EP4537564A1 - Method and apparatus for secure lower layer mobility - Google Patents
Method and apparatus for secure lower layer mobilityInfo
- Publication number
- EP4537564A1 EP4537564A1 EP22734866.1A EP22734866A EP4537564A1 EP 4537564 A1 EP4537564 A1 EP 4537564A1 EP 22734866 A EP22734866 A EP 22734866A EP 4537564 A1 EP4537564 A1 EP 4537564A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- mobility
- security
- encoded
- token
- signaling element
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/16—Implementing security features at a particular protocol layer
- H04L63/162—Implementing security features at a particular protocol layer at the data link layer
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/043—Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W36/00—Hand-off or reselection arrangements
- H04W36/0005—Control or signalling for completing the hand-off
- H04W36/0055—Transmission or use of information for re-establishing the radio link
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/10—Integrity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W36/00—Hand-off or reselection arrangements
- H04W36/0005—Control or signalling for completing the hand-off
- H04W36/0011—Control or signalling for completing the hand-off for data sessions of end-to-end connection
- H04W36/0033—Control or signalling for completing the hand-off for data sessions of end-to-end connection with transfer of context information
- H04W36/0038—Control or signalling for completing the hand-off for data sessions of end-to-end connection with transfer of context information of security context information
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W36/00—Hand-off or reselection arrangements
- H04W36/08—Reselecting an access point
- H04W36/087—Reselecting an access point between radio units of access points
Definitions
- Various example embodiments relate to wireless communications.
- 5G New Radio (NR) Release 18 aims to enable the so- called layer 1/layer 2 (Ll/2) -mobility, which in practice means that the control of mobility would be moved from the central unit (CU) of the access node to the distributed unit(s) (DU(s)) of the access node.
- the handover could be activated, e.g., via the medium access control (MAC) layer.
- DU- based mobility is the inter-DU mobility, i.e., mobility between cells within the same CU but different DUs.
- the present L1/L2 inter-DU mobility schemes have problems when it comes to enabling secure communications when inter-DU mobility occurs.
- an apparatus comprising: at least one processor; and at least one transceiver, wherein the at least one processor is configured to: obtain one or more security keys for handover; wherein the at least one transceiver is configured to: receive a mobility signaling element of a first and/or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and wherein the at least one processor is configured to: decode the encoded security token using the at least one of the one or more security keys.
- an apparatus comprising: at least one processor; and at least one transceiver, wherein the at least one processor is configured to: generate one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys, wherein the at least one transceiver is configured to: transmit at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmit at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein the second configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
- an apparatus comprising: at least one processor; and at least one transceiver, wherein the at least one transceiver is configured to: receive at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; and in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forward said at least one second mobility configuration message to a terminal device, wherein the at least one processor is configured to: select one of the one or more encoded security tokens for handover, wherein the at least one transceiver is configured to: transmit a mobility signaling element of the first and/or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
- a method comprising: obtaining one or more security keys for handover; receiving a mobility signaling element of a first and/or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
- a method comprising: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys, transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein the second configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
- a method comprising: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; and in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of the first and / or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
- a non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the following: obtaining one or more security keys for handover; receiving a mobility signaling element of a first and/or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
- a non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the following: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys, transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein the second configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
- a non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the following: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of the first and / or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
- an apparatus comprising means for performing: obtaining one or more security keys for handover; receiving a mobility signaling element of a first and/or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
- an apparatus comprising at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code being configured, with the at least one processor, to cause the apparatus at least to perform: obtaining one or more security keys for handover; receiving a mobility signaling element of a first and/or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
- an apparatus comprising means for performing: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys; transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein said at least one second mobility configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities
- an apparatus comprising at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code being configured, with the at least one processor, to cause the apparatus at least to perform: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys; transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein said at least one second mobility configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities
- an apparatus comprising means for performing: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; and in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of the first and / or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
- an apparatus comprising at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code being configured, with the at least one processor, to cause the apparatus at least to perform: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of a first and/or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
- a computer program comprising instructions for causing an apparatus to perform at least the following: obtaining one or more security keys for handover; receiving a mobility signaling element of a first and/or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
- a computer program comprising instructions for causing an apparatus to perform at least the following: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys, transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein the second configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
- a computer program comprising instructions for causing an apparatus to perform at least the following: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of a first and/or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
- Figure 1 illustrates an exemplified wireless communication system
- FIG. 2A, figure 2B and figure 2C illustrate exemplary processes according to embodiments
- FIG. 3 illustrates an example of a medium access control control element (MAC CE) structure for a mobility signaling element according to an embodiment
- Figure 4 illustrates signaling between at terminal device, a first (source) distributed unit of an access node, a second (target) distributed unit of the access node and the central unit of the access node according to an embodiment
- Figure 5 illustrates an apparatus according to embodiments.
- layer 1 refers to layers of an Open Systems Interconnection (OS1) model.
- layer 1 corresponds to a physical layer
- layer 2 corresponds to a data link layer
- layer 3 correspond to a network layer.
- Ll/2 as used in the following (e.g., in “Ll/2 mobility” or “Ll/2-based handover”) may imply operation on layer 1 or on layer 2 or on layers 1 & 2.
- UMTS universal mobile telecommunications system
- UTRAN radio access network
- LTE long term evolution
- WLAN wireless local area network
- WiFi worldwide interoperability for microwave access
- Bluetooth® personal communications services
- PCS personal communications services
- WCDMA wideband code division multiple access
- UWB ultra-wideband
- sensor networks mobile ad-hoc networks
- IMS Internet Protocol multimedia subsystems
- Figure 1 depicts examples of simplified system architectures showing some elements and functional entities, all being logical units, whose implementation may differ from what is shown.
- the connections shown in Figure 1 are logical connections; the actual physical connections may be different. It is apparent to a person skilled in the art that the system typically comprises also other functions and structures than those shown in Figure 1.
- Figure 1 shows a part of an exemplifying radio access network.
- Figure 1 shows user devices 100 and 102 configured to be in a wireless connection on one or more communication channels in a cell with an access node (such as (e/g)NodeB) 104 providing the cell.
- the physical link from a user device to a (e/g)NodeB is called uplink or reverse link and the physical link from the (e/g)NodeB to the user device is called downlink or forward link.
- (e/g)NodeBs or their functionalities may be implemented by using any node, host, server or access point etc. entity suitable for such a usage.
- a communications system typically comprises more than one (e/g)NodeB in which case the (e/g)NodeBs may also be configured to communicate with one another over links, wired or wireless, designed for the purpose. These links may be used for signaling purposes.
- the (e/g)NodeB is a computing device configured to control the radio resources of communication system it is coupled to.
- the NodeB may also be referred to as a base station, an access point or any other type of interfacing device including a relay station capable of operating in a wireless environment.
- the (e/g) NodeB includes or is coupled to transceivers. From the transceivers of the (e/g) NodeB, a connection is provided to an antenna unit that establishes bi-directional radio links to user devices.
- the antenna unit may comprise a plurality of antennas or antenna elements.
- the (e/g) NodeB is further connected to core network 110 (CN or next generation core NGC).
- core network 110 CN or next generation core NGC.
- the counterpart on the CN side can be a serving gateway (S-GW, routing and forwarding user data packets), packet data network gateway (P-GW), for providing connectivity of user devices (UEs) to external packet data networks, or mobile management entity (MME), etc.
- S-GW serving gateway
- P-GW packet data network gateway
- MME mobile management entity
- the user device also called UE, user equipment, user terminal, terminal device, etc.
- UE user equipment
- user terminal terminal device
- any feature described herein with a user device may be implemented with a corresponding apparatus, such as a relay node.
- a relay node is a layer 3 relay (self-backhauling relay) towards the base station.
- the user device typically refers to a portable computing device that includes wireless mobile communication devices operating with or without a subscriber identification module (SIM), including, but not limited to, the following types of devices: a mobile station (mobile phone), smartphone, personal digital assistant (PDA), handset, device using a wireless modem (alarm or measurement device, etc.), laptop and/or touch screen computer, tablet, game console, notebook, and multimedia device.
- SIM subscriber identification module
- a user device may also be a nearly exclusive uplink only device, of which an example is a camera or video camera loading images or video clips to a network.
- a user device may also be a device having capability to operate in Internet of Things (loT) network which is a scenario in which objects are provided with the ability to transfer data over a network without requiring human-to-human or human-to-computer interaction.
- the user device (or in some embodiments a layer 3 relay node) is configured to perform one or more of user equipment functionalities.
- the user device may also be called a subscriber unit, mobile station, remote terminal, access terminal, user terminal or user equipment (UE) just to mention but a few names or apparatuses.
- CPS cyberphysical system
- ICT devices sensors, actuators, processors microcontrollers, etc.
- Mobile cyber physical systems in which the physical system in question has inherent mobility, are a subcategory of cyber-physical systems. Examples of mobile physical systems include mobile robotics and electronics transported by humans or animals.
- 5G enables using multiple input - multiple output (M1M0) antennas, many more base stations or nodes than the LTE (a so-called small cell concept), including macro sites operating in co-operation with smaller stations and employing a variety of radio technologies depending on service needs, use cases and/or spectrum available.
- 5G mobile communications supports a wide range of use cases and related applications including video streaming, augmented reality, different ways of data sharing and various forms of machine type applications, including vehicular safety, different sensors and real-time control.
- 5G is expected to have multiple radio interfaces, namely below 6GHz, cmWave and mmWave, and also being integratable with existing legacy radio access technologies, such as the LTE.
- Integration with the LTE may be implemented, at least in the early phase, as a system, where macro coverage is provided by the LTE and 5G radio interface access comes from small cells by aggregation to the LTE.
- 5G is planned to support both inter-RAT operability (such as LTE-5G) and inter-Rl operability (inter-radio interface operability, such as below 6GHz - cmWave, below 6GHz - cmWave - mmWave).
- inter-RAT operability such as LTE-5G
- inter-Rl operability inter-radio interface operability, such as below 6GHz - cmWave, below 6GHz - cmWave - mmWave.
- One of the concepts considered to be used in 5G networks is network slicing in which multiple independent and dedicated virtual sub-networks (network instances) may be created within the substantially same infrastructure to run services that have different requirements on latency, reliability, throughput and mobility.
- the current architecture in LTE networks is fully distributed in the radio and fully centralized in the core network.
- the low latency applications and services in 5G require to bring the content close to the radio which leads to local break out and multi-access edge computing (MEC).
- MEC multi-access edge computing
- 5G enables analytics and knowledge generation to occur at the source of the data. This approach requires leveraging resources that may not be continuously connected to a network such as laptops, smartphones, tablets and sensors.
- MEC provides a distributed computing environment for application and service hosting. It also has the ability to store and process content in close proximity to cellular subscribers for faster response time.
- Edge computing covers a wide range of technologies such as wireless sensor networks, mobile data acquisition, mobile signature analysis, cooperative distributed peer- to-peer ad hoc networking and processing also classifiable as local cloud/fog computing and grid/mesh computing, dew computing, mobile edge computing, cloudlet, distributed data storage and retrieval, autonomic self-healing networks, remote cloud services, augmented and virtual reality, data caching, Internet of Things (massive connectivity and/or latency critical), critical communications (autonomous vehicles, traffic safety, real-time analytics, time-critical control, healthcare applications).
- the communication system is also able to communicate with other networks, such as a public switched telephone network or the Internet 112, or utilize services provided by them.
- the communication network may also be able to support the usage of cloud services, for example at least part of core network operations may be carried out as a cloud service (this is depicted in Figure 1 by “cloud” 114).
- the communication system may also comprise a central control entity, or a like, providing facilities for networks of different operators to cooperate for example in spectrum sharing.
- Edge cloud may be brought into radio access network (RAN) by utilizing network function virtualization (NVF) and software defined networking (SDN).
- RAN radio access network
- NVF network function virtualization
- SDN software defined networking
- Using edge cloud may mean access node operations to be carried out, at least partly, in a server, host or node operationally coupled to a remote radio head or base station comprising radio parts. It is also possible that node operations will be distributed among a plurality of servers, nodes or hosts.
- Application of cloudRAN architecture enables RAN real time functions being carried out at the RAN side (in a distributed unit, DU 104) and non-real time functions being carried out in a centralized manner (in a central or centralized unit, CU 108).
- 5G may also utilize satellite communication to enhance or complement the coverage of 5G service, for example by providing backhauling.
- Possible use cases are providing service continuity for machine-to-machine (M2M) or Internet of Things (loT) devices or for passengers on board of vehicles, or ensuring service availability for critical communications, and future railway/maritime/aeronautical communications.
- Satellite communication may utilize geostationary earth orbit (GEO) satellite systems, but also low earth orbit (LEO) satellite systems, in particular mega-constellations (systems in which hundreds of (nano) satellites are deployed).
- GEO geostationary earth orbit
- LEO low earth orbit
- At least one satellite 106 in the mega-constellation may cover several satellite-enabled network entities that create on-ground cells.
- the on-ground cells may be created through an on-ground relay node 104 or by a gNB located on- ground or in a satellite.
- the depicted system is only an example of a part of a radio access system and in practice, the system may comprise a plurality of (e/g)NodeBs, the user device may have an access to a plurality of radio cells and the system may comprise also other apparatuses, such as physical layer relay nodes or other network elements, etc. At least one of the (e/g)NodeBs or may be a Home(e/g)nodeB. Additionally, in a geographical area of a radio communication system a plurality of different kinds of radio cells as well as a plurality of radio cells may be provided.
