WO2025233045A1 - Method, apparatus and computer program - Google Patents

Method, apparatus and computer program

Info

Publication number
WO2025233045A1
WO2025233045A1 PCT/EP2025/057441 EP2025057441W WO2025233045A1 WO 2025233045 A1 WO2025233045 A1 WO 2025233045A1 EP 2025057441 W EP2025057441 W EP 2025057441W WO 2025233045 A1 WO2025233045 A1 WO 2025233045A1
Authority
WO
WIPO (PCT)
Prior art keywords
satellite
target satellite
user equipment
physical cell
target
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/EP2025/057441
Other languages
French (fr)
Inventor
Ayaz AHMED
Saurabh Khare
Rakshesh PRAVINCHANDRA BHATT
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nokia Technologies Oy
Original Assignee
Nokia Technologies Oy
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nokia Technologies Oy filed Critical Nokia Technologies Oy
Publication of WO2025233045A1 publication Critical patent/WO2025233045A1/en
Pending legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/041Key generation or derivation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • H04W76/19Connection re-establishment
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/20Manipulation of established connections
    • H04W76/27Transitions between radio resource control [RRC] states
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/04Large scale networks; Deep hierarchical networks
    • H04W84/06Airborne or Satellite Networks

Definitions

  • NTNs Non-Terrestrial Networks
  • a communication network can be seen as a facility that enables communications between two or more communication devices, or provides communication devices access to a data network.
  • a mobile or wireless communication network is one example of a communication network.
  • a communication device may be provided with a service by an application server.
  • Such communication networks operate in according with standards such as those provided by 3GPP (Third Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). Examples of standards are the so-called 4G (4 th Generation), 5G (5th Generation) standards provided by 3GPP.
  • an apparatus comprising: means for receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; means for determining a security key for the user equipment using the identity and the channel number; means for updating an access stratum security context using the determined security key; means for sending the updated access stratum security context to the target satellite.
  • the channel number of the physical cell comprises a E-UTRA Absolute Radio Frequency Channel Number.
  • the channel number of the physical cell identifies at least one of: a frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode.
  • the apparatus comprises: means for determining that a serving satellite for the user equipment has lost connectivity with a core network of the apparatus; means for determining the target satellite as the next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state after the serving satellite has lost connectivity with the core network of the apparatus and before the target satellite has connectivity with the core network.
  • the target satellite is determined as the next satellite using satellite ephemeris.
  • the MAC comprises a shortResumeMAC-l.
  • the identity of the physical cell of the target satellite and the channel number of the target physical cell are received over a feeder link between the target satellite and the apparatus.
  • the feeder link comprises a 3GPP standardized (e.g. S1 interface) or proprietary interface between a base station onboard the target satellite and a core network.
  • 3GPP standardized e.g. S1 interface
  • proprietary interface between a base station onboard the target satellite and a core network.
  • the apparatus comprises: a core network node; a non-terrestrial network gateway node; or a proxy node. According to some examples, the apparatus comprises: means for sending, to the target satellite, an indication that the access stratum security context has been updated.
  • an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; determining a security key for the user equipment using the identity and the channel number; updating an access stratum security context using the determined security key; sending the updated access stratum security context to the target satellite.
  • the channel number of the physical cell comprises a E-UTRA Absolute Radio Frequency Channel Number.
  • the channel number of the physical cell identifies at least one of: a frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode.
  • the instructions when executed by the at least one processor, cause the apparatus to perform: determining that a serving satellite for the user equipment has lost connectivity with a core network of the apparatus; determining the target satellite as the next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state after the serving satellite has lost connectivity with the core network of the apparatus and before the target satellite has connectivity with the core network.
  • the target satellite is determined as the next satellite using satellite ephemeris.
  • the instructions when executed by the at least one processor, cause the apparatus to perform: determining that the identity of the physical cell of the target satellite and the serving satellite are the same, and in response, determining the security key using a target base station identifier of the target satellite or using any unique identifier of the next satellite after the target satellite that will have connectivity with the core network.
  • the instructions when executed by the at least one processor, cause the apparatus to perform: generating a message authentication code, MAC, for each UE and per non-terrestrial network cell hosted by the target satellite to provide a list of one or more MACs; sending the list to the target satellite.
  • MAC message authentication code
  • the MAC comprises a shortResumeMAC-l.
  • the identity of the physical cell of the target satellite and the channel number of the target physical cell are received over a feeder link between the target satellite and the apparatus.
  • the feeder link comprises a 3GPP standardized (e.g. S1 interface) or proprietary interface between a base station onboard the target satellite and a core network.
  • 3GPP standardized e.g. S1 interface
  • proprietary interface between a base station onboard the target satellite and a core network.
  • the apparatus comprises: a core network node; a non-terrestrial network gateway node; or a proxy node.
  • the instructions when executed by the at least one processor, cause the apparatus to perform: sending, to the target satellite, an indication that the access stratum security context has been updated.
  • a method comprising: receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; determining a security key for the user equipment using the identity and the channel number; updating an access stratum security context using the determined security key; sending the updated access stratum security context to the target satellite.
  • the channel number of the physical cell comprises a E-UTRA Absolute Radio Frequency Channel Number.
  • the channel number of the physical cell identifies at least one of: a frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode.
  • the method comprises: determining that a serving satellite for the user equipment has lost connectivity with a core network of the apparatus; determining the target satellite as the next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state after the serving satellite has lost connectivity with the core network of the apparatus and before the target satellite has connectivity with the core network.
  • the target satellite is determined as the next satellite using satellite ephemeris.
  • the method comprises: determining that the identity of the physical cell of the target satellite and the serving satellite are the same, and in response, determining the security key using a target base station identifier of the target satellite or using any unique identifier of the next satellite after the target satellite that will have connectivity with the core network.
  • the method comprises: generating a message authentication code, MAC, for each UE and per non-terrestrial network cell hosted by the target satellite to provide a list of one or more MACs; sending the list to the target satellite.
  • MAC message authentication code
  • the MAC comprises a shortResumeMAC-l.
  • the identity of the physical cell of the target satellite and the channel number of the target physical cell are received over a feeder link between the target satellite and the apparatus.
  • the feeder link comprises a 3GPP standardized (e.g. S1 interface) or proprietary interface between a base station onboard the target satellite and a core network.
  • 3GPP standardized e.g. S1 interface
  • proprietary interface between a base station onboard the target satellite and a core network.
  • the apparatus comprises: a core network node; a non-terrestrial network gateway node; or a proxy node.
  • a computer readable medium comprising instructions which, when executed by a user equipment, cause the user equipment to perform at least the following: receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; determining a security key for the user equipment using the identity and the channel number; updating an access stratum security context using the determined security key; sending the updated access stratum security context to the target satellite.
  • a non-transitory computer readable medium comprising program instructions that, when executed by a user equipment, cause the user equipment to perform at least the following: receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; determining a security key for the user equipment using the identity and the channel number; updating an access stratum security context using the determined security key; sending the updated access stratum security context to the target satellite.
  • an apparatus comprising: means for sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; means for receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.
  • the user equipment is in a radio resource control suspended state after a serving satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.
  • the apparatus comprises: means for receiving, from the network node, a list comprising a message authentication code, MAC, for each user equipment per non-terrestrial network cell hosted by the apparatus.
  • MAC message authentication code
  • the apparatus comprises: means for receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first MAC; means for determining that the first MAC is in the list received from the network node and then authenticating the first MAC; means for resuming the radio resource control connection with the network of the apparatus.
  • the identity of the physical cell of the apparatus and the channel number of the target physical cell is sent over a feeder link between the target satellite and the apparatus.
  • the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.
  • the apparatus comprises: means for determining at least one further access stratum integrity and encryption key using the security key.
  • the apparatus comprises: means for receiving, from the network node, an indication that the updated access stratum security context has been updated.
  • an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.
  • the user equipment is in a radio resource control suspended state after a serving satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.
  • the instructions when executed by the at least one processor, cause the apparatus to perform: receiving, from the network node, a list comprising a message authentication code, MAC, for each user equipment per non-terrestrial network cell hosted by the apparatus.
  • the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.
  • a satellite comprises the apparatus.
  • the instructions when executed by the at least one processor, cause the apparatus to perform: determining at least one further access stratum integrity and encryption key using the security key.
  • the instructions when executed by the at least one processor, cause the apparatus to perform: receiving, from the network node, an indication that the updated access stratum security context has been updated.
  • a method comprising: sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.
  • the user equipment is in a radio resource control suspended state after a serving satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.
  • the method comprises: receiving, from the network node, a list comprising a message authentication code, MAC, for each user equipment per non-terrestrial network cell hosted by the apparatus.
  • the method comprises: receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first MAC; determining that the first MAC is in the list received from the network node and then authenticating the first MAC; resuming the radio resource control connection with the network of the apparatus.
  • the identity of the physical cell of the apparatus and the channel number of the target physical cell is sent over a feeder link between the target satellite and the apparatus.
  • the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.
  • a satellite comprises the apparatus.
  • the method comprises: determining at least one further access stratum integrity and encryption key using the security key.
  • the method comprises: receiving, from the network node, an indication that the updated access stratum security context has been updated.
  • a computer readable medium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.
  • a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.
  • a user equipment comprising: means for sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; means for receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
  • the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell
  • the user equipment comprises: means for determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; means for connecting to the target satellite using the determined security key.
  • the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite
  • the user equipment comprising: means for determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; means for connecting to the target satellite using the determined security key
  • a user equipment comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
  • the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell
  • the instructions when executed by the at least one processor, cause the apparatus to perform: determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; connecting to the target satellite using the determined security key.
  • the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same
  • the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite
  • the instructions when executed by the at least one processor, cause the apparatus to perform: cause the apparatus at least to perform: determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; connecting to the target satellite using the determined security key.
  • a method comprising: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
  • the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell
  • the method comprises: determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; connecting to the target satellite using the determined security key.
  • the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, and the method comprises: determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; connecting to the target satellite using the determined security key.
  • a fourteenth aspect there is provided a computer readable medium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
  • a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
  • an apparatus comprising: means for receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; means for determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; means for determining an updated access stratum security context for the user equipment using the security key.
  • the user equipment is in a radio resource control suspended state after the source satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.
  • the apparatus comprises: means for determining a list comprising a message authentication code for each user equipment per non-terrestrial network cell hosted by the apparatus.
  • the apparatus comprises: means for receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first message authentication code; means for determining that the first message authentication code is in the list received from the network node and then authenticating the first message authentication code; means for resuming the radio resource control connection with the user equipment.
  • the message authentication code comprises a shortResumeMAC-l.
  • the apparatus comprises: means for determining that the identity of the physical cell of the apparatus and the source satellite are the same, and in response, determining the security key using a base station identifier of the apparatus or using any unique identifier of the next satellite after the apparatus that will have connectivity with the core network.
  • the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.
  • a satellite comprises the apparatus.
  • an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; determining an updated access stratum security context for the user equipment using the security key.
  • the user equipment is in a radio resource control suspended state after the source satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.
