Communication methods, devices, and systems

KR103000827B1Active Publication Date: 2026-08-05HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
KR1020247010737
Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-08-30
Filing Date
2022-08-25
Publication Date
2026-08-05
Estimated Expiration
2042-08-25

Smart Images

  • Figure 112024035417213-PCT00003_ABST
    Figure 112024035417213-PCT00003_ABST
Patent Text Reader

Abstract

The present application discloses a communication method, apparatus, and system and relates to the field of communication technology. The method comprises the steps of: obtaining a second key used for communication authentication with a second node—the second key being different from a pre-configured first key—; receiving a request to release a first communication connection from the second node—the first key being used for communication authentication for the first communication connection—and transmitting a request to establish a connection to the second node—the request to establish a connection is used to request the establishment of a connection based on the second key. The method provides a technical solution in which the first node and the second node release the connection after determining the updated key and establish a connection using the new key, thereby implementing an authentication procedure in a multi-communication scenario convergence scenario.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] Cross-reference regarding related applications

[0002] This application claims priority to Chinese patent application No. 202111005514.2, titled "COMMUNICATION METHOD, APPARATUS, AND SYSTEM," filed with the State Intellectual Property Administration of China on August 30, 2021, the entirety of which is incorporated herein by reference.

[0003] Technology field

[0004] The embodiments of the present application relate to the field of communication technology, and in particular to communication methods, devices, and systems. Background Technology

[0005] The rapid development of mobile communication has facilitated the continuous emergence of various application scenarios, and communication systems based on different communication technologies are inevitably converging. For example, through the significant advancement of 5G technology and the widespread application of wireless short-range communication systems, a scenario in which wireless short-range communication and 5G cellular networks converge has become a new trend. At the same time, this new convergence scenario requires higher communication transmission security.

[0006] However, conventional standards do not provide a safe and effective communication method for convergence scenarios of different communication systems. means of solving the problem

[0007] Embodiments of the present application provide a communication method, device, and system for updating a communication authentication key and improving communication security.

[0008] According to a first aspect, one embodiment of the present application provides a communication method, and the communication method can be applied to a first node. This method is:

[0009] The method includes the step of obtaining a second key used for communication authentication with a second node—the second key is different from a pre-configured first key—and the step of receiving a request to release a first communication connection from the second node—the first key is used for communication authentication for the first communication connection—and the step of sending a request to establish a connection to the second node—the request to establish a connection is used to request that a connection be established based on the second key.

[0010] According to the method described above, an embodiment of the present application provides a technical solution in which a first node and a second node disconnect after determining an updated key, and establish a connection using a new key. By doing so, communication security is effectively enhanced by implementing the switching of different communication connections and the update process of the key used for communication authentication.

[0011] In a possible implementation, a connection build request used to request to build a connection based on a second key includes a connection build request used to request to perform an authentication and security context negotiation procedure based on the second key.

[0012] In a possible implementation, the method further includes the step of receiving authentication information from a second node based on a second key, and the authentication information is used to verify the identity of the second node.

[0013] In a possible embodiment, the use of authentication information to verify the identity of the second node includes the use of authentication information to verify whether a second communication connection to the second node was established based on the second key.

[0014] In a possible embodiment, the first key is a key derived (or negotiated) based on a first communication system, and / or the second key is a key derived (or negotiated) based on a second communication system, and the first communication system is different from the second communication system.

[0015] In a possible embodiment, the first communication system may be a single communication system, and the second communication system may be a communication system obtained after different communication systems are fused.

[0016] According to the method described above, an embodiment of the present application provides a communication method in a scenario where different communication systems perform fused communication. This effectively improves communication security.

[0017] In a possible implementation, an authentication response based on a second key is transmitted to a second node, and the authentication response is used to verify the identity of the first node.

[0018] In a possible implementation, the authentication response used to verify the identity of the first node includes: verifying whether the authentication response is used to verify whether the second node establishes a second communication connection to the first node based on the second key.

[0019] According to the method described above, the first node transmits an authentication response to the second node, enabling the second node to further determine whether authentication based on the second key was successful based on this authentication response.

[0020] In a possible implementation, the release request includes request cause information, and the request cause information indicates that the key used for communication authentication is updated.

[0021] According to the method described above, since the release request conveys the cause of the request, the first node can learn the cause of the request after receiving the release request from the second node, so the first node responds to the request more appropriately, thereby increasing adaptability.

[0022] In a possible implementation, the second key is valid within a first period, and the first period is defined by a timer or timestamp.

[0023] According to the method described above, during the process in which the first node and the second node perform communication transmission using the second key, the validity of the second key is further verified. This ensures the time validity of the second key and better guarantees the security of the communication transmission.

[0024] In a possible implementation, the second key is valid within a first period starting from a first time point, where the first time point is when the first communication connection is released or when a connection establishment request is transmitted.

[0025] According to the method described above, the present application provides a plurality of cases at a first point in time. Accordingly, a plurality of solutions for determining the validity of the second key are provided, and greater flexibility is achieved.

[0026] In a possible implementation, the method further includes the step of performing information transmission with a third node using a backhaul link between a second node and a third node within the validity period of the second key.

[0027] According to a second aspect, one embodiment of the present application provides a communication method, and the communication method may be applied to a second node. This method is:

[0028] The method includes the step of obtaining a second key used for communication authentication with a first node—the second key is different from a pre-configured first key—and the step of transmitting a request to release a first communication connection to the first node—the first key is used for communication authentication for the first communication connection—and the step of receiving a connection establishment request transmitted by the first node—the connection establishment request is used to request the establishment of a connection based on the second key.

[0029] According to the method described above, an embodiment of the present application provides a technical solution in which a first node and a second node disconnect after determining an updated key, and establish a connection using a new key. By doing so, communication security is effectively enhanced by implementing the switching of different communication connections and the update process of the key used for communication authentication.

[0030] In a possible implementation, a connection build request used to request to build a connection based on a second key includes a connection build request used to request to perform an authentication and security context negotiation procedure based on the second key.

[0031] In a possible implementation, the method further includes the step of transmitting authentication information based on a second key to a first node, and the authentication information is used to verify the identity of the second node.

[0032] In a possible embodiment, the use of authentication information to verify the identity of the second node includes the use of authentication information to verify whether the second communication connection to the second node was established by the first node based on the second key.

[0033] In a possible embodiment, the first key is a key derived (or negotiated) based on a first communication system, and / or the second key is a key derived (or negotiated) based on a second communication system, and the first communication system is different from the second communication system.

[0034] In a possible embodiment, the first communication system may be a single communication system, and the second communication system may be a communication system obtained after different communication systems are fused.

[0035] According to the method described above, an embodiment of the present application provides a communication method in a scenario where different communication systems perform fused communication. This effectively improves communication security.

[0036] In a possible implementation, the method further includes the step of receiving an authentication response from a first node based on a second key, and the authentication response is used to verify the identity of the first node.

[0037] In a possible embodiment, the authentication response used to verify the identity of the first node includes: verifying whether the authentication response is used by the second node to establish a second communication connection to the first node based on the second key. According to the method described above, the first node transmits the authentication response to the second node, enabling the second node to further determine whether the authentication based on the second key was successful based on this authentication response.

[0038] In a possible implementation, the release request includes request cause information, and the request cause information indicates that the key used for communication authentication is updated.

[0039] According to the method described above, since the release request conveys the cause of the request, the first node can learn the cause of the request after receiving the release request from the second node, so the first node responds to the request more appropriately, thereby increasing adaptability.

[0040] In a possible implementation, the second key is valid within a first period, and the first period may be defined by a timer or timestamp.

[0041] According to the method described above, during the process in which the first node and the second node perform communication transmission using the second key, the validity of the second key is further verified. This ensures the time validity of the second key and better guarantees the security of the communication transmission.

[0042] In a possible implementation, the second key is valid within a first period starting from a first time point, where the first time point is when the first communication connection is released or when the second node receives the connection establishment request.

[0043] According to the method described above, the present application provides a plurality of cases at a first point in time. Accordingly, a plurality of solutions for determining the validity of the second key are provided, and greater flexibility is achieved.

[0044] In a possible embodiment, the method further includes the step of transmitting transmission information from a first node to a third node using a backhaul link between a second node and a third node within the validity period of a second key.

