IP Library Granted Patent US 12,389,301
Granted Patent B2
US 12,389,301 · App. 18/923,586 · Granted Aug 12, 2025

Security key management in dual connectivity operation

Inventors: Srinivasan Selvaganapathy (Bangalore, IN); Ahmad Awada (Munich, DE); Halit Murat Gürsu (Munich, DE)
Assignee: Nokia Technologies Oy
H04W36/362H04W12/041H04W88/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,389,301
App. No.
18/923,586
Granted
Aug 12, 2025
Kind
B2
Abstract

The disclosure inter alia relates to a user equipment configured to support dual connectivity operation towards a master node and a secondary node of a radio access network, the user equipment comprising at least one processor and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment to perform at least the following: establishing a connection towards the master node; receiving configuration information from the master node, wherein the configuration information comprises key counter information which defines a sequence of at least two different key counter values to generate at least two different security keys for at least two different target secondary nodes.

Claims (87)

1. A user equipment configured to support dual connectivity operation towards a master node and a secondary node of a radio access network, the user equipment comprising at least one processor and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment to perform at least the following:

establishing a connection towards the master node;

receiving configuration information from the master node, wherein the configuration information comprises key counter information which defines a sequence of at least two different key counter values to generate at least two different security keys for at least two different target secondary nodes; wherein a first target secondary node is configured for a first conditional PSCell addition or change (CPAC) or a conditional handover (CHO) towards the first target secondary node, and wherein a second target secondary node is configured for a subsequent conditional PSCell addition or change (CPAC) or a conditional handover (CHO) towards the second target secondary node;

generating a first security key using a first key counter value derived from the key counter information;

using the first security key for integrity protection and/or ciphering of data exchanged between the user equipment and the first target secondary node; and

processing the key counter information such that the user equipment is enabled to derive, from the processed key counter information, at least a second key counter value, which is different from the first key counter value,

wherein the generating the first security key comprises using a first list element in a list of key counter values included in the key counter information as the first key counter value, wherein processing the key counter information comprises removing the first list element from the list of key counter values.

2. The user equipment according to claim 1 , the at least one memory further storing instructions that, when executed by the at least one processor, cause the user equipment to perform at least one of the following:

generating a second security key, which is different from the first security key, using the second key counter value derived from the processed key counter information;

using the second security key for integrity protection and/or ciphering of data exchanged between the user equipment and the second target secondary node, which is different from the first target secondary node;

further processing the key counter information such that the user equipment is enabled to derive, from the further processed key counter information, at least a further key counter value, which is different from the first key counter value and different from the second key counter value.

3. The user equipment according to claim 1 , wherein the key counter information received from the master node defines a list of at least two different key counter values.

4. The user equipment according to claim 2 , wherein generating the second security key comprises using the presently first list element in the list of key counter values as the second key counter value, wherein further processing the key counter information comprises removing the presently first list element from the list of key counter values.

5. The user equipment according to claim 4 ,

wherein the configuration information comprises key counter information which defines a list of at least two different SN counter values to generate at least two different K SN security keys for at least two different target secondary nodes,

wherein the first key counter value is a first SN counter value, wherein the second key counter value is a second SN counter value, wherein the first security key is a first K SN security key, wherein the second security key is a second K SN security key,

wherein the configuration information further comprises a radio resource control reconfiguration request,

wherein the configuration information further comprises information which is related to a conditional addition or change of a primary cell of a secondary cell group associated with the first target secondary node or related to a conditional handover towards the first target secondary node,

wherein the configuration information further comprises information which is related to a conditional addition or change of a primary cell of a secondary cell group associated with the second target secondary node or related to a conditional handover towards the second target secondary node,

the at least one memory further storing instructions that, when executed by the at least one processor, cause the user equipment to perform at least one of the following:

determining whether at least one condition for a conditional addition or change of a primary cell of a secondary cell group associated with the first target secondary node or at least one condition for a conditional handover towards the first target secondary node is fulfilled;

initiating, via a random access channel, a random access procedure towards the first target secondary node using the first K SN security key;

determining whether at least one condition for a conditional addition or change of a primary cell of a secondary cell group associated with the second target secondary node or at least one condition for a conditional handover towards the second target secondary node is fulfilled;

initiating, via a random access channel, a random access procedure towards the second target secondary node using the second K SN security key.

