Security information related to LTM mobility procedures

WO2026206226A1PCT designated stage Publication Date: 2026-10-01TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/SE2026/050206
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-27
Filing Date
2026-03-26
Publication Date
2026-10-01

Smart Images

  • Figure SE2026050206_01102026_PF_FP_ABST
    Figure SE2026050206_01102026_PF_FP_ABST
Patent Text Reader

Abstract

A method is performed by a wireless device The method comprises: transmitting, to a first network node or a second network node, security information for the wireless device. The security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device. The first network node acts as a Master Node (MN) serving the wireless device, or as a target MN for the LTM mobility procedure. In the latter case, at least one cell of the target MN is included in an LTM candidate cell configuration of the wireless device. The second network node acts as a Secondary Node (SN) serving the wireless device subsequent to the performance of the LTM mobility procedure.
Need to check novelty before this filing date? Find Prior Art

Description

Security Information related to LTM Mobility ProceduresTechnical FieldEmbodiments of the disclosure relate to wireless communication, and particularly to methods, apparatus and computer program products for mobility procedures.BackgroundL1 / L2 Triggered Mobility (LTM) in 3GPP Rel-18 and Rel-19

[0001] In 3 GPP Release 18, as part of a work item known as Further NR mobility enhancements, a technical area entitled L1 / L2 based inter-cell mobility is included. According to the Work Item Description, WID [Error! Reference source not found. , the goal of L1 / L2 based inter-cell mobility (also known as L1 / L2 Triggered Mobility) is to enable a serving cell change, sometimes also known as an LTM cell switch or an LTM cell switch procedure, via L1 / L2 signalling, in order to reduce the latency, overhead and interruption time.

[0002] A basic principle with L1 / L2 triggered mobility is that the UE is pre-configured, by the network, with an LTM configuration which includes information such as measurement configuration and an RRC configuration per LTM candidate cell, sometimes also known as an LTM candidate cell configuration. Such an LTM candidate cell configuration may be an RRCReconfiguration message or one or more IEs / fields / parameters such as CellGroupConfig. The UE performs measurements on LTM candidate cells and beams in those cells, according to the measurement configuration included in the LTM configuration received from the network. The UE transmits LI measurement reports for LTM including Ll-RSRP measurements for up to four LTM candidate cells and up to four beams in each cell. When the network (e.g. a gNB or a gNB-DU) receives the LI measurement report for LTM, it may use the content of this report to trigger an LTM cell switch towards one of the LTM candidate cells.

[0003] The network triggers the execution of an LTM cell switch procedure in the UE to one of these LTM candidate cells by transmitting an LTM cell switch command Medium Access control (MAC) Control Element (MAC CE) to the UE. The LTM cell switch command includes information such as a reference to an LTM candidate cell configuration and an indication of a target beam in the LTM candidate cell. The UE then connects to the beam and switches to the LTM candidate cell configuration.

[0004] The overall procedures for LTM in Rel-18 are described in 3GPP TS 38.300 V18.5.0, subclause 9.2.3.5, and for the gNB-CU / gNB-DU Architecture in 3GPP TS 38.401 V18.5.0, subclauses 8.2.1.4-8.2.1.6.

[0005] LTM in Rel-18 is limited to intra-gNB (including intra-CU intra-DU and intra-CU inter-DU) mobility.

[0006] In 3 GPP Rel-19, a work item on NR Mobility enhancements Phase 4 has started, which aims to enhance mobility features, including introducing support for inter-CU LTM according to the objective below.Specify support for inter-CU Layerl / Layer 2 Triggered Mobility (LTM) [RAN2, RAN3]- Prioritize the case when CU is acting as MN when DC is not configuredAs secondary priority, support the case when NR-DC is configured and CU is acting as SN and MCG is unchangedAs secondary priority, support the case when NR-DC is configured, CU is acting as MN and SCG is unchanged or SCG is releasedo Note: The case that LTM is configured in both MCG and SCG is excludedSpecify support for subsequent LTM mobility procedures aiming to avoid RRC configuration between cell switches as per Rel-18 LTMo Coordination with SA3 needed with respect to security key handling - Note: Rel. 18 intra-CU LTM procedure is considered as baseline for adding inter-CU support3GPP Dual Connectivity

[0007] In 3 GPP Rel- 12, the LTE feature Dual Connectivity (DC) was introduced, to enable the UE to be connected in two cell groups, each controlled by an LTE access node, eNBs, labelled as the Master eNB, MeNB and the Secondary eNB, SeNB. The UE still only has one RRC connection with the network. In 3 GPP, the DC solution has since then evolved and is now also specified for NR as well as between LTE and NR. With the introduction of 5G, the term MR-DC (Multi-Radio Dual Connectivity, see also 3GPP TS 37.340 vl8.5.0 / ) was defined as a generic term for all dual connectivity options which include at least one NR access node. Using the MR-DC generalized terminology, the UE is connected in a Master Cell Group (MCG), controlled by the Master Node (MN), and in a Secondary Cell Group (SCG) controlled by a Secondary Node (SN).

[0008] Further, in MR-DC, when dual connectivity is configured for the UE, within each of the two cell groups, MCG and SCG, carrier aggregation may be used as well. In this case,within the MCG, controlled by the MN, the UE may use one PCell and one or more SCell(s). And within the SCG, controlled by the SN, the UE may use one Primary SCell (PSCell, also known as the primary SCG cell in NR) and one or more SCell(s). This combined case is illustrated in Figure 1, which shows dual connectivity combined with carrier aggregation in MR DC. In NR, the primary cell of a master or secondary cell group is sometimes also referred to as the Special Cell (SpCell). Hence, the SpCell in the MCG is the PCell and the SpCell in the SCG is the PSCell.

[0009] In NR-DC, NR dual connectivity, both the MN controlling the MCG, and the SN, controlling the SCG, use NR as the radio access technology.Conditional LTM in Rel-19

[0010] LTM was introduced in Rel-18 and can offer improvements in handover latency and interruption time compared to Layer 3 based mobility. However, LTM as introduced in Rel-18 also has a number of limitations compared to Layer 3 mobility. The Rel-19 work item aims to remove a number of these limitations. Layer 3 mobility has evolved over several releases and includes Conditional handover (CHO) and other conditional mobility procedures (CP AC, SCPAC) were developed to achieve high robustness by enabling the procedure to be executed without necessitating a signaling exchange with the source cell beforehand. LTM as introduced in Rel-18 offers short interruption time but not with the same level of robustness as the conditional L3 mobility procedures. In Rel-19, enhancements should be specified so that the system can benefit from both the high robustness of CHO and short interruption offered by LTM.

[0011] One such attempt to provide the benefits of both the LTM and CHO is Conditional LTM (CLTM), which is proposed to be a part of Rel-19 Mobility enhancements. Regarding conditional LTM, the following objectives have been captured:Specify support of conditional LTM [RAN2, RAN 3, RANI ]o Specify UE evaluated conditions for triggering LTM.o Aim to support conditional LTM including subsequent LTM.

[0012] In CLTM, the UE (and not the serving gNB-DU) initiates the LTM cell switch execution, and there are a number of steps included in the non-conditional LTM execution which are not used to decide to trigger the LTM cell switch, namely:The UE does not need to send LI measurements on LTM candidate cells to the serving gNB-DUThe serving gNB-DU does not take the decision to trigger the LTM cell switch executionThe serving gNB-DU does not send an LTM cell switch command to the UE

[0013] There are also other steps which cannot be present in CLTM:Since the serving gNB-DU does not take the decision to trigger the LTM cell switch execution, it cannot notify the gNB-CU about it, i.e., the DU-CU CELL SWITCH NOTIFICATION message is not presentThe gNB-CU is not informed by the serving gNB-DU that LTM execution has initiated, therefore it cannot notify the candidate DU about it, i.e., the CU-DU CELL SWITCH NOTIFICATION message is not present.

[0014] The steps included in the execution phase of the intra-CU LTM procedure and not executed in case of intra-CU CLTM are shown in Figure 2.Counter and generation of keys in the SN

[0015] The existing Sk-Counter is a numerical value used when the UE first connects to an SN. The UE uses this counter to derive fresh security keys specifically for use in the SN.

[0016] As outlined in 3GPP TS 33.501, vl9.1.0, Chapter 6.10.1.2:When the MN establishes security context between an SN and the UE for the first time for a given AS security context shared between the MN and the UE, the MN generates the KSN for the SN and sends it to the SN over the Xn-C. To generate the KSN, the MN associates a counter, called an SN Counter, with the current AS security context. The SN Counter is used as freshness input into KSN derivations as described in the clause 6.10.3.2. The MN sends the value of the SN Counter to the UE over the RRC signalling path when it is required to generate a new KSN. The KSN is used to derive further RRC and UP keys that are used between the UE and SN.

[0017] According to 3GPP TS 38.331, vl8.5.1, Chapter 6.3.2:- SK-CounterThe IE SK-Counter is a counter used upon initial configuration of SN security for NR- DC and NE-DC, as well as upon refresh of S-KgNB or S-K6NB based on the current or newly derived KSNB during RRC Resume or RRC Reconfiguration, as defined in TS 33.501

[0011] ,- ASN1 START- TAG- SKCOUNTER- STARTSK-Counter ::= INTEGER (0..65535)- TAG- SKCOUNTER- STOP- ASN1STOP

[0018] The sk-counter is delivered to the UE via the RRCReconfiguration message and is applied when the UE processes the corresponding RRCReconfiguration. This field is determined and set by the MN.sk-CounterA counter used upon initial configuration of S-KgNB or S-K6NB, as well as upon refresh of S-KgNB or S-KeNB. This field is always included either upon initial configuration of an NR SCG or upon configuration of the first RB with keyToUse set to secondary, whichever happens first. This field is absent if there is neither any NR SCG nor any RB with keyToUse set to secondary, or if the RRCReconfiguration message is contained in condRRCReconfig for subsequent CP AC.

[0019] There currently exist certain challenge(s). During inter-SN LTM procedures, both the SN and the UE may need to derive new security keys for the cell switch. However, the method for transferring this information from the MN to the SN remains unclear in the current XnAP signaling. This challenge also applies to Conditional LTM in future releases.

[0020] This is equally true when an inter-MN LTM procedure is executed, as a change of the security key at the MN requires also a change of the security key at the SN. This is because the derivation of the security key for the SN is based on the security key of the MN.

[0021] At the configuration of the candidate target SN for the inter-MN LTM with SCG, the secondary key that will be used between the UE and the SN at the execution of that procedure is however not known. It is therefore today not possible to inform the candidate target SN about which secondary key it shall then use towards the UE.Summary

[0022] Certain aspects of the disclosure and their embodiments may provide solutions to these or other challenges.

[0023] To address the above challenges, embodiments of the present disclosure enable the transfer of new security information during, e.g., inter-SN LTM / CLTM procedures. The embodiments also enable the MN to send the received new security keys to the candidate SN over Xn interface.

[0024] In a first aspect of the disclosure, a method is performed by a wireless device. The method comprises: transmitting, to a first network node or a second network node, security information for the wireless device. The security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device. The first network node acts as a Master Node (MN) serving the wireless device, or as a target MN for the LTM mobility procedure. In the latter case, at least one cell of the target MN is included in an LTM candidate cell configuration of the wireless device. The second network node acts as a Secondary Node (SN) serving the wireless device subsequent to the performance of the LTM mobility procedure.

[0025] In a second aspect of the disclosure, a method is performed by a first network node. The first network node acts as a Master Node (MN) serving the wireless device, or as a target MN for the LTM mobility procedure. In the latter case, at least one cell of the target MN is included in an LTM candidate cell configuration of the wireless device. The method comprises: transmitting, to a second network node, security information for the wireless device. The security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device. The second network node acts as a Secondary Node (SN) serving the wireless device subsequent to the performance of the LTM mobility procedure.

[0026] In a third aspect of the disclosure, a method is performed by a second network node which acts as a Secondary Node (SN) serving a wireless device subsequent to the performance of the LTM mobility procedure by the wireless device. The method comprises: receiving security information for the wireless device. The security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device. The security information is received from the wireless device or a first network node.The first network node acts as a Master Node (MN) serving the wireless device or acts as a candidate or target MN for the wireless device. At least one cell of the candidate or target MN is included in an LTM candidate cell configuration of the wireless device.

[0027] Apparatus and computer-readable media for performing the methods according to the first, second and third aspects is also provided.

[0028] Thus a further aspect provides a wireless device configured to perform the method according to the first aspect. For example, a wireless device comprises processing circuitry and a memory. The memory contains instructions executable by the processing circuitry whereby the wireless device is operative to transmit, to a first network node or a second network node, security information for the wireless device. The security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device. The first network node acts as a Master Node (MN) serving the wireless device, or as a target MN for the LTM mobility procedure. In the latter case, at least one cell of the target MN is included in an LTM candidate cell configuration of the wireless device. The second network node acts as a Secondary Node (SN) serving the wireless device subsequent to the performance of the LTM mobility procedure.

[0029] Another aspect provides a first network node configured to perform the method according to the second aspect. For example, a first network node comprises processing circuitry and a memory. The first network node acts as a Master Node (MN) serving the wireless device, or as a target MN for the LTM mobility procedure. In the latter case, at least one cell of the target MN is included in an LTM candidate cell configuration of the wireless device. The memory contains instructions executable by the processing circuitry whereby the first network node is operative to transmit, to a second network node, security information for the wireless device. The security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device. The second network node acts as a Secondary Node (SN) serving the wireless device subsequent to the performance of the LTM mobility procedure.

[0030] Another aspect provides a second network node configured to perform the method according to the third aspect. For example, a second network node comprises processing circuitry and a memory. The second network node acts as a Secondary Node (SN) serving a wireless device subsequent to the performance of the LTM mobility procedure by the wireless device. The memory contains instructions executable by the processing circuitry whereby thefirst network node is operative to receive security information for the wireless device. The security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device. The security information is received from the wireless device or a first network node. The first network node acts as a Master Node (MN) serving the wireless device or acts as a candidate or target MN for the wireless device. At least one cell of the candidate or target MN is included in an LTM candidate cell configuration of the wireless device.

[0031] The disclosure further provides a computer program product for performing the methods according to the first, second and / or third aspects.

[0032] Embodiments of the present disclosure also include methods to inform a candidate / target SN about the secondary key that it shall use when an inter-MN LTM (with SCG) procedure (where the SN is the candidate SN) is executed. The methods may include the target MN (of the procedure) sending this information to the SN when the execution procedure is triggered or performed.

[0033] Certain embodiments may provide one or more of the following technical advantage(s). Embodiments of the present disclosure facilitate the transfer of security information between network nodes and wireless devices, particularly when the wireless devices are subject to LTM mobility procedures. As such, embodiments of the present disclosure provide robust and efficient methods that enable secure communication between wireless devices and network nodes after such LTM mobility procedures have been performed.Brief Description of the Drawings

[0034] For a better understanding of the embodiments of the present disclosure, and to show how it may be put into effect, reference will now be made, by way of example only, to the accompanying drawings, in which:

[0035] Fig. 1 is a schematic diagram of dual connectivity combined with carrier aggregation in MR-DC;

[0036] Fig. 2 is a signalling flow illustrating the differences between Intra-CU CLTM execution and Intra-CU LTM execution;

[0037] Fig. 3 is a flow chart illustrating a method in accordance with some embodiments;

[0038] Fig. 4 is a flow chart illustrating a method in accordance with some embodiments;

[0039] Fig. 5 is a flow chart illustrating a method in accordance with some embodiments;

[0040] Figures 6 - 12 are signalling flows illustrating methods in accordance with some embodiments;

[0041] Fig. 13 shows an example of a communication system in accordance with some embodiments;

[0042] Fig. 14 shows an example of another communication system in accordance with some embodiments;

[0043] Fig. 15 shows a wireless device in accordance with some embodiments;

[0044] Fig. 16 shows a network node in accordance with some embodiments; and

[0045] Fig. 17 is a block diagram illustrating a virtualization environment in which functions implemented by some embodiments may be virtualized.Detailed description

[0046] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.