[0045] In a possible implementation, after the first communication connection to the first node is released, the backhaul link is suspended.

[0046] According to the method described above, after releasing the first communication connection, the second node suspends the backhaul link. This effectively reduces system overhead and saves resources.

[0047] In a possible embodiment, the method further includes the step of activating a backhaul link after determining that a second communication connection to a first node has been successfully established, and communication authentication is performed for the second communication connection based on a second key.

[0048] According to the method described above, when it is determined that a second communication connection to the first node has been successfully established, the previously suspended backhaul link is activated so that the backhaul link can continue to be used for communication transmission. This effectively reduces system overhead and saves resources.

[0049] According to a third aspect, one embodiment of the present application provides a communication method, and the communication method can be applied to a first node. This method is:

[0050] The method includes the step of obtaining a second key used for communication authentication with a second node—the second key is different from a pre-configured first key—and the step of disconnecting a first communication connection to the second node—the first key is used for communication authentication for the first communication connection—and the step of sending a connection establishment request to the second node—the connection establishment request is used to request the establishment of a connection based on the second key.

[0051] According to the method described above, an embodiment of the present application provides a technical solution in which a first node and a second node disconnect after determining an updated key, and establish a connection using a new key. By doing so, communication security is effectively enhanced by implementing the switching of different communication connections and the update process of the key used for communication authentication.

[0052] In a possible implementation, a connection build request used to request to build a connection based on a second key includes a connection build request used to request to perform an authentication and security context negotiation procedure based on the second key.

[0053] In a possible implementation, the method further includes the step of receiving authentication information from a second node based on a second key, and the authentication information is used to verify the identity of the second node.

[0054] In a possible embodiment, the use of authentication information to verify the identity of the second node includes the use of authentication information to verify whether a second communication connection to the second node was established based on the second key.

[0055] In a possible embodiment, the first key is a key derived (or negotiated) based on a first communication system, and / or the second key is a key derived (or negotiated) based on a second communication system, and the first communication system is different from the second communication system.

[0056] In a possible embodiment, the first communication system may be a single communication system, and the second communication system may be a communication system obtained after different communication systems are fused.

[0057] According to the method described above, an embodiment of the present application provides a communication method in a scenario where different communication systems perform fused communication. This effectively improves communication security.

[0058] In a possible implementation, the method further includes the step of transmitting an authentication response based on a second key to a second node, and the authentication response is used to verify the identity of the first node.

[0059] In a possible implementation, the authentication response used to verify the identity of the first node includes: verifying whether the authentication response is used to verify whether the second node establishes a second communication connection to the first node based on the second key.

[0060] According to the method described above, the first node transmits an authentication response to the second node, enabling the second node to further determine whether authentication based on the second key was successful based on this authentication response.

[0061] In a possible implementation, the release request includes request cause information, and the request cause information indicates that the key used for communication authentication is updated.

[0062] According to the method described above, since the release request conveys the cause of the request, the first node can learn the cause of the request after receiving the release request from the second node, so the first node responds to the request more appropriately, thereby increasing adaptability.

[0063] In a possible implementation, the second key is valid within a first period, and the first period is defined by a timer or timestamp.

[0064] According to the method described above, during the process in which the first node and the second node perform communication transmission using the second key, the validity of the second key is further verified. This ensures the time validity of the second key and better guarantees the security of the communication transmission.

[0065] In a possible implementation, the second key is valid within a first period starting from a first time point, where the first time point is when the first communication connection is released or when a connection establishment request is transmitted.

[0066] According to the method described above, the present application provides a plurality of cases at a first point in time. Accordingly, a plurality of solutions for determining the validity of the second key are provided, and greater flexibility is achieved.

[0067] In a possible implementation, the method further includes the step of performing information transmission with a third node using a backhaul link between a second node and a third node within the validity period of the second key.

[0068] According to a fourth aspect, one embodiment of the present application provides a communication method, and the communication method may be applied to a second node. This method is:

[0069] The method includes the step of obtaining a second key used for communication authentication with a first node—the second key is different from a pre-configured first key—and the step of releasing a first communication connection to the first node—the first key is used for communication authentication for the first communication connection—and the step of receiving a connection establishment request transmitted by the first node—the connection establishment request is used to request the establishment of a connection based on the second key.

[0070] According to the method described above, an embodiment of the present application provides a technical solution in which a first node and a second node disconnect after determining an updated key, and establish a connection using a new key. By doing so, communication security is effectively enhanced by implementing the switching of different communication connections and the update process of the key used for communication authentication.

[0071] In a possible implementation, a connection build request used to request to build a connection based on a second key includes a connection build request used to request to perform an authentication and security context negotiation procedure based on the second key.

[0072] In a possible implementation, the method further includes the step of transmitting authentication information based on a second key to a first node, and the authentication information is used to verify the identity of the second node.

[0073] In a possible embodiment, the use of authentication information to verify the identity of the second node includes the use of authentication information to verify whether the second communication connection to the second node was established by the first node based on the second key.

[0074] In a possible embodiment, the first key is a key derived (or negotiated) based on a first communication system, and / or the second key is a key derived (or negotiated) based on a second communication system, and the first communication system is different from the second communication system.

[0075] In a possible embodiment, the first communication system may be a single communication system, and the second communication system may be a communication system obtained after different communication systems are fused.

[0076] According to the method described above, an embodiment of the present application provides a communication method in a scenario where different communication systems perform fused communication. This effectively improves communication security.

[0077] In a possible implementation, the method further comprises the step of receiving an authentication response fed back by a first node, and the authentication response is used to verify the identity of the first node.

[0078] In a possible implementation, the authentication response used to verify the identity of the first node includes: verifying whether the authentication response is used to verify whether the second node establishes a second communication connection to the first node based on the second key.

[0079] According to the method described above, the first node transmits an authentication response to the second node, enabling the second node to further determine whether authentication based on the second key was successful based on this authentication response.

[0080] In a possible implementation, the release request includes request cause information, and the request cause information indicates that the key used for communication authentication is updated.

[0081] According to the method described above, since the release request conveys the cause of the request, the first node can learn the cause of the request after receiving the release request from the second node, so the first node responds to the request more appropriately, thereby increasing adaptability.

[0082] In a possible implementation, the second key is valid within a first period, and the first period may be defined by a timer or timestamp.

[0083] According to the method described above, during the process in which the first node and the second node perform communication transmission using the second key, the validity of the second key is further verified. This ensures the time validity of the second key and better guarantees the security of the communication transmission.

[0084] In a possible implementation, the second key is valid within a first period starting from a first time point, where the first time point is when the first communication connection is released or when the second node receives the connection establishment request.

[0085] According to the method described above, the present application provides a plurality of cases at a first point in time. Accordingly, a plurality of solutions for determining the validity of the second key are provided, and greater flexibility is achieved.

[0086] In a possible embodiment, the method further includes the step of transmitting transmission information from a first node to a third node using a backhaul link between a second node and a third node within the validity period of a second key.

[0087] In a possible implementation, after the first communication connection to the first node is released, the backhaul link is suspended.

[0088] According to the method described above, after releasing the first communication connection, the second node suspends the backhaul link. This effectively reduces system overhead and saves resources.

[0089] In a possible embodiment, the method further includes the step of activating a backhaul link after determining that a second communication connection to a first node has been successfully established, and communication authentication is performed for the second communication connection based on a second key.

[0090] According to the method described above, when it is determined that a second communication connection to the first node has been successfully established, the previously suspended backhaul link is activated so that the backhaul link can continue to be used for communication transmission. This effectively reduces system overhead and saves resources.

[0091] According to a fifth aspect, an embodiment of the present application provides a communication device. The device is configured to implement the first aspect or any method of the first aspect and includes a corresponding functional module or unit, which is individually configured to implement a step of the method in the first aspect. This function may be implemented by hardware or by executing corresponding software. The hardware or software includes one or more modules or units corresponding to the aforementioned function. Alternatively,

[0092] The device is configured to implement a third embodiment or any method of the third embodiment and includes a corresponding functional module or unit, which is individually configured to implement a step of the method in the third embodiment. This function may be implemented by hardware or by executing corresponding software. The hardware or software includes one or more modules or units corresponding to the aforementioned function.