- Radio cells may be macro cells (or umbrella cells) which are large cells, usually having a diameter of up to tens of kilometers, or smaller cells such as micro-, femto- or picocells.
- the (e/g)NodeBs of Figure 1 may provide any kind of these cells.
- a cellular radio system may be implemented as a multilayer network including several kinds of cells. Typically, in multilayer networks, one access node provides one kind of a cell or cells, and thus a plurality of (e/g)NodeBs are needed to provide such a network structure.
- a network which is able to use “plug-and-play” (e/g)Node Bs includes, in addition to Home (e/g)NodeBs (H(e/g)nodeBs), a home node B gateway, or HNB-GW (not shown in Figure 1).
- HNB-GW HNB Gateway
- a HNB Gateway (HNB-GW) which is typically installed within an operator’s network may aggregate traffic from a large number of HNBs back to a core network.
- 6G networks are expected to adopt flexible decentralized and/or distributed computing systems and architecture and ubiquitous computing, with local spectrum licensing, spectrum sharing, infrastructure sharing, and intelligent automated management underpinned by mobile edge computing, artificial intelligence, short-packet communication and blockchain technologies. Key features of 6G will include intelligent connected management and control functions, programmability, integrated sensing and communication, reduction of energy footprint, trustworthy infrastructure, scalability and affordability. In addition to these, 6G is also targeting new use cases covering the integration of localization and sensing capabilities into system definition to unifying user experience across physical and digital worlds.
- the (access node) functions may be split between the CU 108 and the DU 104 of the system of Figure 1 in several different ways.
- the CU 108 may host radio resource control (RRC) and packet data convergence protocol (PDCP) layers for control plane and service data application protocol (SDAP) and PDCP layers for user plane and the DU 104 may host the radio link control (RLC) and MAC layers and layer- 1/physical layer (Ll/PHY).
- RRC radio resource control
- PDCP packet data convergence protocol
- SDAP control plane and service data application protocol
- PDCP radio link control
- Ll/PHY layer- 1/physical layer
- the RLC may be split between the CU 108 and DU 104.
- the system of Figure 1 may be a (5G NR or 6G) communication system configured to support L1/L2 mobility or more specifically at least L1/L2 inter-cell mobility.
- L1/L2 mobility the control of mobility is moved from the CU to the DU and therefore may be activated, e.g., via the MAC layer or PHY layer.
- intra-DU mobility i.e., mobility between cells within the same DU
- inter-DU mobility i.e. mobility between cells within the same CU but different DUs
- DU has all the information needed to decide on the serving cell change.
- the embodiments to be discussed below are targeting specifically the inter-DU mobility and overcoming certain problems associated with it (to be discussed below). However, the embodiments are equally applicable to the intra-DU mobility cases.
- the Ll/2 inter-cell mobility may be performed (predominantly) by the MAC layer terminated in the DU.
- a terminal device sends measurement report containing the cell quality measurements of serving and neighboring cells via the DU1 to a central unit (CU) of the access node.
- the terminal device may be configured by the serving cell (i.e., by the DU1) to send the measurement report early when it still has a good connection to the serving cell (i.e., to the DU1).
- the CU is able to identify a potential set of candidate target cells to which the terminal device can be handed over.
- the CU identifies candidate target cells that are served by the DU1 (controlling the serving DU/cell as well) and another DU2 that is controlled by the same CU.
- the CU requests the preparation of a candidate target cell controlled by DU1 by sending UE context setup request message to the DU1.
- the DU1 In response to receiving the UE context setup request, the DU1 transmits information on a configuration of the terminal device in a UE context setup response message containing a container to the CU.
- steps 3) -4) are performed in a similar manner between the CU and the DU2 in order to prepare target cell(s) that are controlled by DU2.
- the CU Having received the terminal device’s configurations for the candidate target cell(s), the CU generates an RRC Reconfiguration that is sent from the CU to the terminal device (via the DU1).
- the RRC Reconfiguration message may comprise at least measurement reporting configuration for Ll/2 handover, i.e., configuration on how to report the LI beam measurements of serving and target cells and configuration of the prepared candidate cell(s) which the terminal device needs to execute when it receives a MAC CE command to change the serving cell (perform handover).
- the terminal device receives/obtains the RRC reconfiguration message and transmits an RRC reconfiguration complete message back to the CU (via the DU1).
- the terminal device starts to report periodically the LI beam measurement of serving and candidate target cells.
- the DU1 Upon determining that there is a target candidate cell having a better radio link/beam measurement than the serving cell, e.g., Ll-reference signal received power (RSRP) of target beam measurement is larger than Ll-RSRP of serving beam measurement summed with an offset for an amount of time e.g., time -to- trigger (TTT), the DU1 sends a MAC CE or a LI message to the terminal device for triggering the cell change to the target candidate cell.
- RSRP Ll-reference signal received power
- TTTT time -to- trigger
- the terminal device may perform handover from the serving cell to the target cell.
- the Ll/2 mobility may be carried out via a MAC CE transmitted towards the terminal device.
- MAC CEs are sent in plaintext, i.e., without any ciphering or integrity protection. This means that once a terminal device is configured with Ll/2 mobility, a rogue access node (rogue gNB) could start sending Ll/2 mobility commands to the terminal device and either cause a DoS attack or force the terminal device to perform additional (unwanted) procedures. It should be noted no such problem exists with L3 mobility since RRC commands are both ciphered and integrity protected and thus it is not possible to spoof the L3 mobility command as easily.
- ciphering and integrity protection are performed in packet data convergence protocol (PDCP) layer.
- PDCP packet data convergence protocol
- any layer below PDCP is used for the Ll/2 mobility purpose, e.g., RLC, MAC or PHY/L1, the same problem exists.
- Figures 2A, 2B and 2C illustrate processes carried out (in parallel) by a terminal device, a central unit (CU) of an access node and a distributed unit (DU) of the access node.
- the terminal device is communicatively connected at least to the DU
- the DU is communicatively connected to both the terminal device and the CU
- the CU is communicatively connected at least to the DU (and to a core network).
- the DU may be specifically a DU providing a serving cell used at the start of each of the processes for serving the terminal device.
- the terminal device, the DU and the CU may correspond, respectively, to one of the terminal devices 100, 102 of Figure 1, to the DU 104 of Figure 1 and to the CU 108 of Figure 1.
- any of the definitions provided in connection with one of Figures 2A, 2B and 2C may apply equally for the others of Figures 2A, 2B and 2C.
- the terminal device may be initially assumed that the terminal device is being served via a serving cell provided by a DU of an access node.
- the terminal device may be operating a RRC connected mode (with said DU).
- the terminal device obtains, in block 201, one or more security keys for handover (i.e., to be used for a handover or at least a handover attempt).
- the handover may correspond here at least to first and/or second protocol layer -based handover.
- the first and second protocol layers may comprise (or be), respectively, the physical layer of 3PGG protocol architecture and the MAC layer of the 3GPP protocol architecture.
- the first and second protocol layers may correspond to OS1 layers 1 and 2 (LI & L2), i.e., to physical and data link layers, respectively.
- each of the first and second protocol layers may correspond to or comprise any of the 3GPP defined layers or sublayers, e.g., PHY /LI, MAC, RLC, PDCP and RRC.
- the one or more security keys are usable for decoding associated encoded security tokens.
- the one or more security keys may have been configured using the RRC protocol before decoding the encoded security tokens.
- the obtaining in block 201 may comprise receiving information suitable for deriving said one or more security keys (e.g., from said DU providing the serving cell or from the CU) and subsequently deriving the one or more security keys based on said information.
- Said information suitable for deriving said one or more security keys may be transmitted as a part of a (second) mobility configuration message for (Ll/2) mobility configuration of the terminal device (as will be discussed in more detail in connection with Figure 2B).
- said information suitable for deriving said one or more security keys may be or comprise one or more (security) token identities.
- the one or more security keys comprise one or more security keys for one or more signalling radio bearers (SRBs) and/or one or more security keys for one or more data radio bearers (DRBs).
- SRBs signalling radio bearers
- DRBs data radio bearers
- the terminal device receives, in block 202, a mobility signaling element of the first and/or second protocol layer.
- the mobility signaling element may be or form a part of a mobility command.
- the mobility signaling element may be an Ll/2 mobility signaling element.
- the mobility signaling element comprises an encoded security token which has been encoded (e.g., ciphered and/or integrity protected) using at least one of the one or more security keys.
- the transmission and subsequent reception of the mobility signaling element may be indicative of a decision by the access node (or specifically by the DU) that (Ll/2) mobility to a particular target cell is to be executed.
- Said target cell may be specifically a cell provided by another DU of the same access node (i.e., connected to the same CU) or a cell provided by the same DU of the same access node.
- said first and/or second protocol layer associated with the mobility signaling element comprise or consist of one or two of the physical layer, the MAC layer and the RLC layer.
- said first and/or second protocol layer associated with the mobility signaling element comprise or consist of one or two of the physical layer, the MAC layer, the RLC layer and the PDCP layer.
- said first and/or second protocol layer associated with the mobility signaling element comprise or consist of one or two of the physical layer, the MAC layer, the RLC layer, the PDCP layer and the RRC layer.
- the mobility signaling element may be or comprise a MAC CE. In some alternative embodiments, the mobility signaling element may be or comprise downlink control information (DC1).
- the DC1 may be provided by the Physical Downlink Control Channel (PDCCH) of the physical layer (LI).
- the encoded security token comprised in the mobility signaling element may be or correspond to a PDCP protocol data unit (PDU).
- Said PDCP PDU may be either a data PDU or a control PDU.
- the terminal device may, upon reception of the mobility signaling element, forward the PDCP PDU (i.e., the encoded security token) to the PDCP layer.
- the subsequent decoding i.e., block 203 may be carried out by the PDCP layer.
- the encoded security token comprised in the mobility signaling element may be or correspond to an encoded message authentication code for an integrity protection check (e.g., an encoded message authentication code for integrity, MAC-1).
- the encoded message authentication code may be checked for integrity protection by the PDCP layer.
- the encoded and/or decoded security token may comprise random data (i.e., random bits), pre-defined data (provided via RRC) or additional control information.
- Said additional control information may be control information provided by the CU to the terminal device.
- Said additional control information may concern, e.g., control information relating to the mobility execution (e.g., related to DRB security keys and/or related to the target cell for the handover).
- the mobility signaling element or at least the security token may have been scrambled (by the DU or CU) using a radio network temporary identifier (RNT1) for indicating that a payload or at least part of the mobility signaling element has been ciphered and/or integrity protected.
- RNT1 radio network temporary identifier
- the security key comprises the RNT1.
- the terminal device decodes, in block 203, the encoded security token using said at least one of the one or more security keys.
- the decoding may be performed specifically using a PDCP entity of the terminal device.
- Information identifying said at least one of the one or more security keys i.e., information for determining which of the one or more security keys should be used for the decoding in block 203) may be comprised in the mobility signaling element.
- the mobility signaling element e.g., the MAC CE
- the token identity serves to identify which of the one or more security keys is to be used for decoding the encoded security token.
- the RNT1 When RNT1 is used to scramble the mobility signaling element or at least a part of the mobility signaling element (e.g., the encoded security token), the RNT1 may not be explicitly indicated in the mobility signaling element (e.g., MAC CE).
- the decoding may be done in MAC layer (L2).
- the decoding in block 203 may comprise deciphering and/or verifying integrity of the ciphered and/or integrity protected security token, respectively. Both deciphering and integrity verification may be performed in PDCP.
- the decoding in block 203 may, additionally or alternatively, comprise descrambling the mobility signaling element or a part of the mobility signaling element (e.g., the encoded security token) to obtain at least the security token.
- the terminal device may trigger or cause execution of handover from the serving cell to the target cell (the target cell being specified, e.g., in the mobility signaling element).
- the terminal device may (initially) indicate (Ll/2) handover execution from the PDCP entity or other entity performing the integrity verification to RRC and/or MAC layer.
- the transmitted indication of the (Ll/2) handover execution may comprise a mobility command.
- the (encoded) security token may be provided in same or different mobility signaling element (e.g., MAC CE) as the actual mobil- ity/handover command.
- the (encoded) security token and the actual mobility /handover command may be transmitted as separate MAC CEs or within the same MAC CE.
- the terminal device may indicate (Ll/2) handover failure (from PDCP entity or other entity performing the integrity verification) to RRC layer.
- the encoded security token may be simply discarded.
- the terminal device may cause transmission of one or more RRC messages indicating that the decoding was successful (or that the decoding was not successful, if this is the case) to one or more distributed units of one or more access nodes (e.g., to old and/or new serving distributed units).
- the RRC message may be transmitted via a MAC CE.
- the CU of the access node is initially configured with one or more security keys.
- the CU generates, in block 211, one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys.
- the generating of the one or more encoded security tokens may comprise ciphering and/or integrity protecting of one or more security tokens.
- the CU transmits, in block 212, a first (Ll/2) mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a DU of the access node (or multiple DUs of the access node).
- the DU is configured to store the one or more encoded security tokens and the one or more token identities to at least one memory, to configure terminal device (s) based on them and to use them for triggering the (Ll/2) handover in a data secure manner, as will be described below in connection with Figure 2C.
- a plurality of (first) mobility messages may be transmitted from the CU to the DU for communicating the one or more encoded security tokens and the one or more token identities to the DU.