  • the instructions when executed by the at least one processor, cause the apparatus to perform determining a list comprising a message authentication code for each user equipment per non-terrestrial network cell hosted by the apparatus.
  • the instructions when executed by the at least one processor, cause the apparatus to perform: receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first message authentication code; determining that the first message authentication code is in the list received from the network node and then authenticating the first message authentication code; resuming the radio resource control connection with the user equipment.
  • the message authentication code comprises a shortResumeMAC-l.
  • the instructions when executed by the at least one processor, cause the apparatus to perform: determining that the identity of the physical cell of the apparatus and the source satellite are the same, and in response, determining the security key using a base station identifier of the apparatus or using any unique identifier of the next satellite after the apparatus that will have connectivity with the core network.
  • the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.
  • a satellite comprises the apparatus.
  • a method comprising: receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; determining an updated access stratum security context for the user equipment using the security key.
  • the user equipment is in a radio resource control suspended state after the source satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.
  • the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.
  • a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; determining an updated access stratum security context for the user equipment using the security key.
  • the target satellite is determined as the next satellite using satellite ephemeris.
  • the apparatus comprises one of: a core network node; a nonterrestrial network gateway node; a proxy node.
  • the target satellite is determined as the next satellite using satellite ephemeris.
  • the apparatus comprises one of: a core network node; a nonterrestrial network gateway node; a proxy node.
  • a method comprising: determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.
  • the target satellite is determined as the next satellite using satellite ephemeris.
  • the method if performed by one of: a core network node; a nonterrestrial network gateway node; a proxy node.
  • a computer readable medium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.
  • a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.
  • a user equipment comprising: means for sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; means for receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
  • the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell
  • the user equipment comprises: means for determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; means for connecting to the target satellite using the security key.
  • the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, and the user equipment comprises: means for determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; means for connecting to the target satellite using the security key
  • an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
  • the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell
  • the instructions when executed by the at least one processor, cause the apparatus to perform: determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; connecting to the target satellite using the security key.
  • the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, and the instructions, when executed by the at least one processor, cause the apparatus to perform: determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; connecting to the target satellite using the security key.
  • a method comprising: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
  • the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell
  • method comprises: determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; connecting to the target satellite using the security key.
  • the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, and the method comprises determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; connecting to the target satellite using the security key
  • a computer readable medium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; receiving a response from the target satellite indicating that the radio resource control connection can be resumed
  • a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
  • a computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.
  • a non-transitory computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.
  • non-volatile tangible memory medium comprising program instructions stored thereon for performing at least one of the above methods.
  • a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the method according to any of the preceding aspects.
  • FIG. 1 shows a representation of a communication network comprising a 5 th generation communication system and a data network
  • FIG. 2 shows an example signal flow diagram for an example NTN Store and Forward (S&F) scenario
  • FIG. 3 shows an example signal flow diagram for an example NTN Store and Forward (S&F) scenario with security key computation at a network node;
  • S&F NTN Store and Forward
  • FIG. 5 shows an example method performed by a network node
  • FIG. 8 shows an example method performed by a network node
  • FIG. 9 shows an example method performed by a target satellite
  • FIG. 10 shows an example method performed by a User Equipment (UE);
  • UE User Equipment
  • FIG. 11 shows a representation of an apparatus for the communication system of FIG. 1 according to some example embodiments
  • Satellite networks with incomplete satellite connections may have discontinuous satellite connectivity with User Equipment’s (UEs) and/or may have discontinuous connectivity to a ground station (e.g., ground station connectivity) due to coverage gaps that are caused by satellites that are missing from a full satellite constellation or due to a lack of ground station connectivity at some locations.
  • UEs User Equipment
  • ground station connectivity e.g., ground station connectivity
  • a satellite network with an incomplete satellite constellation cannot be guaranteed to have ground station connectivity via a feeder link to the ground station at all times, and also cannot be guaranteed to provide continuous coverage to a UE in the satellite network (instead, only intermittent coverage may be available).
  • S&F Store and Forward operations allow a satellite to provide service to NTN devices even when the satellite is not connected to the NTN Gateway (GW) on the ground.
  • a typical S&F scenario may involve a non-simultaneous connection between UE and satellite comprising a base station as regenerative payload (also called Access link) and satellite comprising a base station as regenerative payload and the CN on the ground (on the feeder link).
  • a communication network comprising a 5 th generation communication system (5GS), a radio access network and a core network (5GC) thereof, are briefly explained with reference to FIG. 1.
  • 5GS 5 th generation communication system
  • 5GC core network
  • FIG. 1 shows a schematic representation of a communication network comprising a cellular or mobile communication system (e.g., a 5G communication system (5GS), and data network.
  • the 5GS may comprise a radio access network such as a 5G radio access network (5G-RAN) or next generation radio access network (NG-RAN), a 5G core network (5GC).
  • An application function may be deployed in the 5GS (e.g., hosted on an apparatus of the 5GC) and hence are generally referred to as a trusted application function or an AF may be deployed or hosted on one or more application servers of the data network and communicate with 5GC via a network exposure function of the 5GC as described in further detailed below.
  • FIG. 2 shows a method flow diagram for an example NTN S&F scenario where an RRC connection for UE 200 can be suspended and resumed.
  • UE 200 is in an connected RRC state (RRC_CONNECTED) and/or a Connection Management connected state (CM-CONNECTED).
  • RRC_CONNECTED RRC_CONNECTED
  • CM-CONNECTED Connection Management connected state
  • a proxy gateway (P-GW) 208 sends downlink (DL) data to a serving base station on board satellite 1 204.
  • the base station may comprise an eNB or gNB.
  • Satellite 204 may comprise a Non-Geo Synchronous Orbit (NGSO) satellite 1 204.
  • serving satellite 1 204 suspends the context of UE 200 by sending an RRC Connection Suspend request to MME 206. This can be performed before serving satellite 1 204 loses feeder link connectivity.
  • the request sent at 205a may be sent using S1 Application Protocol (S1-AP).
  • S1-AP S1 Application Protocol
  • MME 206 responds to the message sent at 205a.
  • the response may indicate that the UE context has been suspended.
  • an indication of a Next Hop (NH) satellite and corresponding Nokia Converged Charging (NCC) value may be provided at 205b.
  • This can be stored at 207 at the serving satellite 204.
  • the serving satellite 1 204 indicates to UE 200 that the RRC connection has been suspended, and will send an identifier for resuming the RRC connection (Resume ID) and a NCC value.
  • the NCC value may be the new value received at 205b, or may be an existing value received prior to 205b.
  • the serving satellite 1 204 stores the Resume ID and the UE context.
  • the UE context included an Access Stratum (AS) security.
  • AS Access Stratum
  • serving satellite 1 204 may keep key KRRCint and delete other AS keys such as KeNB, KRRCenc, KUPenc. If a new NH and new NCC value were not received at 205b, serving satellite 1 204 may keep all AS keys.
  • UE 200 stores the Resume ID received at 209 with the UE context.
  • the UE context may include the AS security context.
  • UE 200 may also store the NCC value to be used in the next resumption of RRC connectivity.
  • UE 200 is in an RRC inactive (RRCJNACTIVE) and CM-CONNECTED state.
  • RRCJNACTIVE RRC inactive
  • CM-CONNECTED CM-CONNECTED state
  • the UE context of UE 200 is sent to network node 206.
  • MME Mobility Management Entity
  • NTN gateway NTN gateway
  • serving satellite 1 204 loses connectivity with the CN (or NTN GW) on the ground.
  • the network node 206 (or in some examples, one or more other CN entities) identifies a next target satellite 4 202 that may have connectivity with network node 206. This may be done using know satellite paths and the current time in the schedule (satellite ephemeris information), for example.
  • network node 206 sends the UE context to the next serving satellite 4202.
  • UE 200 determines that there is Uplink (UL) data to send.
  • UE 200 sends to target satellite 4204 a request to resume the RRC configuration (RRCResumeRequest).
  • the request may comprise a resume ID and a message authentication code (e.g., ShortResumeMAC-l).
  • the target satellite 4 202 e.g., an comprising eNB or gNB
  • the target satellite 4 202 extracts the Resume ID and ShortResumeMAC-l from the RRCResumeRequest.
  • the target satellite 4202 may then contact the cell at the source satellite 1 204 based on the information in the Resume ID by sending a Retrieve UE Context Request message (e.g., on an X2 interface), the message including the Resume ID, the ShortResumeMAC-l and Cell-ID of target cell, in order to retrieve the UE context (including the AS security context).
  • the source satellite 1 204 retrieves the stored UE context including the AS security context from its database identified by the Resume ID and the source eNB calculates and verifies the ShortResumeMAC-l.
  • the source eNB shall derive a new KeNB*, based on the target Physical Cell ID (PCI) and target Evolved Universal Mobile Telecommunications System Terrestrial Radio Access Network (E-UTRAN) Absolute Radio Frequency Channel Number Downlink frequency (EARFCN-DL). If source satellite 1 204 received a new ⁇ NH, NCC ⁇ pair from MME 206 at 205b, then that pair shall be used, and the new NH shall be used in the new KeNB* derivation.
  • PCI Physical Cell ID
  • E-UTRAN Evolved Universal Mobile Telecommunications System Terrestrial Radio Access Network
  • E-DL Evolved Universal Mobile Telecommunications System Terrestrial Radio Access Network Absolute Radio Frequency Channel Number Downlink frequency
  • the source satellite 1 204 responds with a Retrieve UE Context Response message to the target satellite 4 202 (e.g., on an X2 interface) including the UE context that is updated with AS security context using the new key.
  • the AS security context sent to the target satellite eNB shall include a new derived security key (KeNB*), the NCC associated to the KeNB*.
  • KeNB* new derived security key
  • the UE context of RRCJNACTIVE state UEs is forwarded by the last serving satellite 1 204 to network node 206 (e.g., CN node or the NTN GW node) before the last serving satellite 1 204 loses connectivity with network node 206.
  • network node 206 When network node 206 identifies the next serving target satellite that shall have connectivity to network node 206, network node 206 forwards the stored UE contexts blindly to the target satellite (without updating AS security context). As a result, an attempt by the RRCJNACTIVE state UE 200 to resume the connection at the target satellite will fail, as the AS security in the UE context is not updated with a new security key relevant to target satellite 4202.
  • a network node e.g., a CN node, proxy node or an NTN GW node
  • a network node forwards the UE context of RRCJNACTIVE state UE(s) to a target satellite, unless the AS security context that is part of UE context is updated with new security key derived using security parameters relevant to the next serving target satellite, either by the CN node before forwarding or by the target node on receiving, the UE context is not valid for a successful connection resume at the target satellite.
  • a failure is shown at 231 , where the RRC connection is released, and 233 where the connection resume fails.
  • FIG. 3 and FIG. 4 show two different methods for S&F scenarios to enable either the network node (FIG. 3) or target satellite node (FIG. 4) to compute a new security key and update the AS security context. This prevents the connection resume in NTN S&F scenarios failing as in FIG. 2, where the connection resume for a UE fails due to an outdated AS security context that is not updated using a new security key derived using input parameters relevant to the target satellite for the UE.
  • 201 to 221 may occur before the method of FIG. 3. The method of FIG. 3 then takes place instead of 223 to 233. Entities 200 to 208 correspond to entities 300 to 308. 201 to 221 may also occur before the method of FIG. 4. The method of FIG. 4 then takes place instead of 223 to 233. Entities 200 to 208 correspond to entities 400 to 408.
  • network node 306 e.g., a CN node, NTN GW node or proxy node
  • network node 306 that has stored UE context(s) of one or more RRCJNACTIVE UEs (this may have been received over an S1 interface from source (last serving) satellite 1 304) computes a new security key using an identified next serving satellite 4 302’s security parameters.
  • Network node 306 then updates the AS security context of UE 300 before pushing the updated AS security context to the next serving target satellite 4302 (e.g., via an S1 interface) that has connectivity with network node 306. This enables successful connection resume at the next serving target satellite.
  • network node 306 determines a next serving satellite for UE 300 as target satellite 4 302.
  • network node 306 retrieves, from target satellite 4 302, a target cell PCI of target satellite 4 302 and channel number (e.g., EARFCN-DL). This may be retried over an S1 interface or a proprietary interface, for example. Based on the number of NTN cells hosted by target satellite 4302, target satellite 4 302 may provide a list of target cell PCIs and target EARFCN-DL associated with the target NTN cells. In examples where UE context(s) are stored at network node 306, network node 306 may retrieve a target satellite 1 304 and target EARFCN-DL via a proprietary interface (e.g., Stream Control Transmission Protocol (STCP), Next Generation Application Protocol (NGAP) or Operations & Management (O&M)).
  • STCP Stream Control Transmission Protocol
  • NGAP Next Generation Application Protocol
  • OFM Operations & Management
  • network node 306 computes a new security key (KeNB*) using security parameter(s) related to target satellite node 4 302.
  • the new security key may be determined using a PCI of target satellite node 4 302 and a channel number of a physical cell of the target satellite node 4 302 (e.g., EARFCN-DL).
  • the channel number may identify at least one of: frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode.
  • an additional parameter e.g. target eNB Id or next serving target satellite Id or any other unique parameter
  • target eNB Id e.g. target eNB Id or next serving target satellite Id or any other unique parameter
  • the additional parameter is also used by UE 300 to compute the same key (see below).
  • the network node may compute the new key (KeNB*) using any suitable key derivation function, such as the “A.5 KeNB* derivation function” in 3GPP TS33.401.
  • an equivalent list of message authentication codes (e.g., shortResumeMAC-l’s) are generated by network node 306, where each message authentication code can be associated with a UE context.
