Inter-central-unit lower layer triggered mobility recovery

WO2026206641A1PCT designated stage Publication Date: 2026-10-01QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/US2026/018975
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2026-03-11
Filing Date
2026-03-12
Publication Date
2026-10-01

Smart Images

  • Figure US2026018975_01102026_PF_FP_ABST
    Figure US2026018975_01102026_PF_FP_ABST
Patent Text Reader

Abstract

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a user equipment (UE) may receive a lower layer triggered mobility (LTM) cell switch command associated with an LTM cell switch from a first cell. The UE may perform, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, and based at least in part on the UE having a valid security parameter for a third cell that is associated with a second central unit (CU) different from a first CU associated with the first cell, an inter-CU LTM cell switch from the first cell to the third cell. Numerous other aspects are described.
Need to check novelty before this filing date? Find Prior Art

Description

INTER-CENTRAL-UNIT LOWER LAYER TRIGGERED MOBILITY RECOVERYCROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This Patent Application claims priority to U.S. Provisional Patent Application No.63 / 777,323, filed on March 25, 2025, entitled “INTER-CENTRAL-UNIT LOWER LAYER TRIGGERED MOBILITY RECOVERY,” and U.S. Nonprovisional Patent Application No.19 / 563,624, filed on March 11, 2026, entitled “INTER-CENTRAL-UNIT LOWER LAYER TRIGGERED MOBILITY RECOVERY,” and assigned to the assignee hereof. The disclosure of the prior Applications are considered part of and are incorporated by reference into this Patent Application.FIELD OF THE DISCLOSURE

[0002] Aspects of the present disclosure generally relate to wireless communication and specifically relate to techniques, apparatuses, and methods associated with inter-central-unit lower layer triggered mobility recovery.DESCRIPTION OF THE RELATED TECHNOLOGY

[0003] Wireless communication systems are widely deployed to provide various services, which may involve carrying or supporting voice, text, other messaging, video, data, or other traffic. Typical wireless communication systems may employ multiple-access radio access technologies (RATs) capable of supporting communication among multiple wireless communication devices including user devices or other devices by sharing the available system resources (for example, time domain resources, frequency domain resources, spatial domain resources, or device transmit power, among other examples). Such multiple-access RATs are supported by technological advancements that have been adopted in various telecommunication standards, which define common protocols that enable different wireless communication devices to communicate on a local, municipal, national, regional, or global level. An example telecommunication standard is New Radio (NR). NR, which also may be referred to as 5G, is part of a continuous mobile broadband evolution promulgated by the Third Generation Partnership Project (3GPP). As the demand for connectivity continues to increase, further improvements in NR may be implemented, and other RATs, such as 6G and beyond, may be introduced to enable new applications and facilitate new use cases.

[0004] In some wireless communication systems, a user equipment (UE) may be configured to perform lower layer triggered mobility (LTM) procedures. In such procedures, lower layer signaling may be used by a network node to activate or deactivate candidate cells in a set of cells configured for LTM or to provide reference signals for measurement by the UE, by which0097-6316PCTthe UE may select a candidate beam as a target beam for a lower layer handover operation. In some examples, a UE may perform an LTM recovery procedure in which, based at least in part on an unsuccessful LTM cell switch procedure to a first candidate cell, the UE may perform an LTM cell switch to a different candidate cell.BRIEF DESCRIPTION OF THE DRAWINGS

[0005] Fig. 1 is a diagram illustrating an example of a wireless communication network.

[0006] Fig. 2 is a diagram illustrating an example of a lower layer triggered mobility (LTM) procedure.

[0007] Fig. 3 is a diagram of an example associated with inter-central-unit LTM recovery.

[0008] Fig. 4 is a diagram illustrating an example process performed, for example, at a user equipment (UE) or an apparatus of a UE.

[0009] Fig. 5 is a diagram illustrating an example process performed, for example, at a network node or an apparatus of a network node.

[0010] Fig. 6 is a diagram of an example apparatus for wireless communication.

[0011] Fig. 7 is a diagram of another example apparatus for wireless communication.SUMMARY

[0012] The systems, methods, and devices of this disclosure each have several innovative aspects, no single one of which is solely responsible for the desirable attributes disclosed herein.

[0013] Some aspects described herein relate to a method of wireless communication performed by a user equipment (UE). The method may include receiving a lower layer triggered mobility (LTM) cell switch command associated with an LTM cell switch from a first cell. The method may include performing, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, and based at least in part on the UE having a valid security parameter for a third cell that is associated with a second central unit (CU) different from a first CU associated with the first cell, an inter-CU LTM cell switch from the first cell to the third cell.

[0014] Some aspects described herein relate to a method of wireless communication performed by a network node. The method may include transmitting, to a UE, configuration information indicating a set of LTM candidate cells. The method may include transmitting, to the UE, an LTM cell switch command associated with an LTM cell switch from a first cell, where, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, and based at least in part on the third cell being included in the set of configured LTM candidate0097-6316PCTcells, transmission of the LTM cell switch results in an inter-CU LTM cell switch from the first cell to the third cell.

[0015] Some aspects described herein relate to a UE. The UE may include a processing system. The processing system may include one or more processors and one or more code-storing memories coupled with the one or more processors. The processing system may be configured to cause the UE to receive an LTM cell switch command associated with an LTM cell switch from a first cell. The processing system may be configured to cause the UE to perform, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, and based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, an inter-CU LTM cell switch from the first cell to the third cell.

[0016] Some aspects described herein relate to a network node. The network node may include a processing system. The processing system may include one or more processors and one or more code-storing memories coupled with the one or more processors. The processing system may be configured to cause the network node to transmit, to a UE, configuration information indicating a set of LTM candidate cells. The processing system may be configured to cause the network node to transmit, to the UE, an LTM cell switch command associated with an LTM cell switch from a first cell, where, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, and based at least in part on the third cell being included in the set of configured LTM candidate cells, transmission of the LTM cell switch results in an inter-CU LTM cell switch from the first cell to the third cell.

[0017] Some aspects described herein relate to a non-transitory computer-readable medium that stores a set of instructions for wireless communication by a UE. The set of instructions, when executed by one or more processors of the UE, may cause the UE to receive an LTM cell switch command associated with an LTM cell switch from a first cell. The set of instructions, when executed by one or more processors of the UE, may cause the UE to perform, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, and based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, an inter-CU LTM cell switch from the first cell to the third cell.

[0018] Some aspects described herein relate to a non-transitory computer-readable medium that stores a set of instructions for wireless communication by a network node. The set of instructions, when executed by one or more processors of the network node, may cause the network node to transmit, to a UE, configuration information indicating a set of LTM candidate0097-6316PCTcells. The set of instructions, when executed by one or more processors of the network node, may cause the network node to transmit, to the UE, an LTM cell switch command associated with an LTM cell switch from a first cell, where, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, and based at least in part on the third cell being included in the set of configured LTM candidate cells, transmission of the LTM cell switch results in an inter-CU LTM cell switch from the first cell to the third cell.

[0019] Some aspects described herein relate to an apparatus for wireless communication. The apparatus may include means for receiving an LTM cell switch command associated with an LTM cell switch from a first cell. The apparatus may include means for performing, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, and based at least in part on the apparatus having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, an inter-CU LTM cell switch from the first cell to the third cell.

[0020] Some aspects described herein relate to an apparatus for wireless communication. The apparatus may include means for transmitting, to a UE, configuration information indicating a set of LTM candidate cells. The apparatus may include means for transmitting, to the UE, an LTM cell switch command associated with an LTM cell switch from a first cell, where, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, and based at least in part on the third cell being included in the set of configured LTM candidate cells, transmission of the LTM cell switch results in an inter-CU LTM cell switch from the first cell to the third cell.

[0021] Aspects of the present disclosure may generally be implemented by or as a method, apparatus, system, computer program product, non-transitory computer-readable medium, user equipment, network node, wireless communication device, or processing system as substantially described in the Detailed Description with reference to, and as illustrated by, the accompanying drawings. Details of one or more implementations of the subject matter described in this disclosure are set forth in the accompanying drawings and the description below. Other features, aspects, and advantages will become apparent from the description, the drawings, and the claims. Note that the relative dimensions of the following figures may not be drawn to scale.0097-6316PCTDETAILED DESCRIPTION

[0022] Wireless communication systems, such as 5G networks, employ various features to enhance connection reliability and network resilience. One such feature is lower layer trigger mobility (LTM). This feature enables a user equipment (UE) to perform a cell switch to a candidate cell by using lower layer signaling (e.g., medium access control (MAC) signaling, such as a MAC control element (MAC-CE), or physical layer signaling, such as downlink control information (DCI)). In some examples, if an LTM cell switch is unsuccessful, the UE may be configured to perform an LTM recovery procedure, in which the UE performs a cell switch to another candidate cell. In such examples, LTM recovery may be confined to intracentral -unit (CU) LTM cell switches.

[0023] With the evolution of certain wireless communication procedures, it may be desirable to expand the scope of LTM recovery to inter-CU cell switches. However, doing so introduces complexities in maintaining security parameters during the subsequent LTM cell switches. For example, a UE may not have up-to-date security parameters to perform inter-CU LTM cell switches in LTM recovery situations. In this regard, a UE attempting to perform an inter-CU LTM recovery procedure using a mismatched or outdated security parameter may lead to unsuccessful LTM recovery, thereby increasing latency associated with cell switching procedures, resulting in increased network overhead and resource consumption associated with cell switching procedures, and, in some examples, resulting in compromised communication integrity and system failures. Moreover, inter-CU LTM recovery may require coordination between different network nodes (e.g., different CUs) to ensure that the security parameters are updated across candidate cells. The lack of an effective signaling mechanism among CUs for security parameter updates, as well as between the CUs and UEs, may further result in unsuccessful LTM procedures and thus high power, computing, and network resource consumption associated with unsuccessful cell switch and recovery operations.

[0024] Various aspects relate generally to enhancing reliability in wireless communication systems through improved LTM cell switch recovery procedures. Some aspects more specifically relate to enabling a UE to perform, in response to an unsuccessful LTM cell switch attempt, an inter-CU LTM cell switch from a cell associated with a first CU to a cell associated with a second CU different from the first CU. In some aspects, the inter-CU LTM cell switch may be performed based at least in part on the UE determining that one or more inter-CU LTM cell switch conditions are met. For example, in some aspects, the inter-CU LTM cell switch may be performed based at least in part on the UE having a valid security parameter for the cell associated with the second CU. Additionally, or alternatively, the inter-CU LTM cell switch may be performed based at least in part on the cell associated with the second CU being0097-6316PCTincluded in a configured set of LTM candidate cells. Additionally, or alternatively, the inter-CU LTM cell switch may be performed based at least in part on the UE being configured to perform inter-CU cell recovery (e.g., based at least in part on the UE receiving configuration information enabling inter-CU LTM cell recovery procedures).

[0025] Particular aspects of the subject matter described herein can be implemented to realize one or more of the following potential technical advantages. By enabling the UE to verify the validity of security parameters, such as a next hop chaining count or similar security parameters, the described techniques can be used to prevent outdated security information from compromising communication during inter-CU LTM recovery. In this regard, particular aspects of the subject matter described herein may result in a secure and reliable connection during LTM recovery procedures, thereby conserving network resources that might otherwise be expended on reestablishing connections and reauthenticating the UE. Additionally, or alternatively, aspects described herein may enable efficient signaling of security parameter updates, thereby ensuring that the UE’s security parameters are continually updated and thus maintaining the integrity of secure communication during multiple LTM switches. In some aspects, various CUs may communicate in order to update security parameters based on the successful completion of the inter-CU LTM cell switch. This network-side coordination may ensure that UEs are provided with the most current security parameters, reducing the risk of compromised security during LTM recovery. In this way, the aspects and techniques described herein enable a more reliable LTM recovery process, reduce the potential for interrupted service due to security parameter mismatches, and enhance the overall security posture of the wireless communication system during LTM recovery processes, thus resulting in a more efficient use of network and processing resources by reducing the need for redundant security checks and minimizing service interruptions.

[0026] 5G New Radio (NR) may support enhanced mobile broadband (eMBB) access, Internet of Things (loT) networks or reduced capability (RedCap) device deployments, ultrareliable low-latency communication (URLLC) applications, or massive machine-type communication (mMTC), among other examples. To support these and other target verticals, a wireless communication system may be designed to implement a modularized functional infrastructure, a disaggregated and service-based network architecture, network function virtualization, network slicing, multi-access edge computing, millimeter wave (mmWave) technologies including massive multiple-input multiple-output (MIMO), beamforming, loT device or RedCap device connectivity and management, industrial connectivity, licensed and unlicensed spectrum access, sidelink and other device-to-device direct communication (for example, cellular vehicle-to-everything (CV2X) communication), frequency spectrum expansion, overlapping spectrum use, small cell deployments, non-terrestrial network (NTN)0097-6316PCTdeployments, device aggregation, advanced duplex communication (for example, sub -band full-duplex (SBFD)), multiple-subscriber implementations, high-precision positioning, radio frequency (RF) sensing, network energy savings (NES), low-power signaling and radios, or artificial intelligence or machine learning (AI / ML), among other examples.

[0027] The foregoing and other technological improvements may support use cases, such as wireless fronthauls, wireless midhauls, wireless backhauls, wireless data centers, extended reality (XR) and metaverse applications, meta services for supporting vehicle connectivity, holographic and mixed reality communication, autonomous and collaborative robots, vehicle platooning and cooperative maneuvering, sensing networks, gesture monitoring, human-brain interfacing, digital twin applications, asset management, and universal coverage applications using non-terrestrial or aerial platforms, among other examples.

[0028] The methods, operations, apparatuses, and techniques described herein may enable one or more of the foregoing technologies or new technologies or support one or more of the foregoing use cases or new use cases.

[0029] Fig. 1 is a diagram illustrating an example of a wireless communication network 100. The wireless communication network 100 may be or may include elements of a 5G network or a 6G network, among other examples. The wireless communication network 100 may include multiple network nodes 110. For example, in Fig. 1, the wireless communication network 100 includes multiple network nodes 110, including a network node 110a and a network node 110b (each of which also may be referred to herein simply as a “network node 110”). The network nodes 110 may support communications with multiple UEs 120. For example, in Fig. 1, the network nodes 110 support communication with a UE 120a, a UE 120b, and a UE 120c (each of which also may be referred to herein simply as a “UE 120”). In some examples, a UE 120 also may communicate with other UEs 120 and a network node 110 also may communicate with a core network and with other network nodes 110.