- the one or more token identities may be communicated in an initial first mobility message and the one or more security tokens may be communicated in a subsequent first mobility message.
- the CU transmits, in block 213, a second (Ll/2) mobility configuration message for first and/or second protocol layer (e.g., Ll/2) mobility of a terminal device to the terminal device via the DU (being specifically a DU providing a serving cell of the terminal device).
- the second (Ll/2) mobility configuration message may be transmitted via RRC signalling.
- the second mobility configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities. It may be especially beneficial if the one or more token identities (but not the one or more security tokens themselves) are included in the transmitted second mobility configuration message as transmitting of the one or more security tokens may render the solution vulnerable to plaintext attacks.
- the decision regarding which security tokens and/or token identities to transmit to the terminal device may be based on RRC configuration of the terminal device.
- a plurality of (second) mobility messages may be transmitted from the CU via the DU to the terminal device for communicating said at least one or all of the one or more security tokens and of the one or more token identities.
- the one or more token identities (or at least some of them) may be communicated in an initial second mobility message and the one or more security tokens (or at least some of them) may be communicated in a subsequent second mobility message.
- the terminal device Based on the RRC configuration, the terminal device is able to understand that the token identity having value of 5 is associated with the RNT1 (or in general, with a particular security key comprising said RNT1) having the value of 12, so it can decode the security token value to check whether or not contains the correct RNT1.
- the DU of the access node is initially communicatively connected to a terminal device operating in the RRC connected mode.
- the DU receives, in block 221, a first mobility configuration message (or at least one first mobility configuration message) comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node (as described in connection with block 212 above).
- the CU configures the DU with the one or more encoded security tokens and associated one or more token identities to be used for handover (e.g., Ll/2-based handover).
- the DU may store the one or more encoded security tokens and the associated one or more token identities to at least one memory (not shown in Figure 2C).
- the DU receives, in block 222, from the central unit of the access node and subsequently forwards, also in block 222, to the terminal device a second mobility configuration message (or at least one second mobility configuration message) for first and/or second protocol layer (e.g., Ll/2) mobility of the terminal device.
- the (at least one) second mobility configuration message comprises at least the one or more token identities.
- the DU selects, in block 223, one of the one or more encoded security tokens for handover (i.e., to be used for a handover or at least a handover attempt).
- the selecting in block 223 may be triggered following a completion of a procedure for evaluating a radio channel between the terminal device and a current serving cell provided by the DU to one or more radio channels between the terminal device and one or more target cells provided by one or more other DUs of the same CU.
- Said evaluating may be based on measurement results acquired from all cells.
- the evaluating may be based, e.g., on measurements of reference signal received power (RSRP) and/or reference signal received quality (RSRQ).
- RSRP reference signal received power
- RSRQ reference signal received quality
- the DU transmits, in block 224, a mobility signaling element (e.g., a Ll/2 mobility MAC CE) to the terminal device.
- the mobility signaling element comprises said selected one of the one or more encoded security tokens.
- the mobility signaling element may be or form a part of a mobility command.
- the mobility signaling element may be defined as discussed above in connection with block 202 of Figure 2A.
- Figure 3 illustrates an exemplary MAC CE structure for a mobility signaling element transmitted from a DU of a serving cell to a terminal device.
- the MAC CE structure illustrated in Figure 3 corresponds to the mobility signaling element received in block 202 of Figure 2A and transmitted in block 224 of Figure 2C according to an embodiment.
- the MAC CE may comprise at least one of the following fields (exemplary sizes indicated in parentheses): a reserved (R) field (e.g., 1 bit), a (security) token identity field (e.g., 4 bits), a cell identity field (e.g., 3 bits) and a security token field (e.g., N x 8 bits, N being any positive integer).
- R reserved
- the sizes of the fields provided here and shown in Figure 3 may be considered exemplary and may thus differ in other embodiments from the ones described/illustrated here.
- the first octet shown in Figure 3 is the header of the MAC CE which is created by the DU.
- the remaining octets comprise (or consist of) the (encoded) security token. While Figure 3 shows specifically a MAC CE usable in connection with embodiments, the mobility signaling elements other than MAC CE (e.g., DC1) may also comprise any of the fields discussed here.
- the cell identity field indicates the target cell of the mobility (or handover).
- the terminal device may be configured to, in response to the decoding being successful, cause execution of the (Ll/2-based) handover based on the cell identity field (i.e., to cause execution of the handover towards the target cell specified by the cell identity field).
- the cell identity field may comprise a physical cell identifier (PCI).
- PCI physical cell identifier
- the cell identity field may comprise an indirect indication to a stored handover command such as a conditional handover identifier (CHO ID) or an indirect indication to the target cell of the handover based on the RRC configuration of the terminal device.
- CHO ID conditional handover identifier
- the token identity field (equally called a security token identity field) indicates which security key a terminal device should use to decode the encoded security token (see next paragraphs).
- the terminal device may be configured to select the at least one of the one or more security keys to be used for the deciphering based on the token identity field.
- the token identity field is used by the terminal device to derive the security key for the decoding (e.g., for deciphering and/or integrity verification) of the security token field.
- the token identity field may have a size of 4 bits though other (especially larger) sizes such as 16 bits are also feasible.
- the token identity field may comprise an encoded SRB or DRB identifier usable by the terminal device for determining a PDCP entity which may be used for decoding the security token.
- the security token field is an encoded (i.e., ciphered and/or integrity protected) field consisting of N octets.
- the security token field comprises a security token in an encoded format.
- the security token field may correspond to a PDCP PDU.
- the security token field may be generated by the CU based on a derived security key for SRB1 (or any other SRB or DRB).
- the generation of the security token field may be carried out in a similar manner to derivation of a secondary node key (S-KgNB) for New Radio Dual Connectivity (NR-DC).
- S-KgNB secondary node key
- NR-DC New Radio Dual Connectivity
- the token identity field may be used as the so-called SK-counter for the S-KgNB type key derivation (i.e., for a counter for guaranteeing the freshness of the derived key).
- the token identity field may be indicated, by the terminal device, to the PDCP layer for security key derivation.
- the PDCP PDU comprised in the security token field as described above may be either an (empty) data PDU (D-PDU) or an (empty) control PDU (C-PDU).
- D-PDU data PDU
- C-PDU control PDU
- the contents of the PDCP PDU may be either random bits, pre-defined information provided via RRC or additional control information provided by the CU to the terminal device concerning the mobility execution (e.g., related to DRB security keys).
- one or more of the fields illustrated in Figure 3 may be omitted.
- the cell identity field may be omitted (and the associated information may be communicated separately to the terminal device if it is not already available).
- the token identity field may be omitted if the RNT1 is used for scrambling/encoding as another example.
- Figure 4 illustrates signaling between a terminal device, a first distributed unit (first DU or DU 1) of an access node, a second distributed unit (second DU or DU 2) of the access node and a central unit (CU) of the access node according to an embodiment.
- the first DU may correspond to an initial serving distributed unit for the terminal device while the second DU may correspond to a target distributed unit for (potential) handover.
- the firstand second DUs maybe distributed units of the same access node (and thus connected to the same CU).
- the terminal device, the first and/or second DU and the CU may correspond, respectively, to one of the terminal devices 100, 102 of Figure 1, to the DU 104 of Figure 1 and to the CU 108 of Figure 1.
- the terminal device may initially be operating in an RRC connected mode and is being served via a serving cell provided by the first CU.
- the terminal device may initially be operating in an (RRC) inactive mode.
- the CU generates, in block 401, one or more encoded security tokens and associated one or more token identities for (Ll/2-based) handover based on one or more security keys.
- the one or more security keys may be pre-defined.
- the encoding may comprise, here and in the following, ciphering and/or integrity protection.
- the one or more encoded security tokens may be, for example, encoded PDCP security tokens.
- the CU transmits, in message 402, a first (Ll/2) mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to the first DU.
- a first (Ll/2) mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to the first DU.
- only the one or more encoded security tokens may be transmitted in message 402.
- the first DU receives, in block 403, the one or more encoded security tokens and the one or more token identities in the first mobility configuration message and stores, also in block 403, them to at least one memory.
- the CU also transmits, in elements 404 to 406, a second (Ll/2) mobility configuration message comprising at least one or all of the one or more encoded security tokens and/or of the one or more token identities to the terminal device via the first DU.
- the CU transmits, in message 404, the second mobility configuration message to the first DU and subsequently the first DU, upon receiving the second mobility configuration message in block 405, forwards the second mobility configuration message to the terminal device.
- message 404 may be omitted (as the same information is communicated already in message 402).
- the terminal device receives, in block 407, the second (Ll/2) mobility configuration message from the first DU. Subsequently, the terminal device configures, in block 407, itself according to the received second mobility configuration message. If no security tokens were included in the second mobility configuration message (but one or more token identities were), said configuring in block 407 may comprise, first, generating one or more security tokens based on one or more token identities comprised in the second mobility configuration message. Said configuring in block 407 may further comprise deriving (or generating) one or more security keys based on the one or more token identities either comprised in the second mobility configuration message or generated by the terminal device. The terminal device may, thereafter, operate using (Ll/2) mobility procedures defined in the second mobility configuration message.
- the terminal device may perform, in message 408, one or more (radio) measurements of a target cell provided by the second DU.
- the terminal device may generate, in block 409, a measurement report for the target cell based on the one or more measurements and transmits, in message 410, the measurement report for the target cell to the first DU for evaluation.
- the first DU may receive, in block 411, the measurement report and evaluates, in block 411, a need for executing a (Ll/2-based) handover from the serving cell provided by the first DU to the target cell provided by the second DU based at least on the measurement report.
- the evaluating in block 411 may take into account one or more further measurement reports pertaining to the target cell and/or one or more measurement report pertaining to the serving cell.
- the first DU may select, in block 413, one of the one or more encoded security tokens (that is, one of the one or more encoded security tokens configured to the terminal device by the CU) for (Ll/2- based) handover.
- the first DU transmits, in message 414, a mobility signaling element of the first and/or second protocol layer (e.g., Ll/2) to the terminal device.
- the mobility signaling element may be equally called or be comprised in a mobility command.
- the mobility signaling element comprises said selected one of the one or more encoded security tokens.
- the mobility signaling element may be, for example, a MAC CE or an RRC message.
- the terminal device receives, in block 415, the mobility signaling element. If the mobility signaling element is the MAC CE comprising a PDCP PDU corresponding to the encoded security token, the terminal device may forward, in block 415, said PDCP PDU to the PDCP layer for decoding.
- the terminal device decodes (e.g., deciphers and/or verifies integrity of), in block 416, the encoded security token comprised in the mobility signaling element using at least one of the one or more security keys which were configured to the terminal device in block 407 (being the same security key that was used for the encoding).
- the terminal device (or a PDCP entity thereof) may indicate, in block 417, handover execution to the RRC layer. In other words, if the decoding is successful, the terminal device may cause or trigger execution of the handover.
- the terminal device may indicate, in block 417, handover failure to the RRC layer.
- said failure indication may be omitted.
- the terminal device may, when the decoding is unsuccessful, switch from the RRC connected mode to an RRC idle or inactive mode. Additionally or alternatively, the terminal device may, when the decoding is unsuccessful, trigger an RRC re-establishment procedure. Additionally or alternatively, the terminal device may, when the decoding is unsuccessful, indicate the decoding failure over the RRC layer to the network (i.e., to the first and/or second DU). Based on said indication, the network (e.g., a first or second DU or the CU of the access node) may check whether or not an associated MAC CE for mobility (i.e., message 414) was transmitted by it or not. This may also allow the network to safely to update the security configuration via RRC.
- the network e.g., a first or second DU or the CU of the access node
- the network may check whether or not an associated MAC CE for mobility (i.e., message 414) was transmitted by it or not. This may also allow the network to safely to update the security configuration via RRC
- the terminal device may optionally also indicate, in message(s) 418, the mobility success or failure to the first DU and/or the second DU via MAC CE(s). This may allow the network to determine whether or how it should retransmit the mobility signaling element (or the mobility command).
- the first and second DUs receive, in blocks 419, 420, said indication.
- said indication 418 may be transmitted also to the CU (e.g., using RRC signaling).
- a PDCP entity e.g., of SRB1 or of any other SRB or DRB
- a DU of an access node may be configured to generate a MAC CE and provide it to a CU of the access node (or specifically to the given PDCP entity thereof) for MAC-1 generation.
- the resulting MAC-1 is then embedded into the MAC CE in a similar manner as discussed above (e.g., in connection with Figure 3) for the PDCP PDU.
- the terminal device may, then, be configured to provide the whole MAC CE and the embedded MAC-1 to the PDCP entity of the terminal device for integrity verification.
- the MAC CE should introduce some kind of token identity which can be changed for each MAC CE so as not to use the same MAC-1 multiple times.
- the decoding may be performed on MAC layer (L2) if the RNT1 is used for scrambling/encoding of the mobility signaling element.
- the MAC layer may decide whether or not the decoding is considered a success and thus whether or not to transmit the results of the decoding to RRC layer.
- a distributed unit of an access node may be configured to transmit the MAC CE for the mobility command without any security material (e.g., without the PDCP PDU/MAC-1, security token and so on). This may occur specifically in the case where one or more control plane (CP) and/or user plane (UP) packets are transmitted, by the distributed unit, to the terminal device along with the same MAC PDU as the MAC CE of the mobility command.
- the terminal device may be configured to determine the integrity of the network based on the one or more CP and/or UP packet(s) received.