  • Target satellite 4 302 can implicitly authenticate the UE by validating the message authentication code(s).
  • network node 306 updates the AS security context within each stored UE context using the newly computed security key (KeNB*), and at 329 sends the UE context(s) to the next serving target satellite 4 302.
  • the updated UE context(s) include a UE context of UE 300.
  • the updated UE context(s) include updated AS security context determined using the new key (KeNB*), NCC value associated with the KeNB* and a list of one or more message authentication code(s) (e.g. , shortResumeMAC-l’s) associated with each UE context.
  • the message sent at 329 may comprise an indication that the AS security context has been updated.
  • target satellite 4302 derives new AS keys (e.g., RRC integrity key, RRC encryption key, User Plane (UP) key(s)) using the new key KeNB*.
  • AS keys e.g., RRC integrity key, RRC encryption key, User Plane (UP) key(s)
  • UE 300 has UL data to send.
  • UE 300 attempts to resume the RRC connection by sending an RRC resume request (RRCResumeRequest) including a Resume ID and a message authentication code (e.g., shortResumeMAC-l).
  • RRC resume request RRCResumeRequest
  • target satellite 4 302 can then retrieve the UE context using the Resume ID and authenticate the UE context by comparing the shortResumeMAC-l received from UE 300 with the list of shortResumeMAC- I’s received from network node 306 with the UE context, which is referred to herein as (implicit) authentication.
  • target satellite 4 302 triggers resumption of the RRC connection (RRCResume).
  • the RRCResume message may be sent towards UE 300 and include an NCC value, if an NCC value was previously received from network node 306 (e.g., in an S1-AP UE Context Suspend Response message, similar to 205b).
  • the RRCResume message may additionally include an eNB ID, gNB ID or satellite ID of the target satellite (or other unique identifier of the target satellite or next satellite after the target satellite). This can be used by UE 300 as an additional parameter for security key competition in the case that the target cell PCI is same as the last serving cell.
  • the NCC value in RRCResume can be used by UE 300 at 343 to compare it with the NCC store at UE 300; if it is the same, then UE 300 derives the security key (KeNB*) at 345; otherwise, UE 300 can synchronize the locally kept NH and then compute the security key (KeNB*) at 345.
  • UE 300 may use an optional parameter (satellite ID, eNB ID or any other unique identifier of target satellite 4302) as an input parameter for new key computation, wherein the optional parameter is included in the RRCResume message sent at 341 .
  • UE 300 is in an RRC connected an CM-connected state, and can send a message indicating that the RRC resumption is complete (RRCResumeComplete) to network node 306.
  • a path switch request is sent from target satellite 4 302 to network node 306 at 351 and network node 306 responds at 353.
  • DL data may be sent from P-GW 306 to satellite 4 302 (now a serving satellite for UE 300).
  • UE 300 and target satellite 4 302 will have the same key KeNB*, so that the interface between them can be protected.
  • the next serving target satellite 4402 upon receiving the UE context of RRCJNACTIVE state UEs, computes the new security key using relevant target satellite specific security parameters and updates the AS security context in each of the UE context(s). This enables successful connection resume at the next serving target satellite 402.
  • Network node 406 determines a next serving satellite for UE 400 as target satellite 4 402.
  • network node 406 node pushes (or forwards) the stored UE context of all the Inactive state UEs to the next serving target satellite as was received from last serving satellite 1 404 (without generating the new security key or updating the AS security context as in FIG. 3).
  • target satellite 4402 computes a new security key (KeNB*) using security parameter(s) related to target satellite node 4 402.
  • the new security key may be determined using a PCI of target satellite node 4 402 and a channel number of a physical cell of the target satellite node 4402 (e.g., EARFCN-DL).
  • the channel number may identify at least one of: frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode.
  • an additional parameter e.g. target eNB Id or next serving target satellite Id or any other unique parameter
  • target satellite 4402 computes a new security key (KeNB*) using security parameter(s) related to target satellite node 4 402.
  • the new security key may be determined using a PCI of target satellite node 4 402 and a channel number of a physical cell of the target satellite node 4402 (e.g., EARFCN-DL).
  • the channel number may identify at least one of: frequency of the physical cell; a bandwidth
  • the additional parameter is also used by UE 400 to compute the same key (see below).
  • the network node may compute the new key (KeNB*) using any suitable key derivation function, such as the “A.5 KeNB* derivation function” in 3GPP TS33.401.
  • target satellite 4 402 derives new AS keys (e.g., RRC integrity key, RRC encryption key, User Plane (UP) key(s)) using the new key KeNB*.
  • AS keys e.g., RRC integrity key, RRC encryption key, User Plane (UP) key(s)
  • UE 400 has UL data to send.
  • UE 400 attempts to resume the RRC connection by sending an RRC resume request (RRCResumeRequest) including a Resume ID and a message authentication code (e.g., shortResumeMAC-l).
  • RRC resume request RRCResumeRequest
  • target satellite 4 402 can then retrieve the UE context using the Resume ID and authenticate the UE context by comparing the shortResumeMAC-l received from UE 400 with the list of shortResumeMAC- I’s received from network node 406 with the UE context, which is referred to herein as (implicit) authentication.
  • target satellite 4 402 triggers resumption of the RRC connection (RRCResume).
  • the RRCResume message may be sent towards UE 400 and include an NCC value, if an NCC value was previously received from network node 406 (e.g., in an S1-AP UE Context Suspend Response message, similar to 205b).
  • the RRCResume message may additionally include an eNB ID, gNB ID or satellite ID of the target satellite (or other unique identifier of the target satellite or next satellite after the target satellite). This can be used by UE 400 as an additional parameter for security key competition in the case that the target cell PCI is same as the last serving cell.
  • the NCC value in RRCResume can be used by UE 400 at 475 to compare it with the NCC stored at UE 400; if it is the same, then UE 400 derives the security key (KeNB*) at 477; otherwise, UE 400 can synchronize the locally kept NH and then compute the security key (KeNB*) at 477.
  • UE 400 may use an optional parameter (satellite ID, eNB ID or any other unique identifier of target satellite 4402) as an input parameter for new key computation, wherein the optional parameter is included in the RRCResume message sent at 473.
  • UE 400 is in an RRC connected an CM-connected state, and at 481 can send a message indicating that the RRC resumption is complete (RRCResumeComplete) to network node 406.
  • a path switch request is sent from target satellite 4402 to network node 406 at 483 and network node 406 responds at 485.
  • DL data may be sent from P-GW 406 to satellite 4404 (now a serving satellite for UE 400).
  • UE 300 and target satellite 4 302 will have the same key KeNB*, so that the interface between them can be protected.
  • FIG. 5 shows an example method flow.
  • the method may be performed by a network node such as a CN node, network node 306 or 406, an NTN GW node or a proxy node, for example.
  • a network node such as a CN node, network node 306 or 406, an NTN GW node or a proxy node, for example.
  • the method comprises receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell.
  • the method comprises determining a security key for the user equipment using the identity and the channel number.
  • the method comprises updating an access stratum security context using the determined security key.
  • the method comprises sending the updated access stratum security context to the target satellite.
  • FIG. 6 shows an example method flow. The method may be performed by an apparatus at a target satellite, for example target base station 302 or 402.
  • a target satellite for example target base station 302 or 402.
  • the method comprises sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus.
  • the method comprises receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.
  • the method comprises sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC.
  • the method comprises receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
  • FIG. 8 shows an example method flow. The method may be performed by an apparatus at a target satellite, for example target base station 302 or 402.
  • a target satellite for example target base station 302 or 402.
  • the method comprises receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite.
  • the method comprises determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus.
  • the method comprises determining an updated access stratum security context for the user equipment using the security key.
  • FIG. 9 shows an example method flow.
  • the method may be performed by a network node such as a CN node, network node 306 or 406, an NTN GW node or a proxy node, for example.
  • a network node such as a CN node, network node 306 or 406, an NTN GW node or a proxy node, for example.
  • the method comprises for determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state.
  • the method comprises sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.
  • FIG. 10 shows an example method flow. The method may be performed by a user equipment such as UE 300 or 400, for example.
  • the method comprises sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code.
  • the method comprises receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
  • FIG. 11 illustrates an example of an apparatus 1100 that may implement or comprise at least a core network entity or AF of the communication network illustrated in FIG. 1.
  • the apparatus 1100 may comprise at least one random access memory (RAM) 1111 a, at least on read only memory (ROM) 1111 b, at least one processor 1112, 1113 and a network interface 1114.
  • the at least one processor 1112, 813 may be coupled to the RAM 1111a and the ROM 1111b.
  • the at least one processor 1112, 1113 may be configured to execute an appropriate software code 1115. Execution of the software code 1115 (or execution of instructions of the software code 1115.
  • the software code 1115 may be stored in the ROM 1111 b.
  • the apparatus 1100 may be interconnected with another apparatus 1100 for controlling other network functions of the 5GC, for example.
  • one or more network functions of the 5GC is deployed or hosted on an apparatus 1100.
  • the apparatus may include software code of additional network functions of the core network of the communication network.
  • the apparatus 1100 may comprise a computing device (e.g., a server), a computing system, such as a distributed computing system, or a virtual machine provided by a cloud computing system.
  • the apparatus 1100 may comprise a cloud computing system (e.g., a cloud core network), and other network functions of the core network shown in FIG. 1.
  • FIG. 2 illustrates an example of a communication device 1200, such as the terminal illustrated on FIG. 1.
  • the communication device 1200 may be provided by any device capable of sending and receiving radio signals.
  • Non-limiting examples of a communication device 1200 comprise a user equipment, a mobile station (MS) or mobile device such as a mobile phone or what is known as a ’smart phone’, a computer provided with a wireless interface card or other wireless interface facility (e.g., USB dongle), a personal data assistant (PDA) or a tablet provided with wireless communication capabilities, a machine-type communications (MTC) device, an Internet of things (loT) type communication device or any combinations of these or the like.
  • the communication device 1200 may comprise a transceiver for transmitting and/or receiving, for example, wireless signals carrying communications, for example radio signals.
  • the communications may be one or more of voice, electronic mail (email), text messages, multimedia data, machine data and so on.
  • the communication device 1200 may receive wireless signals (e.g., radio signals) over an air or radio interface 1207 via appropriate apparatus for receiving and may transmit wireless signals via appropriate apparatus for transmitting radio signals.
  • a transceiver is designated schematically by block 1206.
  • the transceiver 1206 may comprise, for example, a radio part and associated antenna arrangement.
  • the antenna arrangement may be arranged internally or externally to the mobile device and may comprise one or more antenna elements.
  • the antenna arrangement may be a multi-input multi output (MIMO) antenna.
  • MIMO multi-input multi output
  • the communication device 1200 may be provided with at least one processor 1201, at least one memory ROM 1202a, at least one RAM 1202b and other possible components 1203 for use in software and hardware aided execution of tasks it is configured to perform, including control of access to and communications with radio access networks (e.g., the 5G-RAN or NG-RAN illustrated in FIG. 1) and other communication devices.
  • the at least one processor 901 is coupled to the RAM 1202b and the ROM 1202a.
  • the at least one processor 901 may be configured to execute an appropriate software code 1208 (e.g., the at least one processor may execute instructions of the software code 1208).
  • the execution of the software code 908 may for example allow the communication device to perform one or more operations, including the operations described herein.
  • the software code 1208 may be stored in the ROM 1202a.
  • the processor, the ROM, and the RAM, the transceiver and other circuitry of the communication device can be provided on a circuit board, in chipsets, or in a system on chip.
  • the circuit board, chipsets or system on chip is denoted by reference 1204.
  • the communication device 1200 may optionally have a user interface such as key pad 1205, touch sensitive screen or pad, combinations thereof or the like.
  • a display, a speaker and a microphone may be provided depending on the type of communication device.
  • FIG. 13 shows a schematic representation of non-volatile memory media 1300a (e.g. computer disc (CD) or digital versatile disc (DVD)) and 1300b (e.g. universal serial bus (USB) memory stick) storing instructions and/or parameters 1302 which when executed by a processor allow the processor to perform one or more of the steps of any method flow described herein.
  • CD computer disc
  • DVD digital versatile disc
  • USB universal serial bus
  • references in the above to various network functions may comprise apparatus that perform at least some of the functionality associated with those network functions.
  • an apparatus comprising a network function may comprise a virtual network function instance of that network function.
  • apparatuses may comprise or be coupled to other units or modules etc., such as radio parts or radio heads, used in or for transmission and/or reception.
  • apparatuses have been described as one entity, different modules and memory may be implemented in one or more physical or logical entities.
  • the various embodiments may be implemented in hardware or special purpose circuitry, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
  • circuitry may refer to one or more or all of the following:
  • circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and/or firmware.
  • circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
  • the embodiments of this disclosure may be implemented by computer software executable by a data processor of the mobile device, such as in the processor entity, or by hardware, or by a combination of software and hardware.
  • Computer software or program also called program product, including software routines, applets and/or macros, may be stored in any apparatus-readable data storage medium and they comprise program instructions to perform particular tasks.
  • a computer program product may comprise one or more computerexecutable components which, when the program is run, are configured to carry out embodiments.
  • the one or more computer-executable components may be at least one software code or portions of it.
  • any blocks of the logic flow as in the Figures may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions.
  • the software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media such as hard disk or floppy disks, and optical media such as for example DVD and the data variants thereof, CD.
  • the physical media is a non-transitory media.
  • non-transitory is a limitation of the medium itself (i. e. , tangible, not a signal ) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).
  • the memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory.
  • the data processors may be of any type suitable to the local technical environment, and may comprise one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), FPGA, gate level circuits and processors based on multi core processor architecture, as non-limiting examples.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Physics & Mathematics (AREA)
  • Astronomy & Astrophysics (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