[0030] The network nodes 110 and the UEs 120 of the wireless communication network 100 communicate using the electromagnetic spectrum, which may be subdivided into various licensed or unlicensed operating bands, frequency ranges, component carriers, or channels that define associated frequencies available for communications. In some examples, each of the network nodes 110 and the UEs 120 may communicate using one or multiple component carriers in one or more operating bands or ranges. Typically, various operating bands are defined as frequency range designations FR1 (410 MHz through 7.125 GHz), FR2 (24.25 GHz through 52.6 GHz), FR3 (7.125 GHz through 24.25 GHz), FR4a or FR4-1 (52.6 GHz through 71 GHz), FR4 (52.6 GHz through 114.25 GHz), and FR5 (114.25 GHz through 300 GHz). Although a portion of FR1 is greater than 6 GHz, FR1 is often referred to0097-6316PCT(interchangeably) as a “sub-6 GHz” band in some documents and articles. Similarly, FR2 is often referred to (interchangeably) as a “millimeter wave” band in some documents and articles .

[0031] A network node 110 or a UE 120 may include one or more devices, components, or systems that enable communication with other devices, components, or systems of the wireless communication network 100. For example, a UE 120 and a network node 110 may each include one or more chips, system-on-chips (SoCs), chipsets, packages, or devices that individually or collectively constitute or comprise a processing system. As shown in Fig. 1, each UE 120 includes a processing system 140 and each network node 110 includes a processing system 145. A processing system (for example, the processing system 140 or the processing system 145) includes processor (or “processing”) circuitry in the form of one or multiple processors, microprocessors, processing units (such as central processing units (CPUs), graphics processing units (GPUs), neural processing units (NPUs) (also referred to as neural network processors or deep learning processors (DLPs)), or digital signal processors (DSPs)), processing blocks, application-specific integrated circuits (ASICs), programmable logic devices (PLDs), or other discrete gate or transistor logic or circuitry (any one or more of which may be generally referred to herein individually as a “processor” or collectively as “the processor” or “the processor circuitry”). Such processors may be individually or collectively configurable or configured to perform various functions or operations described herein. A group of processors collectively configurable or configured to perform a set of functions may include a first processor configurable or configured to perform a first function of the set and a second processor configurable or configured to perform a second function of the set. In some other examples, each of a group of processors may be configurable or configured to perform a same set of functions.

[0032] The processing system 140 and the processing system 145 may each include memory circuitry in the form of one or multiple memory devices, memory blocks, memory elements, or other discrete gate or transistor logic or circuitry, each of which may include or implement tangible storage media, such as random-access memory, or read-only memory, or combinations thereof (any one or more of which may be generally referred to herein individually as a “memory” or collectively as “the memory” or “the memory circuitry”). One or more of the memories may be coupled (for example, operatively coupled, communicatively coupled, electronically coupled, or electrically coupled) with one or more of the processors . One or more of the memories may individually or collectively store processor-executable code or instructions (such as software) (for example, which may be referred to as “one or more code-storing memories” or “code-storing memory circuitry”). For example, “code-storing memory” or “code-storing memory circuitry” refers to memory (or memory circuitry) that is configured to store processor-executable code or instructions. The processor-executable code or instructions,0097-6316PCTwhen executed by one or more of the processors, may configure one or more of the processors (or processing circuitry) to perform various functions or operations described herein.Additionally, or alternatively, in some examples, one or more of the processors may be configured to perform various functions or operations described herein without requiring configuration by software. Software shall be construed broadly to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executables, threads of execution, procedures, or functions, among other examples, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise.

[0033] The processing system 140 and the processing system 145 may each include or be coupled with one or more modems (such as a cellular (for example, a 5G or 6G compliant) modem). In some examples, one or more processors of the processing system 140 or the processing system 145 may include or implement one or more of the modems. The processing system 140 and the processing system 145 also may include or be coupled with multiple radios (collectively “the radio”), multiple RF chains, or multiple transceivers, each of which may in turn be coupled with one or more of multiple antennas. In some examples, one or more processors of the processing system 140 or the processing system 145 may include or implement one or more of the radios, RF chains, or transceivers. An RF chain may include one or more filters, mixers, oscillators, amplifiers, analog -to-digital converters (ADCs), or other devices that convert between an analog signal (such as for transmission or reception via an air interface) and a digital signal (such as for processing by the processing system 140 or by the processing system 145).

[0034] A network node 110 and a UE 120 may each include one or multiple antennas or antenna arrays. Typical network nodes 110 and UEs 120 may include multiple antennas, which may be organized or structured into one or more antenna panels, one or more antenna groups, one or more sets of antenna elements, or one or more antenna arrays, among other examples. As used herein, the term “antenna” can refer to one or more antennas, one or more antenna panels, one or more antenna groups, one or more sets of antenna elements, or one or more antenna arrays. The term “antenna panel” can refer to a group of antennas (such as antenna elements) arranged in an array or panel, which may facilitate beamforming by manipulating parameters associated with the group of antennas. The term “antenna module” may refer to circuitry including one or more antennas as well as one or more other components (such as filters, amplifiers, or processors) associated with integrating the antenna module into a wireless communication device, such as the network node 110 and the UE 120.0097-6316PCT

[0035] A network node 110 may be, may include, or also may be referred to as an NR network node, a 5G network node, a 6G network node, a Node B, a gNB, an access point (AP), a transmission reception point (TRP), a network entity, a network element, a network equipment, or another type of device, component, or system included in a radio access network (RAN). In various deployments, a network node 110 may be implemented as a single physical node (for example, a single physical structure) or may be implemented as two or more physical nodes (for example, two or more distinct physical structures). For example, a network node 110 may be a device or system that implements a part of a radio protocol stack, a device or system that implements a full radio protocol stack (such as a full gNB protocol stack), or a collection of devices or systems that collectively implement the full radio protocol stack. For example, and as shown, a network node 110 may be an aggregated network node having an aggregated architecture, meaning that the network node 110 may implement a full radio protocol stack that is physically and logically integrated within a single physical structure in the wireless communication network 100. For example, an aggregated network node 110 may include a single standalone base station or a single TRP that operates with a full radio protocol stack to enable or facilitate communication between a UE 120 and a core network of the wireless communication network 100.

[0036] Alternatively, a network node 110 may be a disaggregated network node 110 (sometimes referred to as a disaggregated base station), having a disaggregated architecture, meaning that the network node 110 may operate with a radio protocol stack that is physically distributed or logically distributed among two or more nodes in the same geographic location or in different geographic locations. In some deployments, disaggregated network nodes 110 may be used in an integrated access and backhaul (IAB) network, in an open radio access network (O-RAN) (such as a network configuration in compliance with the O-RAN Alliance), or in a virtualized radio access network (vRAN), also known as a cloud radio access network (C-RAN), to facilitate scaling by separating network functionality into multiple units or modules that can be individually deployed.

[0037] The disaggregated network nodes 110 of the wireless communication network 100 may include one or more CUs, one or more distributed units (DUs), and one or more radio units (RUs). A CU may host one or more higher layers, such as a radio resource control (RRC) layer, a packet data convergence protocol (PDCP) layer, and a service data adaptation protocol (SDAP) layer, among other examples. A CU can communicate with a core network either directly (for example, via a backhaul link) or indirectly (for example, via one or more disaggregated control units, such as a non-real-time (Non-RT) RAN intelligent controller (RIC) associated with a Service Management and Orchestration (SMO) framework or a near-real-time (Near-RT) RIC). A DU may host one or more of a radio link control (REC) layer, a MAC layer,0097-6316PCTor one or more higher physical (PHY) layers depending, at least in part, on a functional split, such as a functional split defined by the 3GPP. In some examples, a DU also may host a lower PHY layer that is configured to perform functions, such as a fast Fourier transform (FFT), an inverse FFT (IFFT), beamforming, or physical random access channel (PRACH) extraction and filtering, among other examples. An RU may perform RF processing functions or lower PHY layer functions, such as an FFT, an IFFT, beamforming, or PRACH extraction and filtering, among other examples, according to a functional split, such as a lower layer split (LLS). In such an architecture, each RU can be operated to handle over the air (OTA) communication with one or more UEs 120. A CU may communicate with one or more DUs via respective midhaul links, such as via Fl interfaces. Each of the DUs may communicate with one or more RUs via respective fronthaul links. Each of the RUs may communicate with one or more UEs 120 via respective RF access links. In some deployments, a UE 120 may be simultaneously served by multiple RUs.

[0038] In some examples, a single network node 110 may include a combination of one or more CUs, one or more DUs, or one or more RUs. In some examples, a CU, a DU, or an RU may be implemented as a virtual unit, such as a virtual central unit (VCU), a virtual distributed unit (VDU), or a virtual radio unit (VRU), among other examples, which may be implemented as a virtual network function, such as in a cloud deployment (for example, an open cloud (O-Cloud) platform). An SMO framework may support RAN deployment and provisioning of nonvirtualized and virtualized network elements.

[0039] In some examples, the wireless communication network 100 may be a heterogeneous network that includes network nodes 110 of various types. Different types of network nodes 110 may generally operate on the same or different operating bands, transmit at different power levels, or serve different coverage areas, each of which may be referred to as or associated with a particular cell 130 (for example, a cell 130a and a cell 130b).

[0040] The UEs 120 may be physically dispersed throughout the coverage area of the wireless communication network 100, and each UE 120 may be stationary or mobile. A UE 120 may be, may include, or also may be referred to as an access terminal, a mobile station, a client device, or a subscriber unit. A UE 120 may be, include, or be coupled with a cellular phone (for example, a smart phone), a personal digital assistant (PDA), a wireless modem, a wireless communication device, a handheld device, a laptop computer, a cordless phone, a wireless local loop (WLL) station, a tablet, a camera, a netbook, a smartbook, an ultrabook, a medical device, a biometric device, a wearable device (for example, a smart watch, smart clothing, smart glasses, a smart wristband, or smart jewelry), a gaming device, an entertainment device (for example, a music device, a video device, or a satellite radio), an XR device, a vehicular component or sensor, a smart meter or sensor, industrial manufacturing equipment, a Global0097-6316PCTNavigation Satellite System (GNSS) device (such as a Global Positioning System device or another type of positioning device), an artificially intelligent robot or other device implementing artificial intelligence, a UE function of a network node, or any other suitable device or function that may communicate in the wireless communication network 100.

[0041] Some UEs 120 may be classified according to different categories in association with different complexities or different capabilities. UEs 120 in a first category may be associated with relatively low complexity or cost such as NB-IoT devices or eMTC UEs. UEs 120 in a second category may include higher complexity or cost devices, such as mission-critical loT devices, baseline UEs, high-tier UEs, advanced UEs, full -capability UEs, or premium UEs that are capable of URLLC, eMBB, or precise positioning in the wireless communication network 100. A third category of UEs 120 may have mid-tier complexity or capabilities (for example, capabilities between that of the UEs 120 of the first category and the UEs 120 of the second category). A UE 120 of the third category may be referred to as a reduced capability UE (“RedCap UE”), a mid-tier UE, an NR-Light UE, or an NR-Lite UE, among other examples.

[0042] In some examples, a network node 110 may be, may include, or may operate as an RU, a TRP, or a base station that communicates with one or more UEs 120 via a radio access link (which may be referred to as a “Uu” link). The radio access link may include a downlink and an uplink. “Downlink” (or “DL”) refers to a communication direction from a network node 110 to a UE 120, and “uplink” (or “UL”) refers to a communication direction from a UE 120 to a network node 110. Downlink and uplink resources may include time domain resources (for example, frames, subframes, slots, and symbols), frequency domain resources (for example, frequency bands, component carriers (CCs), subcarriers, resource blocks, and resource elements), and spatial domain resources (for example, particular transmit directions or beams).

[0043] Frequency domain resources may be subdivided into bandwidth parts (BWPs). A BWP may be a block of frequency domain resources (for example, a continuous set of resource blocks (RBs) within a full component carrier bandwidth) that may be configured at a UE-specific level. A UE 120 may be configured with both an uplink BWP and a downlink BWP (which may be the same or different). Each BWP may be associated with its own numerology (indicating a sub-carrier spacing (SCS) and cyclic prefix (CP)). A BWP may be dynamically configured or activated (for example, by a network node 110 transmitting a DCI configuration to the one or more UEs 120) or reconfigured (for example, in real-time or near-real-time) according to changing network conditions in the wireless communication network 100 or specific requirements of one or more UEs 120. An active BWP defines the operating bandwidth of the UE 120 within the operating bandwidth of the serving cell.

[0044] As used herein, a downlink signal may be or include a reference signal, control information, or data. For example, downlink reference signals include a primary0097-6316PCTsynchronization signal (PSS), a secondary SS (SSS), an SS block (SSB) (for example, that includes a PSS, an SSS, and a physical broadcast channel (PBCH)), a demodulation reference signal (DMRS), a phase tracking reference signal (PTRS), a tracking reference signal (TRS), and a channel state information (CSI) reference signal (CSI-RS), among other examples. A downlink signal carrying control information or data may be transmitted via a downlink channel. Downlink channels may include one or more control channels for transmitting control information and one or more data channels for transmitting data. Downlink reference signals may be transmitted in addition to, or multiplexed with, downlink control channel communications or downlink data channel communications. A downlink control channel may be specifically used to transmit DCI from a network node 110 to a UE 120. DCI generally contains the information the UE 120 needs to identify RBs in a subsequent subframe and how to decode them, including a modulation and coding scheme (MCS) or redundancy version parameters. Different DCI formats carry different information, such as scheduling information in the form of downlink or uplink grants, slot format indicators (SFIs), preemption indicators (Pls), transmit power control (TPC) commands, hybrid automatic repeat request (HARQ) information, new data indicators (NDIs), among other examples. A downlink data channel may be used to transmit downlink data (for example, user data associated with a UE 120) from a network node 110 to a UE 120. Downlink control channels may include physical downlink control channels (PDCCHs), and downlink data channels may include physical downlink shared channels (PDSCHs). Control information or data communications may be transmitted on a PDCCH and PDSCH, respectively. For example, a PDCCH can carry DCI, while a PDSCH can carry a MAC-CE, an RRC message, or user data, among other examples. Each PDSCH may carry one or more transport blocks (TBs) of data.