- Figure 5 provides an apparatus 501 according to some embodiments. Specifically, Figure 5 may illustrate an apparatus 501 configured to carry out at least some of the functions described above in connection with performing (lower layer) mobility in a secure manner.
- the apparatus may be or form a part of a terminal device, a distributed unit of a distributed access node or a central unit of a distributed access node.
- the apparatus 501 may comprise one or more control circuitry 520, such as at least one processor, and/or at least one memory 530, including one or more algorithms 531, such as a computer program code (software) wherein the at least one memory and the computer program code (software) are configured, with the at least one processor, to cause the apparatus 501 to carry out any one of the exemplified functionalities of the terminal device, the distributed unit of an access node or a central unit of an access node.
- Said at least one memory 530 may also comprise at least one database 532.
- the one or more communication control circuitry 520 of the apparatus 501 comprise at least mobility circuitry 521 which is configured to perform the secure mobility functionalities according to embodiments.
- the mobility circuitry 521 may be configured to perform functionalities described in connection with the terminal device, the (first and/or second) distributed unit or the central unit described above, e.g., by means of any of elements of any of Figures 2A, 2B, 2C, 3 and 4, using one or more individual circuitries.
- the memory 530 may be implemented using any suitable data storage technology, such as semiconductor based memory devices, flash memory, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory.
- the apparatus 501 may further comprise different interfaces 510 such as one or more communication interfaces (TX/RX) comprising hardware and/or software for realizing communication connectivity according to one or more communication protocols.
- the one or more communication interfaces 510 may comprise, for example, interfaces providing a connection to the Internet and a core network of a wireless communications network.
- the one or more communication interface 510 may provide the apparatus with communication capabilities to communicate in a cellular communication system and enable communication with user devices (terminal devices) and different network nodes or elements (e.g., distributed and/or central units of access nodes) and/or a communication interface to enable communication between different network nodes or elements, for example.
- the one or more communication interfaces 510 may comprise standard well-known components such as an amplifier, filter, frequencyconverter, (de)modulator, and encoder/decoder circuitries, controlled by the corresponding controlling units, and one or more antennas.
- circuitry may refer to one or more or all of the following: (a) hardware-only circuit implementations, such as implementations in only analog and/or digital circuitry, and (b) combinations of hardware circuits and software (and/or firmware), such as (as applicable): (i) a combination of analog and/or digital hardware circuit(s) with software/firmware and (ii) any portions of hardware processor(s) with software, including digital signal processor(s), software, and memory(ies) that work together to cause an apparatus, such as a terminal device or an access node, to perform various functions, and (c) hardware circuit(s) and processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g.
- circuitry for operation, but the software may not be present when it is not needed for operation.
- circuitry applies to all uses of this term in this application, including any claims.
- the term ‘circuitry’ also covers an implementation of merely a hardware circuit or processor (or multiple processors) or a portion of a hardware circuit or processor and its (or their) accompanying software and/or firmware.
- circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit for an access node or a terminal device or other computing or network device.
- At least some of the processes described in connection with Figures 2A, 2B, 2C, 3 and 4 may be carried out by an apparatus comprising corresponding means for carrying out at least some of the described processes.
- Some example means for carrying out the processes may include at least one of the following: detector, processor (including dual-core and multiple-core processors), digital signal processor, controller, (radio) receiver, (radio) transmitter, (radio) transceiver, encoder, decoder, memory, RAM, ROM, software, firmware, display, user interface, display circuitry, user interface circuitry, user interface software, display software, circuit, antenna, antenna circuitry, and circuitry.
- said means comprise at least at least one processor and a (radio) transceiver.
- the at least one processor, the memory, and the computer program code form processing means or comprises one or more computer program code portions for carrying out one or more operations according to any one of the embodiments of 2A, 2B, 2C, 3 and 4 or operations thereof.
- an apparatus e.g., a terminal device or a part thereof comprising means for performing: obtaining one or more security keys for handover; receiving a mobility signaling element of a first and/or second protocol layer (e.g., of Ll/2), wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
- a mobility signaling element of a first and/or second protocol layer e.g., of Ll/2
- an apparatus e.g., a terminal device or a part thereof comprising at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code being configured, with the at least one processor, to cause the apparatus at least to perform: obtaining one or more security keys for handover; receiving a mobility signaling element of a first and/or second protocol layer (e.g., of Ll/2), wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
- a mobility signaling element of a first and/or second protocol layer e.g., of Ll/2
- an apparatus e.g., a central unit of an access node or a part thereof comprising means for performing: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys; transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein said at least one second mobility configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
- an apparatus e.g., a central unit of an access node or a part thereof comprising at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code being configured, with the at least one processor, to cause the apparatus at least to perform: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys; transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein said at least one second mobility configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
- an apparatus e.g., a distributed unit of an access node or a part thereof comprising means for performing: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; and in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of the first and / or second protocol layer (e.g., Ll/2) to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
- a mobility signaling element of the first and / or second protocol layer e.g., Ll/2
- an apparatus e.g., a distributed unit of an access node or a part thereof comprising at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code being configured, with the at least one processor, to cause the apparatus at least to perform: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of the first and / or second protocol layer (e.g., Ll/2] to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
- a mobility signaling element of the first and / or second protocol layer
- Embodiments as described may also be carried out in the form of a computer process defined by a computer program or portions thereof. Embodiments of the methods described in connection with Figures 2A, 2B, 2C, 3 and 4 may be carried out by executing at least one portion of a computer program comprising corresponding instructions.
- the computer program may be provided as a computer readable medium comprising program instructions stored thereon or as a non-transitory computer readable medium comprising program instructions stored thereon.
- the computer program may be in source code form, object code form, or in some intermediate form, and it may be stored in some sort of carrier, which may be any entity or device capable of carrying the program.
- the computer program may be stored on a computer program distribution medium readable by a computer or a processor.
- the computer program medium may be, for example but not limited to, a record medium, computer memory, read-only memory, electrical carrier signal, telecommunications signal, and software distribution package, for example.
- the computer program medium maybe a non-transi- tory medium. Coding of software for carrying out the embodiments as shown and described is well within the scope of a person of ordinary skill in the art.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
According to an aspect, there is provided an apparatus for performing the following. The apparatus obtains one or more security keys for handover. Then, the apparatus receives a mobility signaling element of a first and/or second protocol layer. The mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys. Finally, the apparatus decodes the encoded security token using the at least one of the one or more security keys.
Description
METHOD AND APPARATUS FOR SECURE LOWER LAYER MOBILITY
TECHNICAL FIELD
Various example embodiments relate to wireless communications.
BACKGROUND
Fifth Generation (5G) New Radio (NR) Release 18 aims to enable the so- called layer 1/layer 2 (Ll/2) -mobility, which in practice means that the control of mobility would be moved from the central unit (CU) of the access node to the distributed unit(s) (DU(s)) of the access node. Thus, the handover could be activated, e.g., via the medium access control (MAC) layer. One of the possible modes for DU- based mobility is the inter-DU mobility, i.e., mobility between cells within the same CU but different DUs. However, the present L1/L2 inter-DU mobility schemes have problems when it comes to enabling secure communications when inter-DU mobility occurs.
SUMMARY
According to an aspect, there is provided the subject matter of the independent claims. Embodiments are defined in the dependent claims.
According to an aspect, there is provided an apparatus comprising: at least one processor; and at least one transceiver, wherein the at least one processor is configured to: obtain one or more security keys for handover; wherein the at least one transceiver is configured to: receive a mobility signaling element of a first and/or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and wherein the at least one processor is configured to: decode the encoded security token using the at least one of the one or more security keys.
According to an aspect, there is provided an apparatus comprising: at least one processor; and at least one transceiver, wherein the at least one processor is configured to: generate one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys,
wherein the at least one transceiver is configured to: transmit at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmit at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein the second configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
According to an aspect, there is provided an apparatus comprising: at least one processor; and at least one transceiver, wherein the at least one transceiver is configured to: receive at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; and in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forward said at least one second mobility configuration message to a terminal device, wherein the at least one processor is configured to: select one of the one or more encoded security tokens for handover, wherein the at least one transceiver is configured to: transmit a mobility signaling element of the first and/or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
According to an aspect, there is provided a method comprising: obtaining one or more security keys for handover; receiving a mobility signaling element of a first and/or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
According to an aspect, there is provided a method comprising: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys,
transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein the second configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
According to an aspect, there is provided a method comprising: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; and in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of the first and / or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the following: obtaining one or more security keys for handover; receiving a mobility signaling element of a first and/or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the following: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys,
transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein the second configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the following: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of the first and / or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
According to an embodiment, there is provided an apparatus comprising means for performing: obtaining one or more security keys for handover; receiving a mobility signaling element of a first and/or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
According to an embodiment, there is provided an apparatus comprising at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code being configured, with the at least one processor, to cause the apparatus at least to perform: obtaining one or more security keys for handover;
receiving a mobility signaling element of a first and/or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
According to an embodiment, there is provided an apparatus comprising means for performing: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys; transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein said at least one second mobility configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities
According to an embodiment, there is provided an apparatus comprising at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code being configured, with the at least one processor, to cause the apparatus at least to perform: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys; transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein said at least one second mobility configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities
According to an embodiment, there is provided an apparatus comprising means for performing: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; and in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or
of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of the first and / or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
According to an embodiment, there is provided an apparatus comprising at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code being configured, with the at least one processor, to cause the apparatus at least to perform: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of a first and/or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
According to an aspect, there is provided a computer program comprising instructions for causing an apparatus to perform at least the following: obtaining one or more security keys for handover; receiving a mobility signaling element of a first and/or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
According to an aspect, there is provided a computer program comprising instructions for causing an apparatus to perform at least the following: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys,
transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein the second configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
According to an aspect, there is provided a computer program comprising instructions for causing an apparatus to perform at least the following: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of a first and/or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
One or more examples of implementations are set forth in more detail in the accompanying drawings and the description below. Other features will be apparent from the description and drawings, and from the claims.
BRIEF DESCRIPTION OF DRAWINGS
In the following, example embodiments will be described in greater detail with reference to the attached drawings, in which
Figure 1 illustrates an exemplified wireless communication system;
Figure 2A, figure 2B and figure 2C illustrate exemplary processes according to embodiments;
Figure 3 illustrates an example of a medium access control control element (MAC CE) structure for a mobility signaling element according to an embodiment;
Figure 4 illustrates signaling between at terminal device, a first (source) distributed unit of an access node, a second (target) distributed unit of the access node and the central unit of the access node according to an embodiment; and
Figure 5 illustrates an apparatus according to embodiments.
DETAILED DESCRIPTION OF SOME EMBODIMENTS
The following embodiments are only presented as examples. Although the specification may refer to “an”, “one”, or “some” embodiment(s) and/or example's) in several locations of the text, this does not necessarily mean that each reference is made to the same embodiment(s) or example(s), or that a particular feature only applies to a single embodiment and/or example. Single features of different embodiments and/or examples may also be combined to provide other embodiments and/or examples.
The terms “layer 1”, “layer 2” and “layer 3” (abbreviated as LI, L2 and L3) as used in this application refer to layers of an Open Systems Interconnection (OS1) model. In the OS1 model, layer 1 corresponds to a physical layer, layer 2 corresponds to a data link layer and layer 3 correspond to a network layer. The term “Ll/2” as used in the following (e.g., in “Ll/2 mobility” or “Ll/2-based handover”) may imply operation on layer 1 or on layer 2 or on layers 1 & 2.
In the following, different exemplifying embodiments will be described using, as an example of an access architecture to which the embodiments may be applied, a radio access architecture based on long term evolution advanced (LTE Advanced, LTE-A) or new radio (NR, 5G), without restricting the embodiments to such an architecture, however. It is obvious for a person skilled in the art that the embodiments may also be applied to other kinds of communications networks having suitable means by adjusting parameters and procedures appropriately. Some examples of other options for suitable systems are the universal mobile telecommunications system (UMTS) radio access network (UTRAN or E-UTRAN), long term evolution (LTE, the substantially same as E-UTRA), wireless local area network (WLAN or WiFi), worldwide interoperability for microwave access (WiMAX), Bluetooth®, personal communications services (PCS), ZigBee®, wideband code division multiple access (WCDMA), systems using ultra-wideband (UWB) technology, sensor networks, mobile ad-hoc networks (MANETs) and Internet Protocol multimedia subsystems (IMS) or any combination thereof.
Figure 1 depicts examples of simplified system architectures showing some elements and functional entities, all being logical units, whose implementation may differ from what is shown. The connections shown in Figure 1 are logical connections; the actual physical connections may be different. It is apparent to a
person skilled in the art that the system typically comprises also other functions and structures than those shown in Figure 1.
The embodiments are not, however, restricted to the system given as an example but a person skilled in the art may apply the solution to other communication systems provided with necessary properties.
The example of Figure 1 shows a part of an exemplifying radio access network.
Figure 1 shows user devices 100 and 102 configured to be in a wireless connection on one or more communication channels in a cell with an access node (such as (e/g)NodeB) 104 providing the cell. The physical link from a user device to a (e/g)NodeB is called uplink or reverse link and the physical link from the (e/g)NodeB to the user device is called downlink or forward link. It should be appreciated that (e/g)NodeBs or their functionalities may be implemented by using any node, host, server or access point etc. entity suitable for such a usage.