[0047] The text refers to the term “L1 / L2 based inter-cell mobility” as used in the Work Item Description in 3GPP, though it interchangeably also uses the terms L1 / L2 mobility, Ll-mobility, LI based mobility, Ll / L2-centric inter-cell mobility, L1 / L2 inter-cell mobility L1 / L2 Triggered Mobility, Lower-layer triggered Mobility or LTM. The basic principle is that the UE receives a lower layer signaling (e.g. a MAC CE) from the network indicating to the UE a change (or switch or activation) of serving cell (e.g. change of PCell, from a source to a target PCell), wherein a lower layer signaling is a message / signaling of a lower layer protocol, which may be referred as a L1 / L2 inter-cell mobility execution command or LTM cell switch command. The change of serving cell (e.g. change of PCell) may also lead to a change in Scell(s) for the same cell group e.g. in case the command triggers the UE to change to another cell group configuration of the same type (e.g. another MCG configuration). Before the UE receives the LTM cell switch command, the UE is configured by the network with one or more LTM candidate cells (e.g. reception of an RRC Reconfiguration message, with at least one LTM candidate cell configuration) A candidate cell configuration may include parameters in the IE CellGroupConfig per candidate cell and / or an embedded RRC Reconfiguration per candidate cell.

[0048] The term LTM cell switch procedure refers to the process of a UE changing its cell from a source cell to a target cell (which may be called here a candidate cell or a neighbourcell), using L1 / L2 triggered mobility (LTM). In the context of L1 / L2 triggered mobility (LTM), an LTM cell switch procedure may sometimes also be known as dynamic switch, LTM switch, (LTM) cell switch, (LTM) serving cell change or (LTM) cell change. Even if the term change of cell is used, that may comprise a change of a whole cell group configuration, which includes a change in the SpCell (e.g. change of PCell, or change of PSCell) and a change in sCells of the cell group (e.g. addition, modification and / or release of one or more sCells). The LTM cell switch procedure may be triggered by the UE receiving an LTM cell switch command from the network. The source and target cells in an LTM cell switch procedure may be controlled by the same gNB, which sometimes is referred to as the intra-gNB case, or when the gNB uses a distributed CU / DU RAN architecture, the intra-CU inter-DU case or the intra-CU intra-DU case (depending on whether the cells are controlled by the same DU or different DUs). When the source and target cells in an LTM cell switch procedure are controlled by different gNBs, this is sometimes referred to as the inter-gNB case, or inter-CU case, or sometimes known as an inter-CU LTM cell switch procedure.

[0049] The text refers to at least one LTM candidate cell configuration. This is also sometimes referred to as a configuration of an LTM candidate cell, which may be an RRC configuration, such as encapsulated in an RRC Reconfiguration message, that the UE receives when being configured with L1 / L2 Triggered Mobility. An LTM candidate cell configuration comprises the configuration according to which the UE may operate when it performs an LTM cell switch procedure to that LTM candidate cell e.g. upon reception of the LTM cell switch command indicating the UE to perform an LTM cell switch procedure to that LTM candidate cell, which becomes the target cell and the current (new) SpCell, or an sCell in a serving frequency. The LTM candidate cell configuration comprises parameters of a serving cell (or multiple serving cells, such as a cell group), comprising one or more of the groups of parameters, such as an RRCReconfiguration message, an IE CellGroupConfig or an IE SpCellConfig (or the IE sCellConfig, in the case of a Secondary Cell).

[0050] An LTM candidate cell configuration is associated with an identifier which is used in the signaling when referring to a certain LTM candidate cell configuration, such as when the UE receives the LTM candidate cell configuration and when the UE receives an LTM cell switch command indicating the UE to perform an LTM cell switch procedure to that LTM candidate cell. This identifier is sometimes known as the LTM candidate cell configuration identity or LTM candidate configuration index (or similar).

[0051] An inter-CU LTM cell switch procedure, sometimes also referred to as inter-CU LTM or inter-gNB LTM, is an LTM cell switch procedure resulting in a change of serving cell,e.g. change of SpCell, PCell, PSCell, to an LTM candidate cell controlled by a different gNB than the source gNB or serving gNB of the UE when the execution LTM cell switch procedure was triggered (e.g. upon reception of the LTM cell switch command). From UE point of view, the actions performed during an inter-CU LTM cell switch procedure may be the same type of actions of an LTM cell switch procedure, but may also include additional actions, such as change of security key(s).

[0052] The text refers to inter Secondary Node L1 / L2 Triggered Mobility, inter-SN LTM, configuration of inter-SN LTM, execution of inter-SN LTM and an inter-SN LTM cell switch procedure. In the context of this disclosure, inter-SN LTM refers to inter-CU LTM, sometimes also referred to as inter-gNB LTM, handover or SCG mobility, when the UE is configured with dual connectivity, such as NR-DC, and where the source cell and target cell are both part of the source and target SCG, respectively, and controlled by different CUs or different gNBs.

[0053] The term conditional LTM refers to L1 / L2 Triggered Mobility where the execution of the LTM cell switch is triggered by the UE when an execution condition, such as a layer 1, layer 2 or a layer 3 event, criterion or condition related to, for example, a radio measurement, is fulfilled. Upon the cell switch the UE applies a stored LTM candidate cell configuration.

[0054] The text refers to an inter-CU LTM candidate cell configuration. An inter-CU LTM candidate cell configuration is an LTM candidate cell configuration which contains the configuration according to which the UE may start to operate when it performs an LTM cell switch procedure to an LTM candidate cell which is controlled by a different base station, e.g. gNB, from the current source base station e.g. serving gNB of the UE. In some cases, the UE may receive an inter-CU LTM candidate cell configuration during configuration of inter-MN LTM. In some cases, the UE may apply an inter-CU LTM candidate cell configuration during execution of inter-MN LTM.

[0055] An inter-CU LTM candidate cell configuration may be the same as an LTM candidate cell configuration but it may also include additional information than what is included in the LTM candidate cell configuration used for inter-CU cell switch. This additional information may be, for example:Information to perform security key refresh, e.g. the RRC IE MasterKeyUpdate or a RRC IE RadioBearerConfig that includes SecurityConfig with Security AlgorithmConfigIndication to perform PDCP re-establishmentIndication to perform a full configuration, e.g. the RRC field fullConfig

[0056] The text refers to a mobility procedure, configuration of a mobility procedure or execution of a mobility procedure. In the context of this disclosure, a mobility procedure may be L1 / L2 Triggered Mobility, LTM, inter-CU LTM, inter-SN LTM, L3 handover, PCell handover, conditional handover (CHO), conditional LTM, PSCell change or conditional PSCell Addition or Change (CP AC). The embodiments of the present disclosure may use inter-SN LTM as an example. However, many of the examples may also be applied for other mobility procedures, for example, LTM, inter-CU LTM, conditional LTM or CHO.

[0057] The text refers to a mobility configuration. When the UE has been configured with a mobility configuration, it may use the mobility configuration during preparation of a mobility procedure, including measurements (such as RSRP measurements on neighbor or serving cells), triggering and transmission of measurement reports, synchronization towards neighbor cells, evaluation of conditions (for conditional mobility, e.g. CHO), and during the execution of a mobility procedure (e.g. execution of an LTM cell switch procedure, execution of an inter-MN LTM cell switch procedure or execution of handover).

[0058] A mobility configuration may include one or multiple of the following type of elements where each element contains a configuration of one aspect of LTM, for example as follows:- LTM candidate cell configuration(s),inter-CU LTM candidate cell configuration(s),lower layer information, such as physical layer configuration, MAC layer configuration or RLC layer configuration, Cell Group configuration, serving cell configuration higher layer information, such as RRC protocol parameters, such as timer values, PDCP layer configuration, radio bearer configuration or measurement configuration Configuration of measurements for LTMConfiguration for measurement reports for LTMCSI resource configuration(s) for LTMCSI report configuration for LTMConfigurations of early synchronization procedures, such aso Configurations for DL pre-sync for LTM, such as configurations for early TCI state activationo Configurations for UL pre-sync for LTM, such as configurations for reception of PDCCH ordered triggered preamble transmission and reception of TA Configurations for the execution of an LTM cell switch procedure for a given LTM candidate cell configuration or inter-CU LTM candidate cell configuration (e.g.,whether to perform random access procedure, whether to perform RLC reestablishment, or MAC reset, or PDCP recovery), a timer value, configured UL grants, dedicated RA preambles .A configuration according to which the UE may to start to operate when it performs an LTM cell switch procedure to an LTM candidate cell which is controlled by a different base station, e.g. gNB, from the current source base station e.g. serving gNB of the UE. Information to perform security key refresh, e.g. the RRC IE MasterKeyUpdate or a RRC IE RadioBearerConfig that includes SecurityConfig with Security AlgorithmConfig.Indication to perform a full configuration, e.g. the RRC field fullConfig.Indication to perform L2 re-establishment, such as an indication to perform PDCP reestablishment for one or multiple bearers.

[0059] The term “subsequent LTM”, sometimes also referred to a “subsequent LTM cell switch (procedures)” refers to that the UE performs a first LTM cell switch procedure from a source cell to a first target cell, then performs a second LTM cell switch procedure from the first target cell (which is now the new source cell) to a second target cell, and between the first and second LTM cell switch procedures there is no RRC reconfiguration of the UE. This implies also that the network does not add / remove / modify the LTM candidate cell configuration(s) or inter-CU LTM candidate cell configuration(s) in the UE between the two LTM cell switch procedures.

[0060] The text refers also to “handling of the configuration of the mobility procedure”. This is the case where a network node indicates to another network node either an indication to configuration or not configure a certain procedure (e.g., a mobility procedure) where this indication is in the form of a suggestion. Alternatively, this indication is in a form of a restriction, and in this case a network node indicates to another network node whether the another network node is allowed or not to configure a certain procedure (e.g., a mobility procedure).

[0061] The text uses the term “cell” to identify a location (or coverage) on which the UE is located. However, the term “cell” can also be exchanged without any loss of meaning with the terms “radio resources”, “beams”, “TCI state”, or “TRS”. This is just to clarify that embodiments of the present disclosure do not target specifically a scenario where there is a cell, but rather when a UE uses a set of source radio resources and subsequently switches to a target set of radio resources. In such a case, radio resource can also identify a set of configurations, field, parameters, or ASN.1 structures or IES.

[0062] The text further uses the term MCG to identify a first network node that provides a first connectivity link to the UE and SCG to identify the second network node that provides a second connectivity link to the UE. However, the terms “MCG” and “MN” can be exchanged without any loss of meaning as well as the terms “SCG” and “SN”.

[0063] The text discloses Conditional LTM (CLTM), which can be viewed as a form of conditional reconfiguration. In CLTM, the UE is configured with at least one LTM candidate cell (denoted as a CLTM candidate cell), by receiving an LTM candidate cell configuration, as in legacy LTM, and called herein a Conditional LTM candidate cell configuration, and an associated execution condition, denoted as CLTM execution condition. The evaluation of CLTM execution condition associated to a CLTM candidate cell is performed by the assessment of lower layer measurements, such as Layer 1 reference signal received power (Ll-RSRP) and / or SS-RSRP, derived from SSBs and / or CSLRSs of either the source cell and / or an LTM candidate cell. Lower layer measurements, in this context, are measurements reported to support lower layer procedures like beam management, candidate cell TCI state activation / deactivation, early timing advance (TA) acquisition, and link adaptation, and they aren't filtered based on Layer 3 (L3) parameters, though there may or may not be some filtering of these measurements based on the other lower layer parameters. The reception of CLTM execution condition may also involve receiving an indication of the condition and / or configuring it with parameters such as event identifier(s), offset(s), threshold(s), reference signal (RS) type, trigger quantity such as RSRP, reference signal received quality (RSRQ) or signal-to-interference-plus-noise ratio (SINR), time-to-trigger (TTT), and so forth.

[0064] In the context of CLTM, the UE may rely on evaluating one or two condition(s), referred to as CLTM execution condition(s), LTM execution condition(s), or triggering condition(s), or a combination thereof. And, when the condition(s) for a CLTM candidate cell is fulfilled, the UE performs a cell switch, which may be seen as a kind of LTM execution which is not triggered by the reception of an LTM cell switch command; this may also be considered as a kind of LTM cell switch, or LTM cell switch execution, or Conditional LTM cell switch, or Conditional LTM execution, or CLTM execution, or simply cell switch. According to the methods outlined in the present disclosure, upon satisfaction of the execution condition(s), the UE initiates an LTM cell switch. The term LTM cell switch refers to the process of a UE changing its cell from a source cell to a target cell, using L1 / L2 triggered mobility (LTM). In the context of Conditional LTM execution, the text may refer to the serving cell before the LTM cell switch as source cell, old source cell, or previous source cell.

[0065] The text also discusses the concept of an LTM candidate cell within the framework of Conditional LTM. The candidate cell may be referred to as a CLTM candidate cell, CLTM cell, simply candidate cell, candidate target cell, simply target cell, LTM candidate cell, LTM cell, or L1 / L2 inter-cell mobility candidate cell, depending on the context or terminology used in the present disclosure. Essentially, it denotes a cell to which the UE is directed or switches to in the event of executing a conditional L1 / L2 inter-cell mobility procedure after meeting the associated execution condition(s) and may also be termed as new source cell or next source cell after the LTM cell switch. These cells may also be termed as candidate cells, mobility candidates, non-serving cells, additional cells, candidate target cell, simply target cell or deactivated cells. An LTM candidate cell might also pertain to a candidate cell in a 5G Radio Access Technology like NR or a future 6G Radio Access Technology.

[0066] In the methods outlined in the present disclosure, the UE may receive an LTM candidate cell configuration for Conditional LTM, typically through an RRC Reconfiguration message, which is stored in the UE and applied upon fulfillment of the associated CLTM execution conditions. An LTM candidate cell configuration comprises the configuration according to which the UE may start to operate when it performs a Conditional LTM execution to that LTM candidate cell e.g., upon the fulfilment of CLTM execution conditions. A candidate cell configuration may include parameters in the information element (IE) CellGroupConfig per LTM candidate cell and / or an embedded RRC Reconfiguration per candidate cell. An LTM candidate cell configuration is associated with an identifier which is used in the signaling when referring to a certain LTM candidate cell configuration, such as when performing the early UL or DL synchronization with that LTM cell. This identifier is sometimes known as the LTM candidate cell configuration identifier (ID) or LTM candidate configuration index (or similar).

[0067] Figure 3 depicts a method in accordance with particular embodiments. The method of Figure 3 may be performed by a wireless device (e.g. UE 1312, station 1412 or wireless device 1500 as described later with reference to Figures 13, 14 and 15 respectively). The wireless device may correspond to the “UE” referenced in any of embodiments A1-A9, Bl-B4, AB1-AB9, BA1-BA7, and C1-C9 discussed below.