[0045] As used herein, an uplink signal may include a reference signal, control information, or data. For example, uplink reference signals include a sounding reference signal (SRS), a PTRS, and a DMRS, among other examples. An uplink signal carrying control information or data may be transmitted via an uplink channel. An uplink channel may include one or more control channels for transmitting control information and one or more data channels for transmitting data. Uplink reference signals may be transmitted in addition to, or multiplexed with, uplink control channel communications or uplink data channel communications. An uplink control channel may be specifically used to transmit uplink control information (UCI) from a UE 120 to a network node 110. An uplink data channel may be used to transmit uplink data (for example, user data associated with a UE 120) from a UE 120 to a network node 110. Uplink control channels may include physical uplink control channels (PUCCHs), and uplink data channels may include physical uplink shared channels (PUSCHs). Control information or data communications may be transmitted on a PUCCH and PUS CH,0097-6316PCTrespectively. For example, a PUCCH can carry UCI, while a PUSCH can carry a MAC-CE, an RRC message, or user data, among other examples. UCI can include a scheduling request (SR), HARQ feedback information (for example, a HARQ acknowledgement (ACK) indication or a HARQ negative acknowledgement (NACK) indication), uplink power control information (for example, an uplink TPC parameter), or CSI, among other examples. CSI can include a channel quality indicator (CQI) (indicative of downlink channel conditions to facilitate selection of transmission parameters, such as an MCS, by a network node 110), a precoding matrix indicator (PMI), a CSI-RS resource indicator (CRI) (for example, indicative of a beam used to transmit a CSI-RS), an SS / PBCH resource block indicator (SSBRI) (for example, indicative of a beam used to transmit an SSB), a layer indicator (LI), a rank indicator (RI), or measurement information (for example, a layer 1 (LI)- reference signal received power (RSRP) parameter, a received signal strength indicator (RS SI) parameter, a reference signal received quality (RSRQ) parameter, among other examples) which can be used for beam management, among other examples. Each PUSCH may carry one or more TBs of data.

[0046] The information (for example, data, control information, or reference signal information) transmitted by a network node 110 to a UE 120, or vice versa, may be represented as a sequence of binary bits that are mapped (for example, modulated) to an analog signal waveform (for example, a discrete Fourier transform (DFT)-spread-orthogonal frequency division multiplexing (OFDM) (DFT-s-OFDM) waveform or a CP-OFDM waveform) that is transmitted by the network node 110 or UE 120 over a wireless communication channel. In some examples, the network node 110 or the UE 120 (for example, using the processing system 145 or the processing system 140, respectively) may select an MCS (for example, an order of quadrature amplitude modulation (QAM), such as 64-QAM, 128-QAM, or 256-QAM, among other examples) for a downlink signal or an uplink signal. For example, the network node 110 may select an MCS for a downlink signal in accordance with UCI received from the UE 120 or may transmit, to the UE 120, an indication of an MCS to be applied for an uplink signal.

[0047] A network node 110 or a UE 120 (such as by using the processing system 145 or the processing system 140, respectively, or one or more coupled modems) may perform signal processing on the information (such as filtering, amplification, modulation, digital -to-analog conversion, an IFFT operation, multiplexing, interleaving, mapping, or encoding, among other examples) to generate a processed signal in accordance with the selected MCS. In some examples, the network node 110 or the UE 120 (for example, using the processing system 145 or the processing system 140, respectively, or one or more coupled encoders or modems) may perform a channel coding operation or a forward error correction (FEC) operation to control errors in transmitted information. For example, the network node 110 or the UE 120 may perform an encoding operation to generate encoded information (such as by selectively0097-6316PCTintroducing redundancy into the information, typically using an error correction code (ECC), such as a polar code or a low-density parity-check (LDPC) code). The network node 110 or the UE 120 (for example, using the processing system 145 or one or more modems) may further perform spatial processing (for example, precoding) on the encoded information to generate one or more processed or precoded signals for downlink or uplink transmission, respectively. In some examples, the network node 110a or the UE 120a may perform codebook -based precoding or non-codebook-based precoding. Codebook-based precoding may involve selecting a precoder (for example, a precoding matrix) using a codebook. For example, the network node 110a may provide precoding information indicating which precoder, defined by the codebook, is to be used by the UE 120a. Non-codebook-based precoding may involve selecting or deriving a precoder based on, or otherwise associated with, one or more downlink or uplink signal measurements. The network node 110a or the UE 120a may transmit the processed downlink or uplink signals, respectively, via one or more antennas.

[0048] The network node 110a or the UE 120a may receive uplink signals or downlink signals, respectively, via one or more antennas. The network node 110a or the UE 120a (for example, using the processing system 145 or the processing system 140, respectively, or one or more coupled modems) may perform signal processing (for example, in accordance with the MCS) on the received uplink or downlink signals, respectively (such as filtering, amplification, demodulation, analog-to-digital conversion, an FFT operation, demultiplexing, deinterleaving, de-mapping, equalization, interference cancellation, or decoding, among other examples), to map the received signal(s) to a sequence of binary bits (for example, received information) that estimates the information transmitted by the network node 110 or the UE 120 via the downlink or uplink signals. The network node 110a or the UE 120a (for example, using the processing system 145 or the processing system 140, respectively, or a coupled decoder or one or more modems) may decode the received information (such as by using an ECC, a decoding operation, or an FEC operation) to detect errors or correct bit errors in the received information to generate decoded information. The decoded information may estimate the information transmitted via the downlink or uplink signals.

[0049] In some examples, a UE 120 and a network node 110 may perform MIMO communication. MIMO communication generally refers to transmitting or receiving multiple signals (such as multiple layers or multiple data streams) simultaneously over the same time and frequency resources. A network node 110 or a UE 120 may communicate using single-user MIMO or multi-user MIMO (MU-MIMO), the latter of which being used by a network node 110 to simultaneously transmit signals to multiple UEs 120. MIMO techniques may involve spatial multiplexing (multi-layer transmission) or beamforming. To implement beamforming, the amplitudes or phases of signals transmitted via antenna elements may be modulated and0097-6316PCTshifted relative to each other (such as by manipulating a phase shift, a phase offset, or an amplitude) to generate one or more beams. For example, a network node 110 may generate one or more beams 160a, and a UE 120 may generate one or more beams 160b. The term “beam” may refer to a directional transmission of a wireless signal toward a receiving device or otherwise in a desired direction, a directional reception of a wireless signal from a transmitting device or otherwise in a desired direction, a direction associated with such a directional transmission or directional reception, a set of directional resources associated with a signal transmission or signal reception (for example, an angle of arrival, a horizontal direction, or a vertical direction), or a set of parameters or resources associated with one or more aspects of a directional signal, among other examples.

[0050] In some examples, a network node 110 or a UE 120 may implement massive MIMO, which may be associated with an increased (for example, “massive”) quantity of antennas at the network node 110 or at the UE 120, such as in a network implementing mmWave technology, which enables more precise beamforming or reduced interference. In some examples, the wireless communication network 100 may implement multi -TRP (mTRP) operation (including redundant transmission or reception on multiple TRPs) or non -coherent joint transmission (NC-JT).

[0051] The network node 110 and the UE 120 may establish a communication link or beam pair, and otherwise increase reliability, throughput, signal strength, or other signal properties for MIMO communications, by performing beam management operations, such as an initial beam acquisition operation, a beam refinement operation, or a beam recovery operation. For example, an initial beam acquisition operation may involve the network node 110 transmitting signals (for example, SSBs or other signals) via respective beams (for example, of the beams 160 of the network node 110) and the UE 120 receiving and measuring the signal(s) via respective beams of multiple beams (for example, from the beams 160 of the UE 120) to identify a best beam (or beam pair) for communication between the UE 120 and the network node 110. A beam refinement operation may involve a first device (for example, the UE 120 or the network node 110) transmitting signal(s) via a subset of beams (for example, identified based on, or otherwise associated with, measurements reported as part of one or more other beam management operations). A second device (for example, the network node 110 or the UE 120) may receive the signal(s) via a single beam (for example, to identify the best beam for communication from the subset of beams). The beam(s) may be identified or defined via one or more spatial parameters, such as a transmission configuration indicator (TCI) state or a quasi co -location (QCL) parameter, among other examples.

[0052] Some aspects and techniques as described herein may be implemented, at least in part, using an artificial intelligence (Al) program (for example, referred to herein as an “AI / ML0097-6316PCTmodel”), such as a program that includes a machine learning (ML) model or an artificial neural network (ANN) model. The AI / ML model may be deployed at one or more devices 165 (for example, one or more network nodes 110, one or more UEs 120, one or more servers, or one or more components of a cloud computing network, among other examples). For example, in a deployment in which AI / ML functionality is performed independently at a device 165, sometimes referred to as “overlay AI / ML,” the AI / ML model (or an instance or portion of the AI / ML model) may be deployed at a UE 120 (for example, by the processing system 140), a network node 110 (for example, by the processing system 145), one or more servers, or one or more components of a cloud computing network, among other examples. Additionally, or alternatively, in a deployment where AI / ML functionality is coordinated between different devices 165, sometimes referred to as “coordinated AI / ML,” or performed at all device and network layers, sometimes referred to as “native AI / ML,” the AI / ML model (or an instance of the AI / ML model) may be deployed at multiple devices 165 (for example, a first portion of the AI / ML model may be deployed at a UE 120 and a second portion of the AI / ML model may be deployed at a network node 110). In other examples of coordinated AI / ML or native AI / ML, a first AI / ML model may be deployed at a UE 120 and a second AI / ML model may be deployed at a network node 110. The AI / ML model(s) may be configured to enhance various aspects of the wireless communication network 100 (for example, to increase privacy, reliability, or efficient use of network bandwidth, or to reduce latency, among other examples). For example, the AI / ML model(s) may be trained to identify patterns or relationships in data corresponding to the wireless communication network 100, a device, or an air interface, among other examples. The AI / ML model(s) may support operational decisions relating to one or more aspects associated with wireless communications devices, networks, or services.

[0053] Accordingly, in some examples, the AI / ML model(s) may enable Al-as-a-Service (for example, an end-to-end AI / ML service via a user plane) for use cases, such as a self-organizing network (SON), minimization of drive test (MDT), quality of experience (QoE), positioning, sensing, predictive mobility, or traffic prediction, among other examples. In some examples, Al-as-a-Service use cases may include measurement collection reporting by a UE 120, device selection criteria (for example, according to a geographical area where measurements are to be collected or UE capabilities to be used to collected measurements), or reporting configurations (for example, reporting parameters such as location, time, or sensor information, among other examples). Additionally, or alternatively, the AI / ML model(s) may enable AI / ML procedures (for example, RAN-triggered service establishment, configuration, inferencing using UE-side or network-side models, performance monitoring or management, or capability signaling, among other examples). Additionally, or alternatively, the AI / ML model(s) may enable RAN -based AI / ML services via one or more application program interfaces (APIs) or management0097-6316PCTinterfaces for use cases, such as beam management, radio resource monitoring (RRM) relaxation, mobility prediction, load prediction, network energy savings, or coverage and capacity improvements, among other examples).

[0054] One enhancement for multi-beam operation at higher carrier frequencies is facilitation of efficient (for example, low latency and low overhead) downlink or uplink beam management operations to support Layer 1 or Layer 2 (L1 / L2) -centric inter-cell mobility. L1 / L2 signaling may be referred to as “lower layer” signaling. L1 / L2 signaling may be used to activate or deactivate candidate cells in a set of cells configured for LTM or to provide reference signals for measurement by the UE 120, by which the UE 120 may select a candidate beam as a target beam for a lower layer handover operation. Accordingly, L1 / L2 -centric inter-cell mobility may enable a UE 120 to perform a cell switch via dynamic control signaling at lower layers (for example, DCI for LI signaling or a MAC-CE for L2 signaling), rather than semi-static Layer 3 (L3) RRC signaling. Thus, L1 / L2 centric inter-cell mobility may reduce latency, reduce overhead, or otherwise increase efficiency of the cell switch.

[0055] In some aspects, the UE 120 may include a communication manager 150. As described in more detail elsewhere herein, the communication manager 150 may receive an LTM cell switch command associated with an LTM cell switch from a first cell; and perform, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, and based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, an inter-CU LTM cell switch from the first cell to the third cell. Additionally, or alternatively, the communication manager 150 may perform one or more other operations described herein.

[0056] In some aspects, the network node 110 may include a communication manager 155. As described in more detail elsewhere herein, the communication manager 155 may transmit, to a UE, configuration information indicating a set of LTM candidate cells; and transmit, to the UE, an LTM cell switch command associated with an LTM cell switch from a first cell, wherein, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, and based at least in part on the third cell being included in the set of configured LTM candidate cells, transmission of the LTM cell switch results in an inter-CU LTM cell switch from the first cell to the third cell. Additionally, or alternatively, the communication manager 155 may perform one or more other operations described herein.

[0057] The network node 110, the processing system 145 of the network node 110, the UE 120, the processing system 140 of the UE 120, or any other component(s) of Fig. 1 may implement one or more techniques or perform one or more operations associated with inter-CU0097-6316PCTLTM recovery, as described in more detail elsewhere herein. For example, the processing system 145 of the network node 110, or the processing system 140 of the UE 120 may perform or direct operations of, for example, process 400 of Fig. 4, process 500 of Fig. 5, or other processes as described herein (alone or in conjunction with one or more other processors). Memory of the network node 110 may store data and program code (or instructions) for the network node 110. In some examples, the memory of the network node 110 may store data relating to a UE 120, such as RRC state information or a UE context. Memory of a UE 120 may store data and program code (or instructions) for the UE 120, such as context information. In some examples, the memory of the UE 120 or the memory of the network node 110 may include a non-transitory computer-readable medium storing a set of instructions for wireless communication. For example, the set of instructions, when executed by one or more processors (for example, of the processing system 145 or the processing system 140) of the network node 110, or the UE 120, may cause the one or more processors to perform process 400 of Fig. 4, process 500 of Fig. 5, or other processes as described herein. In some examples, executing instructions may include running the instructions, converting the instructions, compiling the instructions, or interpreting the instructions, among other examples.