A communications system typically comprises more than one (e/g)NodeB in which case the (e/g)NodeBs may also be configured to communicate with one another over links, wired or wireless, designed for the purpose. These links may be used for signaling purposes. The (e/g)NodeB is a computing device configured to control the radio resources of communication system it is coupled to. The NodeB may also be referred to as a base station, an access point or any other type of interfacing device including a relay station capable of operating in a wireless environment. The (e/g) NodeB includes or is coupled to transceivers. From the transceivers of the (e/g) NodeB, a connection is provided to an antenna unit that establishes bi-directional radio links to user devices. The antenna unit may comprise a plurality of antennas or antenna elements. The (e/g) NodeB is further connected to core network 110 (CN or next generation core NGC). Depending on the system, the counterpart on the CN side can be a serving gateway (S-GW, routing and forwarding user data packets), packet data network gateway (P-GW), for providing connectivity of user devices (UEs) to external packet data networks, or mobile management entity (MME), etc.
The user device (also called UE, user equipment, user terminal, terminal device, etc.) illustrates one type of an apparatus to which resources on the air interface are allocated and assigned, and thus any feature described herein with a user device may be implemented with a corresponding apparatus, such as a relay node. An example of such a relay node is a layer 3 relay (self-backhauling relay) towards the base station.
The user device typically refers to a portable computing device that includes wireless mobile communication devices operating with or without a subscriber identification module (SIM), including, but not limited to, the following types of devices: a mobile station (mobile phone), smartphone, personal digital assistant (PDA), handset, device using a wireless modem (alarm or measurement device, etc.), laptop and/or touch screen computer, tablet, game console, notebook, and multimedia device. It should be appreciated that a user device may also be a nearly exclusive uplink only device, of which an example is a camera or video camera loading images or video clips to a network. A user device may also be a device having capability to operate in Internet of Things (loT) network which is a scenario in which objects are provided with the ability to transfer data over a network without requiring human-to-human or human-to-computer interaction. The user device (or in some embodiments a layer 3 relay node) is configured to perform one or more of user equipment functionalities. The user device may also be called a subscriber unit, mobile station, remote terminal, access terminal, user terminal or user equipment (UE) just to mention but a few names or apparatuses.
Various techniques described herein may also be applied to a cyberphysical system (CPS) (a system of collaborating computational elements controlling physical entities). CPS may enable the implementation and exploitation of massive amounts of interconnected ICT devices (sensors, actuators, processors microcontrollers, etc.) embedded in physical objects at different locations. Mobile cyber physical systems, in which the physical system in question has inherent mobility, are a subcategory of cyber-physical systems. Examples of mobile physical systems include mobile robotics and electronics transported by humans or animals.
It should be understood that, in Figure 1, user devices are depicted to include 2 antennas only for the sake of clarity. The number of reception and/or transmission antennas may naturally vary according to a current implementation.
Additionally, although the apparatuses have been depicted as single entities, different units, processors and/or memory units (not all shown in Figure 1) may be implemented.
5G enables using multiple input - multiple output (M1M0) antennas, many more base stations or nodes than the LTE (a so-called small cell concept), including macro sites operating in co-operation with smaller stations and employing a variety of radio technologies depending on service needs, use cases and/or spectrum available. 5G mobile communications supports a wide range of use cases and related applications including video streaming, augmented reality, different
ways of data sharing and various forms of machine type applications, including vehicular safety, different sensors and real-time control. 5G is expected to have multiple radio interfaces, namely below 6GHz, cmWave and mmWave, and also being integratable with existing legacy radio access technologies, such as the LTE. Integration with the LTE may be implemented, at least in the early phase, as a system, where macro coverage is provided by the LTE and 5G radio interface access comes from small cells by aggregation to the LTE. In other words, 5G is planned to support both inter-RAT operability (such as LTE-5G) and inter-Rl operability (inter-radio interface operability, such as below 6GHz - cmWave, below 6GHz - cmWave - mmWave). One of the concepts considered to be used in 5G networks is network slicing in which multiple independent and dedicated virtual sub-networks (network instances) may be created within the substantially same infrastructure to run services that have different requirements on latency, reliability, throughput and mobility.
The current architecture in LTE networks is fully distributed in the radio and fully centralized in the core network. The low latency applications and services in 5G require to bring the content close to the radio which leads to local break out and multi-access edge computing (MEC). 5G enables analytics and knowledge generation to occur at the source of the data. This approach requires leveraging resources that may not be continuously connected to a network such as laptops, smartphones, tablets and sensors. MEC provides a distributed computing environment for application and service hosting. It also has the ability to store and process content in close proximity to cellular subscribers for faster response time. Edge computing covers a wide range of technologies such as wireless sensor networks, mobile data acquisition, mobile signature analysis, cooperative distributed peer- to-peer ad hoc networking and processing also classifiable as local cloud/fog computing and grid/mesh computing, dew computing, mobile edge computing, cloudlet, distributed data storage and retrieval, autonomic self-healing networks, remote cloud services, augmented and virtual reality, data caching, Internet of Things (massive connectivity and/or latency critical), critical communications (autonomous vehicles, traffic safety, real-time analytics, time-critical control, healthcare applications).
The communication system is also able to communicate with other networks, such as a public switched telephone network or the Internet 112, or utilize services provided by them. The communication network may also be able to support the usage of cloud services, for example at least part of core network operations may be carried out as a cloud service (this is depicted in Figure 1 by “cloud”
114). The communication system may also comprise a central control entity, or a like, providing facilities for networks of different operators to cooperate for example in spectrum sharing.
Edge cloud may be brought into radio access network (RAN) by utilizing network function virtualization (NVF) and software defined networking (SDN). Using edge cloud may mean access node operations to be carried out, at least partly, in a server, host or node operationally coupled to a remote radio head or base station comprising radio parts. It is also possible that node operations will be distributed among a plurality of servers, nodes or hosts. Application of cloudRAN architecture enables RAN real time functions being carried out at the RAN side (in a distributed unit, DU 104) and non-real time functions being carried out in a centralized manner (in a central or centralized unit, CU 108).
It should also be understood that the distribution of labor between core network operations and base station operations may differ from that of the LTE or even be non-existent. Some other technology advancements probably to be used are Big Data and all-lP, which may change the way networks are being constructed and managed. 5G (or new radio, NR) networks are being designed to support multiple hierarchies, where MEC servers can be placed between the core and the base station or nodeB (gNB). It should be appreciated that MEC can be applied in 4G networks as well.
5G may also utilize satellite communication to enhance or complement the coverage of 5G service, for example by providing backhauling. Possible use cases are providing service continuity for machine-to-machine (M2M) or Internet of Things (loT) devices or for passengers on board of vehicles, or ensuring service availability for critical communications, and future railway/maritime/aeronautical communications. Satellite communication may utilize geostationary earth orbit (GEO) satellite systems, but also low earth orbit (LEO) satellite systems, in particular mega-constellations (systems in which hundreds of (nano) satellites are deployed). At least one satellite 106 in the mega-constellation may cover several satellite-enabled network entities that create on-ground cells. The on-ground cells may be created through an on-ground relay node 104 or by a gNB located on- ground or in a satellite.
It is obvious for a person skilled in the art that the depicted system is only an example of a part of a radio access system and in practice, the system may comprise a plurality of (e/g)NodeBs, the user device may have an access to a plurality of radio cells and the system may comprise also other apparatuses, such as physical layer relay nodes or other network elements, etc. At least one of the
(e/g)NodeBs or may be a Home(e/g)nodeB. Additionally, in a geographical area of a radio communication system a plurality of different kinds of radio cells as well as a plurality of radio cells may be provided. Radio cells may be macro cells (or umbrella cells) which are large cells, usually having a diameter of up to tens of kilometers, or smaller cells such as micro-, femto- or picocells. The (e/g)NodeBs of Figure 1 may provide any kind of these cells. A cellular radio system may be implemented as a multilayer network including several kinds of cells. Typically, in multilayer networks, one access node provides one kind of a cell or cells, and thus a plurality of (e/g)NodeBs are needed to provide such a network structure.
For fulfilling the need for improving the deployment and performance of communication systems, the concept of “plug-and-play” (e/g)NodeBs has been introduced. Typically, a network which is able to use “plug-and-play” (e/g)Node Bs, includes, in addition to Home (e/g)NodeBs (H(e/g)nodeBs), a home node B gateway, or HNB-GW (not shown in Figure 1). A HNB Gateway (HNB-GW), which is typically installed within an operator’s network may aggregate traffic from a large number of HNBs back to a core network.
Sixth Generation (6G) networks are expected to adopt flexible decentralized and/or distributed computing systems and architecture and ubiquitous computing, with local spectrum licensing, spectrum sharing, infrastructure sharing, and intelligent automated management underpinned by mobile edge computing, artificial intelligence, short-packet communication and blockchain technologies. Key features of 6G will include intelligent connected management and control functions, programmability, integrated sensing and communication, reduction of energy footprint, trustworthy infrastructure, scalability and affordability. In addition to these, 6G is also targeting new use cases covering the integration of localization and sensing capabilities into system definition to unifying user experience across physical and digital worlds.
The (access node) functions may be split between the CU 108 and the DU 104 of the system of Figure 1 in several different ways. For example, the CU 108 may host radio resource control (RRC) and packet data convergence protocol (PDCP) layers for control plane and service data application protocol (SDAP) and PDCP layers for user plane and the DU 104 may host the radio link control (RLC) and MAC layers and layer- 1/physical layer (Ll/PHY). In other systems (e.g., future 6G systems), the RLC may be split between the CU 108 and DU 104.
The system of Figure 1 may be a (5G NR or 6G) communication system configured to support L1/L2 mobility or more specifically at least L1/L2 inter-cell mobility. In L1/L2 mobility, the control of mobility is moved from the CU to the DU
and therefore may be activated, e.g., via the MAC layer or PHY layer. There are two modes for DU-based mobility: 1) intra-DU mobility (i.e., mobility between cells within the same DU) and 2) inter-DU mobility (i.e. mobility between cells within the same CU but different DUs). For intra-DU mobility, DU has all the information needed to decide on the serving cell change. The embodiments to be discussed below are targeting specifically the inter-DU mobility and overcoming certain problems associated with it (to be discussed below). However, the embodiments are equally applicable to the intra-DU mobility cases.
In contrast to layer 3 (L3) mobility procedures where the handover between two cells is decided by the RRC layer, the Ll/2 inter-cell mobility may be performed (predominantly) by the MAC layer terminated in the DU.
The main steps of an exemplary execution of L1/L2 inter-cell mobility between an (initial) serving cell provided by a first distributed unit (DU1) and a target cell provided by a second distributed units (DU2) of an access node (gNB) are summarized in the following:
1) Initially, a terminal device (UE) sends measurement report containing the cell quality measurements of serving and neighboring cells via the DU1 to a central unit (CU) of the access node. The terminal device may be configured by the serving cell (i.e., by the DU1) to send the measurement report early when it still has a good connection to the serving cell (i.e., to the DU1).
2) Using the reported cell quality measurements, the CU is able to identify a potential set of candidate target cells to which the terminal device can be handed over. In this example, the CU identifies candidate target cells that are served by the DU1 (controlling the serving DU/cell as well) and another DU2 that is controlled by the same CU.
3) The CU requests the preparation of a candidate target cell controlled by DU1 by sending UE context setup request message to the DU1.
4) In response to receiving the UE context setup request, the DU1 transmits information on a configuration of the terminal device in a UE context setup response message containing a container to the CU.
5) The steps 3) -4) are performed in a similar manner between the CU and the DU2 in order to prepare target cell(s) that are controlled by DU2.
6) Having received the terminal device’s configurations for the candidate target cell(s), the CU generates an RRC Reconfiguration that is sent from the CU to the terminal device (via the DU1). The RRC Reconfiguration message may comprise at least measurement reporting configuration for Ll/2 handover, i.e., configuration on how to report the LI beam measurements of serving and target
cells and configuration of the prepared candidate cell(s) which the terminal device needs to execute when it receives a MAC CE command to change the serving cell (perform handover).
7) The terminal device receives/obtains the RRC reconfiguration message and transmits an RRC reconfiguration complete message back to the CU (via the DU1).
8) The terminal device starts to report periodically the LI beam measurement of serving and candidate target cells.
9) Upon determining that there is a target candidate cell having a better radio link/beam measurement than the serving cell, e.g., Ll-reference signal received power (RSRP) of target beam measurement is larger than Ll-RSRP of serving beam measurement summed with an offset for an amount of time e.g., time -to- trigger (TTT), the DU1 sends a MAC CE or a LI message to the terminal device for triggering the cell change to the target candidate cell.
10) Finally, the terminal device may perform handover from the serving cell to the target cell.
As described above in connection with step 9), the Ll/2 mobility may be carried out via a MAC CE transmitted towards the terminal device. However, this solution has one serious downside: MAC CEs are sent in plaintext, i.e., without any ciphering or integrity protection. This means that once a terminal device is configured with Ll/2 mobility, a rogue access node (rogue gNB) could start sending Ll/2 mobility commands to the terminal device and either cause a DoS attack or force the terminal device to perform additional (unwanted) procedures. It should be noted no such problem exists with L3 mobility since RRC commands are both ciphered and integrity protected and thus it is not possible to spoof the L3 mobility command as easily. Additionally, ciphering and integrity protection are performed in packet data convergence protocol (PDCP) layer. Thus, it is not desirable to duplicate those ciphering and integrity protection functions in MAC layer even for this purpose. Similarly, if any layer below PDCP is used for the Ll/2 mobility purpose, e.g., RLC, MAC or PHY/L1, the same problem exists.