6. The user equipment according to claim 3 , the at least one memory further storing instructions that, when executed by the at least one processor, cause the user equipment to perform at least the following:

receiving at least one additional list element for the list of key counter values from the master node.

7. The user equipment according to claim 1 , wherein the key counter information received from the master node comprises a key counter value and an instruction to maintain the key counter value.

8. The user equipment according to claim 1 , wherein generating the first security key comprises using the key counter value received from the master node as the first key counter value, wherein processing the key counter information comprises adding a predefined step value to the key counter value received from the master node.

9. The user equipment according to claim 2 , wherein generating the second security key comprises using the present key counter value as the second key counter value, wherein further processing the key counter information comprises adding a predefined step value to the present key counter value.

10. The user equipment according to claim 9 ,

wherein the configuration information comprises key counter information which defines a sequence of at least two different SN counter values to generate at least two different K SN security keys for at least two different target secondary nodes,

wherein the key counter information received from the master node comprises an SN counter value and an instruction to maintain the SN counter value,

wherein the first key counter value is a first SN counter value, wherein the second key counter value is a second SN counter value, wherein the first security key is a first K SN security key, wherein the second security key is a second K SN security key,

wherein the configuration information further comprises a radio resource control reconfiguration request,

wherein the configuration information further comprises information which is related to a conditional addition or change of a primary cell of a secondary cell group associated with the first target secondary node or related to a conditional handover towards the first target secondary node,

wherein the configuration information further comprises information which is related to a conditional addition or change of a primary cell of a secondary cell group associated with the second target secondary node or related to a conditional handover towards the second target secondary node,

the at least one memory further storing instructions that, when executed by the at least one processor, cause the user equipment to perform at least one of the following:

determining whether at least one condition for a conditional addition or change of a primary cell of a secondary cell group associated with the first target secondary node or at least one condition for a conditional handover towards the first target secondary node is fulfilled;

initiating, via a random access channel, a random access procedure towards the first target secondary node using the first K SN security key;

determining whether at least one condition for a conditional addition or change of a primary cell of a secondary cell group associated with the second target secondary node or at least one condition for a conditional handover towards the second target secondary node is fulfilled;

initiating, via a random access channel, a random access procedure towards the second target secondary node using the second K SN security key.

11. The user equipment according to claim 8 , wherein the key counter information received from the master node defines a maximum allowed number of additions of the predefined step value to the key counter value received from the master node, the at least one memory further storing instructions that, when executed by the at least one processor, cause the user equipment to perform at least the following:

determining whether the maximum allowed number of additions has been reached;

in response to determining that the maximum allowed number of additions has been reached, preventing further additions of the predefined step value to the present key counter value.

12. The user equipment according to claim 2 , the at least one memory further storing instructions that, when executed by the at least one processor, cause the user equipment to perform at least one of the following:

generating a further security key, which is different from the first security key and different from the second security key, using the further key counter value derived from the further processed key counter information;

using the further security key for integrity protection and/or ciphering of data exchanged between the user equipment and a further target secondary node, which is different from the second target secondary node;

further processing the key counter information such that the user equipment is enabled to derive, from the further processed key counter information, at least one further key counter value, which is different from the first key counter value, different from the second key counter value, and different from any other key counter value derived previously from the non-processed, processed or further processed key counter information.

13. The user equipment according to claim 1 , wherein the configuration information further comprises information indicative of at least one target secondary cell for which generating a security key is not required.

14. The user equipment according to claim 1 , the at least one memory further storing instructions that, when executed by the at least one processor, cause the user equipment to further perform: establishing a connection towards the secondary node; and

wherein the first target secondary node is configured for a first conditional PSCell addition or change (CPAC) or a conditional handover (CHO) from the secondary node the UE is connected to towards the first target secondary node, and wherein a second target secondary node is configured for a subsequent conditional PSCell addition or change (CPAC) or a conditional handover (CHO) from the first target secondary node the UE is connected to after the first CPAC or CHO towards the second target secondary node.