[0058] In some aspects, the UE 120 includes means for receiving an LTM cell switch command associated with an LTM cell switch from a first cell; or means for performing, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, and based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, an inter-CU LTM cell switch from the first cell to the third cell. The means for the UE 120 to perform operations described herein may include, for example, one or more of communication manager 150, processing system 140, a radio, one or more RF chains, one or more transceivers, one or more antennas, one or more modems, a reception component (for example, reception component 602 depicted and described in connection with Fig. 6), or a transmission component (for example, transmission component 604 depicted and described in connection with Fig. 6), among other examples.

[0059] In some aspects, the network node 110 includes means for transmitting, to a UE, configuration information indicating a set of LTM candidate cells; or means for transmitting, to the UE, an LTM cell switch command associated with an LTM cell switch from a first cell, wherein, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, and based at least in part on the third cell being included in the set of configured LTM candidate cells transmission of the LTM cell switch results in an inter-CU LTM cell switch from the first0097-6316PCTcell to the third cell. The means for the network node 110 to perform operations described herein may include, for example, one or more of communication manager 155, processing system 145, a radio, one or more RF chains, one or more transceivers, one or more antennas, one or more modems, a reception component (for example, reception component 702 depicted and described in connection with Fig. 7), or a transmission component (for example, transmission component 704 depicted and described in connection with Fig. 7), among other examples.

[0060] Fig. 2 is a diagram illustrating an example 200 of an LTM procedure.

[0061] In some examples, a network node 110 may instruct a UE 120 to change serving cells, such as when the UE 120 moves away from coverage of a current serving cell (sometimes referred to as a source cell) and toward coverage of a neighboring cell (sometimes referred to as a target cell). In some cases, the network node 110 may instruct the UE 120 to change cells using an L3 handover procedure. An L3 handover procedure may include the network node 110 transmitting, to the UE 120, an RRC reconfiguration message indicating that the UE 120 should perform a handover procedure to a target cell, which may be transmitted in response to the UE 120 providing the network node 110 with an L3 measurement report indicating signal strength measurements associated with various cells (e.g., measurements associated with the source cell and one or more neighboring cells). In response to receiving the RRC reconfiguration message, the UE 120 may communicate with the source cell and the target cell to detach from the source cell and connect to the target cell (e.g., the UE 120 may establish an RRC connection with the target cell). Once handover is complete, the target cell may communicate with a user plane function (UPF) of a core network to instruct the UPF to switch a user plane path of the UE 120 from the source cell to the target cell. The target cell may also communicate with the source cell to indicate that handover is complete and that the source cell may be released.

[0062] L3 handover procedures may be associated with high latency and high overhead due to the multiple RRC reconfiguration messages or other L3 signaling and operations used to perform the handover procedures. Accordingly, in some examples, a UE 120 may be configured to perform a lower-layer (e.g., LI or L2) handover procedure, sometimes referred to an LTM procedure, such as the example 200 LTM procedure shown in Fig 2. As shown in Fig.2, the LTM procedure may include four phases: an LTM preparation phase, an early synchronization phase (shown as “early sync” in Fig. 2), an LTM execution phase, or an LTM completion phase.

[0063] During the LTM preparation phase, and as shown by reference number 205, the UE 120 may be in an RRC connected state (sometimes referred to as RRC Connected) with a source cell. As shown by reference number 210, the UE 120 may transmit, and the network node 110 may receive, a measurement report (sometimes referred to as a. Measurement Report).0097-6316PCTwhich may be an L3 measurement report. The measurement report may indicate signal strength measurements (e.g., RSRP, RSSI, RSRQ, or CQI) or similar measurements associated with the source cell or one or more neighboring cells. In some examples, based at least in part on the measurement report or other information, the network node 110 may decide to use LTM, and thus, as shown by reference number 215, the network node 110 may initiate LTM candidate preparation. For example, in some cases, the network node 110 may decide to use LTM if a serving cell measurement quantity degrades (e.g., if RSRP, RSRQ, RSSI, signal to interference plus noise ratio (SINR), or a similar metric of the serving cell falls below a threshold).Additionally, or alternatively, the network node 110 may decide to use LTM if a neighboring cell measurement quantity becomes better than a corresponding measurement quantity of the serving cell (e.g., if RSRP, RSRQ, RSSI, SINR, or a similar metric of the neighboring cell is OFFSET better than that of serving cell).

[0064] As shown by reference number 220, the network node 110 may transmit, and the UE 120 may receive, an RRC reconfiguration message (sometimes referred to as an RRCReconfiguration message), which may include an LTM candidate configuration. More particularly, the RRC reconfiguration message may indicate a configuration of one or more LTM candidate target cells, which may be candidate cells to become a serving cell of the UE or cells for which the UE 120 may later be triggered to perform an LTM procedure. In some examples, the RRC reconfiguration message, which may include, or which may correspond to, LTM-Config, may indicate an LTM reference configuration, one or more LTM candidate cell configurations, an LTM CSI measurement resource configuration, or similar configuration information. As shown by reference number 225, the UE 120 may store the configuration of the one or more LTM candidate cell configurations and, in response, may transmit, to the network node 110, an RRC reconfiguration complete message (sometimes referred to as an RRCReconfigurationComplete message).

[0065] During the early synchronization phase, and as shown by reference number 230, the UE 120 may optionally perform downlink / uplink synchronization with the candidate cells associated with the one or more LTM candidate cell configurations. For example, the UE 120 may perform downlink synchronization and timing advance acquisition with the one or more candidate target cells prior to receiving an LTM switch command (which is described in more detail below in connection with reference number 225). In some aspects, performing the early synchronization with the one or more candidate cells may reduce latency associated with performing a random access channel (RACH) procedure later in the LTM procedure, which is described in more detail below in connection with reference number 255.

[0066] During the LTM execution phase, and as shown by reference number 235, the UE 120 may perform LI measurements on the configured LTM candidate target cells, and thus may0097-6316PCTtransmit, to the network node 110, lower-layer (e.g., LI) measurement reports. As shown by reference number 240, based at least in part on the lower-layer measurement reports, the network node 110 may decide to execute an LTM cell switch to a target cell. For example, the network node 110 may decide to execute an LTM cell switch based at least in part on one or more measurement quantities from the L 1 measurement report or an L3 measurement report. For example, the network node 110 may determine that the UE 120 is to perform an LTM cell switch to a specific candidate cell, of the configured candidate cells, if a serving cell measurement quantity, included in the L3 measurement report or the L 1 measurement report, degrades to a certain level (e.g., if RSRP, RSRQ, RSSI, SINR, or a similar metric of the serving cell falls below a threshold). Additionally, or alternatively, the network node 110 may determine that the UE 120 is to perform an LTM cell switch to a specific candidate cell, of the configured candidate cells, if a measurement quantity associated with the candidate cell becomes better than a corresponding measurement quantity of the serving cell (e.g., if RSRP, RSRQ, RSSI, SINR, or a similar metric of the neighboring cell is OFFSET better than that of serving cell). Accordingly, as shown by reference number 245, the network node 110 may transmit, and the UE 120 may receive, a MAC-CE or similar message triggering an LTM cell switch (the MAC-CE or similar message is sometimes referred to herein as a cell switch command). The cell switch command may include an indication of a candidate configuration index associated with the target cell. As shown by reference number 250, based at least in part on receiving the cell switch command, the UE 120 may switch to the configuration of the LTM candidate target cell (e.g., the UE 120 may detach from the source cell and apply the target cell configuration). Moreover, as shown by reference number 255, the UE 120 may perform a RACH procedure toward the target cell, such as when a timing advance associated with the target cell is not available (e.g., in examples in which the UE 120 did not perform the early synchronization as described above in connection with reference number 230).

[0067] During the LTM completion phase, and as shown by reference number 260, the UE 120 may indicate successful completion of the LTM cell switch toward the target cell. In this way, cell switch to a target cell may be performed using less overhead than for an L3 handover procedure or a cell switch to a target cell may be associated with reduced latency as compared to L3 handover procedure.

[0068] In some examples, if an LTM cell switch to a first cell is unsuccessful, the UE 120 may attempt to perform an LTM cell switch to a different candidate cell (e.g., a different cell included in the list of configured candidate cells), which is sometimes referred to as an LTM recovery procedure. For example, the UE 120 may attempt to perform an LTM recovery procedure toward a selected cell if an attempt LTM switch parameter is configured (e.g., if attemptLTM-Switch is configured or set to “TRUE”) and if the selected cell is part of a0097-6316PCTcandidate cell list (e.g., if the selected cell is one of the LTM candidate cells in an LTM-candidate IE within LTM-Config associated with a master cell group (MCG)). In such examples, the UE 120 may be confined to performing the LTM recovery procedure to intra-CU cells (e.g., configured candidate cells associated with a same CU as a current serving cell). This is because the UE 120 may not have an updated security parameter (e.g., a security key) needed to perform an inter-CU LTM cell switch. Put another way, a master key update field (sometimes referred to as MasterKeyUpdate) may be absent in RRC reconfiguration (sometimes referred to as RRCReconfiguratiori) within an LTM configuration information element (IE) due to only intra-CU LTM being supported.

[0069] More particularly, in L3 inter-CU handover procedures, a UE and the CUs associated with the handover may be capable of deriving various keys in order to provide secure communications associated with the handover procedures. For example, a UE and a source network node may initially communicate using a security key, sometimes referred to herein as KgNB. KgNB may be derived from one or more parameters, such as a next hop (NH) parameter or a next hop chaining count (NCC) parameter. At handover, the source network node may derive a new key, sometimes referred to herein as KNG-RAN*, which may be a function of an NH parameter, a target physical cell identifier (PCI), and a target absolute RF channel number (ARFCN) associated with a downlink band (e.g., ARFCN-DL). The source network node may provide the newly derived key to the target network node at handover (e.g., in a handover request), and the target network node may set the target key as the newly derived key (e.g., target KgNB = KNG-RAN*). Moreover, the target network node may include a security parameter (e.g., the NCC parameter) in the handover command message transmitted to the source network node, which in turn is forwarded to the UE. Upon receiving the handover command (e.g., an RRC configuration message), the UE may derive the new target key (e.g., target KgNs) in a same manner as the network node does, and may update the NH or NCC parameters, if needed. Upon successful handover completion, a core network entity (e.g., an access and mobility management function (AMF)) may provide fresh keying material (e.g., NH or NCC) for a subsequent handover.

[0070] In some examples, it may be beneficial to perform inter-CU LTM recovery, such as to enable an increased number of candidate cells for performing an LTM recovery procedure or to enable LTM recovery to stronger cells, thereby increasing network performance or reducing communication errors following the LTM cell switch. However, because there currently is no procedure for exchanging security parameters (e.g., an NCC parameter used to derive a security key, among other examples) during an LTM cell switch or an LTM recovery procedure, current LTM recovery procedures may be limited to intra-CU LTM cell switches. This may result in degraded communication channels, increased communication errors, increased incidence of0097-6316PCTLTM cell switch failures, and thus increased power, computing, and network resource consumption for correcting communication errors or reestablishing wireless communications following failed LTM cell switch procedures.

[0071] Some aspects and techniques described herein enable inter-CU LTM recovery procedures. More particularly, some aspects relate to enabling a UE to perform, in response to an unsuccessful LTM cell switch attempt, an inter-CU LTM cell switch from a cell associated with a first CU to a cell associated with a second CU different from the first CU. In some aspects, the inter-CU LTM cell switch may be performed based at least in part on the UE determining that one or more inter-CU LTM cell switch conditions are met. For example, in some aspects, the inter-CU LTM cell switch may be performed based at least in part on the UE having a valid security parameter for the cell associated with the second CU. Additionally, or alternatively, the inter-CU LTM cell switch may be performed based at least in part on the cell associated with the second CU being included in a configured set of LTM candidate cells. Additionally, or alternatively, the inter-CU LTM cell switch may be performed based at least in part on the UE being configured to perform inter-CU cell recovery (e.g., based at least in part on the UE receiving configuration information enabling inter-CU LTM cell recovery procedures). As a result, the described techniques can be used to enable secure inter-CU LTM recovery procedures, resulting in improved communication channels, decreased communication errors, decreased LTM cell switch failures, and thus decreased power, computing, and network resource consumption otherwise required for correcting communication errors or reestablishing wireless communications following failed LTM cell switch procedures.

[0072] As indicated above, Fig. 2 is provided as an example. Other examples may differ from what is described with respect to Fig. 2.

[0073] Fig. 3 is a diagram of an example 300 associated with inter-CU LTM recovery. As shown in Fig. 3, a first network node 110-1 (e.g., a first base station or a first CU), a second network node 110-2 (e.g., a second base station or a second CU), and a UE 120 may communicate with each other. The first network node 110-1, the second network node 110-2, and the UE 120 may be part of a wireless network (e.g., the wireless communication network 100). The first network node 110-1, the second network node 110-2, or the UE 120 may have established a wireless connection prior to operations shown in Fig. 3. For example, the first network node 110-1 and the UE 120 may have established a wireless communication prior to the operations shown in Fig. 3 (e.g., the first network node 110-1 may be associated with a serving cell or source cell of the UE 120). Additionally, or alternatively, the first network node 110-1 and the second network node 110-2 may have established a connection prior to the operations shown in Fig. 3 or may be otherwise capable of communicating with one another, such as via an inter-CU link (e.g., via an Xn interface, among other examples).0097-6316PCT

[0074] As shown by reference number 305, the first network node 110-1 (e.g., the source network node) may transmit, and the UE 120 may receive, configuration information. In some aspects, the UE 120 may receive the configuration information via one or more of system information signaling (e.g., a master information block (MIB) or a system information block (SIB), among other examples), RRC signaling, MAC signaling (e.g., one or more MAC-CEs), or physical layer signaling (e.g., DCI), among other examples.

[0075] In some aspects, the configuration information may indicate one or more candidate configurations or communication parameters. In some aspects, the one or more candidate configurations or communication parameters may be selected, activated, or deactivated by a subsequent indication. For example, the subsequent indication may select a candidate configuration or communication parameter from the one or more candidate configurations or communication parameters. In some aspects, the subsequent indication may include a dynamic indication, such as one or more MAC CEs or one or more DCI messages, among other examples.

[0076] In some aspects, the configuration information may include an indication of a selection of one or more configuration parameters (e.g., a selection of the one or more configuration parameters already known to the UE 120 or previously indicated by the network node or other network device), or explicit configuration information for the UE 120 to use to configure the UE 120, among other examples.