[0093] According to a sixth aspect, an embodiment of the present application provides a communication device. The device is configured to implement a second aspect or any method of the second aspect and includes a corresponding functional module or unit, which is individually configured to implement a step of the method in the second aspect. This function may be implemented by hardware or by executing corresponding software. The hardware or software includes one or more modules or units corresponding to the aforementioned function. Alternatively,

[0094] The device is configured to implement a fourth embodiment or any method of the fourth embodiment and includes a corresponding functional module or unit, which is individually configured to implement a step of the method in the fourth embodiment. This function may be implemented by hardware or by executing corresponding software. The hardware or software includes one or more modules or units corresponding to the aforementioned function.

[0095] According to a seventh embodiment, a communication device is provided, wherein the device comprises a processor and memory. The memory is configured to store a computing program or instruction, and the processor is coupled to the memory. When the processor executes the computer program or instruction, the device performs the first embodiment or any method in the first embodiment, or the device performs the third embodiment or any method in the third embodiment. The communication device may be the first device, or a device capable of supporting the first device in implementing the function required by the method provided in the first embodiment, or a device capable of supporting the first device in implementing the function required by the method provided in the third embodiment, e.g., a chip system. For example, the communication device may be a terminal device or a component (e.g., a chip) within the terminal device. The terminal device may be, for example, an intelligent mobile terminal, a smart home device, a smart car, or an intelligent wearable device. Intelligent mobile terminals may include, for example, mobile phones, tablet computers, laptop computers, ultra-mobile personal computers (UMPCs), netbooks, or personal digital assistants (PDAs). Smart home devices include smart refrigerators, smart washing machines, smart TVs, speakers, etc. Wearable devices for smart cars include, for example, smart headsets, smart glasses, smart clothing, or shoes.

[0096] According to the eighth embodiment, a communication device is provided, wherein the device comprises a processor and memory. The memory is configured to store a computing program or instruction, and the processor is coupled to the memory. When the processor executes the computer program or instruction, the device performs the second embodiment or any method in the second embodiment, or the device performs the fourth embodiment or any method in the fourth embodiment. The communication device may be the second device, or a device capable of supporting the second device in implementing the function required by the method provided in the second embodiment, or a device capable of supporting the second device in implementing the function required by the method provided in the fourth embodiment, e.g., a chip system. For example, the communication device may be a terminal device or a component (e.g., a chip) within the terminal device. The terminal device may be, for example, an intelligent mobile terminal, a smart home device, a smart car, or an intelligent wearable device. Intelligent mobile terminals may include, for example, mobile phones, tablet computers, laptop computers, ultra-mobile personal computers (UMPCs), netbooks, or personal digital assistants (PDAs). Smart home devices include smart refrigerators, smart washing machines, smart TVs, speakers, etc. Wearable devices for smart cars include, for example, smart headsets, smart glasses, smart clothing, or shoes.

[0097] According to the ninth embodiment, a terminal is provided. The terminal may include a device according to the fifth or seventh embodiment and a device according to the sixth or eighth embodiment. Optionally, the device may be a smart home device, an intelligent manufacturing device, an intelligent transportation device, etc., and may include, for example, a vehicle, an unmanned aerial vehicle, an unmanned transport vehicle, an automobile and vehicle, a robot, etc. Alternatively, the device may be a mouse, a keyboard, a wearable device, a TWS headset, etc.

[0098] According to the tenth aspect, the present application provides a chip, wherein the chip is connected to a memory and configured to read and execute a computer program or instruction stored in the memory, thereby implementing a method of the first aspect or any one of the possible implementations of the first aspect; or implementing a method of the second aspect or any one of the possible implementations of the second aspect; or implementing a method of the third aspect or any one of the possible implementations of the third aspect; or implementing a method of the fourth aspect or any one of the possible implementations of the fourth aspect.

[0099] According to the eleventh embodiment, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program or instructions. When the computer program or instructions are executed by a device, the device performs a method of the first embodiment or any one of the possible embodiments of the first embodiment, or the device performs a method of the third embodiment or any one of the possible embodiments of the third embodiment.

[0100] According to the 12th embodiment, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program or instructions. When the computer program or instructions are executed by the device, the device performs a method of the 2nd embodiment or any one of the possible embodiments of the 2nd embodiment, or the device performs a method of the 4th embodiment or any one of the possible embodiments of the 4th embodiment.

[0101] According to the 13th aspect, a computer program product provided in the present application is provided. The computer program product includes a computer program or instructions. When the computer program or instructions are executed by a device, the device performs a method of the first aspect or any one of the possible embodiments of the first aspect, or the device performs a method of the third aspect or any one of the possible embodiments of the third aspect.

[0102] According to the 14th aspect, a computer program product provided in the present application is provided. The computer program product includes a computer program or instructions. When the computer program or instructions are executed by a device, the device performs a method of the second aspect or any one of the possible embodiments of the second aspect, or the device performs a method of the third aspect or any one of the possible embodiments of the third aspect.

[0103] It should be understood that the technical solution provided in this application can be applied to convergence scenarios of different communication systems, and that a communication method is provided in a scenario where different communication systems perform converged communication. This effectively enhances communication security. Furthermore, the validity of the key used for communication authentication is established, thereby ensuring the time validity of the key used for communication authentication. This better guarantees communication transmission security. Brief explanation of the drawing

[0104] FIG. 1 is a specific exemplary diagram of a first communication system according to an embodiment of the present application. FIG. 2 is a specific example diagram of a first communication system according to an embodiment of the present application. FIG. 3 is a schematic flowchart of a first communication method according to an embodiment of the present application. FIG. 4 is a schematic flowchart of a second communication method according to one embodiment of the present application. FIG. 5 is a schematic flowchart of a third communication method according to one embodiment of the present application. FIG. 6 is a schematic flowchart of a fourth communication method according to one embodiment of the present application. FIG. 7 is a schematic flowchart of a fifth communication method according to one embodiment of the present application. FIG. 8 is a schematic flowchart of a sixth communication method according to one embodiment of the present application. FIG. 9 is a schematic flowchart of a sixth communication method according to one embodiment of the present application. FIG. 10 is a schematic diagram of the structure of a first communication device according to one embodiment of the present application. FIG. 11 is a schematic diagram of the structure of a second communication device according to one embodiment of the present application. FIG. 12 is a schematic diagram of the structure of a terminal according to an embodiment of the present application. Specific details for implementing the invention

[0105] Embodiments of the present application provide a communication method and apparatus for implementing an authentication process for the convergence of a wireless short-range network and a 5G cellular network. In order to clarify the purpose, technical solution, and advantages of the embodiments of the present application, the embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0106] The communication method provided in the embodiments of the present application may be applied to a 5th generation (5G) communication system, for example, 5G new radio (NR), or to various future communication systems, for example, a 6th generation (6G) communication system. This is not limited to the present invention.

[0107] As illustrated in FIG. 1, an embodiment of the present application provides an architecture of a communication system to which a communication method may be applied. The communication system may include a first node (100), a second node (110), and a third node (120). Optionally, in the communication system, the first node may be connected to the second node, and the second node may be connected to the third node.

[0108] The communication system in this application may be a communication system obtained after different communication systems are fused, for example, a communication system obtained after a wireless short-range communication system is fused with a 5G cellular network communication system. This is not limited to this. The fused communication system may also be referred to as a tight interworking communication system or an interworking communication system.

[0109] For example, in this application, a fused communication system is described by temporarily using a communication system obtained after a wireless short-range communication system and a 5G cellular network communication system are fused.

[0110] In a converged communication system, a terminal node supporting wireless short-range communication may use a control node or a gateway node to access a 5G network and, furthermore, utilize services provided by the 5G network. Furthermore, in order to provide granular services to the terminal node, the 5G network may further configure and manage data transmission policies for the terminal node based on the terminal node's subscription information and link state information. In other words, in a converged communication system, the wireless short-range communication system and the 5G cellular network communication system can interact with each other and operate in a mutually complementary manner.

[0111] Optionally, the wireless short-range communication system described in this application may be any possible short-range communication system, for example, Bluetooth, Wi-Fi, a vehicle-mounted universal short-range communication system, and a short-range communication system that may appear now and in the future, such as SparkLink.