An apparatus comprising: means for receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; means for determining a security key for the user equipment using the identity and the channel number; means for updating an access stratum security context using the determined security key; means for sending the updated access stratum security context to the target satellite.

Description

METHOD, APPARATUS AND COMPUTER PROGRAM
TECHNICAL FIELD
Various example embodiments of this disclosure relate to a method, apparatus, and computer program for a communications network. Some examples relate to a method, apparatus, and computer program for security principles in Non-Terrestrial Networks (NTNs).
BACKGROUND
A communication network can be seen as a facility that enables communications between two or more communication devices, or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network. A communication device may be provided with a service by an application server.
Such communication networks operate in according with standards such as those provided by 3GPP (Third Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). Examples of standards are the so-called 4G (4th Generation), 5G (5th Generation) standards provided by 3GPP.
SUMMARY
Some example embodiments of this disclosure will be described with respect to certain aspects. These aspects are not intended to indicate key or essential features of the embodiments of this disclosure, nor are they intended to be used to limit the scope of thereof. Other features, aspects, and elements will be readily apparent to a person skilled in the art in view of this disclosure.
According to a first aspect there is provided an apparatus comprising: means for receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; means for determining a security key for the user equipment using the identity and the channel number; means for updating an access stratum security context using the determined security key; means for sending the updated access stratum security context to the target satellite.
According to some examples, the channel number of the physical cell comprises a E-UTRA Absolute Radio Frequency Channel Number. According to some examples, the channel number of the physical cell identifies at least one of: a frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode.
According to some examples, the apparatus comprises: means for determining that a serving satellite for the user equipment has lost connectivity with a core network of the apparatus; means for determining the target satellite as the next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state after the serving satellite has lost connectivity with the core network of the apparatus and before the target satellite has connectivity with the core network.
.According to some examples, the target satellite is determined as the next satellite using satellite ephemeris.
According to some examples, the apparatus comprises: means for determining that the identity of the physical cell of the target satellite and the serving satellite are the same, and in response, determining the security key using a target base station identifier of the target satellite or using any unique identifier of the next satellite after the target satellite that will have connectivity with the core network.
According to some examples, the apparatus comprises: means for generating a message authentication code, MAC, for each UE and per non-terrestrial network cell hosted by the target satellite to provide a list of one or more MACs; means for sending the list to the target satellite.
According to some examples, the MAC comprises a shortResumeMAC-l.
According to some examples, the identity of the physical cell of the target satellite and the channel number of the target physical cell are received over a feeder link between the target satellite and the apparatus.
According to some examples, the feeder link comprises a 3GPP standardized (e.g. S1 interface) or proprietary interface between a base station onboard the target satellite and a core network.
According to some examples, the apparatus comprises: a core network node; a non-terrestrial network gateway node; or a proxy node. According to some examples, the apparatus comprises: means for sending, to the target satellite, an indication that the access stratum security context has been updated.
According to a second aspect, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; determining a security key for the user equipment using the identity and the channel number; updating an access stratum security context using the determined security key; sending the updated access stratum security context to the target satellite.
According to some examples, the channel number of the physical cell comprises a E-UTRA Absolute Radio Frequency Channel Number.
According to some examples, the channel number of the physical cell identifies at least one of: a frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode.
According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: determining that a serving satellite for the user equipment has lost connectivity with a core network of the apparatus; determining the target satellite as the next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state after the serving satellite has lost connectivity with the core network of the apparatus and before the target satellite has connectivity with the core network.
.According to some examples, the target satellite is determined as the next satellite using satellite ephemeris.
According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: determining that the identity of the physical cell of the target satellite and the serving satellite are the same, and in response, determining the security key using a target base station identifier of the target satellite or using any unique identifier of the next satellite after the target satellite that will have connectivity with the core network.
According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: generating a message authentication code, MAC, for each UE and per non-terrestrial network cell hosted by the target satellite to provide a list of one or more MACs; sending the list to the target satellite.
According to some examples, the MAC comprises a shortResumeMAC-l.
According to some examples, the identity of the physical cell of the target satellite and the channel number of the target physical cell are received over a feeder link between the target satellite and the apparatus.
According to some examples, the feeder link comprises a 3GPP standardized (e.g. S1 interface) or proprietary interface between a base station onboard the target satellite and a core network.
According to some examples, the apparatus comprises: a core network node; a non-terrestrial network gateway node; or a proxy node.
According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: sending, to the target satellite, an indication that the access stratum security context has been updated.
According to a third aspect there is provided a method comprising: receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; determining a security key for the user equipment using the identity and the channel number; updating an access stratum security context using the determined security key; sending the updated access stratum security context to the target satellite.
According to some examples, the channel number of the physical cell comprises a E-UTRA Absolute Radio Frequency Channel Number.
According to some examples, the channel number of the physical cell identifies at least one of: a frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode.
According to some examples, the method comprises: determining that a serving satellite for the user equipment has lost connectivity with a core network of the apparatus; determining the target satellite as the next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state after the serving satellite has lost connectivity with the core network of the apparatus and before the target satellite has connectivity with the core network.
.According to some examples, the target satellite is determined as the next satellite using satellite ephemeris.
According to some examples, the method comprises: determining that the identity of the physical cell of the target satellite and the serving satellite are the same, and in response, determining the security key using a target base station identifier of the target satellite or using any unique identifier of the next satellite after the target satellite that will have connectivity with the core network.
According to some examples, the method comprises: generating a message authentication code, MAC, for each UE and per non-terrestrial network cell hosted by the target satellite to provide a list of one or more MACs; sending the list to the target satellite.
According to some examples, the MAC comprises a shortResumeMAC-l.
According to some examples, the identity of the physical cell of the target satellite and the channel number of the target physical cell are received over a feeder link between the target satellite and the apparatus.
According to some examples, the feeder link comprises a 3GPP standardized (e.g. S1 interface) or proprietary interface between a base station onboard the target satellite and a core network.
According to some examples, the apparatus comprises: a core network node; a non-terrestrial network gateway node; or a proxy node.
According to some examples, the method comprises sending, to the target satellite, an indication that the access stratum security context has been updated.
According to a fourth aspect there is provided a computer readable medium comprising instructions which, when executed by a user equipment, cause the user equipment to perform at least the following: receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; determining a security key for the user equipment using the identity and the channel number; updating an access stratum security context using the determined security key; sending the updated access stratum security context to the target satellite.
According to a fifth aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by a user equipment, cause the user equipment to perform at least the following: receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; determining a security key for the user equipment using the identity and the channel number; updating an access stratum security context using the determined security key; sending the updated access stratum security context to the target satellite.
According to a sixth aspect there is provided an apparatus comprising: means for sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; means for receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.
According to some examples, the user equipment is in a radio resource control suspended state after a serving satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.
According to some examples, the apparatus comprises: means for receiving, from the network node, a list comprising a message authentication code, MAC, for each user equipment per non-terrestrial network cell hosted by the apparatus.
According to some examples, the apparatus comprises: means for receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first MAC; means for determining that the first MAC is in the list received from the network node and then authenticating the first MAC; means for resuming the radio resource control connection with the network of the apparatus.
According to some examples, the identity of the physical cell of the apparatus and the channel number of the target physical cell is sent over a feeder link between the target satellite and the apparatus. According to some examples, the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.
According to some examples, a satellite comprises the apparatus.
According to some examples, the apparatus comprises: means for determining at least one further access stratum integrity and encryption key using the security key.
According to some examples, the apparatus comprises: means for receiving, from the network node, an indication that the updated access stratum security context has been updated.
According to a seventh aspect, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.
According to some examples, the user equipment is in a radio resource control suspended state after a serving satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.
According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: receiving, from the network node, a list comprising a message authentication code, MAC, for each user equipment per non-terrestrial network cell hosted by the apparatus.
According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first MAC; determining that the first MAC is in the list received from the network node and then authenticating the first MAC; resuming the radio resource control connection with the network of the apparatus. According to some examples, the identity of the physical cell of the apparatus and the channel number of the target physical cell is sent over a feeder link between the target satellite and the apparatus.
According to some examples, the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.
According to some examples, a satellite comprises the apparatus.
According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: determining at least one further access stratum integrity and encryption key using the security key.
According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: receiving, from the network node, an indication that the updated access stratum security context has been updated.
According to an eighth aspect there is provided a method comprising: sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.
According to some examples, the user equipment is in a radio resource control suspended state after a serving satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.
According to some examples, the method comprises: receiving, from the network node, a list comprising a message authentication code, MAC, for each user equipment per non-terrestrial network cell hosted by the apparatus.
According to some examples, the method comprises: receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first MAC; determining that the first MAC is in the list received from the network node and then authenticating the first MAC; resuming the radio resource control connection with the network of the apparatus. According to some examples, the identity of the physical cell of the apparatus and the channel number of the target physical cell is sent over a feeder link between the target satellite and the apparatus.
According to some examples, the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.
According to some examples, a satellite comprises the apparatus.
According to some examples, the method comprises: determining at least one further access stratum integrity and encryption key using the security key.
According to some examples, the method comprises: receiving, from the network node, an indication that the updated access stratum security context has been updated.
According to a ninth aspect there is provided a computer readable medium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.
According to a tenth aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.
According to an eleventh aspect, there is provided a user equipment comprising: means for sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; means for receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
According to some examples, the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell, and the user equipment comprises: means for determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; means for connecting to the target satellite using the determined security key.
According to some examples, the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, the user equipment comprising: means for determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; means for connecting to the target satellite using the determined security key