15. A non-transitory computer-readable medium comprising program instructions that, when executed by a user equipment configured to support dual connectivity operation towards a master node and a secondary node of a radio access network, cause the user equipment to perform at least the following:

establishing a connection towards the master node;

receiving configuration information from the master node, wherein the configuration information comprises key counter information which defines a sequence of at least two different key counter values to generate at least two different security keys for at least two different target secondary nodes; wherein a first target secondary node is configured for a first conditional PSCell addition or change (CPAC) or a conditional handover (CHO) towards the first target secondary node, and wherein a second target secondary node is configured for a subsequent conditional PSCell addition or change (CPAC) or a conditional handover (CHO) towards the second target secondary node;

generating a first security key using a first key counter value derived from the key counter information;

using the first security key for integrity protection and/or ciphering of data exchanged between the user equipment and a first target secondary node; and

processing the key counter information such that the user equipment is enabled to derive, from the processed key counter information, at least a second key counter value, which is different from the first key counter value,

wherein the generating the first security key comprises using a first list element in a list of key counter values included in the key counter information as the first key counter value, wherein processing the key counter information comprises removing the first list element from the list of key counter values.

16. A master node of a radio access network, the master node configured to support dual connectivity operation towards a secondary node of the radio access network and a user equipment, the master node comprising at least one processor and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the master node to perform at least the following:

establishing a connection towards the user equipment;

transmitting configuration information to the user equipment, wherein the configuration information comprises key counter information which defines a sequence of at least two different key counter values to generate at least two different security keys for at least two different target secondary nodes; wherein a first target secondary node is configured for a first conditional PSCell addition or change (CPAC) or a conditional handover (CHO) towards the first target secondary node, and wherein a second target secondary node is configured for a subsequent conditional PSCell addition or change (CPAC) or a conditional handover (CHO) towards the second target secondary node;

generating a first security key using a first key counter value derived from the key counter information;

using the first security key for integrity protection and/or ciphering of data exchanged between the user equipment and the first target secondary node; and

processing the key counter information such that the user equipment is enabled to derive, from the processed key counter information, at least a second key counter value, which is different from the first key counter value, wherein the generating the first security key comprises using a first list element in a list of key counter values included in the key counter information as the first key counter value, wherein processing the key counter information comprises removing the first list element from the list of key counter values.

17. The master node according to claim 16 , wherein the key counter information transmitted to the user equipment defines a list of at least two different key counter values.

18. The master node according to claim 17 , the at least one memory further storing instructions that, when executed by the at least one processor, cause the master node to perform at least the following:

generating a list of at least two different security keys which corresponds to the list of at least two different key counter values defined by the key counter information transmitted to the user equipment;

transmitting request information to at least one target secondary node, wherein the request information comprises the generated list of security keys.

19. The master node according to claim 18 , the at least one memory further storing instructions that, when executed by the at least one processor, cause the master node to perform at least one of the following:

receiving, from a first target secondary node, information indicative of a security key switch;

transmitting, to at least one other target secondary node, an instruction to remove the first list element from the list of security keys, wherein the at least one other target secondary node is different from the first target secondary node.

20. The master node according to claim 19 , the at least one memory further storing instructions that, when executed by the at least one processor, cause the master node to perform at least one of the following:

receiving, from a second target secondary node, information indicative of a security key switch, wherein the second target secondary node is different from the first target secondary node;

transmitting, to at least one further target secondary node, an instruction to remove the presently first list element from the list of security keys, wherein the at least one further target secondary node is different from the second target secondary node.

21. The master node according to claim 18 , the at least one memory further storing instructions that, when executed by the at least one processor, cause the master node to perform at least the following:

transmitting at least one additional list element for the list of key counter values to the user equipment;

transmitting at least one additional list element for the list of security keys to at least one target secondary node.

22. The master node according to claim 16 , wherein the key counter information transmitted to the user equipment comprises a key counter value and an instruction to maintain the key counter value.

23. The master node according to claim 16 , wherein the master node comprises a gNB-CU-CP node comprising at least one processor and at least one memory, wherein the instructions are stored on the at least one memory of the gNB-CU-CP node to be executed by the at least one processor of the gNB-CU-CP node.