[0068] The method of Figure 3 is complementary to the methods of Figures 4 and 5, and should therefore be read in conjunction with the description of the flowcharts of these figures. Additional information for the method of Figure 3 can be found in the sections entitled “UE Embodiments” and “Additional scenarios and embodiments” provided below.

[0069] The method begins at step 302, in which the wireless device transmits, to a first network node or a second network node, security information for the wireless device. This step may correspond to any one or more of step 810 of Figure 8 and / or step 912 of Figure 9. This step may also correspond to step 502.

[0070] The first network node may act as a MN serving the wireless device. In this scenario, the first network node may correspond to the “first network node” referenced in any of embodiments A1-A9 and B1-B4 discussed below.

[0071] Alternatively, the first network node may act as a candidate or target MN for the wireless device, wherein at least one cell of the candidate or target MN may be included in an LTM candidate cell configuration of the wireless device. In this scenario, the first network node may correspond to the “third network node” referenced in any of embodiments AB1-AB9 and BA1-BA7 discussed below.

[0072] The first network node may also correspond to the first network node referenced in any of embodiments C1-C9 discussed below.

[0073] The second network node acts as a SN serving the wireless device subsequent to the performance of the LTM mobility procedure. The second network node may correspond to the “second network node” referenced in any of embodiments A1-A9, B1-B4, AB1-AB9, BA1-BA7, and C1-C9 discussed below.

[0074] The security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device (e.g., an inter-CU LTM mobility procedure and / or a conditional LTM mobility procedure). For example, the security information may comprise one or more of an indication of the at least one security key; an indication of one or more freshness indicators (e.g., sk-counters) that are to be used by the second network node to derive the at least one security key; and an indication of one or more security algorithms used by the wireless device during the LTM mobility procedure, wherein the one or more algorithms are to be used by the second network node to derive the at least one security key.

[0075] The method of Figure 3 will now be discussed for embodiments in which the first network node acts as the MN serving the wireless device.

[0076] Prior to the performance of the LTM mobility procedure, the wireless device may be served by a different SN to the second network node. That is, prior to the performance of the LTM mobility procedure, the wireless device may be in a dual connectivity mode.

[0077] The performance of the LTM mobility procedure may be triggered by one of: the wireless device, the first network node, and the second network node. For example, when the performance of the LTM mobility procedure is triggered by the wireless device (e.g., the LTM mobility procedure is a CLTM mobility procedure), the method of Figure 3 may further comprise the wireless device initiating the performance of the LTM mobility procedure (e.g., see steps 1002 and 1004 of Figure 10). When the performance of the LTM mobility procedure is triggered by the first network node procedure (e.g., see steps 904 and 906 of Figure 9 and steps 1202 and 1204 of Figure 12) (e.g., the LTM mobility procedure is an inter-MN mobility procedure), the method of Figure 3 may further comprise the wireless device receiving, from the first network node, a command or a request to perform the LTM mobility. When the performance of the LTM mobility procedure is triggered by the second network node (e.g., when the second network node is serving the wireless device prior to the performance of the cell switch procedure) (e.g., see step 600 of Figure 6, step 700 of Figure 7, and steps 802 and 804 of Figure 8), the method of Figure 3 may further comprise the wireless device receiving, from the second network node, a command or a request to perform the LTM mobility procedure.

[0078] The wireless device may transmit, to the first network node or second network node, the security information before or after the performance of the LTM mobility procedure. The security information may be transmitted to the first network node or the second network node in, for example, one or more of an RRC message, a MAC CE, and physical layer signalling (e.g., DCI).

[0079] The method of Figure 3 will now be discussed for embodiments in which the first network node acts as the target MN for the wireless device.

[0080] The at least one cell may be included in a MCG of the target MN, and subsequent to the performance of the LTM mobility procedure, the wireless device may be served by the at least one cell. That is, the LTM mobility procedure may be an inter-MN LTM mobility procedure.

[0081] Prior to the performance of the LTM mobility procedure, the wireless device may be in a single connectivity mode. Alternatively, prior to the performance of the LTM mobility procedure, the wireless device may be served by a different SN to the second network node. That is, prior to the performance of the LTM mobility procedure, the wireless device may be in a dual connectivity mode.

[0082] The performance of the LTM mobility procedure may be triggered by one of: the wireless device, the first network node, and a fourth network node. For example, when theperformance of the LTM mobility procedure is triggered by the wireless device (e.g., the LTM mobility procedure is a CLTM mobility procedure) (e.g., see steps 1002 and 1004 of Figure 10), the method of Figure 3 may further comprise the wireless device initiating the performance of the LTM mobility procedure. When the performance of the LTM mobility procedure is triggered by the second network node (e.g., when the second network node is serving the wireless device prior to the performance of the cell switch procedure) (e.g., see step 600 of Figure 6, step 700 of Figure 7, and steps 802 and 804 of Figure 8), the method of Figure 3 may further comprise the wireless device receiving, from the second network node, a command or a request to perform the LTM mobility procedure. When the performance of the LTM mobility procedure is triggered by the fourth network node (e.g., wherein the fourth network node is acting as a MN serving the wireless device) (e.g., see steps 902 to 908 of Figure 9, step 1100 of Figure 11 and step 1200 of Figure 12), the method may further comprise the wireless device receiving, from the fourth network node, a request or a command to perform the LTM mobility procedure.

[0083] The wireless device may transmit, to the first network node or second network node, the security information before or after the performance of the LTM mobility procedure. The security information may be transmitted to the first network node or the second network node in, for example, one or more of an RRC message, a MAC CE, and physical layer signalling (e.g., DCI).

[0084] Figure 4 depicts a method in accordance with particular embodiments. The method of Figure 4 may be performed by a first network node (e.g. network node 1310, access point 1410 or network node 1600 as described later with reference to Figures 13, 14 and 16 respectively).

[0085] The method of Figure 4 is complementary to the method of Figures 3 and 5, and should therefore be read in conjunction with the description of the flowcharts of these figures. Additional information for the method of Figure 4 can be found in the sections entitled “Network Embodiments” and “Additional scenarios and embodiments” provided below.

[0086] The first network node may act as a MN serving a wireless device. In such embodiments, the first network node may correspond to the “first network node” referenced in any of embodiments A1-A9 and B1-B4 discussed below.

[0087] Alternatively, the first network node may act as a candidate or target MN for the wireless device, wherein at least one cell of the candidate or target MN may be included in an LTM candidate cell configuration of the wireless device. In such embodiments, the firstnetwork node may correspond to the “third network node” referenced in any of embodiments AB1-AB9 and BA1-BA7 discussed below.

[0088] The first network node may also correspond to the first network node referenced in any of embodiments C1-C9 discussed below.

[0089] The wireless device may correspond to the “UE” referenced in any of embodiments A1-A9, B1-B4, AB1-AB9, BA1-BA7, and C1-C9 discussed below.

[0090] The method begins at step 402, with the first network node transmitting, to a second network node, security information for the wireless device. This step may correspond to any one or more of: steps 602 and / or 610 of Figure 6; steps 702 and / or 710 of Figure 7; steps 812 and / or 814 of Figure 8; step 910 and / or 914 of Figure 9; steps 1006 and / or 1008 of Figure 10; steps 1102 and / or 1110 of Figure 11; and steps 1202 and / or 1210 of Figure 12. This step may correspond to step 502.

[0091] The second network node acts as a SN serving the wireless device subsequent to the performance of the LTM mobility procedure. The second network node may correspond to the “second network node” referenced in any of embodiments A1-A9, B1-B4, AB1-AB9, BA1-BA7, and C1-C9 discussed below.

[0092] The security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device (e.g., an inter-CU LTM mobility procedure and / or a conditional LTM mobility procedure). For example, the security information may comprise one or more of: an indication of the at least one security key; an indication of one or more freshness indicators (e.g., sk-counters) that are to be used by the second network node to derive the at least one security key; and an indication of one or more security algorithms used by the wireless device during the LTM mobility procedure, wherein the one or more algorithms are to be used by the second network node to derive the at least one security key.

[0093] The method of Figure 4 will now be discussed for embodiments in which the first network node acts as a MN serving a wireless device.

[0094] Prior to the performance of the LTM mobility procedure, the wireless device may be served by a different SN to the second network node. That is, prior to the performance of the LTM mobility procedure, the wireless device may be in a dual connectivity mode.

[0095] The performance of the LTM mobility procedure may be triggered by one of: the wireless device, the first network node, and the second network node. For example, when the performance of the LTM mobility procedure is triggered by the wireless device (e.g., the LTMmobility procedure is a CLTM mobility procedure) (e.g., see steps 1002 - 1004 of Figure 10), the method of Figure 4 may further comprise the first network node receiving, from the wireless device, a command or a request to perform the LTM mobility procedure. When the performance of the LTM mobility procedure is triggered by the first network node (e.g., the LTM mobility procedure is an inter-MN mobility procedure), the method of Figure 4 may further comprise the first network node initiating the performance of the LTM mobility procedure (e.g., see steps 902 - 904 of Figure 9 and steps 1202 - 1204 of Figure 12). When the performance of the LTM mobility procedure is triggered by the second network node (e.g., when the second network node is serving the wireless device prior to the performance of the cell switch procedure) (e.g., see step 600 of Figure 6, step 700 of Figure 7, and steps 902 - 904 of Figure 9), the method of Figure 4 may further comprise the first network node receiving, from the second network node, a command or a request to perform the LTM mobility procedure.

[0096] The first network node may transmit the security information to the second network node before or after the performance of the LTM mobility procedure. The first network node may transmit the security information to the second network node in one of an SN Addition Request, an SN Modification Request, a Cell Switch Notification, an LTM Configuration Update, and an XnAP procedure.

[0097] The first network node may receive the security information from the wireless device before or after the performance of the LTM mobility procedure (e.g., in a step corresponding to step 302). The security information may be received from the wireless device in one or more of an RRC message, a MAC CE, and physical layer signalling (e.g., DCI).

[0098] The method of Figure 4 will now be discussed for embodiments in which the first network node acts as a candidate or target MN for the wireless device.

[0099] The at least one cell may be included in a MCG of the target MN, and subsequent to the performance of the LTM mobility procedure, the wireless device is served by the at least one cell. For example, the LTM mobility procedure may be an inter-SN mobility procedure.

[0100] Prior to the performance of the LTM mobility procedure, the wireless device may be in a single connectivity mode. Alternatively, prior to the performance of the LTM mobility procedure, the wireless device may be served by a different SN to the second network node. That is, prior to the performance of the LTM mobility procedure, the wireless device may be in a dual connectivity mode.

[0101] The performance of the LTM mobility procedure may be triggered by one of: the wireless device, the second network node, and a fourth network node. For example, when theperformance of the LTM mobility procedure is triggered by the wireless device (e.g., the LTM mobility procedure is a CLTM mobility procedure) procedure (e.g., see steps 1002 - 1004 of Figure 10), the method of Figure 4 may further comprise the first network node receiving, from the wireless device, a command or a request to perform the LTM mobility procedure. When the performance of the LTM mobility procedure is triggered by the second network node (e.g., when the second network node is serving the wireless device prior to the performance of the cell switch procedure) (e.g., see step 600 of Figure 6, step 700 of Figure 7, and steps 802 - 804 of Figure 8), the method of Figure 4 may further comprise the first network node receiving, from the second network node, a command or a request to perform the LTM mobility procedure. When the performance of the LTM mobility procedure is triggered by the fourth network node (e.g., wherein the fourth network node is acting as a MN serving the wireless device) (e.g., see steps 902 - 908 of Figure 9, step 1100 of Figure 11 and step 1200 of Figure 12), the method may further comprise the first network node receiving, from the fourth network node, a request or a command to perform the LTM mobility procedure.

[0102] The first network node may transmit the security information to the second network node before or after the performance of the LTM mobility procedure. The first network node may transmit the security information to the second network node in one of an SN Addition Request, an SN Modification Request, a Cell Switch Notification, an LTM Configuration Update, and an XnAP procedure.

[0103] The first network node may receive the security information from the wireless device before or after the performance of the LTM mobility procedure (e.g., in a step corresponding to step 302). The security information may be received from the wireless device in one or more of an RRC message, a MAC CE, and physical layer signalling (e.g., DCI).

[0104] The first network node may additionally or alternatively receive the security information from a fourth network node acting as an MN serving the wireless device.

[0105] Figure 5 depicts a method in accordance with particular embodiments. The method of Figure 5 may be performed by a second network node (e.g. network node 1310, access point 1410 or network node 1600 as described later with reference to Figures 13, 14 and 16 respectively).

[0106] The method of Figure 5 is complementary to the method of Figures 3 and 4, and should therefore be read in conjunction with the description of the flowcharts of these figures. Additional information for the method of Figure 5 can be found in the sections entitled “Network Embodiments” and “Additional scenarios and embodiments” provided below.

[0107] The second network node acts as a SN serving a wireless device subsequent to a performance of an LTM mobility procedure by the wireless device. The second network node may correspond to the “second network node” referenced in any of embodiments A1-A9, Bl-B4, AB1-AB9, BA1-BA7, and C1-C9 discussed below. The wireless device may correspond to the “UE” referenced in any of embodiments A1-A9, B1-B4, AB1-AB9, BA1-BA7, and Cl-C9 discussed below.

[0108] The method begins at step 502, with the second network node receiving security information for the wireless device. The security information may be received from the wireless device or a first network node. This step may correspond to any one or more of: steps 602 and / or 610 of Figure 6; steps 702 and / or 710 of Figure 7; steps 812 and / or 814 of Figure 8; step 910 and / or 914 of Figure 9; steps 1006 and / or 1008 of Figure 10; steps 1102 and / or 1110 of Figure 11; and steps 1202 and / or 1210 of Figure 12. This step may also correspond to step 302 and / or 402.

[0109] The first network node may act as a MN serving a wireless device. The first network node may correspond to the “first network node” referenced in any of embodiments A1-A9 and B1-B4 discussed below.

[0110] Alternatively, the first network node may act as a candidate or target MN for the wireless device, wherein at least one cell of the candidate or target MN may be included in an LTM candidate cell configuration of the wireless device. The first network node may correspond to the “third network node” referenced in any of embodiments AB1-AB9 and BA1-BA7 discussed below.[OHl] The first network node may also correspond to the first network node referenced in any of embodiments C1-C9 discussed below.

[0112] The security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device (e.g., an inter-CU LTM mobility procedure and / or a conditional LTM mobility procedure). For example, the security information may comprise one or more of: an indication of the at least one security key; an indication of one or more freshness indicators (e.g., sk-counters) that are to be used by the second network node to derive the at least one security key; and an indication of one or more security algorithms used by the wireless device during the LTM mobility procedure, wherein the one or more algorithms are to be used by the second network node to derive the at least one security key.

[0113] The method of Figure 5 will now be discussed for embodiments in which the first network node acts as a MN serving a wireless device.

[0114] Prior to the performance of the LTM mobility procedure, the wireless device may be in a single connectivity mode. Alternatively, prior to the performance of the LTM mobility procedure, the wireless device may be served by a different SN to the second network node. That is, prior to the performance of the LTM mobility procedure, the wireless device may be in a dual connectivity mode.