According to a twelfth aspect, there is provided a user equipment comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
According to some examples, the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell, and the instructions, when executed by the at least one processor, cause the apparatus to perform: determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; connecting to the target satellite using the determined security key.
According to some examples, the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, and the instructions, when executed by the at least one processor, cause the apparatus to perform: cause the apparatus at least to perform: determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; connecting to the target satellite using the determined security key. According to an thirteenth aspect, there is provided a method comprising: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
According to some examples, the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell, and the method comprises: determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; connecting to the target satellite using the determined security key.
According to some examples, the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, and the method comprises: determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; connecting to the target satellite using the determined security key.
According to a fourteenth aspect there is provided a computer readable medium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
According to a fifteenth aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
According to sixteenth aspect, there is provided an apparatus comprising: means for receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; means for determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; means for determining an updated access stratum security context for the user equipment using the security key.
According to some examples, the user equipment is in a radio resource control suspended state after the source satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.
According to some examples, the apparatus comprises: means for determining a list comprising a message authentication code for each user equipment per non-terrestrial network cell hosted by the apparatus.
According to some examples, the apparatus comprises: means for receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first message authentication code; means for determining that the first message authentication code is in the list received from the network node and then authenticating the first message authentication code; means for resuming the radio resource control connection with the user equipment.
According to some examples, the message authentication code comprises a shortResumeMAC-l.
According to some examples, the apparatus comprises: means for determining that the identity of the physical cell of the apparatus and the source satellite are the same, and in response, determining the security key using a base station identifier of the apparatus or using any unique identifier of the next satellite after the apparatus that will have connectivity with the core network.
According to some examples, the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.
According to some examples, a satellite comprises the apparatus.
According to some examples, the apparatus comprises: means for determining at least one further access stratum integrity and encryption key using the security key.
According to a seventeenth aspect, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; determining an updated access stratum security context for the user equipment using the security key.
According to some examples, the user equipment is in a radio resource control suspended state after the source satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.
According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform determining a list comprising a message authentication code for each user equipment per non-terrestrial network cell hosted by the apparatus.
According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first message authentication code; determining that the first message authentication code is in the list received from the network node and then authenticating the first message authentication code; resuming the radio resource control connection with the user equipment.
According to some examples, the message authentication code comprises a shortResumeMAC-l.
According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: determining that the identity of the physical cell of the apparatus and the source satellite are the same, and in response, determining the security key using a base station identifier of the apparatus or using any unique identifier of the next satellite after the apparatus that will have connectivity with the core network.
According to some examples, the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.
According to some examples, a satellite comprises the apparatus. According to a eighteenth aspect, there is provided a method comprising: receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; determining an updated access stratum security context for the user equipment using the security key.
According to some examples, the user equipment is in a radio resource control suspended state after the source satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.
According to some examples, the method comprises determining a list comprising a message authentication code for each user equipment per non-terrestrial network cell hosted by the apparatus.
According to some examples, the method comprises: receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first message authentication code; determining that the first message authentication code is in the list received from the network node and then authenticating the first message authentication code; resuming the radio resource control connection with the user equipment.
According to some examples, the message authentication code comprises a shortResumeMAC-l.
According to some examples, the method comprises: determining that the identity of the physical cell of the apparatus and the source satellite are the same, and in response, determining the security key using a base station identifier of the apparatus or using any unique identifier of the next satellite after the apparatus that will have connectivity with the core network.
According to some examples, the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.
According to some examples, a satellite comprises the apparatus that performs the method. According to a nineteenth aspect there is provided a computer readable medium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; determining an updated access stratum security context for the user equipment using the security key.
According to a twentieth aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; determining an updated access stratum security context for the user equipment using the security key.
According to a further aspect, there is provided an apparatus comprising: means for determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; means for sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.
According to some examples, the target satellite is determined as the next satellite using satellite ephemeris.
According to some examples, the apparatus comprises one of: a core network node; a nonterrestrial network gateway node; a proxy node.
According to a further aspect, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.
According to some examples, the target satellite is determined as the next satellite using satellite ephemeris.
According to some examples, the apparatus comprises one of: a core network node; a nonterrestrial network gateway node; a proxy node.
According to a further aspect, there is provided a method comprising: determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.
According to some examples, the target satellite is determined as the next satellite using satellite ephemeris.
According to some examples, the method if performed by one of: a core network node; a nonterrestrial network gateway node; a proxy node.
According to a further aspect there is provided a computer readable medium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.
According to a further aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated. According to a further aspect, there is provided a user equipment comprising: means for sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; means for receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
According to some examples, the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell, and the user equipment comprises: means for determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; means for connecting to the target satellite using the security key.
According to some examples, the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, and the user equipment comprises: means for determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; means for connecting to the target satellite using the security key
According to a further aspect, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
According to some examples, the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell, and the instructions, when executed by the at least one processor, cause the apparatus to perform: determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; connecting to the target satellite using the security key.
According to some examples, the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, and the instructions, when executed by the at least one processor, cause the apparatus to perform: determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; connecting to the target satellite using the security key.
According to a further aspect, there is provided a method comprising: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
According to some examples, the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell, and method comprises: determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; connecting to the target satellite using the security key.
According to some examples, the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, and the method comprises determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; connecting to the target satellite using the security key
According to a further aspect there is provided a computer readable medium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; receiving a response from the target satellite indicating that the radio resource control connection can be resumed
According to a further aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; receiving a response from the target satellite indicating that the radio resource control connection can be resumed. According to an aspect, there is provided a computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.
According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.
According to an aspect, there is provided a non-volatile tangible memory medium comprising program instructions stored thereon for performing at least one of the above methods.
According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the method according to any of the preceding aspects.
In the above, many different embodiments have been described. It should be appreciated that further embodiments may be provided by the combination of any two or more of the embodiments described above.
DESCRIPTION OF FIGURES
Some example embodiments will now be described, by way of non-limiting and illustrative example only, with reference to the accompanying Figures in which:
FIG. 1 shows a representation of a communication network comprising a 5th generation communication system and a data network;
FIG. 2 shows an example signal flow diagram for an example NTN Store and Forward (S&F) scenario;
FIG. 3 shows an example signal flow diagram for an example NTN Store and Forward (S&F) scenario with security key computation at a network node;
FIG. 4 shows an example signal flow diagram for an example NTN Store and Forward (S&F) scenario with security key computation at a next serving target satellite;
FIG. 5 shows an example method performed by a network node;
FIG. 6 shows an example method performed by a target satellite;
FIG. 7 shows an example method performed by a User Equipment (UE);
FIG. 8 shows an example method performed by a network node;
FIG. 9 shows an example method performed by a target satellite; FIG. 10 shows an example method performed by a User Equipment (UE);
FIG. 11 shows a representation of an apparatus for the communication system of FIG. 1 according to some example embodiments;
FIG. 12 shows a representation of an apparatus (e g., a UE) according to some example embodiments; and
FIG. 13 shows a schematic representation of a non-volatile memory medium storing instructions which when executed by a processor allow a processor to perform one or more of the steps of the methods disclosed herein.
DETAILED DESCRIPTION
Some examples described herein relate to a security framework for NTN S&F scenarios.
NTNs are wireless communication systems where at least part of the network is located above the Earth's surface. NTNs may involve satellites at low Earth orbit (LEO), medium Earth orbit (MEO) and geostationary orbit (GEO), high-altitude platforms (HAPS) and drones. Due to the high cost of satellite launch and operation, NTNs comprising satellite networks with incomplete satellite constellations are foreseen. Such satellite networks are often cost-efficient to launch and operate and can be useful for applications that are not time-critical (e.g., Internet of Things (loT) NTN having sparse LEO or MEO constellations and a limited number of ground stations). Satellite networks with incomplete satellite connections may have discontinuous satellite connectivity with User Equipment’s (UEs) and/or may have discontinuous connectivity to a ground station (e.g., ground station connectivity) due to coverage gaps that are caused by satellites that are missing from a full satellite constellation or due to a lack of ground station connectivity at some locations. A satellite network with an incomplete satellite constellation cannot be guaranteed to have ground station connectivity via a feeder link to the ground station at all times, and also cannot be guaranteed to provide continuous coverage to a UE in the satellite network (instead, only intermittent coverage may be available). A satellite may be able to establish a connection to a ground station (“a ground station connection”) for sending Control Plane (CP) data and/or signalling at certain points in the satellite’s orbit, and may not be able to establish a ground station connection at other points. Similarly, the satellite may be able to establish a connection for sending CP data and/or signalling to a UE at certain points in the satellite’s orbit, and may not be able to establish such a connection at other points. Consequently, in some situations a satellite may have either ground station connectivity (e.g., connectivity to a ground station via a feeder link) or satellite connectivity (e.g., connectivity to a UE via a satellite link), but not both at the same time. In NTNs with discontinuous satellite connectivity with UEs or a ground station, using a store- and-forward operation in the NTN can be useful. When a store-and-forward operations is used in a network, downlink CP data and/or signalling can be uploaded by a ground station to the satellite, buffered at the satellite and then transferred to a UE when the satellite has travelled further on its orbit to a point where a connection to the UE can be established. This enables the next hop to the UE for the stored payload. Uplink CP data and/or signalling can be similarly buffered at the satellite when a store-and-forward operation is used in a NTN, such that the CP data and/or signalling is sent by a UE to the satellite, buffered at the satellite and then later transferred to a ground station once the satellite has travelled further on its orbit to a point where a ground station connection to the ground station can be established. This enables the next hop to the ground station for the stored payload. A ground station connection between a ground station and a satellite may be considered to be established on a “feeder link”. When a satellite does not have a ground station connection, the satellite will have discontinuous connectivity to the core network (CN).