The embodiments to be discussed below in detail seek to overcome or alleviate at least some of the problems described above relating vulnerability of (Ll/2) mobility to cyber attacks (e.g., to DoS attacks).
Figures 2A, 2B and 2C illustrate processes carried out (in parallel) by a terminal device, a central unit (CU) of an access node and a distributed unit (DU) of the access node. Here, it is assumed that the terminal device is communicatively
connected at least to the DU, the DU is communicatively connected to both the terminal device and the CU and the CU is communicatively connected at least to the DU (and to a core network). The DU may be specifically a DU providing a serving cell used at the start of each of the processes for serving the terminal device. The terminal device, the DU and the CU may correspond, respectively, to one of the terminal devices 100, 102 of Figure 1, to the DU 104 of Figure 1 and to the CU 108 of Figure 1. In the following, any of the definitions provided in connection with one of Figures 2A, 2B and 2C may apply equally for the others of Figures 2A, 2B and 2C.
Referring to Figure 2A, it may be initially assumed that the terminal device is being served via a serving cell provided by a DU of an access node. The terminal device may be operating a RRC connected mode (with said DU).
The terminal device obtains, in block 201, one or more security keys for handover (i.e., to be used for a handover or at least a handover attempt). The handover may correspond here at least to first and/or second protocol layer -based handover. The first and second protocol layers may comprise (or be), respectively, the physical layer of 3PGG protocol architecture and the MAC layer of the 3GPP protocol architecture. The first and second protocol layers may correspond to OS1 layers 1 and 2 (LI & L2), i.e., to physical and data link layers, respectively. Alternatively, each of the first and second protocol layers may correspond to or comprise any of the 3GPP defined layers or sublayers, e.g., PHY /LI, MAC, RLC, PDCP and RRC. The one or more security keys are usable for decoding associated encoded security tokens. The one or more security keys may have been configured using the RRC protocol before decoding the encoded security tokens.
In some embodiments, the obtaining in block 201 may comprise receiving information suitable for deriving said one or more security keys (e.g., from said DU providing the serving cell or from the CU) and subsequently deriving the one or more security keys based on said information. Said information suitable for deriving said one or more security keys may be transmitted as a part of a (second) mobility configuration message for (Ll/2) mobility configuration of the terminal device (as will be discussed in more detail in connection with Figure 2B). Specifically, said information suitable for deriving said one or more security keys may be or comprise one or more (security) token identities.
In some embodiments, the one or more security keys comprise one or more security keys for one or more signalling radio bearers (SRBs) and/or one or more security keys for one or more data radio bearers (DRBs).
The terminal device receives, in block 202, a mobility signaling element of the first and/or second protocol layer. The mobility signaling element may be or
form a part of a mobility command. For example, the mobility signaling element may be an Ll/2 mobility signaling element. The mobility signaling element comprises an encoded security token which has been encoded (e.g., ciphered and/or integrity protected) using at least one of the one or more security keys. The transmission and subsequent reception of the mobility signaling element may be indicative of a decision by the access node (or specifically by the DU) that (Ll/2) mobility to a particular target cell is to be executed. Said target cell may be specifically a cell provided by another DU of the same access node (i.e., connected to the same CU) or a cell provided by the same DU of the same access node.
In some embodiments, said first and/or second protocol layer associated with the mobility signaling element comprise or consist of one or two of the physical layer, the MAC layer and the RLC layer.
In other embodiments, said first and/or second protocol layer associated with the mobility signaling element comprise or consist of one or two of the physical layer, the MAC layer, the RLC layer and the PDCP layer.
In other embodiments, said first and/or second protocol layer associated with the mobility signaling element comprise or consist of one or two of the physical layer, the MAC layer, the RLC layer, the PDCP layer and the RRC layer.
In some embodiments, the mobility signaling element may be or comprise a MAC CE. In some alternative embodiments, the mobility signaling element may be or comprise downlink control information (DC1). The DC1 may be provided by the Physical Downlink Control Channel (PDCCH) of the physical layer (LI).
The encoded security token comprised in the mobility signaling element (e.g., a MAC CE) may be or correspond to a PDCP protocol data unit (PDU). Said PDCP PDU may be either a data PDU or a control PDU. In such embodiments, the terminal device may, upon reception of the mobility signaling element, forward the PDCP PDU (i.e., the encoded security token) to the PDCP layer. The subsequent decoding (i.e., block 203) may be carried out by the PDCP layer.
In some alternative embodiments, the encoded security token comprised in the mobility signaling element (e.g., a MAC CE) may be or correspond to an encoded message authentication code for an integrity protection check (e.g., an encoded message authentication code for integrity, MAC-1). In some examples, the encoded message authentication code may be checked for integrity protection by the PDCP layer.
The encoded and/or decoded security token may comprise random data (i.e., random bits), pre-defined data (provided via RRC) or additional control
information. Said additional control information may be control information provided by the CU to the terminal device. Said additional control information may concern, e.g., control information relating to the mobility execution (e.g., related to DRB security keys and/or related to the target cell for the handover).
In some embodiments, the mobility signaling element or at least the security token may have been scrambled (by the DU or CU) using a radio network temporary identifier (RNT1) for indicating that a payload or at least part of the mobility signaling element has been ciphered and/or integrity protected. In this case, the security key comprises the RNT1.
The terminal device decodes, in block 203, the encoded security token using said at least one of the one or more security keys. The decoding may be performed specifically using a PDCP entity of the terminal device. Information identifying said at least one of the one or more security keys (i.e., information for determining which of the one or more security keys should be used for the decoding in block 203) may be comprised in the mobility signaling element. For example, the mobility signaling element (e.g., the MAC CE) may comprise a token identity (equally called a security token identity). The token identity (or token identity field) serves to identify which of the one or more security keys is to be used for decoding the encoded security token.
When RNT1 is used to scramble the mobility signaling element or at least a part of the mobility signaling element (e.g., the encoded security token), the RNT1 may not be explicitly indicated in the mobility signaling element (e.g., MAC CE). The decoding may be done in MAC layer (L2).
The decoding in block 203 may comprise deciphering and/or verifying integrity of the ciphered and/or integrity protected security token, respectively. Both deciphering and integrity verification may be performed in PDCP. The decoding in block 203 may, additionally or alternatively, comprise descrambling the mobility signaling element or a part of the mobility signaling element (e.g., the encoded security token) to obtain at least the security token.
Upon successful decoding in block 203, the terminal device may trigger or cause execution of handover from the serving cell to the target cell (the target cell being specified, e.g., in the mobility signaling element). Specifically, the terminal device may (initially) indicate (Ll/2) handover execution from the PDCP entity or other entity performing the integrity verification to RRC and/or MAC layer. The transmitted indication of the (Ll/2) handover execution may comprise a mobility command. In some examples, the (encoded) security token may be provided in
same or different mobility signaling element (e.g., MAC CE) as the actual mobil- ity/handover command. In other words, for example, the (encoded) security token and the actual mobility /handover command may be transmitted as separate MAC CEs or within the same MAC CE.
Upon unsuccessful decoding (not shown in Figure 2A), the terminal device may indicate (Ll/2) handover failure (from PDCP entity or other entity performing the integrity verification) to RRC layer. In such a case, the encoded security token may be simply discarded.
In some embodiments, the terminal device may cause transmission of one or more RRC messages indicating that the decoding was successful (or that the decoding was not successful, if this is the case) to one or more distributed units of one or more access nodes (e.g., to old and/or new serving distributed units). The RRC message may be transmitted via a MAC CE.
Referring to Figure 2B, it may be assumed that the CU of the access node is initially configured with one or more security keys.
The CU generates, in block 211, one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys. Here, the generating of the one or more encoded security tokens may comprise ciphering and/or integrity protecting of one or more security tokens.
The CU transmits, in block 212, a first (Ll/2) mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a DU of the access node (or multiple DUs of the access node). The DU is configured to store the one or more encoded security tokens and the one or more token identities to at least one memory, to configure terminal device (s) based on them and to use them for triggering the (Ll/2) handover in a data secure manner, as will be described below in connection with Figure 2C.
In some alternative embodiments, a plurality of (first) mobility messages may be transmitted from the CU to the DU for communicating the one or more encoded security tokens and the one or more token identities to the DU. For example, the one or more token identities may be communicated in an initial first mobility message and the one or more security tokens may be communicated in a subsequent first mobility message.
The CU transmits, in block 213, a second (Ll/2) mobility configuration message for first and/or second protocol layer (e.g., Ll/2) mobility of a terminal device to the terminal device via the DU (being specifically a DU providing a serving cell of the terminal device). The second (Ll/2) mobility configuration message may
be transmitted via RRC signalling. The second mobility configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities. It may be especially beneficial if the one or more token identities (but not the one or more security tokens themselves) are included in the transmitted second mobility configuration message as transmitting of the one or more security tokens may render the solution vulnerable to plaintext attacks. The decision regarding which security tokens and/or token identities to transmit to the terminal device may be based on RRC configuration of the terminal device.
In some alternative embodiments, a plurality of (second) mobility messages may be transmitted from the CU via the DU to the terminal device for communicating said at least one or all of the one or more security tokens and of the one or more token identities. For example, the one or more token identities (or at least some of them) may be communicated in an initial second mobility message and the one or more security tokens (or at least some of them) may be communicated in a subsequent second mobility message.
To give an example of the terminal device operation. Assume the terminal device is configured with RRC signaling (i.e., using the second mobility configuration message) so that it is aware that there exists a security token with RNT1 = 12 (decimal number), which is associated with token identity = 5 (decimal number). It is assumed that these correspond to a specific encoded token = 0xal2317300 (hexadecimal number). Then, the terminal device receives (as a part of a mobility signaling element) the token identity which is equal to 5 with the security token being equal to 0xal2317300. Based on the RRC configuration, the terminal device is able to understand that the token identity having value of 5 is associated with the RNT1 (or in general, with a particular security key comprising said RNT1) having the value of 12, so it can decode the security token value to check whether or not contains the correct RNT1.
Referring to Figure 2C, it may be initially assumed that the DU of the access node is initially communicatively connected to a terminal device operating in the RRC connected mode.
The DU receives, in block 221, a first mobility configuration message (or at least one first mobility configuration message) comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node (as described in connection with block 212 above). In other words, the CU configures the DU with the one or more encoded security tokens and associated one or more token identities to be used for handover (e.g., Ll/2-based handover). The DU may store the one or more encoded security tokens
and the associated one or more token identities to at least one memory (not shown in Figure 2C).
The DU receives, in block 222, from the central unit of the access node and subsequently forwards, also in block 222, to the terminal device a second mobility configuration message (or at least one second mobility configuration message) for first and/or second protocol layer (e.g., Ll/2) mobility of the terminal device. The (at least one) second mobility configuration message comprises at least the one or more token identities.
The DU selects, in block 223, one of the one or more encoded security tokens for handover (i.e., to be used for a handover or at least a handover attempt). The selecting in block 223 may be triggered following a completion of a procedure for evaluating a radio channel between the terminal device and a current serving cell provided by the DU to one or more radio channels between the terminal device and one or more target cells provided by one or more other DUs of the same CU. Said evaluating may be based on measurement results acquired from all cells. The evaluating may be based, e.g., on measurements of reference signal received power (RSRP) and/or reference signal received quality (RSRQ). The conditions for triggering the selecting in block 223 will be described in further detail in connection with Figure 3.
The DU transmits, in block 224, a mobility signaling element (e.g., a Ll/2 mobility MAC CE) to the terminal device. The mobility signaling element comprises said selected one of the one or more encoded security tokens. The mobility signaling element may be or form a part of a mobility command. The mobility signaling element may be defined as discussed above in connection with block 202 of Figure 2A.
Figure 3 illustrates an exemplary MAC CE structure for a mobility signaling element transmitted from a DU of a serving cell to a terminal device. In other words, the MAC CE structure illustrated in Figure 3 corresponds to the mobility signaling element received in block 202 of Figure 2A and transmitted in block 224 of Figure 2C according to an embodiment.
Referring to Figure 3, the MAC CE may comprise at least one of the following fields (exemplary sizes indicated in parentheses): a reserved (R) field (e.g., 1 bit), a (security) token identity field (e.g., 4 bits), a cell identity field (e.g., 3 bits) and a security token field (e.g., N x 8 bits, N being any positive integer). The sizes of the fields provided here and shown in Figure 3 may be considered exemplary and may thus differ in other embodiments from the ones described/illustrated here. The first octet shown in Figure 3 is the header of the MAC CE which is created
by the DU. The remaining octets comprise (or consist of) the (encoded) security token. While Figure 3 shows specifically a MAC CE usable in connection with embodiments, the mobility signaling elements other than MAC CE (e.g., DC1) may also comprise any of the fields discussed here.
The cell identity field indicates the target cell of the mobility (or handover). The terminal device may be configured to, in response to the decoding being successful, cause execution of the (Ll/2-based) handover based on the cell identity field (i.e., to cause execution of the handover towards the target cell specified by the cell identity field). The cell identity field may comprise a physical cell identifier (PCI). Alternatively, the cell identity field may comprise an indirect indication to a stored handover command such as a conditional handover identifier (CHO ID) or an indirect indication to the target cell of the handover based on the RRC configuration of the terminal device.