[0115] The performance of the LTM mobility procedure may be triggered by one of: the wireless device, the first network node, and the second network node. For example, when the performance of the LTM mobility procedure is triggered by the wireless device (e.g., the LTM mobility procedure is a CLTM mobility procedure) (e.g., see steps 1002 - 1004 of Figure 10), the method of Figure 5 may further comprise the second network node receiving, from the wireless device, a command or a request to perform the LTM mobility procedure. When the performance of the LTM mobility procedure is triggered by the first network node (e.g., the LTM mobility procedure is an inter-MN mobility procedure) (e.g., see steps 901 and 904 of Figure 9, and steps 1202 and 1204 of Figure 12), the method of Figure 5 may further comprise the second network node receiving, from the first network node, a command or a request to perform the LTM mobility procedure. When the performance of the LTM mobility procedure is triggered by the second network node (e.g., when the second network node is serving the wireless device prior to the performance of the cell switch procedure) (e.g., see step 600 of Figure 6, step 700 of Figure 7, and steps 802 - 804 of Figure 8), the method of Figure 5 may further comprise the second network node initiating the performance of the LTM mobility procedure.

[0116] The second network node may receive the security information from the wireless device or first network node before or after the performance of the LTM mobility procedure. The second network node may receive the security information from the first network node in one of an SN Addition Request, an SN Modification Request, a Cell Switch Notification, an LTM Configuration Update, and an XnAP procedure.

[0117] The method of Figure 5 will now be discussed for embodiments in which the first network node acts as a candidate or target MN for the wireless device.

[0118] The at least one cell may be included in an MCG of the one of the candidate or target MN, and subsequent to the performance of the LTM mobility procedure, the wireless device may be served by the at least one cell. For example, the LTM mobility procedure may be an inter-MN mobility procedure.

[0119] Additionally or alternatively, prior to the performance of the LTM mobility procedure, the wireless device may be in a single connectivity mode.

[0120] The performance of the LTM mobility procedure may be triggered by one of the wireless device, the second network node, and a fourth network node. For example, when the performance of the LTM mobility procedure is triggered by the wireless device (e.g., the LTM mobility procedure is a CLTM mobility procedure) (e.g., see steps 1002 - 1004 of Figure 10), the method of Figure 5 may further comprise the second network node receiving, from the wireless device, a request or a command to perform the LTM mobility procedure. When the performance of the LTM mobility procedure is triggered by the second network node (e.g., when the second network node is serving the wireless device prior to the performance of the cell switch procedure) (e.g., see step 600 of Figure 6, step 700 of Figure 7, and steps 802 - 804 of Figure 8), the method of Figure 5 may further comprise the second network node initiating the performance of the LTM mobility procedure. When the performance of the LTM mobility procedure is triggered by the fourth network node (e.g., wherein the fourth network node is acting as a MN serving the wireless device) (e.g., see steps 902 - 908 of Figure 9, step 1100 of Figure 11 and step 1200 of Figure 12), the method of Figure 5 may further comprise the second network node receiving, from the fourth network node, a request or a command to perform the LTM mobility procedure.

[0121] The second network node may receive the security information from the wireless device or first network node before or after the performance of the LTM mobility procedure. The second network node may receive the security information from the first network node in one of an SN Addition Request, an SN Modification Request, a Cell Switch Notification, an LTM Configuration Update, and an XnAP procedure.Network EmbodimentsInter-SN LTM with SCG

[0122] One or more of the following embodiments may correspond to, or be included in, the method of Figure 4 or any steps thereof, particularly when the first network node is acting as the MN serving the wireless device.Al. A method at a first network node, acting as a Master Node (MN), e.g., a gNodeB or a Central Unit gNodeB (CU), which has configured the UE with at least one LTM candidate cell on its MCG or SCG. The method comprises:Transmitting, to a second network node, such as a Secondary Node (SN), a message to update the security information for the User Equipment (UE) for mobility. This step may be performed as part of step 402 and / or 502 discussed above.Optionally receiving, from a second network node, a message to acknowledge that the security information for the User Equipment (UE) for mobility is updated.- Receiving from the UE a message about what security information the UE has applied or derived during a mobility procedure. This step may be performed as part of step 302 discussed above.Transmitting a message to inform the second network node about the security information that the UE applied during mobility. This step may be performed as part of step 402 and / or 502 discussed above.A2. The method according to Al, wherein the procedure between the first network node and the second network node uses one or more XnAP procedures, e.g., SN Addition Request, and / or SN Modification Request, and / or Cell Switch Notification, and / or an LTM Configuration Update, and / or a new XnAP procedure.A3. The method according to Al, which relates to a mobility procedure, configuration of a mobility procedure or execution of a mobility procedure. In the context of this disclosure, a mobility procedure may be L1 / L2 Triggered Mobility, LTM, inter-CU LTM, inter-MN LTM, inter-SN LTM, and Conditional LTM.A4. The method according to Al, wherein a set of security information may include one or more of the following information:A security key which is associated to a second network node.One or more sk-counters that are to be used for the UE to derive security keys in the SN.One sk-counter that the UE already applied during the mobility.A security key which is associated to a first network nodeOne or more security algorithms which have been used by the UEA5. The method according to Al, wherein the security information received by the UE is received in a message which is received before a mobility procedure is triggered by the first network node.A6. The method according to Al, wherein the security information received by the UE is received in a message which is received after a mobility procedure is triggered by the first network node.In one example, the message is received right after the first network node send a command to trigger the initiation of a mobility procedure at the UE.In one example, the message is received within a time T from when the first network node sends a command to trigger the initiation of a mobility procedure at the UE. A7. The method according to Al, wherein the security information received by the UE is received in a message which is received before a mobility procedure is triggered by the first network node.A8. The method according to Al, wherein the security information received by the UE is received in a message which is received when a second network node triggers a mobility procedure at the UE.In this example, the first network node receives a message from the UE with security information that UE has applied or derived for a mobility procedure which was triggered by another network node, e.g., from the second network node.A9. The method according to Al, wherein the message received by the UE is received according to one or more of the following signalling options:An existing or a new RRC messageAn existing or a new MAC CEAn existing or a new physical layer signalling (e.g., DCI)

[0123] One or more of the following embodiments may correspond to, or be included in, the method of Figure 5 or any steps thereof, particularly when the first network node is acting as the MN serving the wireless device.Bl. A method at a second network node, acting as Secondary Node (SN), a candidate SN, or a target SN, e.g., a gNodeB or a Central Unit gNodeB (CU), towards which the UE performs a mobility procedure. The method comprises:- Receiving, from the first network node, a message with the security information during a configuration phase. This step may be performed as part of step 402 and / or 502 discussed above.Optionally transmitting a message to the first network node, to acknowledge that the security information is updated in the second network node.Optionally receiving from a UE which is performing a mobility procedure to the second network node a message containing security information the UE has applied or derivedduring a mobility procedure. This step may be performed as part of step 302 and / or 502 discussed above.- Receiving, from the first network node, a message with the security information that the UE applied. This step may be performed as part of step 402 and / or 502 discussed above.B2. The method according to Bl, wherein a set of security information may include one or more of the following information:A security key which is associated to a first network nodeOne or more sk-counters that are to be used for the UE to derive security keys in the SN.One sk-counter that the UE already applied during the mobility.A security key which is associated to a first network nodeOne or more security algorithms which have been used by the UEB3. The method according to Bl, wherein the message received from the UE is received before the UE indicates to the second network node with a second message that the mobility procedure (towards the second network node) has been completed.B4. The method according to Bl, wherein the message received by the UE is received according to one or more of the following signalling options:An existing or a new RRC messageAn existing or a new MAC CEAn existing or a new physical layer signalling (e.g., DCI)Inter-MN LTM with SCG

[0124] One or more of the following embodiments may correspond to, or be included in, the method of Figure 4 or any steps thereof, particularly when the first network node is acting as a candidate or target MN for the wireless device.ABE A method at a third network node, acting as a candidate target Master Node (MN), e.g., a gNodeB or a Central Unit gNodeB (CU), for an LTM candidate configuration for a User Equipment (UE). The method comprises:- Receiving from a first network node, acting as a serving Master Node (MN) for the UE, a request for an LTM candidate cell configuration for a cell belonging to the third network, i.e. an LTM candidate configuration supporting an inter-MN LTM cell switch. The request optionally includes information about an SCG configuration that the UE has, or may have, prior to an execution of the corresponding MCG LTM cell switch, oran indication about whether the LTM candidate cell configuration for the cell in the third network node should include an SCG configuration for the UE;Generating the MCG LTM candidate cell configuration for the cell (the candidate target PCell) in the third network node, including determining to include an SCG configuration with / in the MCG LTM candidate cell configuration for the candidate target PCell;Transmitting, to a second network node, such as a node acting as a Secondary Node (SN), for the UE, or a node that is requested to act as a candidate target SN for the UE, a message to request the SN to be a candidate target SN for the MCG LTM candidate cell configuration with the candidate target PCell belonging to the third network node; - Receiving, from the second network node, a message to acknowledge that the SN is a candidate target SN for the MCG LTM candidate cell configuration with the candidate target PCell belonging to the third network node. Optionally, the message includes a configuration for the SCG that is to be included in the LTM candidate cell configuration (for the MCG cell switch);Transmitting to the first network node, a message to acknowledge the request for an LTM candidate cell configuration for the cell belonging to the third network, i.e. an LTM candidate configuration supporting an inter-MN LTM cell switch to the third network node; The message includes the LTM candidate cell configuration for the cell in the third network node, optionally with an SCG configuration (for which the second network node acts as an SN for the UE);- Receiving from the first network node a message indicating that the UE performs an LTM cell switch to the third network node based on the LTM candidate cell configuration. Optionally the message includes information about the security key that the UE will use for the MCG in the third network node. This step may be included in the method of any of Figures 3 to 5 discussed above.Optionally receiving a message from the UE including information about the security key that the UE will use for the connection to the SN, e.g. an sk-counter that the UE uses in order to generate the secondary key. This step may be performed as part of step 302 discussed above.- Determining the security key that the UE shall use towards the second network node (acting as an SN) after the LTM cell switch to the candidate target PCell in the third network nodeTransmitting to the second network node a message to inform the second network node about the security information that the UE applied for the SCG, i.e. towards the second network node, during the LTM cell switch procedure to the third network node. This step may be performed as part of step 402 and / or 502 discussed above.AB2. The method according to AB1, wherein the message transmitted to the second network node, to request it to be a candidate target SN for the MCG LTM candidate cell configuration, is an XnAP message, e g. an S-NODE ADDITION REQUEST message, an S-NODE MODIFICATION REQUEST message or an LTM CONFIGURATION UPDATE message. AB3. The method in AB1 or AB2, wherein the message transmitted to the second network node, to request it to be a candidate target SN for the MCG LTM candidate cell configuration, does not include any security information to be used at the execution of the procedure.AB4a. The methods in any of AB1 to AB3, wherein the message transmitted to the second network node, to request it to be a candidate target SN for the MCG LTM candidate cell configuration, corresponds to an SCG reconfiguration for the UE.AB4b. The methods in any of AB1 to AB3, wherein the message transmitted to the second network node, to request it to be a candidate target SN for the MCG LTM candidate cell configuration, corresponds to an SCG addition for the UE.AB5. The methods in any of AB1 to AB4b, wherein the message received from the first network node indicating that the UE performs an LTM cell switch to the third network node, is an (LTM) Cell Switch Notification messageAB6. The methods in any of AB1 to AB5, wherein the message transmitted to the second network node to inform about the security information that the UE applied for the SCG (as part of the LTM cell switch for the MCG) is an (LTM) Cell Switch Notification message, an LTM CONFIGURATION UPDATE message, and S-NODE RECONFIGURATION COMPLETE message, an S-NODE MODIFICATION REQUEST message or a new message.AB7. The methods in any of AB1 to AB6 wherein the third network node receives a message from the UE including information about the security key that the UE will use for the connection to the SN.AB8. The method in AB7 wherein the message is an RRCReconfigurationComplete message. AB9. The method in AB7 or AB8 wherein the information comprises an sk-counter value that the UE uses to generate the secondary key.

[0125] One or more of the following embodiments may correspond to, or be included in, the method of Figure 5 or any steps thereof, particularly when the first network node is acting as a candidate or target MN for the wireless device.BAI. A method at a second network node, acting as Secondary Node (SN), or a candidate SN or target SN (e.g., a gNodeB or a Central Unit gNodeB (CU)) as part of an LTM candidate configuration for MCG (for an LTM cell switch to a candidate target PCell belonging to a third network node), for a User Equipment (UE). The method comprises:- Receiving, from the third network node, a message to request the second network node to be a candidate target SN for the MCG LTM candidate cell configuration with the candidate target PCell belonging to the third network node.Transmitting to the third network node a message to acknowledge that the second network node is a candidate target SN for the MCG LTM candidate cell configuration with the candidate target PCell belonging to the third network node. Optionally, the second network node includes in the message a configuration for the SCG that is to be included in the LTM candidate cell configuration (for the MCG cell switch);- Receiving from the third network node a message with information about the security key that the UE applied for the SCG, i.e. towards the second network node, during the LTM cell switch procedure to the third network node, and using this security key towards the UE after the LTM cell switch procedure to the third network node. This step may be performed as part of step 402 and / or 502 discussed above.BA2. The method according to BAI, wherein the message received from the third network node, requesting the second network node to be a candidate target SN for the MCG LTM candidate cell configuration, is an XnAP message, e.g. an S-NODE ADDITION REQUEST message, an S-NODE MODIFICATION REQUEST message or an LTM CONFIGURATION UPDATE message.BA3. The method according to BAI or BA2, wherein the message received from the third network node, requesting the second network node to be a candidate target SN for the MCG LTM candidate cell configuration, does not include any security key information to be used at the execution of the procedure.BA4. The methods in any of BAI to BA3, wherein the handling of the SCG as part of the execution of the MCG LTM candidate configuration, i.e. when the LTM cell switch is performed to the candidate target PCell in the third network node, corresponds to an SCG reconfiguration for the UE.BA5. The methods in any of BAI to BA3, wherein the handling of the SCG as part of the execution of the MCG LTM candidate configuration, i.e. when the LTM cell switch is performed to the candidate target PCell in the third network node, corresponds to an SCG addition for the UE.BA6. The methods in any of BAI to BA5, wherein the message received from the third network node with information about the security key that the UE applied for the SCG during the LTM cell switch procedure to the third network node, is an (LTM) Cell Switch Notification message, an S-NODE RECONFIGURATION COMPLETE message, an LTM CONFIGURATION UPDATE message, an S-NODE MODIFICATION REQUEST message or a new message. BA7. The methods in any of BAI to BA6, wherein the third network node applies the SCG configuration for the LTM candidate configuration towards the candidate target PCell in the third network node and uses the indicated secondary key towards the UE.UE embodiments

[0126] One or more of the following embodiments may correspond to, or be included in, the method of Figure 3 or any steps thereof.Cl . A method at a User Equipment (UE) configured with at least one LTM candidate cell and a first set of security information associated with the LTM candidate configuration. The method comprises:- Receiving from a first network node a message which triggers the LTM candidate configuration of a mobility procedure which may comprise the change of the security according to a first set of security information associated to the LTM candidate cell. Applying the received security information.Transmitting to the first network node a message to indicate that the RRC Reconfiguration is completed and wherein the message includes also the security information that the UE has applied or derived during a mobility procedure. This step may be performed as part of step 302 discussed above.Optionally transmitting to the second network node a message to indicate the security information that the UE has applied or derived during a mobility procedure. This step may be performed as part of step 302 and / or 502 discussed above.C2. The method according to Cl, wherein a set of security information may include one or more of the following information:A security key which is associated to a second network nodeOne or more sk-counters that are to be used for the UE to derive security keys in the SNA security key which is associated to a first network nodeOne or more security algorithms which have been used by the UEC3. The method according to Cl, wherein the UE derives a key associated to the second network node.C4. The method according to Cl, wherein the security information transmitted to the first network node is transmitted in a message which is received before a mobility procedure is triggered by the first network node.C5. The method according to Cl, wherein the security information transmitted to the first network node is transmitted in a message which is received after a mobility procedure is triggered by the first network node.In one example, the message is received right after the first network node send a command to trigger the initiation of a mobility procedure at the UE.In one example, the message is received within a time T from when the first network node send a command to trigger the initiation of a mobility procedure at the UE. C6. The method according to Cl, wherein the security information transmitted to the first network node is transmitted in a message which is received before a mobility procedure is triggered by the first network node.C7. The method according to Cl, wherein the security information transmitted to the first network node is transmitted in a message which is received when a second network node triggers a mobility procedure at the UE.In this example, the first network node receives a message from the UE with security information that UE has applied or derived for a mobility procedure which was triggered by another network node, e.g., from the second network node.C8. The method according to Cl, wherein the message transmitted to the second network node is transmitted before the UE indicates to the second network node with a second message that the mobility procedure (towards the second network node) has been completed.C9. The method according to Cl, wherein the message transmitted to the first network node or second network node is transmitted according to one or more of the following signalling options:An existing or a new RRC messageAn existing or a new MAC CEAn existing or a new physical layer signalling (e.g., DCI)Additional scenarios and embodiments

[0127] The following discussion provides additional detail for the methods of Figures 3 to 5.