24. The master node according to claim 16 , wherein the configuration information further comprises information indicative of at least one target secondary cell for which generating a security key is not required.

25. A non-transitory computer-readable medium comprising program instructions that, when executed by a master node of a radio access network, the master node configured to support dual connectivity operation towards a secondary node of the radio access network and a user equipment, cause the master node to perform at least the following:

establishing a connection towards the user equipment;

transmitting configuration information to the user equipment, wherein the configuration information comprises key counter information which defines a sequence of at least two different key counter values to generate at least two different security keys for at least two different target secondary nodes; wherein a first target secondary node is configured for a first conditional PSCell addition or change (CPAC) or a conditional handover (CHO) towards the first target secondary node, and wherein a second target secondary node is configured for a subsequent conditional PSCell addition or change (CPAC) or a conditional handover (CHO) towards the second target secondary node;

generating a first security key using a first key counter value derived from the key counter information;

using the first security key for integrity protection and/or ciphering of data exchanged between the user equipment and the first target secondary node; and

processing the key counter information such that the user equipment is enabled to derive, from the processed key counter information, at least a second key counter value, which is different from the first key counter value,

wherein the generating the first security key comprises using a first list element in a list of key counter values included in the key counter information as the first key counter value, wherein processing the key counter information comprises removing the first list element from the list of key counter values.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2024
From: AWADA, AHMAD; MURAT GÜRSU, HALIT
To: NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
Reel/Frame 069589/0839 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2024
From: SELVAGANAPATHY, SRINIVASAN
To: NOKIA SOLUTIONS AND NETWORKS INDIA PRIVATE LIMITED
Reel/Frame 069589/0842 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2024
From: NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
To: NOKIA TECHNOLOGIES OY
Reel/Frame 069589/0848 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2024
From: NOKIA SOLUTIONS AND NETWORKS INDIA PRIVATE LIMITED
To: NOKIA TECHNOLOGIES OY
Reel/Frame 069589/0852 →
Continuity (2)
Continuation PCTEP2023066774 · Jun 21, 2023
Related Publication 20250048226A1 · Feb 6, 2025
References Cited (18)
US 11182566B2 · Jaitly · 2021 [cited by examiner]
US 11251923B2 · Wang · 2022 [cited by examiner]
US 11770830B2 · Lindqvist · 2023 [cited by examiner]
US 11868880B2 · Rangarajan · 2024 [cited by examiner]
US 11917657B2 · Cao · 2024 [cited by examiner]
US 20160119840A1 · Loehr · 2016 [cited by examiner]
US 20210022053A1 · Cirik · 2021 [cited by examiner]
US 20210152350A1 · Ai et al. · 2021 [cited by applicant]
US 20240413836A1 · Marpe · 2024 [cited by examiner]
EP 3361763B1 · 2020 [cited by applicant]
WO 2021064032A1 · 2021 [cited by applicant]
“Msc-generator”, Sourceforge, Retrieved on Feb. 11, 2025, Webpage available at :https://sourceforge.net/projects/msc-generator/. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Radio Access Network; Evolved Universal Terrestrial Radio Access (E-UTRA) and Evolved Universal Terrestrial Radio Access Network (E-UTRAN); Overall desc… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Radio Access Network; Evolved Universal Terrestrial Radio Access (E-UTRA) and NR; Multi-connectivity; Stage 2 (Release 17)”, 3GPP 3GPP TS 37.340, V17.1.… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Radio Access Network; NR; Radio Resource Control (RRC) protocol specification (Release 17)”, 3GPP TS 38.331, V17.1.0, Jun. 2022, pp. 1-1273. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17)”, 3GPP TS 33.501, V17.6.0, Jun. 2022, pp. 1-292. [cited by applicant]
International Search Report and Written Opinion received for corresponding Patent Cooperation Treaty Application No. PCT/EP2023/066774, dated Sep. 28, 2023, 15 pages. [cited by applicant]
“Security support for NR-NR DC”, 3GPP TSG-RAN WG2#103, R2-1811713, Agenda: 10.5.4, Huawei, Aug. 20-24, 2018, 2 pages. [cited by applicant]