[0077] In some examples, the configuration information may not be expressly signaled to the UE 120. For example, in some aspects, the configuration information may at least partially be defined by a wireless communication standard, such as the 3GPP. In such examples, the network node 110 may not explicitly indicate such configuration information to the UE 120. For example, the UE 120 may optionally obtain at least a portion of the configuration information from a configuration stored by the UE 120 (e.g., an original equipment manufacturer (OEM) configuration). In some aspects, the configuration information may include a parameter or index that is indicative of information defined, or otherwise fixed, by a wireless communication standard, such as the 3GPP (e.g., rather than explicitly indicating the information).

[0078] In some aspects, the configuration information may indicate an LTM candidate configuration (e.g., the configuration information described above in connection with reference number 220). For example, the configuration information may indicate a configuration of one or more LTM candidate cells, which may be candidate cells to become a serving cell of the UE 120 or cells for which the UE 120 may later be triggered to perform an LTM procedure, among other examples.0097-6316PCT

[0079] Moreover, in some aspects, the configuration information may indicate enablement of inter-CU LTM recovery. Put another way, the configuration information may include an inter-CU LTM recovery indicator (e.g., an RRC parameter) that indicates whether the UE 120 is permitted to perform inter-CU LTM recovery, such as in a case in which an initial LTM cell switch attempt is unsuccessful. When the parameter is configured (e.g., when the inter-CU LTM recovery indicator is set to “TRUE”), the UE 120 may perform inter-CU LTM recovery when one or more other inter-CU LTM conditions are met (which are described in more detail below in connection with reference number 325).

[0080] In some aspects, the inter-CU LTM recovery indicator may be an inter-CU LTM recovery indicator associated with all candidate cells (e.g., all candidate cells configured by the LTM candidate configuration). Put another way, the inter-CU LTM recovery indicator may indicate whether the UE 120 may perform LTM recovery toward inter-CU candidate cells, and the inter-CU LTM recovery indicator may be applied to all candidate cells. In that regard, the inter-CU LTM recovery indicator may be similar to the attemptLTM-switch parameter described above in connection with intra-CU LTM recovery, and thus is sometimes referred to herein as attemptLTM-sw itch-new . In such aspects, if attemptLTM-sw itch-new is set to “TRUE,” the UE 120 may assume that LTM recovery to inter-CU candidate cells is allowed.

[0081] In some other aspects, the inter-CU LTM recovery indicator may be an inter-CU LTM recovery indicator that is specific to a certain cell. Put another way, the inter-CU LTM recovery indicator may be independently configured per candidate cell to indicate whether the UE 120 may perform LTM recovery toward a corresponding candidate cell. In such aspects, if the inter-CU LTM recovery indicator (e.g., attemptLTM-sw itch-new , or a similar indicator) is set to “TRUE,” the UE 120 may assume that inter-CU LTM recovery to that specific candidate cell is allowed. In some aspects, the inter-CU LTM recovery indicator may be applied to both LTM recovery to intra-CU and inter-CU candidate cells. Lor example, each candidate cell listed in the LTM candidate configuration, regardless of whether that cell is an intra-CU cell or an intra-CU cell, may include a corresponding LTM recovery indicator (e.g., attemptLTM-sw itch-new) that indicates whether the UE may perform LTM recovery toward that cell.

[0082] In some other aspects, the inter-CU LTM recovery indicator may be an LTM recovery indicator associated with both intra-CU LTM recovery and inter-CU LTM recovery. Lor example, the legacy attemptLTM-switch parameter described above in connection with intra-CU LTM recovery may be extended to control both intra-CU LTM recovery and inter-CU LTM recovery. In such aspects, if attemptLTM-switch is set to “TRUE,” the UE 120 may assume that LTM recovery to intra-CU candidate cells is allowed as well as that LTM recovery to inter-CU candidate cells is allowed.0097-6316PCT

[0083] The UE 120 may configure itself based at least in part on the configuration information. In some aspects, the UE 120 may be configured to perform one or more operations described herein based at least in part on the configuration information.

[0084] As described in more detail below in connection with reference number 325, in some aspects the UE 120 may determine whether an inter-CU LTM recovery procedure may be performed based at least in part on whether the UE 120 has previously received a security parameter update message that includes a valid security parameter for an inter-CU cell.Accordingly, as shown by reference number 310, the first network node 110-1 may transmit, and the UE 120 may receive, the security parameter update message. The security parameter update message may indicate one or more security parameters for one or more candidate cells, such as an NCC parameter associated with one or more candidate cells (e.g., an NCC that can be used to generate a security key for an inter-CU cell), a key set change indicator (sometimes referred to as keySetChangelndicator, which indicates whether the UE 120 is to derive a new security key (e.g., K8NB)), or a non-access stratum (NAS) container (sometimes referred to as nas-Container, which is a field is used to transfer UE-specific NAS layer information between the network node 110 and the UE 120), among other examples.

[0085] In some aspects, the UE 120 may receive the security parameter update message via one of an RRC IE or a MAC-CE. For example, in some aspects, the security parameter update message may be indicated via MasterKeyUpdate parameter associated with an RRC reconfiguration IE (e.g., RRCReconfig may include LTM-Config, which may include LTM-Candidate, which may include LTM-CandidateConfig (e.g., candidate RRC container), which may include MasterKeyUpdate indicating the NCC value). In some other aspects, the security parameter update message may be indicated using a dedicated or simplified RRC IE, such as an RRC IE that indicates a list of MasterKeyUpdates across candidate cells or a list of NCC values, among other examples. In some other aspects, the security parameter update message by indicated by a MAC-CE, such as a MAC-CE that indicates the list of MasterKeyUpdates across candidate cells or the list of NCC values, among other examples.

[0086] Additionally, or alternatively, in some aspects, a security parameter (e.g., an NCC value) indicated by the security parameter update message may be indicated as an absolute value, and, in some other aspects, the security parameter indicated by the security parameter update message may be indicated as a relative offset with respect to a previously signaled security parameter value. In aspects in which the security parameter indicated by the security parameter update message is indicated as a relative offset with respect to a previously signaled security parameter value (e.g., an old NCC, sometimes referred to herein as NCCoid), the UE 120 may calculate a new security parameter (e.g., a new NCC, sometimes referred to herein as NCCnew) using the expression mo (NCCoid+ offset, NCCmax), where NCCoid is the NCC value0097-6316PCTassociated with the serving cell which becomes invalid and NCCmax is a maximum NCC value (which, in some aspects, may be equal to 8). In some aspects, according to a predefined rule (e.g., a rule specified by a relevant wireless communication standard, such as a wireless communication standard promulgated by the 3GPP, among other examples), the offset may not be a multiple of NCCmax in order to avoid a same value between NCCnew and NCCoid.

[0087] As indicated by reference number 315, the first network node 110-1 may transmit, and the UE 120 may receive, an LTM cell switch command associated with an LTM cell switch from a first cell (e.g., a cell associated with the first network node 110-1). For example, the first network node 110-1 may transmit, to the UE 120, the cell switch command (e.g., MAC-CE) described above in connection with reference number 245, that instructs the UE 120 to switch from the first cell to a second cell (e.g., one of the candidate cells configured by the LTM candidate configuration described above in connection with reference number 305). In some aspects, the LTM cell switch command may be associated with an intra-CU LTM cell switch (e.g., the second cell may be associated with a same CU as a CU of the first cell). In some other aspects, the LTM cell switch command may be associated with an inter-CU LTM cell switch (e.g., the second cell may be associated with a different CU than a CU of the first cell).

[0088] As indicated by reference number 320, the UE 120 may attempt to perform the LTM cell switch associated with the LTM switch command (e.g., an LTM cell switch from the first cell to the second cell), but may detect that the LTM cell switch attempt is unsuccessful. For example, the UE 120 may detect the unsuccessful LTM cell switch attempt based at least in part an expiration of a timer associated with the LTM cell switch attempt (e.g., a T304 timer) prior to successful execution of the LTM cell switch, among other examples.

[0089] As indicated by reference number 325, based at least in part on detecting the unsuccessful LTM cell switch attempt from the first cell to the second cell, the UE 120 may identify whether one or more inter-CU LTM recovery conditions are met. For example, in aspects involving the inter-CU LTM recovery indication described above in connection with the configuration information of reference number 305, the UE 120 may identify whether the configuration information indicates enablement of the inter-CU LTM recovery to a third cell (e.g., a cell associated with a CU different from a CU associated with the first cell).Additionally, or alternatively, the UE 120 may identify whether the third cell is included in the set of configured LTM candidate cells indicated by the configuration described above in connection with reference number 305. Moreover, the UE may identify whether the UE 120 has a valid (e.g., up-to-date) security parameter for the third cell. For example, the UE 120 may identify whether it has a valid or up-to-date NCC parameter for the third cell (e.g., whether the UE 120 has a valid or up-to-date NCC in a MasterKeyUpdate field, among other examples).0097-6316PCT

[0090] In some aspects, the UE 120 may identify that the security parameter for the third cell is valid based at least in part on the unsuccessful LTM cell switch attempt from the first cell to the second cell being a first-in-time LTM cell switch attempt after reception of an initial LTM configuration. Put another way, in some aspects the UE 120 may assume that the security parameter for the selected cell (e.g., the selected CU) is valid or up-to-date when the unsuccessful LTM cell switch attempt described above in connection with reference number 320 was the first LTM cell switch attempt after receiving the initial LTM configuration provided by the serving cell (e.g., the first network node 110-1). This is because, in some aspects, the LTM configuration itself may have provided up-to-date security parameters for the set of LTM candidate cells. Put another way, all candidate cells’ security parameters from different CUs (compared to the serving CU) may be provided via an RRC reconfiguration message with an LTM configuration or a MAC-CE (e.g., a dedicated MAC-CE for signaling security parameters, or a cell switch command MAC-CE, among other examples). In such aspects, because the UE 120 has not yet performed a successful LTM cell switch (and thus has not yet successfully switched CUs, which may otherwise trigger security parameter update procedures), the UE 120 may assume that the previously provided security parameters are up-to-date.

[0091] In some other aspects, the UE 120 may identify that the security parameter for the third cell is valid based at least in part on the UE 120 performing, prior to the unsuccessful LTM cell switch attempt, an inter-CU LTM cell switch and receiving, after performing the inter-CU LTM cell switch, a security parameter update message (e.g., the security parameter update message described above in connection with reference number 310). Put another way, in some aspects the UE 120 may assume that the security parameter for the selected cell (e.g., the selected CU) is valid or up-to-date if, prior to the failed LTM switch described above in connection with reference number 320, at least one inter-CU LTM cell switch was successful and the UE 120 received the security parameter update message upon or at any time after the latest successful inter-CU LTM cell switch. In such aspects, the UE 120 may identify that the security parameter (e.g., the NCC parameter included in MasterKeyUpdate , among other examples) included in the latest security parameter update message is up-to-date.

[0092] As indicated by reference number 330, based at least in part on identifying that the one or more inter-CU LTM recovery conditions are met, the UE 120 may perform an inter-CU LTM recovery procedure (e.g., an inter-CU LTM cell switch from the first cell to the third cell). More particularly, upon detecting LTM failure, and based at least in part on inter-CU LTM recovery being enabled for the third cell, the third cell being included in the set of configured LTM candidate cells, and the UE 120 having a valid security parameter for a third cell, the UE0097-6316PCT120 may perform an inter-CU LTM cell switch from the first cell to the third cell (e.g., a cell associated with the second network node 110-2).

[0093] As further indicated by reference number 330, based at least in part on successfully performing the inter-CU LTM recovery procedure, the UE 120 may manage one or more security parameters. For example, the UE 120 may release one or more security parameters for one or more inter-CU LTM candidate cells based at least in part on successfully performing the inter-CU LTM cell switch from the first cell to the third cell . Put another way, upon each successful inter-CU LTM cell switch, the UE 120 may release the existing security parameter values for one or more inter-CU LTM candidate cells to avoid the misuse of the now invalid security parameter value for a next LTM recovery to an inter-CU candidate cell, among other examples. Additionally, or alternatively, the UE 120 may store the security parameter for the third cell in an access stratum (AS) context (e.g., the set of information and parameters that are used to manage the radio connection between the UE 120 and the second network node 110-2) based at least in part on successfully performing the inter-CU LTM cell switch from the first cell to the third cell. That is, the UE 120 may store the security parameter in the UE 120’s AS context to be fetched later if the UE 120 comes back to that candidate cell. In such aspects, a timer may be associated with a duration in which the security parameter is to be stored in the AS context, such that, after timer expiry, the UE 120 deletes the security parameter from the AS context.

[0094] As indicated by reference number 335, based at least in part on successful completion of the inter-CU LTM cell switch from the first cell to the third cell, the second network node 110-2 may communicate with one or more other network nodes (e.g., the first network node 110-1 and any additional network nodes associated with inter-CU LTM candidate cells (not shown in Fig. 3)) to update security parameters associated with the one or more network nodes. That is, upon the successful inter-CU LTM cell switch, any security parameters associated with various inter-CU candidate cells may become out-of-date. Thus, the new serving cell (e.g., the third cell, associated with the second network node 110-2, in this example) may trigger a security parameter update process among other candidate cells to update the security parameters so that the security parameters will be up-to-date for any subsequent inter-CU LTM cell switches. In some aspects, the security parameter operations shown in connection with reference number 335 may be associated with an Xn LTM configuration update procedure. Moreover, as indicated by reference number 340, the second network node 110-2 may transmit, and the UE 120 may receive, a security parameter update message indicating one or more valid security parameters for one or more cells different from the third cell (which may be substantially similar to the security parameter update message described above in connection with reference number 310). Put another way, upon a successful inter-CU LTM cell switch, the0097-6316PCTnew serving cell may transmit, to the UE 120, updated security parameters, such as by transmitting the updated security parameters via an RRC IE or MAC-CE (as described above in connection with reference number 310), among other examples.

[0095] Based at least in part on the UE 120 or the network nodes 110-1, 110-2 performing the inter-CU LTM recovery procedure described above, the UE 120 or the network nodes 110-1, 110-2 may conserve computing, power, network, or communication resources that may have otherwise been consumed by LTM recovery procedures that are confined to intra-CU LTM cell switches. For example, based at least in part on the UE 120 or the network nodes 110-1, 110-2 performing the inter-CU LTM recovery procedure described above, the UE 120 may have an expanded list of candidate cells to select from during an LTM recovery procedure, increasing a number of successful LTM recovery procedures or resulting in improved communication channels following an LTM recovery procedure, which may result in reduced communication errors and thus conservation of computing, power, network, or communication resources that may have otherwise been consumed to detect or correct communication errors.