[0128] One scenario where embodiments of the present disclosure may be useful to apply is for the case of a UE in single connectivity which moves from a first network node to a second network node thanks to LTM (or CLTM), and the second network node has prepared a third network node to be used as SN for the UE after the LTM mobility (or CLTM mobility). Before the inter-CU LTM / CLTM mobility, the UE has been configured with inter-CU MCG LTM and an intra-CU SCG LTM. The UE receives an LTM Cell Switch Command (or triggers a Conditional LMT) and moves from the first network node to the second network node, and the UE is reconfigured from single connectivity to dua connectivity, wherein for the SN part, the UE is configured for intra-CU SCG LTM.

[0129] One scenario where embodiments of the present disclosure may be useful to apply may be inter-MN handover with SN Change, where the UE is initially in dual connectivity, the UE moves from source MN to target MN, and the SN is changed (the old source SN is released, and a new target SN is added).

[0130] For the scenario where the UE is in single connectivity and reconfigured to dual connectivity upon LTM / CLTM mobility from a first (originally serving) network node, to a second network node (future MN), during the LTM / CLTM preparation phase, the first network node configures the UE for inter-CU MCG LTM and intra-CU SCG LTM. The LTM / CLTM configuration comprises an inter-CU MCG LTM / CLTM configuration for candidate cells served by one or more second network nodes which are candidate network node to be used as MN, and intra-CU SCG LTM / CLTM configuration for cells served by at least one third network node that at least one of the second network node prepared as potential SN. During the LTM / CLTM preparation phase, the first network node sends a message (e.g., a HANDOVER REQUEST XnAP message) to one or more second network nodes. At least one of the one or more second network nodes prepares one (or more) third network node as SN, so that, in case the UE will be moved to the second network node in question, the UE can have an intra-CU SCG LTM configuration (in addition to the inter-CU MCG LTM configuration). To prepare the security at the third network node SN, the second network node sends a message to the third network node (e.g., an S-NODE ADDITION REQUEST XnAP message) that includes SN security key and a list of sk-counters. The second network node requests the third network node to prepare an intra-CU SCG LTM configuration for the UE, which the thirdnetwork node sends back to the second network node (e.g., in an S-NODE ADDITION REQUEST ACKNOWLEDGE XnAP message). The second network node then sends a response to the first network node (e g., a HANDOVER REQUEST ACKNOWLEDGE XnAP message) carrying the intra-CU SCG LTM configuration prepared by the third network node and to be sent for the UE.

[0131] For the scenario where the UE is in dual connectivity and undergoes an inter-MN handover with SN change, the UE is initially connected to a first network node (source MN) and to a third network node (source SN). During an LTM / CLTM preparation phase, the first network node configures the UE for inter-CU MCG LTM and intra-CU SCG LTM. The LTM / CLTM configuration comprises an inter-CU MCG LTM / CLTM configuration for candidate cells served by one or more second network nodes which are candidate network node to be used as MN, and intra-CU SCG LTM / CLTM configuration for cells served by at least one fourth network node that at least one of the second network node prepared as potential SN. During the LTM / CLTM preparation phase, the first network node sends a message (e.g., a HANDOVER REQUEST XnAP message) to one or more second network nodes. At least one of the one or more second network nodes prepares one (or more) fourth network node as SN, so that, in case the UE will be moved to the second network node in question, the UE can have an intra-CU SCG LTM configuration (in addition to the inter-CU MCG LTM configuration). To prepare the security at the fourth network node SN, the second network node sends a message to the fourth network node (e.g., an S-NODE ADDITION REQUEST XnAP message) that includes SN security key and a list of sk-counters. The second network node requests the fourth network node to prepare an intra-CU SCG LTM configuration for the UE, which the fourth network node sends back to the second network node (e.g., in an S-NODE ADDITION REQUEST ACKNOWLEDGE XnAP message) carrying the intra-CU SCG LTM configuration prepared by the fourth network node and to be sent for the UE.Flow diagrams illustrating embodiments of the disclosure

[0132] Figure 6. is a signaling flow of security handling during inter-SN LTM configuration

[0133] Step 600. The source SN initiates the inter-SN SCG LTM procedure by sending the SN Change Required to the MN providing a list of candidate PSCell(s) for inter-SN SCG LTM preparation. The message may include an SCG reference configuration. Source SN may additionally send measurement results of candidate PSCells and the upper limit for the number of PSCells that can be prepared by each candidate SN to the MN.

[0134] Step 602-604. The MN requests each candidate SN to allocate resources for the UE by means of the SN Addition procedure. The MN may also provide a list of security keys and associated sk-Counter values for each candidate SN, and forward the received measurement results to each candidate SN(s). The MN may select one of the candidate SN(s) and request providing the reference SCG configuration as part of the SN Addition procedure. Once obtained, the MN provides the reference configuration to other candidate SN(s).

[0135] Step 606-608. The MN sends the received LI RS configuration, early UL / DL sync configuration of candidate cells to the source SN via SN Modification Request message. The source SN generates the common CSI resource configuration for LI measurement on candidate PSCells. The source SN sends the generated common CSI resource configuration and the updated source SCG configuration to the MN via SN modification request acknowledge message.

[0136] Step 610-612. The MN transfers, during the LTM preparation phase, the common CSI resource configuration and the collected information of candidate cells to each candidate SN. The candidate SN(s) responds with the updated candidate SCG configuration to the MN.

[0137] Step 614-616. The MN sends an RRCReconfiguration message to the UE. UE replies with an RRCReconfigurationComplete message after successful reconfiguration.

[0138] Step 618. The MN sends an SN Change Confirm message to the source SN to indicate that the SCG is prepared for LTM.

[0139] An alternative flow chart to the one represented in Figure 6 is the one in Figure 7, which also shows a signaling flow of security handling during inter-SN LTM configuration. In this embodiment, where the steps 710 and 712 are realized with an LTM Configuration Update / LTM Configuration Update Acknowledge respectively (as opposed to the SN Modification Request and SN Modification Request Ack in steps 610 and 612 respectively).

[0140] In this alternative, steps 710 and 712 are implemented respectively with LTM CONFIGURATION UPDATE and LTM CONFIGURATION UPDATE ACKNOWLEDGE messages instead of S-NG-RAN NODE MODIFICATION REQUEST and S-NG-RAN NODE MODIFICATION REQUEST. ACKNOWLEDGE.

[0141] Figure 8 is a signaling flow of security handling during inter-SN LTM execution

[0142] Step 800. The inter-SN LTM configuration is prepared, possibly according to one of the options shown in Figure 6 or Figure 7.

[0143] Steps 802-804. The Source SN receives LI measurements from the UE and takes the decision to perform LTM cell switch

[0144] Step 806. The Source SN sends an LTM Cell Switch Command to the UE

[0145] Step 808. The Source SN sends a Cell Switch Notification to the MN to inform the MN that UE moved to another cell (of the target SN)

[0146] Step 810: The UE sends an RRCReconfigurationComplete message to the MN to inform that the LTM Cell Switch is executed, and including the sk-counter applied by the UE.

[0147] Step 812. The MN sends to the target SN a Cell Switch Notification message to inform the target SN which sk-counter the UE has applied.

[0148] Step 814: The MN may send to the target SN an SN Reconfiguration Complete (e g., an S-NG-RAN NODE RECONFIGURATION COMPLETE XnAP message) to inform the target SN which sk-counter the UE applied.

[0149] Figure 9 is a signaling flow of security updates during inter-MN LTM execution according to embodiments of the disclosure.

[0150] Step 900. The inter-MN LTM configuration is prepared.

[0151] Steps 902-904. The Source MN receives LI measurements from the UE and takes the decision to perform LTM cell switch

[0152] Step 906. The Source MN sends an LTM Cell Switch Command to the UE

[0153] Step 908. The Source MN sends a Cell Switch Notification to the target MN to inform the MN that UE moved to another cell (of the target MN)

[0154] Step 910. The target MN sends to the SN a Cell Switch Notification message including the SN security key for the SN to use and a list of associated sk-Counter values

[0155] Step 912. The UE sends an RRCReconfigurationComplete message to the target MN to inform that the LTM Cell Switch is executed, and including the sk-counter applied by the UE.

[0156] Step 914: The target MN sends to the SN an SN Reconfiguration Complete (e.g., an S-NG-RAN NODE RECONFIGURATION COMPLETE XnAP message) to inform the SN which sk-counter the UE applied.

[0157] Figure 10 is a signaling flow of security updates for inter-SN Conditional LTM according to embodiments of the disclosure.

[0158] Step 1000. The inter-SN Conditional LTM configuration is prepared.

[0159] Step 1002-1004. The UE takes the decision to perform Conditional LTM cell switch and performs Random Access to the MN

[0160] Step 1006. The MN sends an Cell Switch Notification to the Source SN, comprising the SN security key and a list of associated sk-Counter values.

[0161] Step 1008. The MN sends a Cell Switch Notification (or a new message / procedure) including the SN security key for the SN to use and a list of associated sk-Counter values

[0162] Figure 11 is a signaling flow of security updates for LTM / CLTM mobility with SN addition according to embodiments of the disclosure.

[0163] Step 1100. The UE is in single connectivity and the first network node (e.g, the serving RAN node) prepares conditional mobility towards Target node 1.

[0164] Step 1102-1004 The candidate target node 1 initiates SN Addition request towards a candidate SN-1 and includes SN security key and a list of associated sk-Counter values for candidate SN 1. The candidate SN 1 acknowledges the request.

[0165] Step.1006 The target node 1 acknowledges the request sent in step 1.

[0166] Steps 1008-1114 . Steps 1100-1006 are repeated to prepare handover towards a target node MN 2..N which prepares an SN addition towards candidate SN-2..N

[0167] Steps 1116-1118. The UE is configured for LTM / CLTM mobility with SN addition.

[0168] Figure 12 is a signaling flow of security updates for Inter-MN LTM / CLTM mobility with SN change according to embodiments of the disclosure.

[0169] Step 1200. The UE is in dual connectivity, and the source MN prepares mobility towards Target MN-1. The candidate SN-1... SN-2 are different from the source SN.

[0170] Step 1202-1204 The target MN-1 initiates SN Addition requests towards candidate SN-1 and includes SN security key and a list of associated sk-Counter values for candidate SN 1. The target node 1 acknowledges the request.

[0171] Step.1206 The target MN 1 acknowledges the request sent in step 1200.

[0172] Steps 1208-1214. Steps 1200-1206 are repeated to prepare handover towards a target MN 2..N which prepares an SN addition towards candidate SN-2..N

[0173] Steps 1216-1218. The UE is configured for LTM / CLTM mobility with SN change.

[0174] Below is an implementation in the 3GPP TS 38.423, vl8.5.0 (2025-03), Xn application protocol (XnAP), with (at least some) amendments to the current specification underlined:9.1 1 x1 CELL SWITCH NOTIFICATIONThis message is sent by the source NG-RAN node to inform the target NG-RAN node about the initiation of the cell switch command to the UE.Direction: source NG-RAN nodetarget NG-RAN node.9.1.2.1 S-NODE ADDITION REQUESTThis message is sent by the M-NG-RAN node to the S-NG-RAN node to request the preparation of resources for dual connectivity operation for a specific UE.Direction: M-NG-RAN node —> S-NG-RAN node.9, 2, 3, xxx LTM Security Configurations List

[0175] Below is an implementation in the 3GPP TS 38.331, vl8.5.1 (2025-03), RRC protocol, with amendments underlined:selectedSK-CounterThis field includes the selected sk-counter value for security key update upon the execution of subsequent CP AC or inter-CU LTM.

[0176] Figure 13 shows an example of a communication system 1300 in accordance with some embodiments.

[0177] In the example, the communication system 1300 includes a telecommunications network 1302 that includes an access network 1304, such as a radio access network (RAN), and a core network 1306, which includes one or more core network nodes 1308. The access network 1304 includes one or more access network nodes or base stations of various types,access network nodes 1310A and 1310B are depicted (which may be collectively referred to as network nodes 1310), or any other similar 3rdGeneration Partnership Project (3GPP) access nodes or non-3GPP access points (APs). Some embodiments of the access network 1304 may include more than one access network technology. The network nodes 1310 of access network 1304 facilitate direct or indirect connection of wireless devices, also referred to as user equipments (UEs), such as by connecting UEs 1312A, 1312B, 1312C, and 1312D (one or more of which may be generally referred to as UEs 1312) to the core network 1306 over one or more wireless connections.

[0178] Moreover, a network node is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that network nodes include disaggregated implementations or portions thereof. For example, in some embodiments, the telecommunications network 1302 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a network node in the telecommunications network 1302 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other network nodes to implement one or more functionalities of any network node in the telecommunications network 1302, including one or more access network nodes 1310 and / or core network nodes 1308.

[0179] Examples of an ORAN network node include an open radio unit (O-RU), an open distributed unit (O-DU), an open central unit (O-CU), including an O-CU control plane (O-CU-CP) or an O-CU user plane (O-CU-UP), a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or any combination thereof (the adjective “open” designating support of an ORAN specification). An ORAN network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an Al, Fl, Wl, El, E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN network node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an O-2 interface defined by the O-RAN Alliance or comparable technologies.

[0180] The network nodes 1310 facilitate direct or indirect connection of one or more UEs 1312 to the core network 1306 over one or more wireless connections. Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system 1300 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system 1300 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.

[0181] The UEs 1312 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes 1310 and other communication devices. Similarly, the network nodes 1308, 1310 are arranged, capable, configured, and / or operable to communicate directly or indirectly (e.g., via other devices of telecommunications network 1302) with the UEs 1312 and / or with other network nodes or equipment in the telecommunications network 1302 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunications network 1302. More specifically, UEs 1312 may send messages, data, and / or other signals to network nodes 1308, 1310 or other elements of the telecommunications network 1302 by transmitting such signals to the relevant device directly without the signals passing through any intervening devices or by transmitting such signals to the relevant device indirectly through an intervening device (or multiple intervening devices) that then transmit the signal to the relevant device. Similarly, network nodes 1308, 1310 may send messages, data, and other signals to UEs 13122, other network nodes 1308, 1310, and other devices in telecommunications network 1302 directly or indirectly. As one specific example, a core network node 108 may transmit a particular message to a UE 1312 by transmitting the message to an access network node 1310 that will then transmit the message to the intended UE 1312. Similarly, a core network node 108 may receive a particular message from a UE 1312 by receiving the message from an access network node 1310 that itself received the message from the UE 1312.