[0112] The first node may be a terminal device or communication device capable of supporting a terminal device when implementing the function required in this method, the first node may be a network device or communication device capable of supporting a network device when implementing the function required in this method, or clearly any other communication device, for example, a chip system. The second node may be a network device or communication device capable of supporting a network device when implementing the function required in this method, the second node may be a terminal device or communication device capable of supporting a terminal device when implementing the function required in this method, or clearly any other communication device, for example, a chip system. The third node may be a network device or communication device capable of supporting a network device when implementing the function required in this method, the third node may be a terminal device or communication device capable of supporting a terminal device when implementing the function required in this method, or clearly any other communication device, for example, a chip system.

[0113] Optionally, in an embodiment of the present application, the terminal device may be a device configured to implement wireless communication functions, for example, a terminal or a chip that can be used in a terminal. For example, the terminal device may include a portable device having wireless connectivity functions or a processing device connected to a wireless modem. The terminal device may communicate with a core network through a radio access network (RAN) and exchange voice and / or data with the RAN. The terminal device may refer to user equipment (UE), wireless terminal device, mobile terminal device, subscriber unit, subscriber station, mobile station, mobile console, remote station, access point (AP), remote terminal, access terminal, user terminal, user agent, user device, etc. For example, the terminal device may include a mobile phone (or referred to as a “cellular” phone), a computer equipped with a mobile terminal device, a portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted mobile device, or a smart wearable device. For example, the terminal device may be a device such as a personal communications service (PCS) phone, a wireless phone set, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, or a personal digital assistant (PDA).The terminal device may alternatively include a limited device, for example, a device with relatively low power consumption, a device with limited storage capacity, or a device with limited computing capacity. For example, the terminal device may include information sensing devices such as a barcode, a radio frequency identification (RFID) sensor, a global positioning system (GPS), or a laser scanner.

[0114] As an example, not a limitation, in the embodiments of the present application, the terminal device may alternatively be a wearable device. A wearable device may also be referred to as a wearable intelligent device and is a general term for wearable devices intelligently designed and developed to be worn daily using wearable technology, e.g., glasses, gloves, watches, clothing, and shoes. A wearable device is a portable device that can be worn directly on the body or integrated into a user's clothing or accessories. A wearable device is not only a hardware device but also enables powerful functions through software support, data exchange, and cloud interaction. In a broad sense, a wearable intelligent device includes large, fully functional devices capable of implementing all or part of functions without relying on a smartphone, e.g., smartwatches or smart glasses; devices dedicated to only one type of application function and required to function in conjunction with other devices, such as smartphones; and various smart bands, smart helmets, or smart jewelry for monitoring physical signs.

[0115] Optionally, the network device in this embodiment of the application may include an access network (AN) device, a radio access network (RAN) device, and an access network device (e.g., an access point) such as a base station. A radio terminal device may refer to a device that communicates with a radio terminal device via a radio interface using one or more cells within the access network. The base station may be configured to convert received over-the-air frames and Internet Protocol (IP) packets and to act as a router between the terminal device and the rest of the access network. The rest of the access network may include an IP network. The network-side device may further coordinate the management of attributes of the radio interface. For example, the network device may include an evolved NodeB (NodeB, eNB, or e-NodeB, evolved NodeB) of a Long Term Evolution (LTE) system or a Long Term Evolution-Advanced (LTE-A) system; It may include a next-generation NodeB (gNB), a next-generation evolved NodeB (ng-eNB), or an enhanced next-generation NodeB (en-gNB) of a 5th generation (5G) mobile communication technology new radio (NR) system; it may include a centralized unit (CU) and a distributed unit (DU) of a cloud radio access network (Cloud RAN) system; or it may further include relay devices.This is not limited to the embodiments of the present application.

[0116] Furthermore, the present application provides other communication systems. As illustrated in FIG. 2, the communication system may further include functional entities such as a session management function (SMF), an access and mobility management function (AMF), a User Plane Function (UPF), and a DN.

[0117] Functions may be connected through interfaces. The sequence number or name of the interface is not limited to the embodiments of this application. Interfaces defined in 3GPP-related standard protocols of 5G systems may be used, or interfaces of future communication systems may be used. For example, a terminal device communicates with an AMF through the interface of the next generation network (N)1 (abbreviated as N1), a network device communicates with an AMF through the N2 interface (abbreviated as N2), and a network device communicates with a local UPF through the N3 interface (abbreviated as N3). The UPF communicates with a DN through the N6 interface (abbreviated as N6). The AMF communicates with an SMF through the N11 interface (abbreviated as N11), and the SMF communicates with a UPF through the N4 interface (abbreviated as N4).

[0118] Functions included in a communication system may also be referred to as function entities, network elements, or other names. For example, an SMF may be referred to as an SMF entity. Optionally, the functions of the embodiments of the present application may be implemented by a single device, jointly implemented by a plurality of devices, or implemented by one or more function modules within a single device. This is not particularly limited to the embodiments of the present application. Each function in the embodiments of the present application may be a network element within a hardware device, a software function running on dedicated hardware, a combination of hardware and software, or a virtualization function instantiated on a platform (e.g., a cloud platform).

[0119] It should be noted that the distribution form of each function is not limited to the embodiments of the present application. Optionally, each function may include other function entities formed after any plurality of functions are combined, for example, a function entity having two functions of session management and policy control, a function entity having three functions of session management, access and mobility management, and policy control, or a function entity having two functions of network exposure and application functions.

[0120] It should be noted that the communication system illustrated in FIGS. 1 and 2 is not limited to any communication system to which the embodiments of the present application are applicable. Of course, the number of terminal devices in FIGS. 2 is merely illustrative. In actual application, a network device may service multiple terminal devices. Some or all of the network device and the multiple terminal devices may each determine scheduling limits according to the method provided in the embodiments of the present application. The communication system architecture illustrated in FIGS. 1 and / or FIGS. 2 may be a non-roaming 5G system architecture. Optionally, the method in the embodiments of the present application may be further applied to roaming 5G system architectures and various future communication networks.

[0121] Each function or device of the embodiments of the present application may be a communication device, a general-purpose device, or a dedicated device. This is not particularly limited to the embodiments of the present application.

[0122] The application architecture in the embodiments of the present application has been described above. The technical functions in the embodiments of the present application will be described below.

[0123] Currently, there is no safe and effective communication method for convergence scenarios of different communication systems. In light of this, embodiments of the present application provide a communication method for a scenario in which different communication systems perform converged communication by providing a technical solution in which a first node and a second node determine an updated key, disconnect the connection, and establish a connection using a new key. This effectively improves communication security. The method and the device are based on the same technical concept. Since the problem-solving principles of the method and the device are similar, the embodiments of the device and the method refer to each other, and repetitive parts are not described again.

[0124] One embodiment of the present application provides a first communication method. FIG. 3 is a flowchart of this method.

[0125] S300: The first node obtains a second key used for communication authentication with the second node.

[0126] In this embodiment of the application, the second key is different from the first key that was pre-configured.

[0127] Optionally, in this embodiment of the present application, the first node is configured to perform communication authentication for the first communication connection, and the second node is configured to perform communication authentication for the second communication connection.

[0128] It should be understood that in an optional manner of the present application, the first key is a key derived (or negotiated) based on a first communication system, and / or the second key is a key derived (or negotiated) based on a second communication system, and the first communication system is different from the second communication system.

[0129] In this application, the first communication system may be a single communication system, for example, a wireless short-range communication system, a 5G cellular network communication system, an ultra-reliable low-latency communication system, an enhanced mobile broadband communication system, or a large-scale machine-connected communication system. In this application, the second communication system may be a communication system obtained after different communication systems are fused, for example, a communication system obtained after a wireless short-range communication system is fused with a 5G cellular network communication system, or a communication system obtained after a 5G cellular network communication system is fused with an ultra-reliable low-latency communication system.

[0130] Specifically, the first key may be a key used for authentication during the initial connection phase between the first node and the second node. The first key may be pre-configured before the first node and the second node are initially connected to each other. Alternatively, the first key may be determined by the second node and displayed to the first node via signaling. Alternatively, the first key may be determined by the first node and displayed to the second node via signaling. This is not limited in the present application.

[0131] Specifically, the second key may be determined by the first node after the first node establishes a first communication connection to the second node and may be displayed to the second node via signaling. Alternatively, the second key may be determined by the second node after the first node establishes a first communication connection to the second node and may be displayed to the first node via signaling. Alternatively, the second key may be jointly negotiated by the first node and the second node after the first node establishes a first communication connection to the second node. This is not limited in the present application.

