management connected mode may include a 6GMM-CONNECTED mode. Additional Notes

[0058] The herein-described subject matter sometimes illustrates different components contained within, or connected with, different other components. It is to be understood that such depicted architectures are merely examples, and that in fact many other architectures can be implemented which achieve the same functionality. In a conceptual sense, any arrangement of components to achieve the same functionality is effectively "associated" such that the desired functionality is achieved. Hence, any two components herein combined to achieve a particular functionality can be seen as "associated with" each other such that the desired functionality is achieved, irrespective of architectures or intermedial components. Likewise, any two components so associated can also be viewed as being "operably connected" , or "operably coupled" , to each other to achieve the desired functionality, and any two components capable of being so associated can also be viewed as being "operably couplable" , to each other to achieve the desired functionality. Specific examples of operably couplable include but are not limited to physically mateable and / or physically interacting components and / or wirelessly interactable and / or wirelessly interacting components and / or logically interacting and / or logically interactable components.

[0059] Further, with respect to the use of substantially any plural and / or singular terms herein, those having skill in the art can translate from the plural to the singular and / or from the singular to the plural as is appropriate to the context and / or application. The various singular / plural permutations may be expressly set forth herein for sake of clarity.

[0060] Moreover, it will be understood by those skilled in the art that, in general, terms used herein, and especially in the appended claims, e.g., bodies of the appended claims, are generally intended as “open” terms, e.g., the term “including” should be interpreted as “including but not limited to, ” the term “having” should be interpreted as “having at least, ” the term “includes” should be interpreted as “includes but is not limited to, ” etc. It will be further understood by those within the art that if a specific number of an introduced claim recitation is intended, such an intent will be explicitly recited in the claim, and in the absence of such recitation no such intent is present. For example, as an aid to understanding, the following appended claims may contain usage of the introductory phrases "at least one" and "one or more" to introduce claim recitations. However, the use of such phrases should not be construed to imply that the introduction of a claim recitation by the indefinite articles "a" or "an" limits any particular claim containing such introduced claim recitation to implementations containing only one such recitation, even when the same claim includes the introductory phrases "one or more" or "at least one" and indefinite articles such as "a" or "an, " e.g., “a” and / or “an” should be interpreted to mean “at least one” or “one or more; ” the same holds true for the use of definite articles used to introduce claim recitations. In addition, even if a specific number of an introduced claim recitation is explicitly recited, those skilled in the art will recognize that such recitation should be interpreted to mean at least the recited number, e.g., the bare recitation of "two recitations, " without other modifiers, means at least two recitations, or two or more recitations. Furthermore, in those instances where a convention analogous to “at least one of A, B, and C, etc. ” is used, in general such a construction is intended in the sense one having skill in the art would understand the convention, e.g., “a system having at least one of A, B, and C” would include but not be limited to systems that have A alone, B alone, C alone, A and B together, A and C together, B and C together, and / or A, B, and C together, etc. In those instances where a convention analogous to “at least one of A, B, or C, etc. ” is used, in general such a construction is intended in the sense one having skill in the art would understand the convention, e.g., “a system having at least one of A, B, or C” would include but not be limited to systems that have A alone, B alone, C alone, A and B together, A and C together, B and C together, and / or A, B, and C together, etc. It will be further understood by those within the art that virtually any disjunctive word and / or phrase presenting two or more alternative terms, whether in the description, claims, or drawings, should be understood to contemplate the possibilities of including one of the terms, either of the terms, or both terms. For example, the phrase “A or B” will be understood to include the possibilities of “A” or “B” or “A and B. ”

[0061] From the foregoing, it will be appreciated that various implementations of the present disclosure have been described herein for purposes of illustration, and that various modifications may be made without departing from the scope and spirit of the present disclosure. Accordingly, the various implementations disclosed herein are not intended to be limiting, with the true scope and spirit being indicated by the following claims.