[0182] In the depicted example, the core network 1306 connects elements of the access network 1304 (e.g., one or more of the network nodes 1310) to one or more host computing systems, such as host 1316. These connections may be direct or indirect via one or moreintermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network 1306 includes one or more core network nodes (e.g., core network node 1308) of various types, one or more of which may be generally referred to as network nodes 1308. Network nodes 1308 are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, access network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node 1308. Example core network nodes provide functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-concealing function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF).

[0183] The host 1316 may be under the ownership or control of a service provider other than an operator or provider of the access network 1304 and / or the telecommunications network 1302. The host 1316 may be operated by the service provider or on behalf of the service provider. The host 1316 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.

[0184] As a whole, the communication system 1300 of Figure 13 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system 1300 may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (Wi-Fi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (Wi-Max), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, Li-Fi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox. Moreover, the communication system 1300 may be configured to support multiple differentstandards, protocols, or other rule sets, with individual components supporting all of the relevant rule sets or with different components or sub-systems within the communication system 1300 supporting different standards, protocols, or rule sets.

[0185] As one example, in certain embodiments, access network 1304 may contain some access network nodes 1310 that support 3GPP radio access technologies (RAT), such as LTE or NR, while other access network nodes 1310 support (or the same access network nodes 1310 additionally support) non-3GPP RATs, such as Wi-Fi or a proprietary RAT. As another example, telecommunications network 1302 may support multiple generations of related communication standards (e.g., 4G and 5G 3GPP communication standards) and, as a result, may include an access network 104 and / or a core network 106 that supports multiple different standard generations or may include multiple access networks 104 and / or multiple core networks 106 with individual networks 104, 106 supporting different standard generations.

[0186] Telecommunications network 1302 may support network slicing to provide different logical networks to different devices that are connected to the telecommunications network 1302. For example, the telecommunications network 1302 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive loT services to yet further UEs.

[0187] In some examples, one or more of the UEs 1312 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network 1304 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network 1304. Additionally, a UE may be configured for operating in single- or multi-RAT or multi-standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC).

[0188] In the example, the hub 1314 communicates with the access network 1304 to facilitate indirect communication between one or more UEs (e.g., UE 1312C and / or 1312D) and network nodes (e.g., network node 1310B). In some examples, the hub 1314 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub 1314 may be a broadband router enabling access to the core network 1306 for the UEs. As another example, the hub 1314 may be a controller that sends commands or instructions to one or more actuators in the UEs.Commands or instructions may be received from the UEs, network nodes 1310, or by executable code, script, process, or other instructions in the hub 1314.

[0189] As another example, the hub 1314 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 1314 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker or other media delivery device, the hub 1314 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub 1314 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub 1314 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy loT devices.

[0190] The hub 1314 may have a constant / persistent or intermittent connection to the network node 1310B. The hub 1314 may also allow for a different communication scheme and / or schedule between the hub 1314 and UEs (e.g., UE 1312C and / or 1312D), and between the hub 1314 and the core network 1306. In other examples, the hub 1314 is connected to the core network 1306 and / or one or more UEs via a wired connection. Moreover, the hub 1314 may be configured to connect to an M2M service provider over the access network 1304 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with the network nodes 1310 while still connected via the hub 1314 via a wired or wireless connection. In some embodiments, the hub 1314 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the UEs from / to the network node 1310B. In other embodiments, the hub 1314 may be a non-dedicated hub - that is, a device which is capable of operating to route communications between the UEs and network node 1310B, but which is additionally capable of operating as a communication start and / or end point for certain data channels.

[0191] Figure 14 is another example of a communication system 1400 according to some embodiments. As used herein, the communication system 1400 includes multiple access points (APs) 1410 (with four exemplary APs 1410A, 1410B, 1410C, and 1410D being depicted) and multiple wireless devices, referred to in the context of communication system 1400 as stations (STAs) 1412 (referred to individually as STA 1412A, STA 1412B, STA 1412C, STA 1412D, and STA 1412E). STA 1412A is served by AP 1410A in a first basic service set (BSS) 1420A. STA 1410B and STA 1410C are served by AP 1410B in a second BSS, BSS 1420B. STA 1412D is served by AP 1410C in a third BSS, BSS 1420C. STA 1412E is served by AP 1410D in a fourth BSS, BSS 1420D. Stations 1412 may be non-AP STAs and correspond to variouskinds of wireless devices, for example, user terminals, such as mobile or stationary computing devices like smartphones, laptop computers, desktop computers, tablet computers, gaming devices, head-mounted displays (HMDs) for Augmented Reality (AR) or Virtual Reality (VR), or the like. Further, stations 1412 could, for example, correspond to other kinds of equipment like smart home devices, printers, multimedia devices, data storage devices, or the like.

[0192] Each of STAs 1412 may connect through a radio link to one of APs 1410. For example, depending on location or channel conditions experienced by a given STA 1412, the STA may select an appropriate AP and BSS for establishing the radio link. The radio link may be based on one or more orthogonal frequency-division multiplexing (OFDM) carriers from a frequency spectrum that is shared on the basis of a contention-based mechanism, e.g., an unlicensed or license exempt band like 2.4 GHz Industrial, Scientific, and Medical (ISM) band, the 5 GHz band, the 6 GHz band, or the 60 GHz band.

[0193] Each AP 1410 may provide data connectivity to STAs 1412 connected to a particular AP 1410. As illustrated, APs 1410 may be connected to a data network 1430. In this way, APs 1410 may also provide data connectivity between STAs 1412 and other entities, e.g., to one or more servers, service providers, data sources, data sinks, user terminals, or the like. Accordingly, the radio link established between a given STA 1412 and its serving AP 1410 may be used for providing various kinds of services to STA 1412, e.g., a voice service, a multimedia service, or other data service. Such services may be based on applications that are executed on STA 1412 and / or on a device linked to STA 1412. By way of example, Figure 14 illustrates an application service platform 1432 provided in data network 1430. The application(s) executed on STA 1412 and / or on one or more other devices linked to STA 1412 may use the radio link for data communication with one or more other STA 1412 and / or the application service platform 1432, thereby enabling utilization of the corresponding service(s) at STA 1412.

[0194] Figure 15 shows a wireless device 1500, which may be configured to operate in communication system 1300 of Figure 13 or in communication system 1400 of Figure 14. The wireless device 1500 may be alternatively referred to as a UE 1500, like a UE 1312 within the context of communication system 1300, or as a station (STA) 1500 or as a non-access-point station (non-AP STA) 1500, like a STA 1412 within the context of the communication system 1400, in accordance with respective embodiments. As used herein, a wireless device refers to a device capable, configured, arranged and / or operable to communicate wirelessly with network nodes and / or other wireless devices. Examples of a wireless device include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wirelesslocal loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage device, playback appliance, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop-embedded equipment (LEE), laptopmounted equipment (LME), smart device, wireless customer-premise equipment (CPE), vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, and wireless terminal. Other examples include any type of UE identified by the 3rd Generation Partnership Project (3 GPP), including a narrow band internet of things (NB-IoT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.

[0195] A wireless device 1500 may support device-to-device (D2D) communication, for example by implementing a 3 GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2X). In other examples, wireless device 1500 may not necessarily have a user in the sense of a human user who owns and / or operates the relevant device. Instead, wireless device 1500 may represent a device that is intended for sale to, or operation by, a human user but which may not, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, wireless device 1500 may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter).

[0196] In particular embodiments, wireless device 1500 includes processing circuitry 1502 that is operatively coupled via a bus 1504 to an input / output interface 1506, a power source 1508, a memory 1510, a communication interface 1512, and / or any other component, or any combination thereof. Certain embodiments of wireless device 1500 may include all or a subset of the components shown in Figure 15. The level of integration between the components may vary from one embodiment of wireless device 1500 to another. In general, in a particular embodiment of wireless device 1500, processing circuitry 1502, input / output interface 1506, power source 1508, memory 1510, and communication interface 1512 may, in whole or in part, represent or include physical components common to or shared by one or more of the other elements of wireless device 1500. Further, certain embodiments of wireless devices 1500 may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0197] The processing circuitry 1502 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in the memory 1510. The processing circuitry 1502 may be implemented as one or more hardware-implemented state machines (e.g., indiscrete logic, field-programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general-purpose processors, such as a microprocessor or digital signal processor (DSP), together with appropriate software; or any combination of the above. For example, the processing circuitry 1502 may include multiple central processing units (CPUs). The processing circuitry 1502 may be configured to cause the wireless device 1500 to perform the methods as described with reference to Figure 3.

[0198] In the example, the input / output interface 1506 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into wireless device 1500. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.

[0199] In some embodiments, the power source 1508 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used to supply power to circuitry or to charge an associated battery. The power source 1508 may further include power circuitry for delivering power from the power source 1508 itself, and / or an external power source, to the various parts of wireless device 1500 via input circuitry or an interface such as an electrical power cable. Power source 1508 may perform any formatting, converting, or other modification to make accessible power suitable for the respective components of the wireless device 1500 to which power is supplied.

[0200] The memory 1510 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks,removable cartridges, flash drives, and so forth. In one example, the memory 1510 includes one or more programs 1514, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data 1516. The memory 1510 may store, for use by wireless device 1500, any of a variety of various operating systems or combinations of operating systems.

[0201] The memory 1510 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID), flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD-DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUICC), integrated UICC (iUICC) or a removable UICC commonly known as ‘SIM card.’ The memory 1510 may allow wireless device 1500 to access instructions, programs and the like, stored on transitory or non-transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing a communication system may be tangibly embodied as or in the memory 1510, which may be or comprise a device-readable storage medium.

[0202] The processing circuitry 1502 may be configured to communicate with an access network or other network via or using the communication interface 1512. The communication interface 1512 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 1522. The communication interface 1512 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another wireless device or a network node in an access network). Each transceiver may include a transmitter 1518 and / or a receiver 1520 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, the transmitter 1518 and receiver 1520 may be coupled to one or more antennas (e.g., antenna 1522) and may share circuit components, software or firmware, or alternatively be implemented separately.

[0203] In the illustrated embodiment, communication functions of the communication interface 1512 may include cellular communication, Wi-Fi communication (e.g., according to an IEEE 802.11 family standard), LPWAN communication, data communication, voicecommunication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / internet protocol (TCP / IP), synchronous optical networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), and so forth.

[0204] In particular embodiments, wireless device 1500 may provide an output of data captured via a sensor, through its communication interface 1512, via a wireless connection to a network node, and / or in any appropriate manner. Data captured by sensors of a wireless device 1500 can be communicated through a wireless connection to a network node via another wireless device 1500. In particular embodiments, such output may be periodic (e.g., once every 15 minutes if it reports the sensed temperature), random (e.g., to even out the load from reporting from several sensors), in response to a triggering event (e.g., when moisture is detected an alert is sent), in response to a request (e.g., a user initiated request), or a continuous stream (e.g., a live video feed of a patient).

[0205] As another example, wireless device 1500 comprises an actuator, a motor, or a switch, related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, wireless device 1500 may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input.

[0206] Wireless device 1500, when in the form of an Internet of Things (loT) device, may be a device for use in one or more application domains, these domains comprising, but not limited to, wearable technology, extended industrial application and healthcare. Non-limiting examples of such an loT device are a device which is or which is embedded in: a connected refrigerator or freezer, a TV, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoringdevice, an electric vehicle charging station, a smart watch, a fitness tracker, a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal- or item-tracking device, a sensor for monitoring a plant or animal, an industrial robot, an Unmanned Aerial Vehicle (UAV), and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot. In particular embodiments, wireless device 1500 represents an loT device that comprises circuitry and / or software in dependence of the intended application of the loT device in addition to other components as described in relation to the example embodiment of wireless device 1500 shown in Figure 15.

[0207] As yet another specific example, in an loT scenario, wireless device 1500 may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another wireless device and / or a network node. Wireless device 1500 may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, wireless device 1500 may implement the 3GPP NB-IoT standard. In other scenarios, wireless device 1500 may represent a vehicle, such as a car, a bus, a truck, a ship and an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.

[0208] In practice, any number of wireless devices 1500 may be used together with respect to a single use case. For example, a first wireless device 1500 might be or be integrated in a drone and provide the drone’s speed information (obtained through a speed sensor) to a second wireless device 1500 that is a remote controller operating the drone. When a user makes changes from the remote controller, the first wireless device 1500 may adjust the throttle on the drone (e.g. by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second wireless device 1500 can also include more than one of the functionalities described above. For example, wireless device 1500 might comprise the sensor and the actuator, and handle communication of data for both the speed sensor and the actuators.

[0209] Figure 16 shows a network node 1600 in accordance with some embodiments. As used herein, network node refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment, in a telecommunications network. In accordance with respective embodiments, network node 1600 may be configured to operate in communication system 1300 of Figure 13, like network nodes 1308 or 1310, or in communication system 1400 of Figure 14, like an AP 1410 or a station 1412. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved NodeBs (eNBs) and NR NodeBs (gNBs)), O-RAN nodes or components of an O-RAN node (e.g., O-RU, O-DU, O-CU).

[0210] Network nodes 1600 may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. Network node 1600 may be a relay node or a relay donor node controlling a relay. Network nodes 1600 may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g., in an O-RAN access node) and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).

[0211] Other examples of network nodes 1600 include multiple transmission point (multi -TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).

[0212] In particular embodiments, network node 1600 includes a processing circuitry 1602, a memory 1604, a communication interface 1606, and a power source 1608. In general, in a particular embodiment of network node 1600, processing circuitry 1602, memory 1604, communication interface 1606, and power source 1608 may, in whole or in part, represent or include physical components common to or shared by one or more of the other elements of network node 1600.

[0213] The network node 1600 may be composed of multiple distinct network entities (e.g., a NodeB entity and a RNC entity, or a BTS entity and a BSC entity, etc.), which may each have or utilize their own respective physical components. In certain scenarios in which the network node 1600 comprises multiple such entities (e.g., BTS and BSC), one or more of the separate entities may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the network node 1600 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memories 1604 orportions of memory 1604 for different RATs) and some components may be reused (e.g., a same antenna 1610 may be shared by different RATs). The network node 1600 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node 1600, for example GSM, WCDMA, LTE, NR, Wi-Fi (e.g., according to an IEEE 802.11 family standard), Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node 1600.

[0214] The processing circuitry 1602 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other components, such as the memory 1604, to provide network node 1600 functionality. For example, the processing circuitry 1602 may be configured to cause the network node 1600 to perform the methods as described with reference to Figure 4 and / or 5.

[0215] In some embodiments, the processing circuitry 1602 includes a system on a chip (SOC). In some embodiments, the processing circuitry 1602 includes one or more of radio frequency (RF) transceiver circuitry 1612 and baseband processing circuitry 1614. In some embodiments, the RF transceiver circuitry 1612 and the baseband processing circuitry 1614 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry 1612 and baseband processing circuitry 1614 may be on the same chip or set of chips, boards, or units.