[0132] In addition, to better ensure the security of the communication system, the second key, which is acquired by the first node and used for authentication of communication with the second node, has a specific time validity. It can be understood that if the second key is valid, the second key can be used for authentication of the second communication connection. Alternatively, if the second key is invalid, the second key cannot be used for authentication of the second communication connection. Furthermore, the key can be updated after the second key becomes invalid.

[0133] Before S300 is implemented, it can be understood that Step 1 may be further included. The first node and the second node are connected in a convergence manner (i.e., an initial authentication procedure in a convergence scenario of different communication systems is implemented).

[0134] The specific implementation process of Step 1 may be as follows: The first node and the second node perform authentication for the initial connection based on the first key. After the first node and the second node determine that the authentication for the initial connection based on the first key is successful, the first node and the second node establish a first communication connection in which communication authentication is performed based on the first key.

[0135] S301: The second node obtains a second key used for communication authentication with the first node.

[0136] Specifically, the second key may be determined by the first node after the first node establishes a first communication connection to the second node and may be displayed to the second node via signaling. Alternatively, the second key may be determined by the second node after the first node establishes a first communication connection to the second node and may be displayed to the first node via signaling. Alternatively, the second key may be jointly negotiated by the first node and the second node after the first node establishes a first communication connection to the second node. This is not limited in the present application.

[0137] S302: The second node sends a request to release the first communication connection to the first node.

[0138] A release request may include one or more of the following information 1 to 4.

[0139] Information 1: Request cause information, where the request cause information indicates that the key used for communication authentication has been updated.

[0140] Information 2: Request time, where the request time indicates the time when the second node sends the release request. Optionally, the request time may be presented using a timestamp.

[0141] Information 3: Release time, where release time indicates the time when the first node releases the first communication connection.

[0142] For example, the release time can represent a specific time. For example, the specific time is the first minute after the first node receives the release request. In this case, after receiving the release request, the first node releases the first communication connection within one minute of receiving the release request, based on the release time included in the release request. Alternatively, the release time can represent a specific period. For example, the specific period is within five minutes after the first node receives the release request. In this case, after receiving the release request, the first node releases the first communication connection within five minutes of receiving the release request, based on the release time included in the release request.

[0143] Information 4: Information instructing to suspend wireless resources.

[0144] Optionally, the release request may further instruct to suspend the wireless resource. For example, the release request may include information instructing to suspend the wireless resource corresponding to the first communication connection.

[0145] After the first node and the second node determine that the first key used for communication authentication has been updated to the second key, if the first communication connection is released and the second communication connection is not successfully established, the wireless resource corresponding to the first communication connection is suspended and not released. This effectively facilitates the rapid restoration of the communication link.

[0146] Please note that the contents of Information 1 through Information 4 included in the release request are merely examples of the information included in the release request and do not limit the information included in the release request.

[0147] Furthermore, the first node receiving a release request from the second node includes, as an unlimited example, the following:

[0148] The release request may be based on an improvement in the signaling transmission between the first node and the second node. Alternatively, the release request may be conveyed via the signaling transmission between the first node and the second node. For example, in actual application, the release request may be transmitted by the first node to the second node and conveyed through a signaling representing the second key; or the release request may be a new signaling between the first node and the second node.

[0149] In addition, the second node disconnects the first communication connection to the first node.

[0150] In an optional manner of the present application, after receiving the second key, the second node may determine that the key is updated. Accordingly, the second node may trigger the disconnection of the first communication connection to the first node and establish a second communication connection in which communication authentication is performed based on the second key.

[0151] Additionally, based on the case where the second node transmits a request to release the first communication connection to the first node, the second node may further receive a release request response from the first node that is used to notify the first node of the release status of the first communication connection.

[0152] Optionally, the second node may release the first communication connection to the first node before performing S302, that is, the second node releases the first communication connection to the first node after acquiring the second key. Alternatively, the second node may release the first communication connection to the first node after performing S302, that is, the second node releases the first communication connection to the first node after transmitting a request to release the first communication connection to the first node. Alternatively, the second node may further release the first communication connection to the first node after receiving a response to the release request from the first node and determining that the first node has completed the release of the first communication connection.

[0153] S303: The first node receives a request from the second node to release the first communication connection.

[0154] In addition, the first node disconnects the first communication connection to the second node.

[0155] It should be understood that, in an optional manner of the present application, after receiving a request to release the first communication connection from the second node, the first node may trigger the release of the first communication connection to the second node.

[0156] Additionally, the first node further transmits a response based on the release request to the second node and can notify the second node of the release status of the first node's first communication connection.

[0157] S304: The first node sends a connection build request to the second node, and the connection build request is used to request the establishment of a connection based on the second key.

[0158] Optionally, a connection establishment request transmitted by the first node to the second node includes, but is not limited to, the following:

[0159] A connection establishment request can be enhanced based on signaling transmission between the first node and the second node. Alternatively, the connection establishment request can be transmitted via signaling transmission between the first node and the second node. Alternatively, the connection establishment request can be transmitted via new signaling between the first node and the second node.

[0160] A request to establish a connection may include one or more of the following information 1 to 4.

[0161] Information 1: Request cause information, where the request cause information indicates that the key used for communication authentication has been updated.

[0162] Information 2: Request time, where the request time indicates the time when the first node sends the connection establishment request. Optionally, the request time may be presented using a timestamp.

[0163] Information 3: Connection establishment time, which indicates the time it takes for the first node to establish a second communication connection to the second node.

[0164] For example, the connection establishment time can represent a specific time. For example, the specific time is the first minute after the second node receives the connection establishment request. In this case, after receiving the connection establishment request, the second node establishes a second communication connection to the first node in the first minute based on the connection establishment time included in the connection establishment request. Alternatively, the connection establishment time can represent a specific time period. For example, the specific time period is within 5 minutes after the second node receives the connection establishment request. In this case, after receiving the connection establishment request, the second node establishes a second communication connection to the first node within 5 minutes based on the connection establishment time included in the connection establishment request.

[0165] Information 4: Information indicating connection restoration.

[0166] It can be understood that a connection establishment request may be a request to restore the connection between the first node and the second node. That is, after the first communication connection between the first node and the second node is terminated, the first node and the second node must establish a second communication connection in which communication authentication is performed based on the second key. In this case, the first node may send a connection restoration request to the second node, and the second node establishes a communication connection with the first node after receiving the connection restoration request.

[0167] Please note that the contents of Information 1 through Information 4 included in the connection establishment request are merely examples of the information included in the connection establishment request and do not limit the information included in the connection establishment request.

[0168] S305: The second node receives a connection establishment request sent by the first node.

[0169] Additionally, a connection establishment request used to request the establishment of a connection based on a second key may include the following. A connection establishment request is used to request the execution of an authentication and security context negotiation procedure based on a second key.

[0170] Optionally, the authentication and security context negotiation procedure may include an identity authentication process of the first node and the second node (e.g., interaction between authentication information and authentication response).

[0171] The details of the identity authentication process for the first and second nodes can be described as follows:

[0172] First, after the second node receives a connection establishment request transmitted by the first node, the second node transmits authentication information based on the second key to the first node, where the authentication information is used to verify the identity of the second node. The first node understands that, by using the authentication information, it can verify whether the first node can establish a second communication connection to the second node based on the second key.

[0173] Optionally, the authentication information may include an authentication vector derived by a second node using a second key.

[0174] Subsequently, the first node receives authentication information from the second node based on the second key, and after determining that the authentication of the second node is successful, the first node transmits an authentication response regarding the authentication information to the second node, where the authentication response is used to verify the identity of the first node. The second node understands that, by using the authentication response, it can verify whether the second node can establish a second communication connection to the first node based on the second key.

[0175] Optionally, the first node can determine whether authentication for the second node was successful based on an authentication vector derived by the second node using the second key included in the received authentication information.

[0176] For example, after receiving authentication information, the first node obtains a first authentication vector derived by the second node based on the second key found in the authentication information. The first node derives a second authentication vector based on the second key and then compares the first authentication vector with the second authentication vector. If the first authentication vector and the second authentication vector satisfy the authentication requirements, for example, the authentication requirements may be that the first authentication vector and the second authentication vector are identical, or that the sum of the first authentication vector and the second authentication vector is zero, the first node may determine that the authentication for the second node is successful. If the first authentication vector and the second authentication vector do not satisfy the authentication requirements, the first node determines that the authentication of the second node has failed.