Claims

1.A method, comprising:indicating, by a processor of a user equipment (UE) , to a network the UE’s current-generation capability in a registration procedure over a new-generation network; andreceiving, by the processor, from the network one or more non-access stratum (NAS) security algorithms for a current-generation network in a security mode control procedure initiated by the network over the new-generation network.2.The method of Claim 1, wherein the current-generation network comprises a 4th Generation (4G) network comprising an Evolved Packet System (EPS) network or a 5th Generation (5G) network, wherein the current-generation capability comprises an S1 mode capability or N1 mode capability, wherein the new-generation network comprises a 6th Generation (6G) network, and wherein the security mode control procedure provides to the UE selected EPS NAS security algorithms or selected 5G system (5GS) NAS security algorithms or new information element (IE) or bits in a security mode command message.3.The method of Claim 1, further comprising:deriving, by the processor during an intersystem transition from a current-generation system to a new-generation system, a new-generation security context from a current-generation security context.4.The method of Claim 3, wherein the current-generation system comprises a 4th Generation (4G) system (4GS) which is an Evolved Packet System (EPS) or a 5th Generation (5G) system (5GS) , wherein the current-generation security context comprises an EPS security context or 5GS security context, wherein the new-generation system comprises a 6th Generation (6G) system (6GS) , and wherein the new-generation security context comprises a 6G security context.5.The method of Claim 3, further comprising:deleting, by the processor, any existing current mapped new-generation NAS security context.6.The method of Claim 1, further comprising:deriving, by the processor during an intersystem transition from a new-generation system to a current-generation system, a current-generation security context from a new-generation security context.7.The method of Claim 6, wherein the current-generation system comprises a 4th Generation (4G) system (4GS) which is an Evolved Packet System (EPS) or a 5th Generation (5G) system (5GS) , wherein the current-generation security context comprises an EPS security context or 5GS security context, wherein the new-generation system comprises a 6th Generation (6G) system (6GS) , and wherein the new-generation security context comprises a 6G security context.8.The method of Claim 1, further comprising:keeping, by the processor, a previously current native new-generation NAS security context as a non-current native new-generation NAS security context responsive to a new mapped new-generation NAS security context or new-generation NAS security context created using a null integrity protection algorithm and a null ciphering algorithm being taken into use during an intersystem transition from a current-generation system to a new-generation system; anddeleting, by the processor, any partial native new-generation NAS security context.9.The method of Claim 1, further comprising:performing, by the processor, an intersystem transition from a current-generation system to a new-generation system in a new-generation mobility management idle mode;treating, by the processor, a non-current full native new-generation NAS security context as a current native new-generation NAS security context; anddeleting, by the processor, a mapped new-generation NAS security context, if any.10.The method of Claim 1, further comprising:performing, by the processor, an intersystem transition from a current-generation system to a new-generation system in a new-generation mobility management connected mode; andsetting, by the processor, both uplink and downlink NAS count counters of a new-generation NAS security context to zero responsive to the new-generation NAS security context having been derived and taken into use.11.A method, comprising:receiving, by a processor of a network node of a network, from a user equipment (UE) the UE’s current-generation capability in a registration procedure over a new-generation network; andinitiating, by the processor, a security mode control procedure over the new-generation network to provide to the UE one or more non-access stratum (NAS) security algorithms for a current-generation network.12.The method of Claim 11, wherein the current-generation network comprises a 4th Generation (4G) network comprising an Evolved Packet System (EPS) network or a 5th Generation (5G) network, wherein the current-generation capability comprises an S1 mode capability or N1 mode capability, wherein the new-generation network comprises a 6th Generation (6G) network, and wherein the security mode control procedure provides to the UE selected EPS NAS security algorithms or selected 5G system (5GS) NAS security algorithms or new information element (IE) or bits in a security mode command message.13.The method of Claim 11, further comprising:keeping, by the processor, a previously current native new-generation NAS security context as a non-current native new-generation NAS security context responsive to a new mapped new-generation NAS security context or new-generation NAS security context created using a null integrity protection algorithm and a null ciphering algorithm being taken into use during an intersystem transition from a current-generation system to a new-generation system; anddeleting, by the processor, any partial native new-generation NAS security context.14.The method of Claim 11, further comprising:deriving, by the processor during an intersystem transition from a current-generation system to a new-generation system, a new-generation security context from a current-generation security context; anddeleting, by the processor, any existing current mapped new-generation NAS security context.15.The method of Claim 14, wherein the current-generation system comprises a 4th Generation (4G) system (4GS) which is an Evolved Packet System (EPS) or a 5th Generation (5G) system (5GS) , wherein the current-generation security context comprises an EPS security context or 5GS security context, wherein the new-generation system comprises a 6th Generation (6G) system (6GS) , and wherein the new-generation security context comprises a 6G security context.16.The method of Claim 11, further comprising:performing, by the processor, an intersystem transition from a current-generation system to a new-generation system in a new-generation mobility management connected mode; andsetting, by the processor, both uplink and downlink NAS count counters of a new-generation NAS security context to zero responsive to the new-generation NAS security context having been derived and taken into use.17.The method of Claim 11, further comprising:incrementing, by the processor during an intersystem transition from a current-generation mode to a new-generation mode in a new-generation mobility management connected mode, a downlink NAS count by one after the network has created a “current-generation mode to new-generation mode” NAS transparent container.18.The method of Claim 17, wherein the current-generation mode comprises an S1 mode or N1 mode, wherein the new-generation mode comprises a 6th Generation (6G) mode, and wherein the new-generation mobility management connected mode comprises a 6G Mobility Management (6GMM) connected (6GMM-CONNECTED) mode.19.The method of Claim 11, further comprising:incrementing, by the processor during an intersystem transition from a current-generation mode to a new-generation mode in a new-generation mobility management connected mode, a downlink NAS count by one after the network has created a “new-generation mode to current-generation mode” NAS transparent container.20.The method of Claim 19, wherein the current-generation mode comprises an S1 mode or N1 mode, wherein the new-generation mode comprises a 6th Generation (6G) mode, and wherein the new-generation mobility management connected mode comprises a 6G Mobility Management (6GMM) connected (6GMM-CONNECTED) mode.