[0216] The memory 1604 may comprise any form of volatile or non-volatile computer-readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computerexecutable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 1602. The memory 1604 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry 1602 and utilized by the network node 1600. The memory 1604 may beused to store any calculations made by the processing circuitry 1602 and / or any data received via the communication interface 1606. In some embodiments, the processing circuitry 1602 and memory 1604 is integrated.

[0217] The communication interface 1606 is used in wired or wireless communication of signaling and / or data with UEs, other network nodes, and / or any other network equipment. In the illustrated embodiment, communication interface 1606 comprises port(s) / terminal(s) 1616 to send and receive data, for example to and from a network over a wired connection. In particular embodiments, network node 1500 may be capable of wireless communication and communication interface 1606 may also include radio front-end circuitry 1618 that may be coupled to, or in certain embodiments a part of, an antenna 1610. Particular embodiments of radio front-end circuitry 1618 include filter(s) 1620 and amplifier(s) 1622. The radio front-end circuitry 1618 may be connected to an antenna 1610 and processing circuitry 1602. The radio front-end circuitry may be configured to condition signals communicated between antenna 1610 and processing circuitry 1602. The radio front-end circuitry 1618 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio frontend circuitry 1618 may convert the digital data into a radio signal(s) having the appropriate channel and bandwidth parameters using a combination of filters 1620 and / or amplifiers 1622. The radio signal(s) may then be transmitted via the antenna 1610. Similarly, when receiving data, the antenna 1610 may collect radio signals which are then converted into digital data by the radio front-end circuitry 1618. The digital data may be passed to the processing circuitry 1602. In other embodiments, the communication interface may comprise different components and / or different combinations of components.

[0218] In certain alternative embodiments, network node 1600 may be capable of wireless communication but does not include separate radio front-end circuitry 1618, instead, the processing circuitry 1602 includes radio front-end circuitry and is connected to the antenna 1610. Similarly, in some embodiments, all or some of the RF transceiver circuitry 1612 is part of the communication interface 1606. In still other embodiments, the communication interface 1606 includes one or more ports or terminals 1616, the radio front-end circuitry 1618, and the RF transceiver circuitry 1612, as part of a radio unit (not shown), and the communication interface 1606 communicates with the baseband processing circuitry 1614, which is part of a digital unit (not shown).

[0219] The antenna 1610 may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. The antenna 1610 may be coupled to the radio frontend circuitry 1618 and may be any type of antenna capable of transmitting and receiving dataand / or signals wirelessly. In certain embodiments, the antenna 1610 is separate from the network node 1600 and connectable to the network node 1600 through one or more interfaces or ports.

[0220] The antenna 1610, communication interface 1606, and / or the processing circuitry 1602 may be configured to perform some or all of the receiving operations and / or obtaining operations described herein as being performed by the network node 1600. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, the antenna 1610, the communication interface 1606, and / or the processing circuitry 1602 may be configured to perform some or all of the transmitting or sending operations described herein as being performed by the network node 1600. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment.

[0221] The power source 1608 provides power to the various components of network node 1600 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source 1608 may further comprise, or be coupled to, power management circuitry to supply the components of the network node 1600 with power for performing the functionality described herein. For example, the network node 1600 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source 1608. As a further example, the power source 1608 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.

[0222] Embodiments of the network node 1600 may include additional components beyond those shown in Figure 16 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node 1600 may include user interface equipment to allow input of information into the network node 1600 and to allow output of information from the network node 1600. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the network node 1600.

[0223] Figure 17 is a block diagram illustrating a virtualization environment 1700 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may includevirtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 1700 hosted by one or more of hardware nodes, such as a hardware computing device that operates as an access network node, UE, core network node, or host. Further, in embodiments in which a virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. In some embodiments, the virtualization environment 1700 includes components defined by the O-RAN Alliance, such as an O-Cloud environment orchestrated by a Service Management and Orchestration Framework via an 0-2 interface.

[0224] Applications 1702 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment Q400 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein.

[0225] Hardware 1704 includes processing circuitry, memory that stores software and / or instructions executable by hardware processing circuitry, and / or other hardware devices as described herein, such as a network interface, input / output interface, and so forth. Software may be executed by the processing circuitry to instantiate one or more virtualization layers 1706 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VM 1708 A and VM 1708B (which may be collectively referred to as VMs 1708), and / or perform any of the functions, features and / or benefits described in relation with some embodiments described herein. The virtualization layer 1706 may present a virtual operating platform that appears like networking hardware to one or more of the VMs 1708.

[0226] The VMs 1708 comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by virtualization layer 1706. Different embodiments of the instance of a virtual appliance 1702 may be implemented on one or more of VMs 1708, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as network function virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server hardware, physical switches, and physical storage, which can be located in data centers, and customer premise equipment.

[0227] In the context of NFV, each of the VMs 1708 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, nonvirtualized machine. Each of the VMs 1708, and that part of hardware 1704 that executes that VM, be it hardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network function is responsible for handling specific network functions that run in one or more of the VMs 1708 on top of the hardware 1704 and corresponds to an application 1702.

[0228] Hardware 1704 may be implemented in a standalone network node with generic or specific components. Hardware 1704 may implement some functions via virtualization. Alternatively, hardware 1704 may be part of a larger cluster of hardware (e.g. such as in a data center or CPE) where many hardware nodes work together and are managed via management and orchestration 1710, which, among others, oversees lifecycle management of applications 1702. In some embodiments, hardware 1704 is coupled to one or more radio units that each include one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. In some embodiments, some signaling can be provided with the use of a control system 1712 which may alternatively be used for communication between hardware nodes and radio units.

[0229] Although the computing devices described herein (e.g., UEs, network nodes, hosts) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components describedherein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0230] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.The following numbered statements set out embodiments of the disclosure:Group A Embodiments1. A method performed by a wireless device, the method comprising:transmitting, to a first network node or a second network node, security information for the wireless device, wherein the security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device, wherein the first network node acts as a Master Node, MN, serving the wireless device, or wherein the first network node acts as a target MN for the LTM mobility procedure and at least one cell of the target MN is included in an LTM candidate cell configuration of the wireless device, andwherein the second network node acts as a Secondary Node, SN, serving the wireless device subsequent to the performance of the LTM mobility procedure.2. The method of embodiment 1, wherein the first network node is acting as the target MN, the at least one cell is included in a Master Cell Group of the target MN, and subsequent to the performance of the LTM mobility procedure, the wireless device is served by the at least one cell.3. The method of any preceding embodiment, wherein prior to the performance of the LTM mobility procedure, the wireless device is in a single connectivity mode.4. The method of embodiment 1, wherein the first network node is acting as the MN serving the wireless device, and prior to the performance of the LTM mobility procedure, the wireless device is served by a different SN to the second network node.5. The method of any preceding embodiment, wherein the LTM mobility procedure is an inter-CU LTM mobility procedure and / or a conditional LTM mobility procedure.6. The method of any preceding embodiment, wherein the performance of the LTM mobility procedure is triggered by one of:- the wireless device, and the method further comprises initiating the performance of the LTM mobility procedure;- the first network node when the first network node is acting as the MN serving the wireless device, and the method further comprises receiving, from the first network node, a command or a request to perform the LTM mobility procedure; and- the second network node when the second network node is serving the wireless device prior to the performance of the cell switch procedure, and the method further comprises receiving, from the second network node, a command or a request to perform the LTM mobility procedure.7. The method of any preceding embodiment, wherein the wireless device transmits, to the first network node or second network node, the security information before or after the performance of the LTM mobility procedure.8. The method of embodiment 7, wherein the security information is transmitted to the first network node or the second network node in one or more of an RRC message, a MAC CE, and physical layer signalling (e.g., DCI).9. The method of any preceding embodiment, wherein the security information comprises one or more ofan indication of the at least one security key;an indication of one or more freshness indicators (e.g., sk-counters) that are to be used by the second network node to derive the at least one security key;an indication of one or more security algorithms used by the wireless device during the LTM mobility procedure, wherein the one or more algorithms are to be used by the second network node to derive the at least one security key; anda fourth network node when the first network node is acting as the target MN, wherein the fourth network node is acting as a MN serving the wireless device, and the method further comprises receiving, from the fourth network node, a request or a command to perform the LTM mobility procedure.10. The method of any of the previous embodiments, further comprising:providing user data; andforwarding the user data to a host via the transmission to the network node.Group B Embodiments11. A method performed by a first network node, wherein the first network node acts as a Master Node, MN, serving a wireless device or acts as a candidate or target MN for the wireless device, wherein at least one cell of the candidate or target MN is included in an LTM candidate cell configuration of the wireless device, the method comprising:transmitting, to a second network node, security information for the wireless device, wherein the security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device, wherein the second network node acts as a Secondary Node, SN, serving the wireless device subsequent to the performance of the LTM mobility procedure.12. The method of embodiment 11, wherein the first network node is acting as one of the candidate or target MN, the at least one cell is included in a Master Cell Group of the one of the candidate or target MN, and subsequent to the performance of the LTM mobility procedure, the wireless device is served by the at least one cell13. The method of embodiment 11 or 12, wherein prior to the performance of the LTM mobility procedure, the wireless device is in a single connectivity mode.14. The method of embodiment 11, wherein the first network node is acting as the MN serving the wireless device, and prior to the performance of the LTM mobility procedure, the wireless device is served by a different SN to the second network node.15. The method of any of embodiments 11-14, wherein the LTM mobility procedure is an inter-CU LTM mobility procedure and / or a conditional LTM mobility procedure.16. The method of any of embodiments 11-15, wherein the LTM mobility procedure is triggered by one of:- the wireless device, and the method further comprises receiving, from the wireless device, a request or a command to perform the LTM mobility procedure;- the first network node when the first network node is acting as the MN serving the wireless device, and the method further comprises initiating the performance of the LTM mobility procedure;- the second network node when the second network node is serving the wireless device prior to the performance of the LTM mobility procedure, and the method further comprises receiving, from the second network node, a request or a command to perform the LTM mobility procedure; anda fourth network node when the first network node is acting as the candidate or target MN, wherein the fourth network node is acting as a MN serving the wireless device, and the method further comprises receiving, from the fourth network node, a request or a command to perform the LTM mobility procedure.17. The method of any of embodiments 11-16, wherein the first network node transmits the security information to the second network node before or after the performance of the LTM mobility procedure.18. The method of any of embodiments 11-17, wherein the first network node transmits the security information to the second network node in one of an SN Addition Request, an SN Modification Request, a Cell Switch Notification, an LTM Configuration Update, and an XnAP procedure.19. The method of any of embodiments 11-18, wherein the first network node receives the security information from the wireless device and / or a fourth network node acting as an MN serving the wireless device, e.g., before or after the performance of the LTM mobility procedure.20. The method of embodiments 19, wherein the security information is received from the wireless device in one or more of an RRC message, a MAC CE, and physical layer signalling (e.g., DCI).21. The method of any of embodiments 11-20, wherein the security information comprises one or more of:an indication of the at least one security key;an indication of one or more freshness indicators (e.g., sk-counters) that are to be used by the second network node to derive the at least one security key; andan indication of one or more security algorithms used by the wireless device during the LTM mobility procedure, wherein the one or more algorithms are to be used by thesecond network node to derive the at least one security key.22. The method of any of the embodiments 11-21, further comprising:obtaining user data; andforwarding the user data to a host or a user equipment.23. A method performed by a second network node, wherein the second network node acts as a Secondary Node, SN, serving a wireless device subsequent to a performance of an LTM mobility procedure by the wireless device, the method comprising:receiving security information for the wireless device, wherein the security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to the performance of the LTM mobility procedure;wherein the security information is received from the wireless device or a first network node, wherein the first network node acts as a Master Node, MN, serving the wireless device or acts as a candidate or target MN for the wireless device, wherein at least one cell of the candidate or target MN is included in an LTM candidate cell configuration of the wireless device.24. The method of embodiment 23, wherein the first network node is acting as one of the candidate or target MN, the at least one cell is included in a Master Cell Group of the one of the candidate or target MN, and subsequent to the performance of the LTM mobility procedure, the wireless device is served by the at least one cell.25. The method of any of embodiments 23 and 24, wherein prior to the performance of the LTM mobility procedure, the wireless device is in a single connectivity mode.26. The method of embodiments 23, wherein the first network node is acting as the MN serving the wireless device, and prior to the performance of the LTM mobility procedure, the wireless device is served by a different SN to the second network node.27. The method of any of embodiments 23-26, wherein the LTM mobility procedure is an inter-CU LTM mobility procedure and / or a conditional LTM mobility procedure.28. The method of any of embodiments 23-27, wherein the LTM mobility procedure is triggered by one of:- the wireless device, and the method further comprises receiving, from the first network node, a command or a request to perform the LTM mobility procedure;the first network node when the first network node is acting as the MN serving the wireless device, and the method further comprises receiving, from the first network node, a command or a request to perform the LTM mobility procedure;- the second network node when the second network node is serving the wireless device prior to the performance of the cell switch procedure, and the method further comprises initiating the performance of the LTM mobility procedure; anda fourth network node when the first network node is acting as the target or candidate MN, wherein the fourth network node is acting as a MN serving the wireless device, and the method further comprises receiving, from the fourth network node, a request or a command to perform the LTM mobility procedure.29. The method of any of embodiments 23-28, the second network node receives the security information from the wireless device or first network node before or after the performance of the LTM mobility procedure.30. The method of embodiment 29, wherein the second network node receives the security information from the first network node in one of an SN Addition Request, an SN Modification Request, a Cell Switch Notification, an LTM Configuration Update, and an XnAP procedure.31. The method of any of embodiments 23-30, wherein the security information comprises one or more of:an indication of the at least one security key;an indication of one or more freshness indicators (e.g., sk-counters) that are to be used by the second network node to derive the at least one security key; andan indication of one or more security algorithms used by the wireless device during the LTM mobility procedure, wherein the one or more algorithms are to be used by the second network node to derive the at least one security key.32. The method of any of the embodiments 23-31, further comprising:obtaining user data; andforwarding the user data to a host or a user equipment.Group C Embodiments33. A wireless device (1312, 1412, 1500), comprising:processing circuitry (1502) configured to cause the wireless device to perform any of the operations of any of the Group A embodiments; anda power source (1508) configured to supply power to the processing circuitry (1502).34. A network node (1310, 1410, 1600), the network node comprising:processing circuitry (1602) configured to cause the network node to perform any of the operations of any of the Group B embodiments;a power source (1608) configured to supply power to the processing circuitry (1602).35. A wireless device, the wireless device comprising:one or more antennas;communication interface connected to the one or more antennas and to processing circuitry;the processing circuitry being configured to cause the wireless device to perform any of the operations of any of the Group A embodiments;an input interface connected to the processing circuitry and configured to allow input of information into the wireless device to be processed by the processing circuitry;an output interface connected to the processing circuitry and configured to output information from the wireless device that has been processed by the processing circuitry; and a power source connected to the processing circuitry and configured to supply power to the wireless device.36. A computer program product comprising a non-transitory computer-readable medium having computer-readable code embodied therein, the computer-readable code being configured such that, on execution by a suitable computer or processing circuitry, the computer or processing circuitry is caused to perform the method of any of the Group A embodiments and the Group B embodiments.37. A wireless device (1312, 1412, 1500) configured to perform the method of any of the Group A embodiments.38. A wireless device (1312, 1412, 1500) comprising processing circuitry (1502) and a memory (1510), said memory containing instructions executable by said processing circuitry whereby said wireless device is operative to perform the method of any of the Group A embodiments.39. A network node (1310, 1410, 1600), configured to perform the method of any of the Group B embodiments.40. A network node (1310, 1410, 1600) comprising processing circuitry (1602) and a memory (1604), said memory containing instructions executable by said processing circuitry whereby said network node is operative to perform the method of any of the Group B embodiments.ABBREVIATIONSAt least some of the following abbreviations may be used in this disclosure. If there is an inconsistency between abbreviations, preference should be given to how it is used above. If listed multiple times below, the first listing should be preferred over any subsequent listing(s).3 GPP 3rd Generation Partnership Project5G 5th Generation6G 6th GenerationABS Almost Blank SubframeARQ Automatic Repeat RequestAWGN Additive White Gaussian NoiseBCCH Broadcast Control ChannelBCH Broadcast ChannelCA Carrier AggregationCC Carrier ComponentCCCH SDU Common Control Channel SDUCDMA Code Division Multiplex AccessCGI Cell Global IdentityCIR Channel Impulse ResponseCP Cyclic PrefixCPICH Common Pilot ChannelCQI Channel Quality InformationC-RNTI Cell RNTICSI Channel State InformationDCCH Dedicated Control ChannelDL DownlinkDM DemodulationDMRS Demodulation Reference SignalDRX Discontinuous ReceptionDTX Discontinuous TransmissionDTCH Dedicated Traffic ChannelDUT Device Under TestE-CID Enhanced Cell-ID (positioning method)Ec / No Received energy per chip divided by the power density in the band eMBMS Evolved Multimedia Broadcast Multicast ServicesECGI Evolved CGIeNB E-UTRAN NodeBePDCCH Enhanced Physical Downlink Control ChannelE-SMLC Evolved Serving Mobile Location CenterE-UTRAN Evolved Universal Terrestrial Radio Access NetworkFDD Frequency Division DuplexFFS For Further StudyBase station in NRGNSS Global Navigation Satellite SystemHARQ Hybrid Automatic Repeat RequestHO HandoverHSPA High Speed Packet AccessHRPD High Rate Packet DataLOS Line of SightLPP LTE Positioning ProtocolLTE Long-Term EvolutionMAC Medium Access ControlMAC Message Authentication CodeMBSFN Multimedia Broadcast Multicast Service Single Frequency Network MBSFN ABS MBSFN Almost Blank SubframeMDT Minimization of Drive TestsMIB Master Information BlockMME Mobility Management EntityMSC Mobile Switching CenterNPDCCH Narrowband Physical Downlink Control ChannelNR New RadioOCNG OFDMA Channel Noise GeneratorOFDM Orthogonal Frequency Division MultiplexingOFDMA Orthogonal Frequency Division Multiple AccessOSS Operations Support SystemOTDOA Observed Time Difference of ArrivalO&M Operation and MaintenancePBCH Physical Broadcast ChannelP-CCPCH Primary Common Control Physical ChannelPCell Primary CellPCFICH Physical Control Format Indicator ChannelPDCCH Physical Downlink Control ChannelPDCP Packet Data Convergence ProtocolPDP Power Delay ProfilePDSCH Physical Downlink Shared ChannelPGW Packet GatewayPHICH Physical Hybrid-ARQ Indicator ChannelPLMN Public Land Mobile NetworkPMI Precoding Matrix IndicatorPRACH Physical Random Access ChannelPRS Positioning Reference SignalPSS Primary Synchronization SignalPUCCH Physical Uplink Control ChannelPUSCH Physical Uplink Shared ChannelRACH Random Access ChannelQAM Quadrature Amplitude ModulationRAN Radio Access NetworkRAT Radio Access TechnologyRLC Radio Link ControlRLM Radio Link MonitoringRNC Radio Network ControllerRNTI Radio Network Temporary IdentifierRRC Radio Resource ControlRRM Radio Resource ManagementRS Reference SignalRSCP Received Signal Code PowerRSRP Reference Symbol Received Power ORReference Signal Received PowerRSRQ Reference Signal Received Quality ORReference Symbol Received QualityRS SI Received Signal Strength Indicator RSTD Reference Signal Time DifferenceSCH Synchronization ChannelSCell Secondary CellSDAP Service Data Adaptation ProtocolSDU Service Data UnitSFN System Frame NumberSGW Serving GatewaySI System InformationSIB System Information BlockSNR Signal to Noise RatioSON Self-Organizing NetworkSS Synchronization SignalSSS Secondary Synchronization SignalTDD Time Division DuplexTDOA Time Difference of ArrivalTOA Time of ArrivalTSS Tertiary Synchronization SignalTTI Transmission Time IntervalUE User EquipmentUL UplinkUMTS Universal Mobile Telecommunications System USIM Universal Subscriber Identity Module UTDOA Uplink Time Difference of Arrival WCDMA Wideband CDMAWLAN Wireless Local Area Network