[0177] Finally, the second node receives the authentication response transmitted by the first node and performs identity authentication at the first node based on the authentication response.

[0178] According to the aforementioned method, after the first and second nodes determine the updated key, they disconnect and subsequently establish a connection using the new key. This implements the switching between different communication connections and the update process of the key used for communication authentication. This effectively enhances communication security.

[0179] To better explain the communication method provided in this application, the following two scenarios are described in detail based on the contents shown in FIG. 3. Some steps in the following scenarios may be optional, and the sequence of steps does not represent the actual order of execution. Accordingly, this application is not limited to performing the following steps and sequence.

[0180] Scenario 1: After acquiring the second key, the first node actively disconnects the first communication connection.

[0181] Refer to Fig. 4. The following steps can be performed in a manner corresponding to Scenario 1.

[0182] S400: The first node establishes a first communication connection to the second node based on the first key.

[0183] S401: The first node obtains a second key used for communication authentication with the second node.

[0184] S402: The second node obtains a second key used for communication authentication with the first node.

[0185] S403: The second node disconnects the first communication connection to the first node.

[0186] S404: The first node disconnects the first communication connection to the second node.

[0187] S405: The first node sends a connection build request to the second node, and the connection build request is used to request the establishment of a connection based on the second key.

[0188] S406: The second node receives a connection establishment request sent by the first node.

[0189] S407: The second node transmits authentication information based on the second key to the first node, and the authentication information is used to verify the identity of the second node.

[0190] S408: The first node receives authentication information from the second node based on the second key.

[0191] S409: The first node determines whether authentication for the second node is successful, performs S410 if authentication for the second node is successful, and performs S411 if authentication for the second node fails.

[0192] S410: The first node sends an authentication response for authentication information to the second node - the authentication response is used to verify the identity of the first node - and then performs S412.

[0193] Optionally, the authentication response includes authentication information generated based on a second key.

[0194] Authentication information may include one or more of the following information 1 and information 2.

[0195] Information 1: An authentication vector obtained by the first node based on the second key, for example, the second authentication vector in the exemplary content of step S305.

[0196] Information 2: This is the result of authentication performed by the first node on the second node.

[0197] It should be noted that the contents of Information 1 and Information 2 included in the authentication information are merely examples of the information included in the authentication information and do not limit the information included in the authentication information.

[0198] S411: After determining that the authentication performed by the second node for the second communication connection based on the second key has failed, the first node terminates the communication transmission.

[0199] In an optional mode of the present application, after the first node determines that authentication for the second node has failed, the second node may also resume communication authentication based on the second key, and when the number of authentication failures reaches a failure threshold, the communication transmission is terminated.

[0200] For example, assume that the failure threshold is 2. After determining that communication authentication for the second node based on the second key initially failed, the first node may send an authentication failure message to the second node. After receiving the authentication failure message, the second node may send authentication information based on the second key back to the first node to perform authentication again.

[0201] The first node receives authentication information from the second node based on the second key and performs communication authentication. If the first node determines in the second authentication that the communication authentication performed by the second node based on the second key still failed, the first node determines that the number of authentication failures has reached a threshold of 2 and terminates the communication transmission.

[0202] Similarly, if the second node receives two consecutive messages indicating that communication authentication based on the second key has failed, the second node can understand that it may terminate the communication transmission. Alternatively, the first node may send a message to the second node to terminate the communication transmission after deciding to terminate the communication transmission, and the second node may terminate the communication transmission after receiving the message to terminate the communication transmission from the first node.

[0203] S412: The second node receives the authentication response sent by the first node.

[0204] Optionally, the second node that receives the authentication response may determine whether the authentication for the first node has been successful based on the authentication information included in the authentication response, which is generated based on the second key. For a specific determination method, refer to the determination method of the first node described above. For brevity, detailed information is not described again herein.

[0205] S413: The second node determines whether authentication for the first node is successful, performs S414 if authentication for the first node is successful, and performs S415 if authentication for the first node fails.

[0206] S414: After determining that authentication for the second node is successful, the second node establishes a second communication connection to the first node and then performs S416.

[0207] S415: After determining that the authentication performed by the first node for the second communication connection based on the second key has failed, the second node terminates the communication transmission.

[0208] In an optional manner of the present application, after the second node decides to terminate the communication transmission, it transmits a communication transmission termination message to the first node, and the first node may terminate the communication transmission after receiving the communication transmission termination message from the second node.

[0209] S416: After the establishment of the second communication connection to the second node is completed, the first node notifies the second node that the establishment of the second communication connection is complete.

[0210] S417: The first node performs information transmission with the third node using the backhaul link between the second node and the third node.

[0211] It should be understood that in the method procedure illustrated in FIG. 4, the sequence numbers of the steps do not imply an order of execution. The order of execution of the processing should be determined based on the function and internal logic of the processing and should be understood as not constituting any limitation on the implementation processing of the embodiments of the present application. For example, S402 may take precedence over S401. Furthermore, in the method procedure illustrated in FIG. 4, the aforementioned steps are not limited, and any addition, deletion, or modification of the aforementioned steps falls within the scope of protection of the present application.

[0212] Scenario 2: After receiving a release request transmitted by the second node regarding the first communication connection, the first node releases the first communication connection.

[0213] Refer to Fig. 5. The following steps can be performed in a manner corresponding to Scenario 2.

[0214] S500: The first node establishes a first communication connection to the second node based on the first key.

[0215] S501: The first node obtains a second key used for communication authentication with the second node.

[0216] S502: The second node obtains a second key used for communication authentication with the first node.

[0217] S503: The second node disconnects the first communication connection to the first node.

[0218] S504: The second node sends a request to release the first communication connection to the first node.

[0219] S505: The first node receives a request from the second node to release the first communication connection.

[0220] S506: The first node disconnects the first communication connection to the second node.

[0221] S507: The first node sends a connection build request to the second node, and the connection build request is used to request the establishment of a connection based on the second key.

[0222] S508: The second node receives a connection establishment request sent by the first node.

[0223] S509: The second node transmits authentication information based on the second key to the first node, and the authentication information is used to verify the identity of the second node.

[0224] S510: The first node receives authentication information from the second node based on the second key.

[0225] S511: The first node determines whether authentication for the second node is successful, performs S512 if authentication for the second node is successful, and performs S513 if authentication for the second node fails.

[0226] S512: After determining that authentication for the second node has been successful, the first node sends an authentication response for the authentication information to the second node - the authentication response is used to verify the identity of the first node - and then performs S514.

[0227] S513: After determining that the authentication performed by the second node for the second communication connection based on the second key has failed, the first node terminates the communication transmission.

[0228] S514: The second node receives the authentication response sent by the first node.

[0229] In the present application, optionally, a second node that receives an authentication response may determine whether authentication for the first node has been successful based on authentication information included in the authentication response, which is generated based on the second key. For a specific method of determination, refer to the determination method of the first node described above. For brevity, details are not described further herein.

[0230] S515: The second node determines whether authentication for the first node is successful, performs S516 if authentication for the first node is successful, and performs S517 if authentication for the first node fails.

[0231] S516: After determining that authentication for the second node is successful, the second node establishes a second communication connection to the first node and then performs S518.

[0232] S517: After determining that the authentication performed by the first node for the second communication connection based on the second key has failed, the second node terminates the communication transmission.

[0233] S518: After the establishment of the second communication connection to the second node is completed, the first node notifies the second node that the establishment of the second communication connection is complete.

[0234] S519: The first node performs information transmission with the third node using the backhaul link between the second node and the third node.

[0235] It should be understood that in the method procedure illustrated in FIG. 5, the sequence numbers of the steps do not imply an order of execution. The order of execution of the processing should be determined based on the function and internal logic of the processing and should be understood as not constituting any limitation on the implementation processing of the embodiments of the present application. For example, S502 may take precedence over S501. Furthermore, in the method procedure illustrated in FIG. 5, the aforementioned steps are not limited, and any addition, deletion, or modification of the aforementioned steps falls within the scope of protection of the present application.