[0096] As indicated above, Fig. 3 is provided as an example. Other examples may differ from what is described with respect to Fig. 3.

[0097] Fig. 4 is a diagram illustrating an example process 400 performed, for example, at a UE or an apparatus of a UE. Example process 400 is an example where the apparatus or the UE (e.g., UE 120) performs operations associated with inter-CU LTM recovery.

[0098] As shown in Fig. 4, in some aspects, process 400 may include receiving an LTM cell switch command associated with an LTM cell switch from a first cell (block 410). For example, the UE 120 (e.g., using reception component 602 or communication manager 606, depicted in Fig. 6) may receive an LTM cell switch command associated with an LTM cell switch from a first cell, such as the LTM switch command described above in connection with reference number 315.

[0099] As further shown in Fig. 4, in some aspects, process 400 may include performing, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, and based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, an inter-CU LTM cell switch from the first cell to the third cell (block 420). For example, the UE 120 (e.g., using communication manager 606, depicted in Fig. 6) may perform, based at least in part on an unsuccessful LTM cell switch attempt from the first cell (e.g., a cell associated with the first network node 110-1) to a second cell (e.g., such as the unsuccessful LTM cell switch attempt described above in connection with reference number 320), and based at least in part on the UE having a valid security parameter (e.g., a valid NCC parameter) for a third cell (e.g., a cell associated with the second network node 110-2) that is associated with a second CU different0097-6316PCTfrom a first CU associated with the first cell, an inter-CU LTM cell switch from the first cell to the third cell (e.g., the inter-CU LTM cell switch described above in connection with reference number 330).

[0100] Process 400 may include additional aspects, such as any single aspect or any combination of aspects described below or in connection with one or more other processes described elsewhere herein.

[0101] In a first aspect, process 400 includes receiving configuration information indicating a set of LTM candidate cells, wherein performing the inter-CU LTM cell switch from the first cell to the third cell is further based at least in part on the third cell being included in the set of configured LTM candidate cells. For example, the UE 120 may receive the LTM candidate configuration described above in connection with reference number 305 or may perform the inter-CU LTM cell switch from the first cell to the third cell based at least in part on identifying that the third cell is included in the set of configured LTM candidate cells indicated by the LTM candidate configuration.

[0102] In a second aspect, alone or in combination with the first aspect, the security parameter for the third cell is associated with at least one of a master key update parameter or a next hop chaining count parameter. For example, as described above in connection with reference numbers 310 and 325, the security parameter may be an NCC value indicated by a MasterKeyUpdate field, among other examples.

[0103] In a third aspect, alone or in combination with one or more of the first and second aspects, process 400 includes identifying that the security parameter for the third cell is valid based at least in part on the unsuccessful LTM cell switch attempt from the first cell to the second cell being a first-in-time LTM cell switch attempt after reception of an initial LTM configuration. For example, as described above in connection with reference number 325, in some aspects the UE 120 may assume that the security parameter for the selected cell (e.g., the selected CU) is valid or up-to-date when the unsuccessful LTM cell switch attempt described above in connection with reference number 320 was the first LTM cell switch attempt after receiving the initial LTM configuration provided by the serving cell.

[0104] In a fourth aspect, alone or in combination with one or more of the first through third aspects, process 400 includes performing, prior to the unsuccessful LTM cell switch attempt, another inter-CU LTM cell switch, receiving, after performing the other inter-CU LTM cell switch, a security parameter update message, and identifying that the security parameter for the third cell is valid based at least in part on the reception of the security parameter update message. For example, as described above in connection with reference number 325, the UE 120 may assume that the security parameter for the selected cell (e.g., the selected CU) is valid or up-to-date if, prior to the failed LTM switch described above in connection with reference0097-6316PCTnumber 320, at least one inter-CU LTM cell switch was successful and the UE 120 received the security parameter update message upon or at any time after the latest successful inter-CU LTM cell switch.

[0105] In a fifth aspect, alone or in combination with one or more of the first through fourth aspects, receiving the security parameter update message includes receiving the security parameter update message via one of an RRC IE, or a MAC-CE. For example, as described above in connection with reference number 310, the security parameter update message may be indicated via a MasterKeyUpdate parameter associated with an RRC reconfiguration IE, via a dedicated or simplified RRC IE (e.g., an RRC IE that indicates a list of MaslerKeyUpdales across candidate cells or a list of NCC values), or via a MAC-CE (e.g., a MAC-CE that indicates the list of MaslerKeyUpdales across candidate cells or the list of NCC values).

[0106] In a sixth aspect, alone or in combination with one or more of the first through fifth aspects, the security parameter update message indicates the security parameter for the third cell as one of an absolute value, or a relative offset with respect to a previously signaled security parameter value. For example, as described above in connection with reference number 310, the security parameter (e.g., an NCC value) may be indicated as an absolute value or as a relative offset with respect to a previously signaled security parameter value (e.g., in which case the UE 120 may calculate bJCCnew using the expression mod(NCCoid-t offset, bJCC max ), among other examples).

[0107] In a seventh aspect, alone or in combination with one or more of the first through sixth aspects, process 400 includes receiving configuration information indicating enablement of inter-CU LTM recovery, wherein performing the inter-CU LTM cell switch from the first cell to the third cell is further based at least in part on the configuration information indicating enablement of the inter-CU LTM recovery. For example, as described above in connection with reference number 305, the UE 120 may receive configuration information that includes an inter-CU LTM recovery indicator or that otherwise enables inter-CU LTM recovery.

[0108] In an eighth aspect, alone or in combination with one or more of the first through seventh aspects, the configuration information indicates the enablement of the inter-CU LTM recovery via one of an inter-CU LTM recovery indicator associated with all candidate cells, an inter-CU LTM recovery indicator that is specific to the third cell, or an LTM recovery indicator associated with both intra-CU LTM recovery and inter-CU LTM recovery. For example, the configuration information may indicate the enablement of the inter-CU LTM recovery via one of the attemptLTM-switch or attemptLTM-switch-new parameters described above in connection with reference number 305, among other examples.

[0109] In a ninth aspect, alone or in combination with one or more of the first through eighth aspects, process 400 includes one of releasing one or more security parameters for one or more0097-6316PCTinter-CU LTM candidate cells based at least in part on successfully performing the inter-CU LTM cell switch from the first cell to the third cell, or storing the security parameter for the third cell in an access stratum context based at least in part on successfully performing the inter-CU LTM cell switch from the first cell to the third cell. For example, as described above in connection with reference number 330, upon successful completion of the inter-CU LTM switch, the UE 120 may release one or more security parameters associated with the first network node 110-1 and any other network nodes associated with the LTM candidate cells, or the UE 120 may store a security parameter associated with the second network node 110-2 in an AS context associated with the second network node 110-2.

[0110] In a tenth aspect, alone or in combination with one or more of the first through ninth aspects, process 400 includes receiving, via the third cell, a security parameter update message based at least in part on successfully performing the inter-CU LTM cell switch from the first cell to the third cell. For example, upon successful completion of the inter-CU LTM cell switch, the UE 120 may receive, from the second network node 110-2, the security parameter update message described above in connection with reference number 340.[OHl] In an eleventh aspect, alone or in combination with one or more of the first through tenth aspects, the security parameter update message indicates at least one or more valid security parameters for one or more cells different from the third cell. For example, as described above in connection with reference number 340, the security parameter update message may include valid security parameters for the first network node 110-1 and any other network nodes associated with the configured LTM candidate cells.

[0112] Although Fig. 4 shows example blocks of process 400, in some aspects, process 400 may include additional blocks, fewer blocks, different blocks, or differently arranged blocks than those depicted in Fig. 4. Additionally, or alternatively, two or more of the blocks of process 400 may be performed in parallel.

[0113] Fig. 5 is a diagram illustrating an example process 500 performed, for example, at a network node or an apparatus of a network node. Example process 500 is an example where the apparatus or the network node (e.g., network node 110) performs operations associated with inter-CU LTM recovery.

[0114] As shown in Fig. 5, in some aspects, process 500 may include transmitting, to a UE, configuration information indicating a set of LTM candidate cells (block 510). For example, as described above in connection with reference number 305, the first network node 110-1 may transmit (e.g., using transmission component 704 or communication manager 706, depicted in Fig. 7), to the UE 120, configuration information indicating a set of LTM candidate cells.

[0115] As further shown in Fig. 5, in some aspects, process 500 may include transmitting, to the UE, an LTM cell switch command associated with an LTM cell switch from a first cell,0097-6316PCTwherein, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, and based at least in part on the third cell being included in the set of configured LTM candidate cells, transmission of the LTM cell switch results in an inter-CU LTM cell switch from the first cell to the third cell (block 520). Lor example, the first network node 110-1 may transmit (e.g., using transmission component 704 or communication manager 706, depicted in Pig. 7), to the UE 120, the LTM cell switch command described above in connection with reference number 315, which may result in the UE 120 performing, based at least in part on an unsuccessful LTM cell switch attempt from the first cell (e.g., a cell associated with the first network node 110-1) to a second cell (e.g., such as the unsuccessful LTM cell switch attempt described above in connection with reference number 320), and based at least in part on the UE 120 having a valid security parameter (e.g., an NCC parameter) for a third cell (e.g., a cell associated with the second network node 110-2) that is associated with a second CU different from a first CU associated with the first cell, an inter-CU LTM cell switch from the first cell to the third cell (e.g., the inter-CU LTM cell switch described above in connection with reference number 330).

[0116] Process 500 may include additional aspects, such as any single aspect or any combination of aspects described below or in connection with one or more other processes described elsewhere herein.

[0117] In a first aspect, the configuration information indicates a set of LTM candidate cells, and transmission of the LTM cell switch results in an inter-CU LTM cell switch from the first cell to the third cell further based at least in part on the third cell being included in the set of configured LTM candidate cells. For example, the first network node 110-1 may transmit, to the UE 120, the LTM candidate configuration described above in connection with reference number 305, which may result in the UE 120 performing the inter-CU LTM cell switch from the first cell to the third cell based at least in part on the UE 120 identifying that the third cell is included in the set of configured LTM candidate cells indicated by the LTM candidate configuration.

[0118] In a second aspect, alone or in combination with the first aspect, the security parameter for the third cell is associated with at least one of a master key update parameter or a next hop chaining count parameter. For example, as described above in connection with reference numbers 310 and 325, the security parameter may be an NCC value indicated by a MasterKeyUpdate field, among other examples.

[0119] In a third aspect, alone or in combination with one or more of the first and second aspects, the security parameter for the third cell is valid based at least in part on the unsuccessful LTM cell switch attempt from the first cell to the second cell being a first-in-time LTM cell0097-6316PCTswitch attempt after transmission of an initial LTM configuration. For example, as described above in connection with reference number 325, in some aspects the UE 120 may assume that the security parameter for the selected cell (e.g., the selected CU) is valid or up-to-date when the unsuccessful LTM cell switch attempt described above in connection with reference number 320 was the first LTM cell switch attempt after receiving the initial LTM configuration provided by the serving cell.

[0120] In a fourth aspect, alone or in combination with one or more of the first through third aspects, process 500 includes transmitting, to the UE after performance of another inter-CU LTM cell switch, a security parameter update message, wherein the security parameter for the third cell is valid based at least in part on the transmission of the security parameter update message. For example, as described above in connection with reference number 325, the UE 120 may assume that the security parameter for the selected cell (e.g., the selected CU) is valid or up-to-date if, prior to the failed LTM switch described above in connection with reference number 320, at least one inter-CU LTM cell switch was successful and the UE 120 received the security parameter update message upon or at any time after the latest successful inter-CU LTM cell switch.

[0121] In a fifth aspect, alone or in combination with one or more of the first through fourth aspects, transmitting the security parameter update message includes transmitting the security parameter update message via one of an RRC IE, or a MAC-CE. For example, as described above in connection with reference number 310, the security parameter update message may be indicated via a MasterKeyUpdate parameter associated with an RRC reconfiguration IE, via a dedicated or simplified RRC IE (e.g., an RRC IE that indicates a list of MaslerKeyUpdales across candidate cells or a list of NCC values), or via a MAC-CE (e.g., a MAC-CE that indicates the list of MaslerKeyUpdales across candidate cells or the list of NCC values).

[0122] In a sixth aspect, alone or in combination with one or more of the first through fifth aspects, the security parameter update message indicates the security parameter for the third cell as one of an absolute value, or a relative offset with respect to a previously signaled security parameter value. For example, as described above in connection with reference number 310, the security parameter (e.g., an NCC value) may be indicated as an absolute value or as a relative offset with respect to a previously signaled security parameter value (e.g., in which case the UE 120 may calculate bJCCnew using the expression mod(NCCoid-t offset, bJCC max ), among other examples).

[0123] In a seventh aspect, alone or in combination with one or more of the first through sixth aspects, the configuration information indicates enablement of the inter-CU LTM recovery via one of an inter-CU LTM recovery indicator associated with all candidate cells, an inter-CU LTM recovery indicator that is specific to the third cell, or an LTM recovery indicator0097-6316PCTassociated with both intra-CU LTM recovery and inter-CU LTM recovery. For example, the configuration information may indicate the enablement of the inter-CU LTM recovery via one of the attemptLTM-switch or attemptLTM-switch-new parameters described above in connection with reference number 305, among other examples.

[0124] In an eighth aspect, alone or in combination with one or more of the first through seventh aspects, process 500 includes communicating with another network node that is associated with the third cell to update a security parameter associated with the first cell based at least in part on successful completion of the inter-CU LTM cell switch from the first cell to the third cell. For example, as described above in connection with reference number 335, following successful completion of the inter-CU LTM cell switch, the first network node 110-1 may communicate with the second network node 110-2 to update a security parameter associated with the first network node 110-1.

[0125] Although Fig. 5 shows example blocks of process 500, in some aspects, process 500 may include additional blocks, fewer blocks, different blocks, or differently arranged blocks than those depicted in Fig. 5. Additionally, or alternatively, two or more of the blocks of process 500 may be performed in parallel.