Store and Forward (S&F) operations allow a satellite to provide service to NTN devices even when the satellite is not connected to the NTN Gateway (GW) on the ground. A typical S&F scenario may involve a non-simultaneous connection between UE and satellite comprising a base station as regenerative payload (also called Access link) and satellite comprising a base station as regenerative payload and the CN on the ground (on the feeder link).
In the following various example embodiments are explained with reference to communication devices (e.g., UEs) that are capable of communication with a communications network (e.g., a 5G or 6G network). Before explaining in detail the embodiments of the methods, apparatuses, and computer programs of the present disclosure, a communication network comprising a 5th generation communication system (5GS), a radio access network and a core network (5GC) thereof, are briefly explained with reference to FIG. 1.
FIG. 1 shows a schematic representation of a communication network comprising a cellular or mobile communication system (e.g., a 5G communication system (5GS), and data network. The 5GS may comprise a radio access network such as a 5G radio access network (5G-RAN) or next generation radio access network (NG-RAN), a 5G core network (5GC). An application function may be deployed in the 5GS (e.g., hosted on an apparatus of the 5GC) and hence are generally referred to as a trusted application function or an AF may be deployed or hosted on one or more application servers of the data network and communicate with 5GC via a network exposure function of the 5GC as described in further detailed below. An application functions deployed or hosted on one or more application servers of the data network is generally referred to as an untrusted application function. The 5GS is configured to establish data sessions (e.g., PDU sessions) to provide a data connection between a UE and a data network via the access network and the 5GC (e.g., a UPF of the 5GC). The data sessions may be used to provide services to the UE.
FIG. 2 shows a method flow diagram for an example NTN S&F scenario where an RRC connection for UE 200 can be suspended and resumed.
At 201, UE 200 is in an connected RRC state (RRC_CONNECTED) and/or a Connection Management connected state (CM-CONNECTED). At 203, a proxy gateway (P-GW) 208 sends downlink (DL) data to a serving base station on board satellite 1 204. The base station may comprise an eNB or gNB. Satellite 204 may comprise a Non-Geo Synchronous Orbit (NGSO) satellite 1 204. At 205a, serving satellite 1 204 suspends the context of UE 200 by sending an RRC Connection Suspend request to MME 206. This can be performed before serving satellite 1 204 loses feeder link connectivity. In some examples, the request sent at 205a may be sent using S1 Application Protocol (S1-AP).
At 205b, MME 206 responds to the message sent at 205a. The response may indicate that the UE context has been suspended. Optionally, an indication of a Next Hop (NH) satellite and corresponding Nokia Converged Charging (NCC) value may be provided at 205b. This can be stored at 207 at the serving satellite 204. At 209 the serving satellite 1 204 indicates to UE 200 that the RRC connection has been suspended, and will send an identifier for resuming the RRC connection (Resume ID) and a NCC value. The NCC value may be the new value received at 205b, or may be an existing value received prior to 205b. At 211 , the serving satellite 1 204 stores the Resume ID and the UE context. The UE context included an Access Stratum (AS) security.
At 213, if a new NH value and NCC value were received at 205b from MME 206, serving satellite 1 204 may keep key KRRCint and delete other AS keys such as KeNB, KRRCenc, KUPenc. If a new NH and new NCC value were not received at 205b, serving satellite 1 204 may keep all AS keys.
At 215, UE 200 stores the Resume ID received at 209 with the UE context. The UE context may include the AS security context. UE 200 may also store the NCC value to be used in the next resumption of RRC connectivity.
At 217, UE 200 is in an RRC inactive (RRCJNACTIVE) and CM-CONNECTED state. At 219, the UE context of UE 200 is sent to network node 206. Although the example of FIG. 2 shows an MME as network node 206, other CN nodes may be used, or a NTN gateway (NTN GW) or a proxy node. At 221 , serving satellite 1 204 loses connectivity with the CN (or NTN GW) on the ground.
At 223, the network node 206 (or in some examples, one or more other CN entities) identifies a next target satellite 4 202 that may have connectivity with network node 206. This may be done using know satellite paths and the current time in the schedule (satellite ephemeris information), for example. At 225, network node 206 sends the UE context to the next serving satellite 4202.
At 227, UE 200 determines that there is Uplink (UL) data to send. At 229, UE 200 sends to target satellite 4204 a request to resume the RRC configuration (RRCResumeRequest). The request may comprise a resume ID and a message authentication code (e.g., ShortResumeMAC-l). When the UE decides at 227 to resume the RRC connection and triggers the RRCResumeRequest including the Resume ID and the ShortResumeMAC-l toward the target satellite 4 202 (e.g., an comprising eNB or gNB), the target satellite 4 202 extracts the Resume ID and ShortResumeMAC-l from the RRCResumeRequest.
The target satellite 4202 may then contact the cell at the source satellite 1 204 based on the information in the Resume ID by sending a Retrieve UE Context Request message (e.g., on an X2 interface), the message including the Resume ID, the ShortResumeMAC-l and Cell-ID of target cell, in order to retrieve the UE context (including the AS security context). The source satellite 1 204 retrieves the stored UE context including the AS security context from its database identified by the Resume ID and the source eNB calculates and verifies the ShortResumeMAC-l. If the check of the ShortResumeMAC-l is successful, then the source eNB shall derive a new KeNB*, based on the target Physical Cell ID (PCI) and target Evolved Universal Mobile Telecommunications System Terrestrial Radio Access Network (E-UTRAN) Absolute Radio Frequency Channel Number Downlink frequency (EARFCN-DL). If source satellite 1 204 received a new {NH, NCC} pair from MME 206 at 205b, then that pair shall be used, and the new NH shall be used in the new KeNB* derivation. The source satellite 1 204 responds with a Retrieve UE Context Response message to the target satellite 4 202 (e.g., on an X2 interface) including the UE context that is updated with AS security context using the new key. The AS security context sent to the target satellite eNB shall include a new derived security key (KeNB*), the NCC associated to the KeNB*. However, in a S&F scenario, the UE context of RRCJNACTIVE state UEs is forwarded by the last serving satellite 1 204 to network node 206 (e.g., CN node or the NTN GW node) before the last serving satellite 1 204 loses connectivity with network node 206. When network node 206 identifies the next serving target satellite that shall have connectivity to network node 206, network node 206 forwards the stored UE contexts blindly to the target satellite (without updating AS security context). As a result, an attempt by the RRCJNACTIVE state UE 200 to resume the connection at the target satellite will fail, as the AS security in the UE context is not updated with a new security key relevant to target satellite 4202.
In other words, a S&F scenario, when a network node (e.g., a CN node, proxy node or an NTN GW node) forwards the UE context of RRCJNACTIVE state UE(s) to a target satellite, unless the AS security context that is part of UE context is updated with new security key derived using security parameters relevant to the next serving target satellite, either by the CN node before forwarding or by the target node on receiving, the UE context is not valid for a successful connection resume at the target satellite. Such a failure is shown at 231 , where the RRC connection is released, and 233 where the connection resume fails.
FIG. 3 and FIG. 4 show two different methods for S&F scenarios to enable either the network node (FIG. 3) or target satellite node (FIG. 4) to compute a new security key and update the AS security context. This prevents the connection resume in NTN S&F scenarios failing as in FIG. 2, where the connection resume for a UE fails due to an outdated AS security context that is not updated using a new security key derived using input parameters relevant to the target satellite for the UE.
201 to 221 may occur before the method of FIG. 3. The method of FIG. 3 then takes place instead of 223 to 233. Entities 200 to 208 correspond to entities 300 to 308. 201 to 221 may also occur before the method of FIG. 4. The method of FIG. 4 then takes place instead of 223 to 233. Entities 200 to 208 correspond to entities 400 to 408.
In FIG. 3, network node 306 (e.g., a CN node, NTN GW node or proxy node) that has stored UE context(s) of one or more RRCJNACTIVE UEs (this may have been received over an S1 interface from source (last serving) satellite 1 304) computes a new security key using an identified next serving satellite 4 302’s security parameters. Network node 306 then updates the AS security context of UE 300 before pushing the updated AS security context to the next serving target satellite 4302 (e.g., via an S1 interface) that has connectivity with network node 306. This enables successful connection resume at the next serving target satellite. At 323, similarly to 223, network node 306 determines a next serving satellite for UE 300 as target satellite 4 302. At 325, network node 306 retrieves, from target satellite 4 302, a target cell PCI of target satellite 4 302 and channel number (e.g., EARFCN-DL). This may be retried over an S1 interface or a proprietary interface, for example. Based on the number of NTN cells hosted by target satellite 4302, target satellite 4 302 may provide a list of target cell PCIs and target EARFCN-DL associated with the target NTN cells. In examples where UE context(s) are stored at network node 306, network node 306 may retrieve a target satellite 1 304 and target EARFCN-DL via a proprietary interface (e.g., Stream Control Transmission Protocol (STCP), Next Generation Application Protocol (NGAP) or Operations & Management (O&M)).
At 327a, network node 306 computes a new security key (KeNB*) using security parameter(s) related to target satellite node 4 302. The new security key may be determined using a PCI of target satellite node 4 302 and a channel number of a physical cell of the target satellite node 4 302 (e.g., EARFCN-DL). The channel number may identify at least one of: frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode. In the case where an NTN target cell 302 PCI same as the last serving NTN cell 304 PCI, an additional parameter (e.g. target eNB Id or next serving target satellite Id or any other unique parameter) may be used to compute the new security key. The additional parameter is also used by UE 300 to compute the same key (see below). The network node may compute the new key (KeNB*) using any suitable key derivation function, such as the “A.5 KeNB* derivation function” in 3GPP TS33.401.
At 327b, based on the number of NTN cells hosted by target satellite 4 302 (or on a list of target cells received form the target satellite at network node 306), an equivalent list of message authentication codes (e.g., shortResumeMAC-l’s) are generated by network node 306, where each message authentication code can be associated with a UE context. Target satellite 4 302 can implicitly authenticate the UE by validating the message authentication code(s).
It should be noted that at 327a and 327b, if there is a new NH value available for YE 300 at network node 306, this may be used in determining KeNB*. After 327a and 327b, network node 306 updates the AS security context within each stored UE context using the newly computed security key (KeNB*), and at 329 sends the UE context(s) to the next serving target satellite 4 302. The updated UE context(s) include a UE context of UE 300. The updated UE context(s) include updated AS security context determined using the new key (KeNB*), NCC value associated with the KeNB* and a list of one or more message authentication code(s) (e.g. , shortResumeMAC-l’s) associated with each UE context. The message sent at 329 may comprise an indication that the AS security context has been updated.
At 331 , the updated UE context is stored at target satellite 4 302. At 333, target satellite 4302 derives new AS keys (e.g., RRC integrity key, RRC encryption key, User Plane (UP) key(s)) using the new key KeNB*.
At 335, UE 300 has UL data to send. At 337, UE 300 attempts to resume the RRC connection by sending an RRC resume request (RRCResumeRequest) including a Resume ID and a message authentication code (e.g., shortResumeMAC-l). At 339, target satellite 4 302 can then retrieve the UE context using the Resume ID and authenticate the UE context by comparing the shortResumeMAC-l received from UE 300 with the list of shortResumeMAC- I’s received from network node 306 with the UE context, which is referred to herein as (implicit) authentication.
At 341 , upon successful authentication, target satellite 4 302 triggers resumption of the RRC connection (RRCResume). The RRCResume message may be sent towards UE 300 and include an NCC value, if an NCC value was previously received from network node 306 (e.g., in an S1-AP UE Context Suspend Response message, similar to 205b). The RRCResume message may additionally include an eNB ID, gNB ID or satellite ID of the target satellite (or other unique identifier of the target satellite or next satellite after the target satellite). This can be used by UE 300 as an additional parameter for security key competition in the case that the target cell PCI is same as the last serving cell.
The NCC value in RRCResume can be used by UE 300 at 343 to compare it with the NCC store at UE 300; if it is the same, then UE 300 derives the security key (KeNB*) at 345; otherwise, UE 300 can synchronize the locally kept NH and then compute the security key (KeNB*) at 345. At 345, UE 300 may use an optional parameter (satellite ID, eNB ID or any other unique identifier of target satellite 4302) as an input parameter for new key computation, wherein the optional parameter is included in the RRCResume message sent at 341 .
At 347, UE 300 is in an RRC connected an CM-connected state, and can send a message indicating that the RRC resumption is complete (RRCResumeComplete) to network node 306. A path switch request is sent from target satellite 4 302 to network node 306 at 351 and network node 306 responds at 353. At 355, DL data may be sent from P-GW 306 to satellite 4 302 (now a serving satellite for UE 300). Using the above method, UE 300 and target satellite 4 302 will have the same key KeNB*, so that the interface between them can be protected.
In FIG. 4, a network node 406 (e.g., a CN node, NTN GW node or a Proxy node) that has stored the UE context of RRC_INACTIVE state UEs, pushed by the last serving satellite 404 (e.g., via an S1 interface), and blindly transfers the stored UE contexts to the next serving target satellite 402 (e.g., via an S1 interface) that will have CN (or NTN GW) connectivity, without updating the AS security context. An indication that the AS security context has not been updated may be included. The next serving target satellite 4402, upon receiving the UE context of RRCJNACTIVE state UEs, computes the new security key using relevant target satellite specific security parameters and updates the AS security context in each of the UE context(s). This enables successful connection resume at the next serving target satellite 402.