[0236] Additionally, in this application, to effectively reduce system overhead, the second node may also suspend the backhaul link after releasing the first communication connection to the first node. Subsequently, after determining that the second communication connection to the first node has been successfully established, the second node may activate the backhaul link.

[0237] In relation to the aforementioned Scenario 2, the details of the operation to temporarily suspend and activate the backhaul link during the communication process are described below. Refer to Fig. 6. The corresponding method procedure is as follows.

[0238] S600: The first node establishes a first communication connection to the second node based on the first key.

[0239] S601: The first node obtains a second key used for communication authentication with the second node.

[0240] S602: The second node obtains a second key used for communication authentication with the first node.

[0241] S603: The second node disconnects the first communication connection to the first node.

[0242] S604: The second node pauses the backhaul link between the second node and the third node.

[0243] S605: The second node sends a request to release the first communication connection to the first node.

[0244] S606: The first node receives a request from the second node to release the first communication connection.

[0245] S607: The first node disconnects the first communication connection to the second node.

[0246] S608: The first node sends a connection build request to the second node, and the connection build request is used to request the establishment of a connection based on the second key.

[0247] S609: The second node receives the connection establishment request sent by the first node.

[0248] S610: The second node transmits authentication information based on the second key to the first node, and the authentication information is used to verify the identity of the second node.

[0249] S611: The first node receives authentication information from the second node based on the second key.

[0250] S612: After determining that authentication for the second node has been successful, the first node transmits an authentication response regarding the authentication information to the second node, wherein the authentication response is used to verify the identity of the first node.

[0251] S613: The second node receives the authentication response sent by the first node.

[0252] S614: After determining that authentication for the second node is successful, the second node establishes a second communication connection to the first node.

[0253] S615: After the establishment of the second communication connection to the second node is completed, the first node notifies the second node that the establishment of the second communication connection is complete.

[0254] S616: The second node activates the backhaul link after determining that the second communication connection to the first node has been successfully established.

[0255] S617: The first node performs information transmission with the third node using the backhaul link between the second node and the third node.

[0256] It should be understood that in the method procedure illustrated in FIG. 6, the sequence numbers of the steps do not imply an order of execution. The order of execution of the processing should be determined based on the function and internal logic of the processing and should be understood as not constituting any limitation on the implementation processing of the embodiments of the present application. For example, S605 may take precedence over S604. Furthermore, in the method procedure illustrated in FIG. 6, the aforementioned steps are not limited, and any addition, deletion, or modification of the aforementioned steps falls within the scope of protection of the present application.

[0257] In this application, the backhaul link is paused after the connection is disconnected, and the backhaul link is activated after the connection is established. This effectively reduces system power consumption, thereby saving resources.

[0258] With respect to the case of the aforementioned Scenario 1, the content of temporarily suspending and activating the backhaul link during the communication process is similar to that of FIG. 6. For brevity, refer to FIG. 6 and the example of the aforementioned Scenario 1. If steps S605 and S606 of FIG. 6a are omitted, the content of temporarily suspending and activating the backhaul link during the communication process is obtained by referring to the case of the aforementioned Scenario 1. Further details are not described herein.

[0259] In addition, in order to better secure the time validity of the second key and improve communication transmission security in the present application, the validity of the second key may be further verified during the process in which the first node and the second node perform communication transmission using the second key.

[0260] In the present application, it may be understood that the first node may notify the second node of the result of the determination of the second key after determining whether the second key is valid. Alternatively, the second node may notify the first node of the result of the determination of the second key after determining whether the second key is valid. Alternatively, both the first node and the second node may determine the validity of the second key.

[0261] In an optional mode of the present application, the second key is valid within a first period, and the first period may be defined by a timer or timestamp. The first period may start timing from a first point in time. The first point in time may be the point in time when the first communication connection is released, or the point in time when the second node receives a connection establishment request and / or the point in time when the first node transmits a connection establishment request. This is not particularly limited.

[0262] Hereinafter, the case where reference is made to the aforementioned Scenario 2 and the case where both the first node and the second node are selected to determine the validity of the second key will be described. The present application provides a plurality of verification methods, which are not specifically limited to the following methods.

[0263] Method 1: The first node and the second node separately determine whether the second key is valid based on their respective corresponding timers.

[0264] Refer to Fig. 7. The method procedure corresponding to Method 1 is as follows:

[0265] S700: The first node establishes a first communication connection to the second node based on the first key.

[0266] S701: The first node obtains a second key used for communication authentication with the second node.

[0267] S702: The second node obtains a second key used for communication authentication with the first node.

[0268] S703: The second node disconnects the first communication connection to the first node.

[0269] S704: The second node starts a corresponding second timer used to determine the validity of the second key.

[0270] The normal execution period of the second timer is the first period.

[0271] S705: The second node sends a request to release the first communication connection to the first node.

[0272] S706: The first node receives a request from the second node to release the first communication connection.

[0273] S707: The first node disconnects the first communication connection to the second node.

[0274] S708: The first node starts a corresponding first timer used to determine the validity of the second key.

[0275] The normal execution period of the first timer is the first period.

[0276] S709: The first node sends a connection build request to the second node, and the connection build request is used to request the establishment of a connection based on the second key.

[0277] S710: The second node receives a connection establishment request sent by the first node.

[0278] S711: The second node transmits authentication information based on the second key to the first node, and the authentication information is used to verify the identity of the second node.

[0279] S712: The first node receives authentication information from the second node based on the second key.

[0280] S713: After determining that authentication for the second node has been successful, the first node transmits an authentication response regarding the authentication information to the second node, wherein the authentication response is used to verify the identity of the first node.

[0281] S714: The second node receives the authentication response sent by the first node.

[0282] S715: After determining that authentication for the second node is successful, the second node establishes a second communication connection to the first node.

[0283] S716: After the establishment of the second communication connection to the second node is completed, the first node notifies the second node that the establishment of the second communication connection is complete.

[0284] S717: The first node stops the corresponding first timer.

[0285] S718. The first node determines whether the first timer has expired, and if the first timer has expired, performs S719, and if the first timer has not expired, performs S720.

[0286] S719: The first node determines that the second key is invalid and terminates the communication transmission.

[0287] S720: The first node performs information transmission with the third node using the backhaul link between the second node and the third node.

[0288] S721: The second node stops the corresponding second timer after receiving a notification from the first node indicating that the establishment of the second communication connection is complete.

[0289] S722: The second node determines whether the second timer has expired, and if the second timer has expired, performs S723, and if the second timer has not expired, performs S724.

[0290] S723: The second node determines that the second key is invalid and terminates the communication transmission.

[0291] S724: The second node transmits transmission information from the first node to the third node using the backhaul link between the second node and the third node.

[0292] In the present application, optionally, in the method procedure illustrated in FIG. 7, the time at which the first node starts the corresponding first timer is not limited to a time after step S707 is performed. For example, the time at which the first node starts the corresponding first timer may, alternatively, be after step S709 is performed. Likewise, the time at which the second node starts the corresponding second timer is not limited to a time after step S704 is performed. For example, the time at which the second node starts the corresponding second timer may, alternatively, be after step S710 is performed.

[0293] It should be understood that in the method procedure illustrated in FIG. 7, the sequence numbers of the steps do not imply an order of execution. The order of execution of the processing should be determined based on the function and internal logic of the processing and should be understood as not constituting any limitation on the implementation processing of the embodiments of the present application. For example, S702 may take precedence over S701. Furthermore, in the method procedure illustrated in FIG. 7, the aforementioned steps are not limited, and any addition, deletion, or modification of the aforementioned steps falls within the scope of protection of the present application.

[0294] With respect to the case of Scenario 1, the method of determining the validity of the second key in Method 1 is similar to the content of FIG. 7. For brevity, refer to the content of FIG. 7 and the case of Scenario 1, and by omitting steps S705 and S706 in FIG. 7, the method of determining the validity of the second key in Method 1, referring to the case of Scenario 1, is obtained. Further details are not described herein.

[0295] Method 2: The first node and the second node jointly maintain the same timer and determine whether the second key is valid.

[0296] Refer to Fig. 8. The method procedure corresponding to Method 2 is as follows:

[0297] S800: The first node establishes a first communication connection to the second node based on the first key.

[0298] S801: The first node obtains a second key used for communication authentication with the second node.

[0299] S802: The second node obtains a second key used for communication authentication with the first node.