The token identity field (equally called a security token identity field) indicates which security key a terminal device should use to decode the encoded security token (see next paragraphs). The terminal device may be configured to select the at least one of the one or more security keys to be used for the deciphering based on the token identity field. The token identity field is used by the terminal device to derive the security key for the decoding (e.g., for deciphering and/or integrity verification) of the security token field. In the illustrated example, the token identity field may have a size of 4 bits though other (especially larger) sizes such as 16 bits are also feasible. Alternatively or additionally, the token identity field may comprise an encoded SRB or DRB identifier usable by the terminal device for determining a PDCP entity which may be used for decoding the security token.
The security token field is an encoded (i.e., ciphered and/or integrity protected) field consisting of N octets. The security token field comprises a security token in an encoded format. The security token field may correspond to a PDCP PDU.
The security token field may be generated by the CU based on a derived security key for SRB1 (or any other SRB or DRB). The generation of the security token field may be carried out in a similar manner to derivation of a secondary node key (S-KgNB) for New Radio Dual Connectivity (NR-DC). Namely, the token identity field may be used as the so-called SK-counter for the S-KgNB type key derivation (i.e., for a counter for guaranteeing the freshness of the derived key). The token identity field may be indicated, by the terminal device, to the PDCP layer for security key derivation.
The PDCP PDU comprised in the security token field as described above may be either an (empty) data PDU (D-PDU) or an (empty) control PDU (C-PDU). However, in either case the contents of the PDCP PDU may be either random bits, pre-defined information provided via RRC or additional control information provided by the CU to the terminal device concerning the mobility execution (e.g., related to DRB security keys).
In some embodiments, one or more of the fields illustrated in Figure 3 may be omitted. For example in some embodiments, the cell identity field may be omitted (and the associated information may be communicated separately to the terminal device if it is not already available). The token identity field may be omitted if the RNT1 is used for scrambling/encoding as another example.
Figure 4 illustrates signaling between a terminal device, a first distributed unit (first DU or DU 1) of an access node, a second distributed unit (second DU or DU 2) of the access node and a central unit (CU) of the access node according to an embodiment. Here, the first DU may correspond to an initial serving distributed unit for the terminal device while the second DU may correspond to a target distributed unit for (potential) handover. The firstand second DUs maybe distributed units of the same access node (and thus connected to the same CU). The terminal device, the first and/or second DU and the CU may correspond, respectively, to one of the terminal devices 100, 102 of Figure 1, to the DU 104 of Figure 1 and to the CU 108 of Figure 1.
The procedure illustrated in Figure 4 corresponds to a more detailed implementation of the processes discussed in connection with Figures 2A, 2B and 2C. Any of the definitions provided in connection with Figures 2A, 2B and 2C as well as Figure 3 apply, mutatis mutandis, also here.
Referring to Figure 4, it may be initially assumed that the terminal device is operating in an RRC connected mode and is being served via a serving cell provided by the first CU. In some other embodiments, the terminal device may initially be operating in an (RRC) inactive mode.
The CU generates, in block 401, one or more encoded security tokens and associated one or more token identities for (Ll/2-based) handover based on one or more security keys. The one or more security keys may be pre-defined. The encoding may comprise, here and in the following, ciphering and/or integrity protection. As described above, the one or more encoded security tokens may be, for example, encoded PDCP security tokens.
The CU transmits, in message 402, a first (Ll/2) mobility configuration message comprising the one or more encoded security tokens and the one or more
token identities to the first DU. In some embodiments, only the one or more encoded security tokens may be transmitted in message 402.
The first DU receives, in block 403, the one or more encoded security tokens and the one or more token identities in the first mobility configuration message and stores, also in block 403, them to at least one memory.
The CU also transmits, in elements 404 to 406, a second (Ll/2) mobility configuration message comprising at least one or all of the one or more encoded security tokens and/or of the one or more token identities to the terminal device via the first DU. In other words, the CU transmits, in message 404, the second mobility configuration message to the first DU and subsequently the first DU, upon receiving the second mobility configuration message in block 405, forwards the second mobility configuration message to the terminal device. In some embodiments, message 404 may be omitted (as the same information is communicated already in message 402).
The terminal device receives, in block 407, the second (Ll/2) mobility configuration message from the first DU. Subsequently, the terminal device configures, in block 407, itself according to the received second mobility configuration message. If no security tokens were included in the second mobility configuration message (but one or more token identities were), said configuring in block 407 may comprise, first, generating one or more security tokens based on one or more token identities comprised in the second mobility configuration message. Said configuring in block 407 may further comprise deriving (or generating) one or more security keys based on the one or more token identities either comprised in the second mobility configuration message or generated by the terminal device. The terminal device may, thereafter, operate using (Ll/2) mobility procedures defined in the second mobility configuration message.
The terminal device may perform, in message 408, one or more (radio) measurements of a target cell provided by the second DU. The terminal device may generate, in block 409, a measurement report for the target cell based on the one or more measurements and transmits, in message 410, the measurement report for the target cell to the first DU for evaluation.
The first DU may receive, in block 411, the measurement report and evaluates, in block 411, a need for executing a (Ll/2-based) handover from the serving cell provided by the first DU to the target cell provided by the second DU based at least on the measurement report. In some embodiments, the evaluating in
block 411 may take into account one or more further measurement reports pertaining to the target cell and/or one or more measurement report pertaining to the serving cell.
In response to results of the evaluating indicating the need for the executing of the (Ll/2-based) handover in block 412, the first DU may select, in block 413, one of the one or more encoded security tokens (that is, one of the one or more encoded security tokens configured to the terminal device by the CU) for (Ll/2- based) handover.
The first DU transmits, in message 414, a mobility signaling element of the first and/or second protocol layer (e.g., Ll/2) to the terminal device. The mobility signaling element may be equally called or be comprised in a mobility command. The mobility signaling element comprises said selected one of the one or more encoded security tokens. As discussed in connection above embodiments, the mobility signaling element may be, for example, a MAC CE or an RRC message.
The terminal device receives, in block 415, the mobility signaling element. If the mobility signaling element is the MAC CE comprising a PDCP PDU corresponding to the encoded security token, the terminal device may forward, in block 415, said PDCP PDU to the PDCP layer for decoding.
The terminal device decodes (e.g., deciphers and/or verifies integrity of), in block 416, the encoded security token comprised in the mobility signaling element using at least one of the one or more security keys which were configured to the terminal device in block 407 (being the same security key that was used for the encoding).
If the decoding is successful in block 416, the terminal device (or a PDCP entity thereof) may indicate, in block 417, handover execution to the RRC layer. In other words, if the decoding is successful, the terminal device may cause or trigger execution of the handover.
If the decoding is not successful in block 416, the terminal device (or a PDCP entity thereof) may indicate, in block 417, handover failure to the RRC layer. In some embodiments, said failure indication may be omitted.
In some embodiments, the terminal device may, when the decoding is unsuccessful, switch from the RRC connected mode to an RRC idle or inactive mode. Additionally or alternatively, the terminal device may, when the decoding is unsuccessful, trigger an RRC re-establishment procedure. Additionally or alternatively, the terminal device may, when the decoding is unsuccessful, indicate the decoding failure over the RRC layer to the network (i.e., to the first and/or second DU). Based on said indication, the network (e.g., a first or second DU or the CU of the access
node) may check whether or not an associated MAC CE for mobility (i.e., message 414) was transmitted by it or not. This may also allow the network to safely to update the security configuration via RRC.
The terminal device may optionally also indicate, in message(s) 418, the mobility success or failure to the first DU and/or the second DU via MAC CE(s). This may allow the network to determine whether or how it should retransmit the mobility signaling element (or the mobility command). The first and second DUs receive, in blocks 419, 420, said indication. In some embodiments, said indication 418 may be transmitted also to the CU (e.g., using RRC signaling).
In an embodiment, a PDCP entity (e.g., of SRB1 or of any other SRB or DRB) of a CU of an access node is configured to encode a MAC-1 based on the MAC CE contents usable for indicating mobility. In other words, a DU of an access node may be configured to generate a MAC CE and provide it to a CU of the access node (or specifically to the given PDCP entity thereof) for MAC-1 generation. The resulting MAC-1 is then embedded into the MAC CE in a similar manner as discussed above (e.g., in connection with Figure 3) for the PDCP PDU. Similarly, the terminal device may, then, be configured to provide the whole MAC CE and the embedded MAC-1 to the PDCP entity of the terminal device for integrity verification. In this alternative, only the integrity check of the network would be performed. Additionally, also in this case, the MAC CE should introduce some kind of token identity which can be changed for each MAC CE so as not to use the same MAC-1 multiple times.
In an embodiment, the decoding may be performed on MAC layer (L2) if the RNT1 is used for scrambling/encoding of the mobility signaling element. The MAC layer may decide whether or not the decoding is considered a success and thus whether or not to transmit the results of the decoding to RRC layer.
In an embodiment, a distributed unit of an access node may be configured to transmit the MAC CE for the mobility command without any security material (e.g., without the PDCP PDU/MAC-1, security token and so on). This may occur specifically in the case where one or more control plane (CP) and/or user plane (UP) packets are transmitted, by the distributed unit, to the terminal device along with the same MAC PDU as the MAC CE of the mobility command. In this case, the terminal device may be configured to determine the integrity of the network based on the one or more CP and/or UP packet(s) received.
The blocks, related functions, and information exchanges (messages) described above by means of Figures 2A, 2B, 2C and 4 are in no absolute chronological order, and some of them may be performed simultaneously or in an order
differing from the given one. Other functions can also be executed between them or within them, and other information may be sent, and/or other rules applied. Some of the blocks or part of the blocks or one or more pieces of information can also be left out or replaced by a corresponding block or part of the block or one or more pieces of information.
Figure 5 provides an apparatus 501 according to some embodiments. Specifically, Figure 5 may illustrate an apparatus 501 configured to carry out at least some of the functions described above in connection with performing (lower layer) mobility in a secure manner. The apparatus may be or form a part of a terminal device, a distributed unit of a distributed access node or a central unit of a distributed access node.
The apparatus 501 may comprise one or more control circuitry 520, such as at least one processor, and/or at least one memory 530, including one or more algorithms 531, such as a computer program code (software) wherein the at least one memory and the computer program code (software) are configured, with the at least one processor, to cause the apparatus 501 to carry out any one of the exemplified functionalities of the terminal device, the distributed unit of an access node or a central unit of an access node. Said at least one memory 530 may also comprise at least one database 532.
Referring to Figure 5, the one or more communication control circuitry 520 of the apparatus 501 comprise at least mobility circuitry 521 which is configured to perform the secure mobility functionalities according to embodiments. The mobility circuitry 521 may be configured to perform functionalities described in connection with the terminal device, the (first and/or second) distributed unit or the central unit described above, e.g., by means of any of elements of any of Figures 2A, 2B, 2C, 3 and 4, using one or more individual circuitries.
Referring to Figure 5, the memory 530 may be implemented using any suitable data storage technology, such as semiconductor based memory devices, flash memory, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory.
Referring to Figure 5, the apparatus 501 may further comprise different interfaces 510 such as one or more communication interfaces (TX/RX) comprising hardware and/or software for realizing communication connectivity according to one or more communication protocols. Specifically, the one or more communication interfaces 510 may comprise, for example, interfaces providing a connection to the Internet and a core network of a wireless communications network. The one
or more communication interface 510 may provide the apparatus with communication capabilities to communicate in a cellular communication system and enable communication with user devices (terminal devices) and different network nodes or elements (e.g., distributed and/or central units of access nodes) and/or a communication interface to enable communication between different network nodes or elements, for example. The one or more communication interfaces 510 may comprise standard well-known components such as an amplifier, filter, frequencyconverter, (de)modulator, and encoder/decoder circuitries, controlled by the corresponding controlling units, and one or more antennas.
As used in this application, the term ‘circuitry’ may refer to one or more or all of the following: (a) hardware-only circuit implementations, such as implementations in only analog and/or digital circuitry, and (b) combinations of hardware circuits and software (and/or firmware), such as (as applicable): (i) a combination of analog and/or digital hardware circuit(s) with software/firmware and (ii) any portions of hardware processor(s) with software, including digital signal processor(s), software, and memory(ies) that work together to cause an apparatus, such as a terminal device or an access node, to perform various functions, and (c) hardware circuit(s) and processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g. firmware) for operation, but the software may not be present when it is not needed for operation. This definition of ‘circuitry’ applies to all uses of this term in this application, including any claims. As a further example, as used in this application, the term ‘circuitry’ also covers an implementation of merely a hardware circuit or processor (or multiple processors) or a portion of a hardware circuit or processor and its (or their) accompanying software and/or firmware. The term ‘circuitry’ also covers, for example and if applicable to the particular claim element, a baseband integrated circuit for an access node or a terminal device or other computing or network device.
In an embodiment, at least some of the processes described in connection with Figures 2A, 2B, 2C, 3 and 4 may be carried out by an apparatus comprising corresponding means for carrying out at least some of the described processes. Some example means for carrying out the processes may include at least one of the following: detector, processor (including dual-core and multiple-core processors), digital signal processor, controller, (radio) receiver, (radio) transmitter, (radio) transceiver, encoder, decoder, memory, RAM, ROM, software, firmware, display, user interface, display circuitry, user interface circuitry, user interface software,
display software, circuit, antenna, antenna circuitry, and circuitry. In some embodiments, said means comprise at least at least one processor and a (radio) transceiver.