At 423, similarly to 223, Network node 406 determines a next serving satellite for UE 400 as target satellite 4 402. At 461 , network node 406 node pushes (or forwards) the stored UE context of all the Inactive state UEs to the next serving target satellite as was received from last serving satellite 1 404 (without generating the new security key or updating the AS security context as in FIG. 3).
At 463, target satellite 4402 computes a new security key (KeNB*) using security parameter(s) related to target satellite node 4 402. The new security key may be determined using a PCI of target satellite node 4 402 and a channel number of a physical cell of the target satellite node 4402 (e.g., EARFCN-DL). The channel number may identify at least one of: frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode. In the case where an NTN target cell 402 PCI same as the last serving NTN cell 404 PCI, an additional parameter (e.g. target eNB Id or next serving target satellite Id or any other unique parameter) may be used to compute the new security key. The additional parameter is also used by UE 400 to compute the same key (see below). The network node may compute the new key (KeNB*) using any suitable key derivation function, such as the “A.5 KeNB* derivation function” in 3GPP TS33.401.
At 465, target satellite 4 402 derives new AS keys (e.g., RRC integrity key, RRC encryption key, User Plane (UP) key(s)) using the new key KeNB*.
At 467, UE 400 has UL data to send. At 469, UE 400 attempts to resume the RRC connection by sending an RRC resume request (RRCResumeRequest) including a Resume ID and a message authentication code (e.g., shortResumeMAC-l). At 471 , target satellite 4 402 can then retrieve the UE context using the Resume ID and authenticate the UE context by comparing the shortResumeMAC-l received from UE 400 with the list of shortResumeMAC- I’s received from network node 406 with the UE context, which is referred to herein as (implicit) authentication.
At 473, upon successful authentication, target satellite 4 402 triggers resumption of the RRC connection (RRCResume). The RRCResume message may be sent towards UE 400 and include an NCC value, if an NCC value was previously received from network node 406 (e.g., in an S1-AP UE Context Suspend Response message, similar to 205b). The RRCResume message may additionally include an eNB ID, gNB ID or satellite ID of the target satellite (or other unique identifier of the target satellite or next satellite after the target satellite). This can be used by UE 400 as an additional parameter for security key competition in the case that the target cell PCI is same as the last serving cell.
The NCC value in RRCResume can be used by UE 400 at 475 to compare it with the NCC stored at UE 400; if it is the same, then UE 400 derives the security key (KeNB*) at 477; otherwise, UE 400 can synchronize the locally kept NH and then compute the security key (KeNB*) at 477. At 477, UE 400 may use an optional parameter (satellite ID, eNB ID or any other unique identifier of target satellite 4402) as an input parameter for new key computation, wherein the optional parameter is included in the RRCResume message sent at 473.
At 479, UE 400 is in an RRC connected an CM-connected state, and at 481 can send a message indicating that the RRC resumption is complete (RRCResumeComplete) to network node 406. A path switch request is sent from target satellite 4402 to network node 406 at 483 and network node 406 responds at 485. At 487, DL data may be sent from P-GW 406 to satellite 4404 (now a serving satellite for UE 400).
Using the above method, UE 300 and target satellite 4 302 will have the same key KeNB*, so that the interface between them can be protected.
FIG. 5 shows an example method flow. The method may be performed by a network node such as a CN node, network node 306 or 406, an NTN GW node or a proxy node, for example.
At 500, the method comprises receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell. At 502, the method comprises determining a security key for the user equipment using the identity and the channel number.
At 504, the method comprises updating an access stratum security context using the determined security key.
At 506, the method comprises sending the updated access stratum security context to the target satellite.
FIG. 6 shows an example method flow. The method may be performed by an apparatus at a target satellite, for example target base station 302 or 402.
At 600, the method comprises sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus.
At 602, the method comprises receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.
FIG. 7 shows an example method flow. The method may be performed by a UE such as UE 300 or 400, for example.
At 700, the method comprises sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC.
At 702, the method comprises receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
FIG. 8 shows an example method flow. The method may be performed by an apparatus at a target satellite, for example target base station 302 or 402.
At 800, the method comprises receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite. At 802, the method comprises determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus.
At 804, the method comprises determining an updated access stratum security context for the user equipment using the security key.
FIG. 9 shows an example method flow. The method may be performed by a network node such as a CN node, network node 306 or 406, an NTN GW node or a proxy node, for example.
At 900, the method comprises for determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state.
At 902, the method comprises sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.
FIG. 10 shows an example method flow. The method may be performed by a user equipment such as UE 300 or 400, for example.
At 1000, the method comprises sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code.
At 1002, the method comprises receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
FIG. 11 illustrates an example of an apparatus 1100 that may implement or comprise at least a core network entity or AF of the communication network illustrated in FIG. 1. The apparatus 1100 may comprise at least one random access memory (RAM) 1111 a, at least on read only memory (ROM) 1111 b, at least one processor 1112, 1113 and a network interface 1114. The at least one processor 1112, 813 may be coupled to the RAM 1111a and the ROM 1111b. The at least one processor 1112, 1113 may be configured to execute an appropriate software code 1115. Execution of the software code 1115 (or execution of instructions of the software code 1115. The software code 1115 may be stored in the ROM 1111 b. The apparatus 1100 may be interconnected with another apparatus 1100 for controlling other network functions of the 5GC, for example. In some embodiments, one or more network functions of the 5GC is deployed or hosted on an apparatus 1100. In alternative embodiments, the apparatus may include software code of additional network functions of the core network of the communication network. The apparatus 1100 may comprise a computing device (e.g., a server), a computing system, such as a distributed computing system, or a virtual machine provided by a cloud computing system. In some examples, the apparatus 1100 may comprise a cloud computing system (e.g., a cloud core network), and other network functions of the core network shown in FIG. 1.
FIG. 2 illustrates an example of a communication device 1200, such as the terminal illustrated on FIG. 1. The communication device 1200 may be provided by any device capable of sending and receiving radio signals. Non-limiting examples of a communication device 1200 comprise a user equipment, a mobile station (MS) or mobile device such as a mobile phone or what is known as a ’smart phone’, a computer provided with a wireless interface card or other wireless interface facility (e.g., USB dongle), a personal data assistant (PDA) or a tablet provided with wireless communication capabilities, a machine-type communications (MTC) device, an Internet of things (loT) type communication device or any combinations of these or the like. The communication device 1200 may comprise a transceiver for transmitting and/or receiving, for example, wireless signals carrying communications, for example radio signals. The communications may be one or more of voice, electronic mail (email), text messages, multimedia data, machine data and so on.
The communication device 1200 may receive wireless signals (e.g., radio signals) over an air or radio interface 1207 via appropriate apparatus for receiving and may transmit wireless signals via appropriate apparatus for transmitting radio signals. In FIG. 12, a transceiver is designated schematically by block 1206. The transceiver 1206 may comprise, for example, a radio part and associated antenna arrangement. The antenna arrangement may be arranged internally or externally to the mobile device and may comprise one or more antenna elements. The antenna arrangement may be a multi-input multi output (MIMO) antenna.
The communication device 1200 may be provided with at least one processor 1201, at least one memory ROM 1202a, at least one RAM 1202b and other possible components 1203 for use in software and hardware aided execution of tasks it is configured to perform, including control of access to and communications with radio access networks (e.g., the 5G-RAN or NG-RAN illustrated in FIG. 1) and other communication devices. The at least one processor 901 is coupled to the RAM 1202b and the ROM 1202a. The at least one processor 901 may be configured to execute an appropriate software code 1208 (e.g., the at least one processor may execute instructions of the software code 1208). The execution of the software code 908 may for example allow the communication device to perform one or more operations, including the operations described herein. The software code 1208 may be stored in the ROM 1202a.
The processor, the ROM, and the RAM, the transceiver and other circuitry of the communication device (e.g., a modem) can be provided on a circuit board, in chipsets, or in a system on chip. The circuit board, chipsets or system on chip is denoted by reference 1204. The communication device 1200 may optionally have a user interface such as key pad 1205, touch sensitive screen or pad, combinations thereof or the like. Optionally one or more of a display, a speaker and a microphone may be provided depending on the type of communication device.
FIG. 13 shows a schematic representation of non-volatile memory media 1300a (e.g. computer disc (CD) or digital versatile disc (DVD)) and 1300b (e.g. universal serial bus (USB) memory stick) storing instructions and/or parameters 1302 which when executed by a processor allow the processor to perform one or more of the steps of any method flow described herein.
It is understood that references in the above to various network functions (e.g., to an MME, proxy node, NTN GW node, target satellite, etc.) may comprise apparatus that perform at least some of the functionality associated with those network functions. Further, an apparatus comprising a network function may comprise a virtual network function instance of that network function.
It should be understood that the apparatuses may comprise or be coupled to other units or modules etc., such as radio parts or radio heads, used in or for transmission and/or reception. Although the apparatuses have been described as one entity, different modules and memory may be implemented in one or more physical or logical entities.
It is noted that whilst some embodiments have been described in relation to 5G networks, similar principles can be applied in relation to other networks and communication systems. Therefore, although certain embodiments were described above by way of example with reference to certain example architectures for wireless networks, technologies and standards, embodiments may be applied to any other suitable forms of communication systems than those illustrated and described herein. It is also noted herein that while the above describes example embodiments, there are several variations and modifications which may be made to the disclosed solution without departing from the scope of the present invention.
As used herein, “at least one of the following: <a list of two or more elements: ” and “at least one of <a list of two or more elements:*” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
In general, the various embodiments may be implemented in hardware or special purpose circuitry, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
As used herein, the term “circuitry” may refer to one or more or all of the following:
(a) hardware-only circuit implementations (such as implementations in only analog and/or digital circuitry) and
(b) combinations of hardware circuits and software, such as (as applicable):
(i) a combination of analog and/or digital hardware circuit(s) with software/firmware and
(ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and
(c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.”
This definition of circuitry applies to all uses of the term “means” herein, including in any claims. As a further example, as used herein, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and/or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
The embodiments of this disclosure may be implemented by computer software executable by a data processor of the mobile device, such as in the processor entity, or by hardware, or by a combination of software and hardware. Computer software or program, also called program product, including software routines, applets and/or macros, may be stored in any apparatus-readable data storage medium and they comprise program instructions to perform particular tasks. A computer program product may comprise one or more computerexecutable components which, when the program is run, are configured to carry out embodiments. The one or more computer-executable components may be at least one software code or portions of it.
Further in this regard it should be noted that any blocks of the logic flow as in the Figures may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media such as hard disk or floppy disks, and optical media such as for example DVD and the data variants thereof, CD. The physical media is a non-transitory media.
The term “non-transitory,” as used herein, is a limitation of the medium itself (i. e. , tangible, not a signal ) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).
The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may comprise one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), FPGA, gate level circuits and processors based on multi core processor architecture, as non-limiting examples.
Various example embodiments of the disclosure may be practiced in various components such as integrated circuit modules. The design of integrated circuits is by and large a highly automated process. Complex and powerful software tools are available for converting a logic level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate. The scope of protection sought for various example embodiments of the disclosure is set out by the independent claims. The example embodiments and features thereof, if any, described in this disclosure that do not fall under the scope of the independent claims are to be interpreted as examples useful for understanding various example embodiments of the disclosure.
The foregoing description has provided, by way of non-limiting and illustrative examples, a full and informative description of the various example embodiments of this disclosure. However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings and the claims. However, all such and similar modifications of the teachings will still fall within the various example embodiments of the disclosure as set forth in the claims. By way of non-limiting and illustrative example, there is a further example embodiment comprising a combination of one or more example embodiments with any of the other example embodiments previously discussed.