[0126] Fig. 6 is a diagram of an example apparatus 600 for wireless communication. The apparatus 600 may be a UE, or a UE may include the apparatus 600. In some aspects, the apparatus 600 includes a reception component 602, a transmission component 604, or a communication manager 606, which may be in communication with one another (for example, via one or more buses or one or more other components). In some aspects, the communication manager 606 is the communication manager 150 described in connection with Fig. 1. As shown, the apparatus 600 may communicate with another apparatus 608, such as a UE or a network node (such as a CU, a DU, an RU, or a base station), using the reception component 602 and the transmission component 604. The communication manager 606 may be included in, or implemented via, a processing system (for example, the processing system 140 described in connection with Fig. 1) of the UE.

[0127] In some aspects, the apparatus 600 may be configured to perform one or more operations described herein in connection with Fig. 3. Additionally, or alternatively, the apparatus 600 may be configured to perform one or more processes described herein, such as process 400 of Fig. 4. In some aspects, the apparatus 600 or one or more components shown in Fig. 6 may include one or more components of the UE described in connection with Fig. 1. Additionally, or alternatively, one or more components shown in Fig. 6 may be implemented within one or more components described in connection with Fig. 1. Additionally, or alternatively, one or more components of the set of components may be implemented at least in part as software stored in one or more memories. For example, a component (or a portion of a0097-6316PCTcomponent) may be implemented as instructions or code stored in a non -transitory computer-readable medium and executable by one or more controllers or one or more processors to perform the functions or operations of the component.

[0128] The reception component 602 may receive communications, such as reference signals, control information, data communications, or a combination thereof, from the apparatus 608. The reception component 602 may provide received communications to one or more other components of the apparatus 600. In some aspects, the reception component 602 may perform signal processing on the received communications, and may provide the processed signals to the one or more other components of the apparatus 600. In some aspects, the reception component 602 may include one or more components of the UE described above in connection with Fig. 1, such as a radio, one or more RF chains, one or more transceivers, or one or more modems, each of which may in turn be coupled with one or more antennas of the UE.

[0129] The transmission component 604 may transmit communications, such as reference signals, control information, data communications, or a combination thereof, to the apparatus 608. In some aspects, one or more other components of the apparatus 600 may generate communications and may provide the generated communications to the transmission component 604 for transmission to the apparatus 608. In some aspects, the transmission component 604 may perform signal processing on the generated communications, and may transmit the processed signals to the apparatus 608. In some aspects, the transmission component 604 may include one or more components of the UE described above in connection with Fig. 1, such as a radio, one or more RF chains, one or more transceivers, or one or more modems, each of which may in turn be coupled with one or more antennas of the UE described in connection with Fig.1. In some aspects, the transmission component 604 may be co-located with the reception component 602.

[0130] The communication manager 606 may support operations of the reception component 602 or the transmission component 604. For example, the communication manager 606 may receive information associated with configuring reception of communications by the reception component 602 or transmission of communications by the transmission component 604.Additionally, or alternatively, the communication manager 606 may generate or provide control information to the reception component 602 or the transmission component 604 to control reception or transmission of communications.

[0131] The reception component 602 may receive an LTM cell switch command associated with an LTM cell switch from a first cell. The communication manager 606 may perform, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, and based at least in part on the UE having a valid security parameter for a third cell that is0097-6316PCTassociated with a second CU different from a first CU associated with the first cell, an inter-CU LTM cell switch from the first cell to the third cell.

[0132] The reception component 602 may receive configuration information indicating a set of LTM candidate cells, wherein performing the inter-CU LTM cell switch from the first cell to the third cell is further based at least in part on the third cell being included in the set of configured LTM candidate cells.

[0133] The communication manager 606 may identify that the security parameter for the third cell is valid based at least in part on the unsuccessful LTM cell switch attempt from the first cell to the second cell being a first-in-time LTM cell switch attempt after reception of an initial LTM configuration.

[0134] The communication manager 606 may perform, prior to the unsuccessful LTM cell switch attempt, another inter-CU LTM cell switch.

[0135] The reception component 602 may receive, after performing the other inter-CU LTM cell switch, a security parameter update message.

[0136] The communication manager 606 may identify that the security parameter for the third cell is valid based at least in part on the reception of the security parameter update message.

[0137] The reception component 602 may receive configuration information indicating enablement of inter-CU LTM recovery, wherein performing the inter-CU LTM cell switch from the first cell to the third cell is further based at least in part on the configuration information indicating enablement of the inter-CU LTM recovery.

[0138] The reception component 602 may receive, via the third cell, a security parameter update message based at least in part on successfully performing the inter-CU LTM cell switch from the first cell to the third cell.

[0139] The number and arrangement of components shown in Fig. 6 are provided as an example. In practice, there may be additional components, fewer components, different components, or differently arranged components than those shown in Fig. 6. Furthermore, two or more components shown in Fig. 6 may be implemented within a single component, or a single component shown in Fig. 6 may be implemented as multiple, distributed components. Additionally, or alternatively, a set of (one or more) components shown in Fig. 6 may perform one or more functions described as being performed by another set of components shown in Fig.6.

[0140] Fig. 7 is a diagram of an example apparatus 700 for wireless communication. The apparatus 700 may be a network node, or a network node may include the apparatus 700. In some aspects, the apparatus 700 includes a reception component 702, a transmission component 704, or a communication manager 706, which may be in communication with one another (for0097-6316PCTexample, via one or more buses or one or more other components). In some aspects, the communication manager 706 is the communication manager 155 described in connection with Fig. 1. As shown, the apparatus 700 may communicate with another apparatus 708, such as a UE or a network node (such as a CU, a DU, an RU, or a base station), using the reception component 702 and the transmission component 704. The communication manager 706 may be included in, or implemented via, a processing system (for example, the processing system 145 described in connection with Fig. 1) of the network node.

[0141] In some aspects, the apparatus 700 may be configured to perform one or more operations described herein in connection with Fig. 3. Additionally, or alternatively, the apparatus 700 may be configured to perform one or more processes described herein, such as process 500 of Fig. 5. In some aspects, the apparatus 700 or one or more components shown in Fig. 7 may include one or more components of the network node described in connection with Fig. 1. Additionally, or alternatively, one or more components shown in Fig. 7 may be implemented within one or more components described in connection with Fig. 1. Additionally, or alternatively, one or more components of the set of components may be implemented at least in part as software stored in one or more memories. For example, a component (or a portion of a component) may be implemented as instructions or code stored in a non -transitory computer-readable medium and executable by one or more controllers or one or more processors to perform the functions or operations of the component.

[0142] The reception component 702 may receive communications, such as reference signals, control information, data communications, or a combination thereof, from the apparatus 708. The reception component 702 may provide received communications to one or more other components of the apparatus 700. In some aspects, the reception component 702 may perform signal processing on the received communications, and may provide the processed signals to the one or more other components of the apparatus 700. In some aspects, the reception component 702 may include one or more components of the network node described above in connection with Fig. 1, such as a radio, one or more RF chains, one or more transceivers, or one or more modems, each of which may in turn be coupled with one or more antennas of the network node. In some aspects, the reception component 702 or the transmission component 704 may include or may be included in a network interface. The network interface may be configured to obtain or output signals for the apparatus 700 via one or more communications links, such as a backhaul link, a midhaul link, or a fronthaul link.

[0143] The transmission component 704 may transmit communications, such as reference signals, control information, data communications, or a combination thereof, to the apparatus 708. In some aspects, one or more other components of the apparatus 700 may generate communications and may provide the generated communications to the transmission component0097-6316PCT704 for transmission to the apparatus 708. In some aspects, the transmission component 704 may perform signal processing on the generated communications, and may transmit the processed signals to the apparatus 708. In some aspects, the transmission component 704 may include one or more components of the network node described above in connection with Fig. 1, such as a radio, one or more RF chains, one or more transceivers, or one or more modems, each of which may in turn be coupled with one or more antennas of the network node described in connection with Fig. 1. In some aspects, the transmission component 704 may be co-located with the reception component 702.

[0144] The communication manager 706 may support operations of the reception component 702 or the transmission component 704. For example, the communication manager 706 may receive information associated with configuring reception of communications by the reception component 702 or transmission of communications by the transmission component 704.Additionally, or alternatively, the communication manager 706 may generate or provide control information to the reception component 702 or the transmission component 704 to control reception or transmission of communications.

[0145] The transmission component 704 may transmit, to a UE, configuration information indicating a set of LTM candidate cells. The transmission component 704 may transmit, to the UE, an LTM cell switch command associated with an LTM cell switch from a first cell wherein, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, and based at least in part on the third cell being included in the set of configured LTM candidate cells, transmission of the LTM cell switch results in an inter-CU LTM cell switch from the first cell to the third cell.

[0146] The transmission component 704 may transmit, to the UE after performance of another inter-CU LTM cell switch, a security parameter update message, wherein the security parameter for the third cell is valid based at least in part on the transmission of the security parameter update message.

[0147] The communication manager 706 may communicate with another network node that is associated with the third cell to update a security parameter associated with the first cell based at least in part on successful completion of the inter-CU LTM cell switch from the first cell to the third cell.

[0148] The number and arrangement of components shown in Fig. 7 are provided as an example. In practice, there may be additional components, fewer components, different components, or differently arranged components than those shown in Fig. 7. Furthermore, two or more components shown in Fig. 7 may be implemented within a single component, or a0097-6316PCTsingle component shown in Fig. 7 may be implemented as multiple, distributed components. Additionally, or alternatively, a set of (one or more) components shown in Fig. 7 may perform one or more functions described as being performed by another set of components shown in Fig.7.

[0149] The following provides an overview of some Aspects of the present disclosure:

[0150] Aspect 1 : A method of wireless communication performed by a user equipment (UE), comprising: receiving a lower layer triggered mobility (LTM) cell switch command associated with an LTM cell switch from a first cell; and performing, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, and based at least in part on the UE having a valid security parameter for a third cell that is associated with a second central unit (CU) different from a first CU associated with the first cell, an inter-CU LTM cell switch from the first cell to the third cell.

[0151] Aspect 2: The method of Aspect 1, further comprising receiving configuration information indicating a set of LTM candidate cells, wherein performing the inter-CU LTM cell switch from the first cell to the third cell is further based at least in part on the third cell being included in the set of configured LTM candidate cells.

[0152] Aspect 3: The method of any of Aspects 1-2, wherein the security parameter for the third cell is associated with at least one of a master key update parameter or a next hop chaining count parameter.

[0153] Aspect 4: The method of any of Aspects 1-3, further comprising identifying that the security parameter for the third cell is valid based at least in part on the unsuccessful LTM cell switch attempt from the first cell to the second cell being a first -in-time LTM cell switch attempt after reception of an initial LTM configuration.

[0154] Aspect 5: The method of any of Aspects 1-4, further comprising: performing, prior to the unsuccessful LTM cell switch attempt, another inter-CU LTM cell switch; receiving, after performing the other inter-CU LTM cell switch, a security parameter update message; and identifying that the security parameter for the third cell is valid based at least in part on the reception of the security parameter update message.

[0155] Aspect 6: The method of Aspect 5, wherein receiving the security parameter update message includes receiving the security parameter update message via one of: a radio resource control (RRC) information element, or a medium access control (MAC) control element (MAC-CE).

[0156] Aspect 7: The method of Aspect 5, wherein the security parameter update message indicates the security parameter for the third cell as one of: an absolute value, or a relative offset with respect to a previously signaled security parameter value.0097-6316PCT

[0157] Aspect 8: The method of any of Aspects 1-7, further comprising receiving configuration information indicating enablement of inter-CU LTM recovery, wherein performing the inter-CU LTM cell switch from the first cell to the third cell is further based at least in part on the configuration information indicating enablement of the inter-CU LTM recovery.

[0158] Aspect 9: The method of Aspect 8, wherein the configuration information indicates the enablement of the inter-CU LTM recovery via one of: an inter-CU LTM recovery indicator associated with all candidate cells, an inter-CU LTM recovery indicator that is specific to the third cell, or an LTM recovery indicator associated with both intra-CU LTM recovery and inter-CU LTM recovery.

[0159] Aspect 10: The method of any of Aspects 1-9, further comprising one of: releasing one or more security parameters for one or more inter-CU LTM candidate cells based at least in part on successfully performing the inter-CU LTM cell switch from the first cell to the third cell, or storing the security parameter for the third cell in an access stratum context based at least in part on successfully performing the inter-CU LTM cell switch from the first cell to the third cell.

[0160] Aspect 11: The method of any of Aspects 1-10, further comprising receiving, via the third cell, a security parameter update message based at least in part on successfully performing the inter-CU LTM cell switch from the first cell to the third cell.

[0161] Aspect 12: The method of Aspect 11, wherein the security parameter update message indicates at least one or more valid security parameters for one or more cells different from the third cell.

[0162] Aspect 13: A method of wireless communication performed by a network node, comprising: transmitting, to a user equipment (UE), configuration information enabling intercentral-unit (inter-CU) lower layer triggered mobility (LTM) recovery; and transmitting, to the UE, an LTM cell switch command associated with an LTM cell switch from a first cell, wherein, based at least in part on the configuration information enabling inter-CU LTM recovery, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, and based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, transmission of the LTM cell switch results in an inter-CU LTM cell switch from the first cell to the third cell.

[0163] Aspect 14: The method of Aspect 13, wherein the configuration information indicates a set of LTM candidate cells, and wherein transmission of the LTM cell switch results in an inter-CU LTM cell switch from the first cell to the third cell further based at least in part on the third cell being included in the set of configured LTM candidate cells.0097-6316PCT

[0164] Aspect 15: The method of any of Aspects 13-14, wherein the security parameter for the third cell is associated with at least one of a master key update parameter or a next hop chaining count parameter.

[0165] Aspect 16: The method of any of Aspects 13-15, wherein the security parameter for the third cell is valid based at least in part on the unsuccessful LTM cell switch attempt from the first cell to the second cell being a first-in-time LTM cell switch attempt after transmission of an initial LTM configuration.

[0166] Aspect 17: The method of any of Aspects 13-16, further comprising transmitting, to the UE after performance of another inter-CU LTM cell switch, a security parameter update message, wherein the security parameter for the third cell is valid based at least in part on the transmission of the security parameter update message.

[0167] Aspect 18: The method of Aspect 17, wherein transmitting the security parameter update message includes transmitting the security parameter update message via one of: a radio resource control (RRC) information element, or a medium access control (MAC) control element (MAC-CE).

[0168] Aspect 19: The method of Aspect 17, wherein the security parameter update message indicates the security parameter for the third cell as one of: an absolute value, or a relative offset with respect to a previously signaled security parameter value.