Claims

Claims1. A method performed by a wireless device, the method comprising:transmitting (302), to a first network node or a second network node, security information for the wireless device, wherein the security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device, wherein the first network node acts as a Master Node, MN, serving the wireless device, or wherein the first network node acts as a target MN for the LTM mobility procedure and at least one cell of the target MN is included in an LTM candidate cell configuration of the wireless device, andwherein the second network node acts as a Secondary Node, SN, serving the wireless device subsequent to the performance of the LTM mobility procedure.

2. The method of claim 1, wherein the first network node is acting as the target MN, the at least one cell is included in a Master Cell Group of the target MN, and subsequent to the performance of the LTM mobility procedure, the wireless device is served by the at least one cell.

3. The method of any preceding claim, wherein prior to the performance of the LTM mobility procedure, the wireless device is in a single connectivity mode.

4. The method of claim 1, wherein the first network node is acting as the MN serving the wireless device, and prior to the performance of the LTM mobility procedure, the wireless device is served by a different SN to the second network node.

5. The method of any preceding claim, wherein the LTM mobility procedure is an inter-CU LTM mobility procedure and / or a conditional LTM mobility procedure.

6. The method of any preceding claim, wherein the performance of the LTM mobility procedure is triggered by one of- the wireless device, and the method further comprises initiating the performance of the LTM mobility procedure;- the first network node when the first network node is acting as the MN serving thewireless device, and the method further comprises receiving, from the first network node, a command or a request to perform the LTM mobility procedure; and- the second network node when the second network node is serving the wireless device prior to the performance of the cell switch procedure, and the method further comprises receiving, from the second network node, a command or a request to perform the LTM mobility procedure.

7. The method of any preceding claim, wherein the wireless device transmits, to the first network node or second network node, the security information before or after the performance of the LTM mobility procedure.

8. The method of claim 7, wherein the security information is transmitted to the first network node or the second network node in one or more of an RRC message, a MAC CE, and physical layer signalling (e.g., DCI).

9. The method of any preceding claim, wherein the security information comprises one or more of:an indication of the at least one security key;an indication of one or more freshness indicators (e.g., sk-counters) that are to be used by the second network node to derive the at least one security key;an indication of one or more security algorithms used by the wireless device during the LTM mobility procedure, wherein the one or more algorithms are to be used by the second network node to derive the at least one security key; anda fourth network node when the first network node is acting as the target MN, wherein the fourth network node is acting as a MN serving the wireless device, and the method further comprises receiving, from the fourth network node, a request or a command to perform the LTM mobility procedure.

10. A method performed by a first network node, wherein the first network node acts as a Master Node, MN, serving a wireless device or acts as a candidate or target MN for the wireless device, wherein at least one cell of the candidate or target MN is included in an LTM candidate cell configuration of the wireless device, the method comprising:transmitting (402), to a second network node, security information for the wireless device, wherein the security information is for determining at least one security key to be usedby the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device, wherein the second network node acts as a Secondary Node, SN, serving the wireless device subsequent to the performance of the LTM mobility procedure.

11. The method of claim 10, wherein the first network node is acting as one of the candidate or target MN, the at least one cell is included in a Master Cell Group of the one of the candidate or target MN, and subsequent to the performance of the LTM mobility procedure, the wireless device is served by the at least one cell12. The method of claim 10 or 11, wherein prior to the performance of the LTM mobility procedure, the wireless device is in a single connectivity mode.

13. The method of claim 10, wherein the first network node is acting as the MN serving the wireless device, and prior to the performance of the LTM mobility procedure, the wireless device is served by a different SN to the second network node.

14. The method of any of claims 10-13, wherein the LTM mobility procedure is an inter-CU LTM mobility procedure and / or a conditional LTM mobility procedure.

15. The method of any of claims 10-14, wherein the LTM mobility procedure is triggered by one of:- the wireless device, and the method further comprises receiving, from the wireless device, a request or a command to perform the LTM mobility procedure;- the first network node when the first network node is acting as the MN serving the wireless device, and the method further comprises initiating the performance of the LTM mobility procedure;- the second network node when the second network node is serving the wireless device prior to the performance of the LTM mobility procedure, and the method further comprises receiving, from the second network node, a request or a command to perform the LTM mobility procedure; anda fourth network node when the first network node is acting as the candidate or target MN, wherein the fourth network node is acting as a MN serving the wireless device, and the method further comprises receiving, from the fourth network node, a request ora command to perform the LTM mobility procedure.

16. The method of any of claims 10-15, wherein the first network node transmits the security information to the second network node before or after the performance of the LTM mobility procedure.

17. The method of any of claims 10-16, wherein the first network node transmits the security information to the second network node in one of an SN Addition Request, an SN Modification Request, a Cell Switch Notification, an LTM Configuration Update, and an XnAP procedure.

18. The method of any of claims 10-17, wherein the first network node receives the security information from the wireless device and / or a fourth network node acting as an MN serving the wireless device, e.g., before or after the performance of the LTM mobility procedure.

19. The method of claims 18, wherein the security information is received from the wireless device in one or more of an RRC message, a MAC CE, and physical layer signalling (e.g., DCI).

20. The method of any of claims 10-19, wherein the security information comprises one or more of:an indication of the at least one security key;an indication of one or more freshness indicators (e.g., sk-counters) that are to be used by the second network node to derive the at least one security key; andan indication of one or more security algorithms used by the wireless device during the LTM mobility procedure, wherein the one or more algorithms are to be used by the second network node to derive the at least one security key.

21. A method performed by a second network node, wherein the second network node acts as a Secondary Node, SN, serving a wireless device subsequent to a performance of an LTM mobility procedure by the wireless device, the method comprising:receiving (502) security information for the wireless device, wherein the security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to the performance of the LTM mobility procedure;wherein the security information is received from the wireless device or a first network node, wherein the first network node acts as a Master Node, MN, serving the wireless device or acts as a candidate or target MN for the wireless device, wherein at least one cell of the candidate or target MN is included in an LTM candidate cell configuration of the wireless device.

22. The method of claim 21, wherein the first network node is acting as one of the candidate or target MN, the at least one cell is included in a Master Cell Group of the one of the candidate or target MN, and subsequent to the performance of the LTM mobility procedure, the wireless device is served by the at least one cell.

23. The method of any of claims 21 and 22, wherein prior to the performance of the LTM mobility procedure, the wireless device is in a single connectivity mode.

24. The method of claims 21, wherein the first network node is acting as the MN serving the wireless device, and prior to the performance of the LTM mobility procedure, the wireless device is served by a different SN to the second network node.

25. The method of any of claims 21-24, wherein the LTM mobility procedure is an inter-CU LTM mobility procedure and / or a conditional LTM mobility procedure.

26. The method of any of claims 21-25, wherein the LTM mobility procedure is triggered by one of:- the wireless device, and the method further comprises receiving, from the first network node, a command or a request to perform the LTM mobility procedure;the first network node when the first network node is acting as the MN serving the wireless device, and the method further comprises receiving, from the first network node, a command or a request to perform the LTM mobility procedure;- the second network node when the second network node is serving the wireless device prior to the performance of the cell switch procedure, and the method further comprises initiating the performance of the LTM mobility procedure; anda fourth network node when the first network node is acting as the target or candidate MN, wherein the fourth network node is acting as a MN serving the wireless device, and the method further comprises receiving, from the fourth network node, a request ora command to perform the LTM mobility procedure.

27. The method of any of claims 21-26, the second network node receives the security information from the wireless device or first network node before or after the performance of the LTM mobility procedure.

28. The method of claim 27, wherein the second network node receives the security information from the first network node in one of an SN Addition Request, an SN Modification Request, a Cell Switch Notification, an LTM Configuration Update, and an XnAP procedure.

29. The method of any of claims 21-28, wherein the security information comprises one or more of:an indication of the at least one security key;an indication of one or more freshness indicators (e.g., sk-counters) that are to be used by the second network node to derive the at least one security key; andan indication of one or more security algorithms used by the wireless device during the LTM mobility procedure, wherein the one or more algorithms are to be used by the second network node to derive the at least one security key.

30. A computer program product comprising a non-transitory computer-readable medium having computer-readable code embodied therein, the computer-readable code being configured such that, on execution by a suitable computer or processing circuitry, the computer or processing circuitry is caused to perform the method of any of the preceding claims.

31. A wireless device (1312, 1412, 1500) configured to perform the method of any of claims 1 to 9.

32. A wireless device (1312, 1412, 1500) comprising processing circuitry (1502) and a memory (1510), said memory containing instructions executable by said processing circuitry whereby said wireless device is operative to:transmit, to a first network node or a second network node, security information for the wireless device, wherein the security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequentto performance of an LTM mobility procedure by the wireless device,wherein the first network node acts as a Master Node, MN, serving the wireless device, or wherein the first network node acts as a target MN for the LTM mobility procedure and at least one cell of the target MN is included in an LTM candidate cell configuration of the wireless device, andwherein the second network node acts as a Secondary Node, SN, serving the wireless device subsequent to the performance of the LTM mobility procedure.

33. The wireless device (1312, 1412, 1500) of claim 32, wherein said wireless device is further operative to perform the method of any of claims 2 to 8.

34. A network node (1310, 1410, 1600), configured to perform the method of any of claims 10 to 20.

35. A network node (1310, 1410, 1600) comprising processing circuitry (1602) and a memory (1604), said memory containing instructions executable by said processing circuitry whereby said network node is operative to:transmit, to a second network node, security information for the wireless device, wherein the security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to performance of an LTM mobility procedure by the wireless device, wherein the second network node acts as a Secondary Node, SN, serving the wireless device subsequent to the performance of the LTM mobility procedure,wherein the first network node acts as a Master Node, MN, serving a wireless device or acts as a candidate or target MN for the wireless device, wherein at least one cell of the candidate or target MN is included in an LTM candidate cell configuration of the wireless device.

36. The network node (1310, 1410, 1600) of claim 35, wherein said network node is further operative to perform the method of any of claims 11 to 20.

37. A network node (1310, 1410, 1600), configured to perform the method of any of claims 21 to 29.

38. A network node (1310, 1410, 1600) comprising processing circuitry (1602) and a memory (1604), said memory containing instructions executable by said processing circuitry whereby said network node is operative to:receive security information for the wireless device, wherein the security information is for determining at least one security key to be used by the second network node for communication with the wireless device subsequent to the performance of the LTM mobility procedure,wherein the second network node acts as a Secondary Node, SN, serving a wireless device subsequent to a performance of an LTM mobility procedure by the wireless device, wherein the security information is received from the wireless device or a first network node, wherein the first network node acts as a Master Node, MN, serving the wireless device or acts as a candidate or target MN for the wireless device, wherein at least one cell of the candidate or target MN is included in an LTM candidate cell configuration of the wireless device.

39. The network node (1310, 1410, 1600) of claim 38, wherein said network node is further operative to perform the method of any of claims 22 to 29.