Claims

1. An apparatus comprising: means for receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; means for determining a security key for the user equipment using the identity and the channel number; means for updating an access stratum security context using the determined security key; means for sending the updated access stratum security context to the target satellite.
2. The apparatus according to claim 1, the apparatus comprising: means for determining that a serving satellite for the user equipment has lost connectivity with a core network of the apparatus; means for determining the target satellite as the next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state after the serving satellite has lost connectivity with the core network of the apparatus and before the target satellite has connectivity with the core network.
3. The apparatus according to claim 2, the apparatus comprising: means for determining that the identity of the physical cell of the target satellite and the serving satellite are the same, and in response, determining the security key using a target base station identifier of the target satellite or using any unique identifier of the next satellite after the target satellite that will have connectivity with the core network.
4. The apparatus according to any preceding claim, the apparatus comprising: means for generating a message authentication code, MAC, for each UE and per nonterrestrial network cell hosted by the target satellite to provide a list of one or more MACs; means for sending the list to the target satellite.
5. The apparatus according to any preceding claim, wherein the identity of the physical cell of the target satellite and the channel number of the target physical cell are received over a feeder link between the target satellite and the apparatus.
6. The apparatus according to any preceding claim, wherein the apparatus comprises one of: a core network node; a non-terrestrial network gateway node; a proxy node.
7. The apparatus according to any preceding claim, the apparatus comprising: means for sending, to the target satellite, an indication that the access stratum security context has been updated.
8. A method comprising: receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; determining a security key for the user equipment using the identity and the channel number; updating an access stratum security context using the determined security key; sending the updated access stratum security context to the target satellite.
9. A computer program comprising instructions stored thereon for performing at least the following: receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; determining a security key for the user equipment using the identity and the channel number ; updating an access stratum security context using the determined security key; sending the updated access stratum security context to the target satellite.
10. An apparatus comprising: means for sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; means for receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.
11 . The apparatus according to claim 10, wherein the user equipment is in a radio resource control suspended state after a serving satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.
12. The apparatus according to claim 10 or claim 11 , the apparatus comprising: means for receiving, from the network node, a list comprising a message authentication code, MAC, for each user equipment per non-terrestrial network cell hosted by the apparatus.
13. The apparatus according to claim 12, the apparatus comprising: means for receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first MAC; means for determining that the first MAC is in the list received from the network node and then authenticating the first MAC; means for resuming the radio resource control connection with the network of the apparatus.
14. The apparatus according to any of claims 10 to 13, wherein the identity of the physical cell of the apparatus and the channel number of the target physical cell is sent over a feeder link between the target satellite and the apparatus.
15. The apparatus according to any of claims 10 to 14, wherein a satellite comprises the apparatus.
16. The apparatus according to any of claims 10 to 15, the apparatus comprising: means for determining at least one further access stratum integrity and encryption key using the security key.
17. The apparatus according to any preceding claim, the apparatus comprising: means for receiving, from the network node, an indication that the updated access stratum security context has been updated.
18. A method comprising: sending, to a network node, an identity of a physical cell of an apparatus and a channel number of a physical cell of an apparatus; receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number and the updated access stratum security context is updated using the security key.
19. A computer program comprising instructions stored thereon for performing at least the following: sending, to a network node, an identity of a physical cell of an apparatus and a channel number of a physical cell of the apparatus; receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number and the updated access stratum security context is updated using the security key.
20. A user equipment comprising: means for sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; means for receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
21. The user equipment according to claim 20, wherein the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell, the user equipment comprising: means for determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; means for connecting to the target satellite using the determined security key.
22. The user equipment according to claim 20, wherein the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, the user equipment comprising: means for determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; means for connecting to the target satellite using the determined security key.
23. A method comprising: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
24. A computer program comprising instructions stored thereon for performing at least the following: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.
PCT/EP2025/057441 2024-05-10 2025-03-19 Method, apparatus and computer program Pending WO2025233045A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
IN202441037142 2024-05-10
IN202441037142 2024-05-10

Publications (1)

Publication Number Publication Date
WO2025233045A1 true WO2025233045A1 (en) 2025-11-13

Family

ID=95123125

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/EP2025/057441 Pending WO2025233045A1 (en) 2024-05-10 2025-03-19 Method, apparatus and computer program

Country Status (1)

Country Link
WO (1) WO2025233045A1 (en)

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2271145A1 (en) * 2008-09-22 2011-01-05 Ntt Docomo, Inc. Mobile communication method
US20190124506A1 (en) * 2017-10-19 2019-04-25 Futurewei Technologies, Inc. System and Method for Communicating with Provisioned Security Protection
US20200351977A1 (en) * 2018-08-17 2020-11-05 Guangdong Oppo Mobile Telecommunications Corp., Ltd. Information transmission method and apparatus, and communication device
AU2018366755B2 (en) * 2017-11-16 2021-11-18 Huawei Technologies Co., Ltd. Connection resume request method and apparatus
CN115175181A (en) * 2021-04-02 2022-10-11 华为技术有限公司 Communication method and device
WO2024026640A1 (en) * 2022-08-01 2024-02-08 Nokia Shanghai Bell Co., Ltd. Apparatus, method, and computer program

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2271145A1 (en) * 2008-09-22 2011-01-05 Ntt Docomo, Inc. Mobile communication method
US20190124506A1 (en) * 2017-10-19 2019-04-25 Futurewei Technologies, Inc. System and Method for Communicating with Provisioned Security Protection
AU2018366755B2 (en) * 2017-11-16 2021-11-18 Huawei Technologies Co., Ltd. Connection resume request method and apparatus
US20200351977A1 (en) * 2018-08-17 2020-11-05 Guangdong Oppo Mobile Telecommunications Corp., Ltd. Information transmission method and apparatus, and communication device
CN115175181A (en) * 2021-04-02 2022-10-11 华为技术有限公司 Communication method and device
WO2024026640A1 (en) * 2022-08-01 2024-02-08 Nokia Shanghai Bell Co., Ltd. Apparatus, method, and computer program

Similar Documents

Publication Publication Date Title
JP7452600B2 (en) Communication terminal device and its method
CN111491338A (en) Context storage method and device
CN108353275A (en) Security of Proxied Devices
WO2024026640A1 (en) Apparatus, method, and computer program
CN113544980B (en) Beam Failure Recovery
CN116709168A (en) A communication method and device
US11849323B2 (en) PDCP count handling in RRC connection resume
WO2021030708A1 (en) Managing security keys in a communication system
CN112243232A (en) Method and apparatus for re-establishing a radio resource control (RRC) connection
US20200323017A1 (en) 5G NAS Recovery from NASC Failure
EP3844998B1 (en) User equipment context transfer over radio access network paging
US20250212292A1 (en) Method, apparatus and computer program
WO2025233042A1 (en) Method, apparatus and computer program
CN116074821A (en) A communication method and device
CN117062253B (en) Communication method
WO2024026642A1 (en) Apparatus, method and computer program
CN117728880A (en) An access verification method, satellite, gateway station and storage medium
EP4145880A1 (en) Communication method and apparatus
WO2025171559A9 (en) Method and apparatus for generating key during switch of serving network node
CN116458184B (en) Method for key transmission
CN121264003A (en) Authentication of terminal equipment
WO2025112008A1 (en) Secure communication in non-terrestrial network store and forward system
WO2024065209A1 (en) Mobile terminated early data transmission for internet of things
GB2633611A (en) Method, apparatus and computer program
WO2026073611A1 (en) Method, apparatus and computer program

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 25714052

Country of ref document: EP

Kind code of ref document: A1