[0169] Aspect 20: The method of any of Aspects 13-19, wherein the configuration information indicates enablement of the inter-CU LTM recovery via one of: an inter-CU LTM recovery indicator associated with all candidate cells, an inter-CU LTM recovery indicator that is specific to the third cell, or an LTM recovery indicator associated with both intra-CU LTM recovery and inter-CU LTM recovery.

[0170] Aspect 21: The method of any of Aspects 13-20, further comprising communicating with another network node that is associated with the third cell to update a security parameter associated with the first cell based at least in part on successful completion of the inter-CU LTM cell switch from the first cell to the third cell.

[0171] Aspect 22: A method of wireless communication performed by a network node, comprising: transmitting, to a user equipment (UE), configuration information indicating a set of lower layer triggered mobility (LTM) candidate cells; and transmitting, to the UE, an LTM cell switch command associated with an LTM cell switch from a first cell, wherein, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, based at least in part on the UE having a valid security parameter for a third cell that is associated with a second CU different from a first CU associated with the first cell, and based at least in part on the third cell being included in the set of configured LTM candidate cells,0097-6316PCTtransmission of the LTM cell switch results in an inter-CU LTM cell switch from the first cell to the third cell.

[0172] Aspect 23 : The method of Aspect 22, wherein the security parameter for the third cell is associated with at least one of a master key update parameter or a next hop chaining count parameter.

[0173] Aspect 24: The method of any of Aspects 22-23, wherein the security parameter for the third cell is valid based at least in part on the unsuccessful LTM cell switch attempt from the first cell to the second cell being a first-in-time LTM cell switch attempt after transmission of an initial LTM configuration.

[0174] Aspect 25: The method of any of Aspects 22-24, further comprising transmitting, to the UE after performance of another inter-CU LTM cell switch, a security parameter update message, wherein the security parameter for the third cell is valid based at least in part on the transmission of the security parameter update message.

[0175] Aspect 26: The method of Aspect 25, wherein transmitting the security parameter update message includes transmitting the security parameter update message via one of: a radio resource control (RRC) information element, or a medium access control (MAC) control element (MAC-CE).

[0176] Aspect 27: The method of any of Aspects 25-26, wherein the security parameter update message indicates the security parameter for the third cell as one of: an absolute value, or a relative offset with respect to a previously signaled security parameter value.

[0177] Aspect 28: The method of any of Aspects 22-27, wherein the configuration information further indicates enablement of inter-CU LTM recovery via one of: an inter-CU LTM recovery indicator associated with all candidate cells, an inter-CU LTM recovery indicator that is specific to the third cell, or an LTM recovery indicator associated with both intra-CU LTM recovery and inter-CU LTM recovery.

[0178] Aspect 29: The method of any of Aspects 22-28, further comprising communicating with another network node that is associated with the third cell to update a security parameter associated with the first cell based at least in part on successful completion of the inter-CU LTM cell switch from the first cell to the third cell.

[0179] Aspect 30: An apparatus for wireless communication at a device, the apparatus comprising one or more processors; one or more memories coupled with the one or more processors; and instructions stored in the one or more memories and executable by the one or more processors to cause the apparatus to perform the method of one or more of Aspects 1-29.

[0180] Aspect 31 : An apparatus for wireless communication at a device, the apparatus comprising one or more memories and one or more processors coupled to the one or more0097-6316PCTmemories, the one or more processors configured to cause the device to perform the method of one or more of Aspects 1-29.

[0181] Aspect 32: An apparatus for wireless communication, the apparatus comprising at least one means for performing the method of one or more of Aspects 1 -29.

[0182] Aspect 33: A non-transitory computer-readable medium storing code for wireless communication, the code comprising instructions executable by one or more processors to perform the method of one or more of Aspects 1-29.

[0183] Aspect 34: A non-transitory computer-readable medium storing a set of instructions for wireless communication, the set of instructions comprising one or more instructions that, when executed by one or more processors of a device, cause the device to perform the method of one or more of Aspects 1-29.

[0184] Aspect 35: A device for wireless communication, the device comprising a processing system that includes one or more processors and one or more memories coupled with the one or more processors, the processing system configured to cause the device to perform the method of one or more of Aspects 1-29.

[0185] Aspect 36: An apparatus for wireless communication at a device, the apparatus comprising one or more memories and one or more processors coupled to the one or more memories, the one or more processors individually or collectively configured to cause the device to perform the method of one or more of Aspects 1-29.

[0186] Aspect 37: A device comprising a processing system that includes one or more processors and one or more code-storing memories coupled with the one or more processors, the processing system configured to cause the device to perform the method of one or more of Aspects 1-29.

[0187] Aspect 38: A device comprising a processing system that includes processor circuitry and code-storing memory circuitry, the processing system configured to cause the device to perform the method of one or more of Aspects 1-29.

[0188] It will be apparent that systems or methods described herein may be implemented in different forms of hardware or a combination of hardware and software. A component being configured to perform a function means that the component has a capability to perform the function, and does not require the function to be actually performed by the component, unless noted otherwise.

[0189] As used herein, the term “determine” or “determining” can encompass one or more of a wide variety of actions. For example, “determining” can include one or more of calculating, computing, processing, deriving, detecting, estimating, investigating, looking up, inferring, ascertaining, measuring, resolving, selecting, choosing, obtaining, identifying, interpreting, demodulating, decoding, reading, establishing, forming or generating, among other0097-6316PCTexamples. In some such examples, determining can involve a processor performing some type of calculating, computing, deriving, estimating, inferring, ascertaining, resolving, predicting or other processing to obtain one or more numerical values, sets, elements or other information or results. In some other such examples, determining can involve a processor identifying, looking up, investigating or otherwise obtaining some type of value, set, element or other information or result from a table, a data structure, a database or other memory device or location. In some other such examples, determining can involve a processor identifying, interpreting, demodulating, decoding, detecting, reading or otherwise obtaining some type of value, set, element or other information or result signaled in, for example, a received wireless packet. In some other such examples, determining can involve a processor selecting or choosing one or more values, sets, elements or other information or results from a larger set of values, sets elements or other information or results. In some other such examples, determining can involve a processor performing a measurement, such as on a received signal.

[0190] As used herein, the articles “a” and “an” are intended to refer to one or more items and may be used interchangeably with “one or more” or “at least one.” As used herein, a phrase referring to “at least one of’ or “one or more of’ a list of items refers to any combination of those items, including single members. As an example, “at least one of: a, b, or c” is intended to cover: a, b, c, a-b, a-c, b-c, and a-b-c. Additionally, as used herein, a phrase referring to “a” or “an” element refers to one or more of such elements acting individually or collectively to perform the recited function(s). Additionally, as used herein, a “set” can refer to one or more items, and a “subset” can refer to a whole set or less than the whole set, but not an empty set. “Set,” “group,” and similar terms are intended to include one or more items and may be used interchangeably with “one or more.” Furthermore, as used herein, the term “or” is intended to be interpreted in the inclusive sense (such as when referring to a series) and may be used interchangeably with “and / or,” unless otherwise explicitly indicated (for example, if used in conjunction with “either” or “only one of’). For example, “A or 5” may include A only, B only, or a combination of A and B. Also, as used herein, the terms “has,” “have,” “having,” “comprise,” “comprising,” “include” and “including,” and derivatives thereof or similar terms are intended to be open-ended terms that do not limit an element that they modify (for example, an element “having” A also may have B).

[0191] As used herein, the phrase “associated with” is intended to be interpreted in the inclusive sense, unless otherwise explicitly indicated. For example, the phrase “associated with” is not to be construed as a reference to a closed set of conditions, factors, criteria, elements, components, or actions, among other examples. Specifically, unless a phrase refers to “associated with only ‘a,’” or the equivalent in context, whatever it is that is “associated with ‘a,’” may be associated with “a” alone or associated with a combination of “a” and one or more0097-6316PCTother conditions, factors, criteria, elements, components, or actions, among other examples. In various examples, the phrase “associated with” may be interpreted to mean “in association with,” “in accordance with,” “based on,” “based at least in part on,” “as a function of,” “in response to,” “responsive to,” or “using” as appropriate in the relevant context unless otherwise explicitly indicated. Furthermore, what follows the phrase “associated with,” “in association with,” “in accordance with,” “based on,” “based at least in part on,” “as a function of,” “in response to,” “responsive to,” or “using” is not necessarily the focal point or primary factor associated with the limitation preceding the phrase.

[0192] As used herein, “satisfying a threshold” may, depending on the context, refer to a value being greater than the threshold, greater than or equal to the threshold, less than the threshold, less than or equal to the threshold, equal to the threshold, or not equal to the threshold, among other examples.

[0193] Even though particular combinations of features are recited in the claims or disclosed in the specification, these combinations are not intended to limit the scope of all aspects described herein. Many of these features may be combined in ways not specifically recited in the claims or disclosed in the specification. The disclosure of various aspects includes each dependent claim in combination with every other claim in the claim set.0097-6316PCT

Claims

WHAT IS CLAIMED IS:

1. A user equipment (UE), comprising:a processing system that includes one or more processors and one or more code-storing memories coupled with the one or more processors, the processing system configured to cause the UE to:receive a lower layer triggered mobility (LTM) cell switch command associated with an LTM cell switch from a first cell; andperform, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, and based at least in part on the UE having a valid security parameter for a third cell that is associated with a second central unit (CU) different from a first CU associated with the first cell, an inter-CU LTM cell switch from the first cell to the third cell.

2. The UE of claim 1, wherein the processing system is configured to cause the UE to receive configuration information indicating a set of LTM candidate cells,wherein the processing system, to cause the UE to perform the inter-CU LTM cell switch from the first cell to the third cell, is configured to cause the UE to perform the inter-CU LTM cell switch from the first cell to the third cell based at least in part on the third cell being included in the set of configured LTM candidate cells.

3. The UE of claim 1, wherein the security parameter for the third cell is associated with at least one of a master key update parameter or a next hop chaining count parameter.

4. The UE of claim 1, wherein the processing system is configured to cause the UE to identify that the security parameter for the third cell is valid based at least in part on the unsuccessful LTM cell switch attempt from the first cell to the second cell being a first -in-time LTM cell switch attempt after reception of an initial LTM configuration.

5. The UE of claim 1, wherein the processing system is configured to cause the UE to: perform, prior to the unsuccessful LTM cell switch attempt, another inter-CU LTM cell switch;receive, after performing the other inter-CU LTM cell switch, a security parameter update message; andidentify that the security parameter for the third cell is valid based at least in part on the reception of the security parameter update message.0097-6316PCT6. The UE of claim 5, wherein the processing system, to cause the UE to receive the security parameter update message, is configured to cause the UE to receive the security parameter update message via one of:a radio resource control (RRC) information element, ora medium access control (MAC) control element (MAC-CE).

7. The UE of claim 5, wherein the security parameter update message indicates the security parameter for the third cell as one of:an absolute value, ora relative offset with respect to a previously signaled security parameter value.

8. The UE of claim 1, wherein the processing system is configured to cause the UE to receive, via the third cell, a security parameter update message based at least in part on successfully performing the inter-CU LTM cell switch from the first cell to the third cell.

9. The UE of claim 8, wherein the security parameter update message indicates at least one or more valid security parameters for one or more cells different from the third cell.

10. A network node, comprising:a processing system that includes one or more processors and one or more code-storing memories coupled with the one or more processors, the processing system configured to cause the network node to:transmit, to a user equipment (UE), configuration information indicating a set of lower layer triggered mobility (LTM) candidate cells; andtransmit, to the UE, an LTM cell switch command associated with an LTM cell switch from a first cell,wherein, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, based at least in part on the UE having a valid security parameter for a third cell that is associated with a second central unit (CU) different from a first CU associated with the first cell, and based at least in part on the third cell being included in the set of configured LTM candidate cells, transmission of the LTM cell switch results in an inter- CU LTM cell switch from the first cell to the third cell.0097-6316PCT11. The network node of claim 10, wherein the security parameter for the third cell is associated with at least one of a master key update parameter or a next hop chaining count parameter.

12. The network node of claim 10, wherein the security parameter for the third cell is valid based at least in part on the unsuccessful LTM cell switch attempt from the first cell to the second cell being a first-in-time LTM cell switch attempt after transmission of an initial LTM configuration.

13. The network node of claim 10, wherein the processing system is configured to cause the network node to transmit, to the UE after performance of another inter-CU LTM cell switch, a security parameter update message,wherein the security parameter for the third cell is valid based at least in part on the transmission of the security parameter update message.

14. The network node of claim 13, wherein the processing system, to cause the network node to transmit the security parameter update message, is configured to cause the network node to transmit the security parameter update message via one of:a radio resource control (RRC) information element, ora medium access control (MAC) control element (MAC-CE).

15. The network node of claim 13, wherein the security parameter update message indicates the security parameter for the third cell as one of:an absolute value, ora relative offset with respect to a previously signaled security parameter value.

16. The network node of claim 10, wherein the processing system is configured to cause the network node to communicate with another network node that is associated with the third cell to update a security parameter associated with the first cell based at least in part on successful completion of the inter-CU LTM cell switch from the first cell to the third cell.

17. A method of wireless communication performed by a user equipment (UE), comprising:receiving a lower layer triggered mobility (LTM) cell switch command associated with an LTM cell switch from a first cell; andperforming, based at least in part on an unsuccessful LTM cell switch attempt from the first cell to a second cell, and based at least in part on the UE having a valid security parameter0097-6316PCTfor a third cell that is associated with a second central unit (CU) different from a first CU associated with the first cell, an inter-CU LTM cell switch from the first cell to the third cell.

18. The method of claim 17, further comprising receiving configuration information indicating a set of LTM candidate cells,wherein performing the inter-CU LTM cell switch from the first cell to the third cell is further based at least in part on the third cell being included in the set of configured LTM candidate cells.

19. The method of claim 17, further comprising identifying that the security parameter for the third cell is valid based at least in part on the unsuccessful LTM cell switch attempt from the first cell to the second cell being a first-in-time LTM cell switch attempt after reception of an initial LTM configuration.

20. The method of claim 17, further comprising:performing, prior to the unsuccessful LTM cell switch attempt, another inter-CU LTM cell switch;receiving, after performing the other inter-CU LTM cell switch, a security parameter update message; andidentifying that the security parameter for the third cell is valid based at least in part on the reception of the security parameter update message.0097-6316PCT