In some embodiment, the at least one processor, the memory, and the computer program code form processing means or comprises one or more computer program code portions for carrying out one or more operations according to any one of the embodiments of 2A, 2B, 2C, 3 and 4 or operations thereof.
According to an embodiment, there is provided an apparatus (e.g., a terminal device or a part thereof) comprising means for performing: obtaining one or more security keys for handover; receiving a mobility signaling element of a first and/or second protocol layer (e.g., of Ll/2), wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
According to an embodiment, there is provided an apparatus (e.g., a terminal device or a part thereof) comprising at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code being configured, with the at least one processor, to cause the apparatus at least to perform: obtaining one or more security keys for handover; receiving a mobility signaling element of a first and/or second protocol layer (e.g., of Ll/2), wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
According to an embodiment, there is provided an apparatus (e.g., a central unit of an access node or a part thereof) comprising means for performing: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys; transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein said at least
one second mobility configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
According to an embodiment, there is provided an apparatus (e.g., a central unit of an access node or a part thereof) comprising at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code being configured, with the at least one processor, to cause the apparatus at least to perform: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys; transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein said at least one second mobility configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
According to an embodiment, there is provided an apparatus (e.g., a distributed unit of an access node or a part thereof) comprising means for performing: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; and in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of the first and / or second protocol layer (e.g., Ll/2) to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
According to an embodiment, there is provided an apparatus (e.g., a distributed unit of an access node or a part thereof) comprising at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code being configured, with the at least one processor, to cause the apparatus at least to perform:
receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of the first and / or second protocol layer (e.g., Ll/2] to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
Embodiments as described may also be carried out in the form of a computer process defined by a computer program or portions thereof. Embodiments of the methods described in connection with Figures 2A, 2B, 2C, 3 and 4 may be carried out by executing at least one portion of a computer program comprising corresponding instructions. The computer program may be provided as a computer readable medium comprising program instructions stored thereon or as a non-transitory computer readable medium comprising program instructions stored thereon. The computer program may be in source code form, object code form, or in some intermediate form, and it may be stored in some sort of carrier, which may be any entity or device capable of carrying the program. For example, the computer program may be stored on a computer program distribution medium readable by a computer or a processor. The computer program medium may be, for example but not limited to, a record medium, computer memory, read-only memory, electrical carrier signal, telecommunications signal, and software distribution package, for example. The computer program medium maybe a non-transi- tory medium. Coding of software for carrying out the embodiments as shown and described is well within the scope of a person of ordinary skill in the art.
Even though the embodiments have been described above with reference to examples according to the accompanying drawings, it is clear that the embodiments are not restricted thereto but can be modified in several ways within the scope of the appended claims. Therefore, all words and expressions should be interpreted broadly and they are intended to illustrate, not to restrict, the embodiment. It will be obvious to a person skilled in the art that, as technology advances, the inventive concept can be implemented in various ways. Further, it is clear to a
person skilled in the art that the described embodiments may, but are not required to, be combined with other embodiments in various ways.
Claims
1. An apparatus comprising: at least one processor; and at least one transceiver, wherein the at least one processor is configured to: obtain one or more security keys for handover; wherein the at least one transceiver is configured to: receive a mobility signaling element of a first and/or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and wherein the at least one processor is configured to: decode the encoded security token using the at least one of the one or more security keys.
2. The apparatus according to claim 1, wherein the decoding comprises performing deciphering and/or integrity verification on the encoded security token and/or the encoded security token has been ciphered and/or integrity protected using the at least one of the one or more security keys.
3. The apparatus according to claim 1 or 2, wherein the mobility signaling element comprises a medium access control, MAC, control element, CE or downlink control information, DCI.
4. The apparatus according to any preceding claim, wherein the at least one processor is configured to: cause performing of handover towards a target cell when the encoded security token is successfully decoded.
5. The apparatus according to any preceding claim, wherein the at least one transceiver is configured to: transmit a message indicating whether or not the decoding of the mobility signaling element was successful to an access node or to a distributed unit of an access node.
6. The apparatus according to any preceding claim, wherein the at least one processor is configured to:
indicate to a radio resource control, RRC, layer that the handover is to be executed when the decoding of the encoded security token is successful; and/or indicate to the RRC layer that the handover was a failure when the decoding of the encoded security token is unsuccessful.
7. The apparatus according to any preceding claim, wherein the at least one processor is configured, when the decoding is unsuccessful, to: switch from an RRC connected mode to an RRC idle or RRC inactive mode; and/or trigger an RRC re-establishment procedure.
8. The apparatus according to any preceding claim, wherein the receiving of the mobility signaling element comprises: receiving the mobility signaling element from an access node or a distributed unit of an access node.
9. The apparatus according to any preceding claim, wherein the encoded and/or decoded security token comprises random data, pre-defined data or additional control information.
10. The apparatus according to any preceding claim, wherein the mobility signaling element further comprises a token identity and/or a cell identity.
11. The apparatus according to claim 10, wherein the at least one processor is configured to: select the at least one of the one or more security keys for decoding the encoded security token based on the token identity comprised in the mobility signaling element.
12. The apparatus according to any preceding claim, wherein the encoded security token comprises: a packet data convergence protocol, PDCP, protocol data unit, PDU, or an encoded message authentication code for integrity, MAC-1.
13. The apparatus according to any preceding claim, wherein the mobility signaling element has been scrambled, at least in part, using a radio network temporary identifier, RNT1, for indicating that a payload of the mobility signaling
element has been ciphered and/or integrity protected, said at least one of the one or more security keys comprising said RNT1.
14. The apparatus according to any preceding claim, wherein the one or more security keys have been configured using an RRC protocol.
15. The apparatus according to any preceding claim, wherein the one or more security keys comprise one or more security keys for one or more signalling radio bearers and/or one or more security keys for one or more data radio bearers.
16. The apparatus according to any preceding claim, wherein said first and/or second protocol layer comprise or consist of one or two of a physical layer, a MAC layer and a radio link control, RLC, layer.
17. The apparatus according to any of claims 1 to 15, wherein said first and/or second protocol layer comprise or consist of one or two of a physical layer, a MAC layer, an RLC layer and a PDCP layer.
18. An apparatus comprising: at least one processor; and at least one transceiver, wherein the at least one processor is configured to: generate one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys, wherein the at least one transceiver is configured to: transmit at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmit at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein the at least one second configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
19. The apparatus according to claim 18, wherein the generating of the one or more encoded security tokens comprises ciphering and/or integrity protecting of one or more security tokens.
20. The apparatus according to claim 18 or 19, wherein the one or more encoded security tokens comprise, in an encoded form, random data, pre-defined data or additional control information.
21. The apparatus according to any of claims 18 to 20, wherein the one or more security keys comprise one or more security keys for one or more signalling radio bearers and/or one or more security keys for one or more data radio bearers.
22. An apparatus comprising: at least one processor; and at least one transceiver, wherein the at least one transceiver is configured to: receive at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; and in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forward the at least one second mobility configuration message to a terminal device, wherein the at least one processor is configured to: select one of the one or more encoded security tokens for handover, wherein the at least one transceiver is configured to: transmit a mobility signaling element of a first and/or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
23. The apparatus according to claim 22, wherein the one or more encoded security tokens are ciphered and/or integrity protected security tokens.
24. The apparatus according to claim 22 or 23, wherein the mobility signaling element comprises a MAC CE or DC1.
25. The apparatus according to any of claims 22 to 24, wherein the at least one processor is configured to:
evaluate a need for executing a handover from a serving cell to a target cell based on one or more measurement reports relating to the serving cell and/or the target cell; and in response to results of the evaluating indicating the need for the executing of the handover, performing the selecting of said one of the one or more encoded security tokens for handover.
26. The apparatus according to any of claims 22 to 25, wherein the at least one transceiver is configured to: receive, from the terminal device, a message indicating whether or not decoding of the mobility signaling element was successful at the terminal device.
27. The apparatus according to any of claims 22 to 26, wherein the mobility signaling element further comprises a token identity and/or a cell identity.
28. The apparatus according to any of claims 22 to 27, wherein the encoded security token is a PDCP PDU or a MAC-1.
29. The apparatus according to any of claims 22 to 28, wherein the at least one processor is configured to: scramble the mobility signaling element, at least in part, before transmission using an RNT1 for indicating that a payload of the mobility signaling element has been ciphered and/or integrity protected.
30. The apparatus according to any of claims 22 to 29, wherein the at least one processor is configured to: store the one or more encoded security tokens and the associated one or more token identities to at least one memory.
31. The apparatus according to any of claims 22 to 30, wherein said first and/or second protocol layer comprise or consist of one or two of a physical layer, a MAC layer and an RLC layer.
32. The apparatus according to any of claims 22 to 30, wherein said first and/or second protocol layer comprise or consist of one or two of a physical layer, a MAC layer, an RLC layer and a PDCP layer.
33. A method comprising: obtaining one or more security keys for handover; receiving a mobility signaling element of a first or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
34. A method comprising: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys, transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein the second configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
35. A method comprising: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; and in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of a first and/or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
36. A non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the following: obtaining one or more security keys for handover;
receiving a mobility signaling element of a first and/or second protocol layer, wherein the mobility signaling element comprises at least one encoded security token which has been encoded using at least one of the one or more security keys; and decoding the encoded security token using the at least one of the one or more security keys.
37. A non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the following: generating one or more encoded security tokens and associated one or more token identities for handover based on one or more security keys, transmitting at least one first mobility configuration message comprising the one or more encoded security tokens and the one or more token identities to a distributed unit of an access node; and transmitting at least one second mobility configuration message to a terminal device via the distributed unit of the access node, wherein the second configuration message comprises at least one or all of the one or more security tokens and/or of the one or more token identities.
38. A non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the following: receiving at least one first mobility configuration message comprising one or more encoded security tokens and associated one or more token identities for handover from a central unit of an access node; in response to receiving at least one second mobility configuration message comprising at least one or all of the one or more security tokens and/or of the one or more token identities from the central unit, forwarding said at least one second mobility configuration message to a terminal device; selecting one of the one or more encoded security tokens for handover; and transmitting a mobility signaling element of the first and / or second protocol layer to the terminal device, wherein the mobility signaling element comprises said one of the one or more encoded security tokens.
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/EP2022/065284 WO2023237172A1 (en) | 2022-06-06 | 2022-06-06 | Method and apparatus for secure lower layer mobility |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4537564A1 true EP4537564A1 (en) | 2025-04-16 |
Family
ID=82308169
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP22734866.1A Pending EP4537564A1 (en) | 2022-06-06 | 2022-06-06 | Method and apparatus for secure lower layer mobility |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP4537564A1 (en) |
| CN (1) | CN119318166A (en) |
| WO (1) | WO2023237172A1 (en) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2025138034A1 (en) * | 2023-12-28 | 2025-07-03 | Oppo广东移动通信有限公司 | Communication method and device |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9960911B2 (en) * | 2015-09-11 | 2018-05-01 | Signalchip Innovations Private Limited | System and method for securing wireless communication through physical layer control and data channel |
| WO2019245329A1 (en) * | 2018-06-21 | 2019-12-26 | Lg Electronics Inc. | Method and apparatus for performing conditional cell change in wireless communication system |
| US11470473B2 (en) * | 2019-01-18 | 2022-10-11 | Qualcomm Incorporated | Medium access control security |
| EP4073996B1 (en) * | 2019-12-09 | 2024-03-20 | Telefonaktiebolaget Lm Ericsson (Publ) | User equipment, network node and methods in a wireless communications network |
-
2022
- 2022-06-06 CN CN202280096733.2A patent/CN119318166A/en active Pending
- 2022-06-06 EP EP22734866.1A patent/EP4537564A1/en active Pending
- 2022-06-06 WO PCT/EP2022/065284 patent/WO2023237172A1/en not_active Ceased
Also Published As
| Publication number | Publication date |
|---|---|
| CN119318166A (en) | 2025-01-14 |
| WO2023237172A1 (en) | 2023-12-14 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12418838B2 (en) | CU-DU communication for multicast with support for switching between unicast and multicast | |
| US10735957B2 (en) | Context preparation | |
| US12063582B2 (en) | Enhancing communication efficiency | |
| US12160734B2 (en) | Methods, apparatuses, computer readable media and computer programs for performing admission control for limited access service | |
| EP4449815A2 (en) | Method for sharing ue-specific information between near-real-time radio access network intelligent controllers | |
| EP3968697B1 (en) | Beam failure reporting | |
| US20220330026A1 (en) | Counter measures for attacking messages | |
| EP3857951B1 (en) | Logical channel cell restriction | |
| WO2018108261A1 (en) | Handover in communications network | |
| US12581375B2 (en) | Interference coordination for mobility | |
| EP4537564A1 (en) | Method and apparatus for secure lower layer mobility | |
| US20240090060A1 (en) | Fast activation of a secondary cell group | |
| CN116602010B (en) | Small data transmission control | |
| US20240073789A1 (en) | Receiving segments of system information block message | |
| EP3311599B1 (en) | Ultra dense network security architecture and method | |
| US20240259807A1 (en) | Attacker identification during small data transmission | |
| US20230007642A1 (en) | Method and apparatus for communication systems involving incorporating user equipment identifiers into control channel transmissions | |
| US20230239753A1 (en) | Reconfiguration failure handling for cpac | |
| WO2024078979A1 (en) | Slice group -specific connected rach configuration |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20250107 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) |