Mobility Security Reuse Across Target Cell Security Groups
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Rel-17, UE devices face increased delay and signaling overhead during frequent Secondary Cell Group changes in FR2 due to the need for reconfiguration and re-initialization of conditional mobility commands during cell changes, which is inefficient and resource-intensive.
Innovation Solution
The method involves receiving a security mode command and information about a target cell belonging to a security group, allowing the UE to continue using the existing security configuration for subsequent mobility without reconfiguration, thereby optimizing mobility procedures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the UE releases CPC/CPA configurations when completing random access towards the target PSCell, then the security security is maintained, but the delay for cell change increases and signaling overhead increases
Solution Approach 1:
The network performs security key update in advance before the actual cell change occurs. The gNB sends a security mode command to the UE containing updated security keys and algorithms, so that when the UE executes the conditional mobility command and switches to the target PSCell, the security configuration is already prepared and can be applied immediately without causing delay.
Solution Approach 2:
The patent introduces a security group concept as an intermediary mechanism. Cells are organized into security groups, and the network indicates whether a target cell belongs to a security group. This intermediary structure allows the UE to determine whether to reuse existing security configuration or perform security update, thereby avoiding unnecessary security reconfiguration delays while maintaining security integrity.
2Reliability
If the UE releases CPC/CPA configurations when completing random access towards the target PSCell, then the security is maintained, but the signaling overhead increases
Solution Approach 1:
The network performs security key update in advance before the actual cell change occurs. The gNB sends a security mode command to the UE containing updated security keys and algorithms, so that when the UE executes the conditional mobility command and switches to the target PSCell, the security configuration is already prepared and can be applied immediately without causing delay.
Solution Approach 2:
Instead of completely releasing and reconfiguring security parameters during each cell change, the patent implements a mechanism where security configurations are retained and reused when appropriate. The UE determines whether to reuse existing security configuration based on the security group indication, thereby recovering from the need to retransmit security signaling in every mobility event.
3Reliability
If the UE performs reconfiguration and re-initialization for subsequent mobility, then the security is updated, but the productivity decreases
Solution Approach 1:
The patent introduces dynamic security configuration management where the UE adapts its behavior based on real-time conditions. The network dynamically indicates whether a target cell belongs to a security group, and the UE dynamically decides whether to reuse existing security configuration or perform security update. This dynamic approach optimizes the balance between security and mobility efficiency.
Solution Approach 2:
The patent changes the parameter of security configuration management from static (always reconfigure) to dynamic (conditional reuse). By introducing the security group indication parameter and conditional reuse logic, the system can adapt security update behavior based on the specific mobility scenario, thereby improving productivity while maintaining security.
Data Source
AI summary
A method and apparatus for security handling for subsequent mobility procedure is provided. A wireless device receives a security mode command including a security configuration from a network, receives information informing whether a target cell belongs to a security group from the network, and continues using the security configuration based on the information informing that the target cell belongs to the security group.