[0300] S803: The second node disconnects the first communication connection to the first node.

[0301] S804: The second node starts a timer used to determine the validity of the second key.

[0302] S805: The second node sends a request to release the first communication connection to the first node.

[0303] S806: The first node receives a request from the second node to release the first communication connection.

[0304] S807: The first node disconnects the first communication connection to the second node.

[0305] S808: The first node sends a connection build request to the second node, and the connection build request is used to request the establishment of a connection based on the second key.

[0306] S809: The second node receives a connection establishment request sent by the first node.

[0307] S810: The second node transmits authentication information based on the second key to the first node, and the authentication information is used to verify the identity of the second node.

[0308] S811: The first node receives authentication information from the second node based on the second key.

[0309] S812: After determining that authentication for the second node has been successful, the first node transmits an authentication response regarding the authentication information to the second node, wherein the authentication response is used to verify the identity of the first node.

[0310] S813: The second node receives the authentication response sent by the first node.

[0311] S814: After determining that authentication for the second node is successful, the second node establishes a second communication connection to the first node.

[0312] S815: After the establishment of the second communication connection to the second node is completed, the first node notifies the second node that the establishment of the second communication connection is complete.

[0313] S816: The first node stops the timer.

[0314] S817: The first node determines whether the timer has expired, and if the timer has expired, performs S818, and if the timer has not expired, performs S819.

[0315] S818: The first node determines that the second key is invalid and terminates the communication transmission.

[0316] In the present application, optionally, the first node may further notify the second node of the result that the second key is invalid.

[0317] S819: The first node performs information transmission with the third node using the backhaul link between the second node and the third node.

[0318] In the method procedure illustrated in FIG. 8, the first node may start the timer and the second node may stop the timer in another way. For example, after performing S807, the first node starts the timer, and the second node stops the timer after receiving a notification from the first node indicating that the establishment of the second communication connection in S815 has been completed. Similarly, the second node may determine whether the timer expires and whether the second key is valid.

[0319] It should be understood that in the method procedure illustrated in FIG. 8, the sequence numbers of the steps do not imply an order of execution. The order of execution of the processing should be determined based on the function and internal logic of the processing and should be understood as not constituting any limitation on the implementation processing of the embodiments of the present application. For example, S802 may take precedence over S801. Furthermore, in the method procedure illustrated in FIG. 8, the aforementioned steps are not limited, and any addition, deletion, or modification of the aforementioned steps falls within the scope of protection of the present application.

[0320] With respect to the case of Scenario 1, the method for determining the validity of the second key in Method 2 is similar to the content of FIG. 8. For brevity, by referring to the content of FIG. 8 and the case of Scenario 1, and omitting steps S805 and S806 in FIG. 7, the method for determining the validity of the second key in Method 2, referring to the case of Scenario 1, is obtained. Further details are not described herein.

[0321] Method 3: The first node and the second node determine whether the second key is valid based on the timestamp transmitted via signaling.

[0322] Refer to Fig. 9. The method procedure corresponding to Method 3 is as follows:

[0323] S900: The first node establishes a first communication connection to the second node based on the first key.

[0324] S901: The first node obtains a second key used for communication authentication with the second node.

[0325] S902: The second node obtains a second key used for communication authentication with the first node.

[0326] S903: The second node disconnects the first communication connection to the first node.

[0327] S904: The second node transmits a request to release the first communication connection to the first node, wherein the release request transmits the first timestamp.

[0328] The first timestamp may be the time when the second node sends a release request to the first node.

[0329] In the present application, optionally, after transmitting a release request to the first node, the second node records a first timestamp.

[0330] S905: The first node receives a request to release the first communication connection from the second node and obtains the first timestamp.

[0331] S906: The first node disconnects the first communication connection to the second node.

[0332] S907: The first node sends a connection build request to the second node, and the connection build request is used to request the establishment of a connection based on the second key.

[0333] S908: The second node receives a connection establishment request sent by the first node.

[0334] S909: The second node transmits authentication information based on the second key to the first node, and the authentication information is used to verify the identity of the second node.

[0335] S910: The first node receives authentication information from the second node based on the second key.

[0336] S911: After determining that authentication for the second node has been successful, the first node transmits an authentication response regarding the authentication information to the second node, wherein the authentication response is used to verify the identity of the first node.

[0337] S912: The second node receives the authentication response sent by the first node.

[0338] S913: After determining that authentication for the second node is successful, the second node establishes a second communication connection to the first node.

[0339] S914: After completing the establishment of the second communication connection to the second node, the first node sends a establishment completion message to the second node, wherein the establishment completion message conveys a second timestamp.

[0340] The establishment complete message is used to notify the second node that the first node has completed establishing the second communication connection.

[0341] The second timestamp may be the time when the first node sends a setup completion message to the second node. Alternatively, the second timestamp may be the time when the first node completes the establishment of the second communication connection.

[0342] In the present application, optionally, the first node records a second timestamp.

[0343] S915: The first node determines whether the time difference between the second timestamp and the first timestamp is not greater than the first period, and if the time difference between the second timestamp and the first timestamp is not greater than the first period, performs S916, or if the time difference between the second timestamp and the first timestamp is not greater than the first period, performs S917.

[0344] S916: The first node performs information transmission with the third node using the backhaul link between the second node and the third node.

[0345] S917: The first node determines that the second key is invalid and terminates the communication transmission.

[0346] S918: After receiving the construction complete message, the second node obtains the second timestamp.

[0347] S919: The second node determines whether the time difference between the second timestamp and the first timestamp is not greater than the first period, and if the time difference between the second timestamp and the first timestamp is not greater than the first period, performs S920, or if the time difference between the second timestamp and the first timestamp is not greater than the first period, performs S921.

[0348] S920: The second node transmits transmission information from the first node to the third node using the backhaul link between the second node and the third node.

[0349] S921: The second node determines that the second key is invalid and terminates the communication transmission.

[0350] It should be understood that the method procedure illustrated in FIG. 9 is merely an example in which the first node and the second node use timestamps to determine whether the second key is valid, and does not limit the method of determining whether the second key is valid using timestamps, nor does it limit the steps described above. Furthermore, any addition, deletion, or modification of the steps described above falls within the scope of protection of this application.

[0351] With respect to the case of Scenario 1, the method for determining the validity of the second key in Method 3 is similar to the content of FIG. 9. For brevity, refer to the content of FIG. 9 and the case of Scenario 1, and by omitting steps S904 and S905 in FIG. 9, the method for determining the validity of the second key in Method 3, referring to the case of Scenario 1, is obtained. Further details are not described herein.

[0352] In the present application, during the process in which a first node and a second node perform communication transmission using a second key, whether the second key is valid is further verified. This ensures the time validity of the second key and better guarantees the security of the communication transmission.

[0353] Up to this point, the communication system and the implemented communication method of the present application have been described above with reference to FIGS. 3 through 9. In this communication solution, the present application provides a communication method in a scenario where different communication systems perform converged communication. This effectively improves communication security.

[0354] Furthermore, the contents of FIGS. 3 through 9 do not limit the communication method provided in this application. Variations of the contents of FIGS. 3 through 9 fall within the scope of protection of this application. For example, the contents of FIGS. 4, 6, and 7 can be combined to obtain a communication solution in which a backhaul link is paused and activated, and the validity of the second key is verified in Scenario 1 of this application. This allows for better reduction of system overhead and improvement of communication security.

[0355] Methods and devices are conceived based on the same or similar technical concepts. These methods and devices solve problems using similar principles. Accordingly, embodiments of devices and methods refer to one another. Details of repetitive parts are not described. In the embodiments of this application, the terms "system" and "network" may be used interchangeably. In the description of the embodiments of this application, the term "and / or" describes an association between associated objects and indicates that three relationships may exist. For example, A and / or B may represent the following three cases: A alone exists, both A and B exist, and B alone exists. The letter " / " generally indicates an "or" relationship between associated objects. In this application, "at least one" means one or more, and "plural" means two or more. Furthermore, it should be understood that in the description of this application, the terms “first,” “second,” and “third” are used merely for distinction and explanation and should not be understood as indicating or implying relative importance, nor should they be understood as indicating or implying order. Referring to “examples,” “partial examples,” etc., described in the examples of the detailed description means that one or more of the embodiments of this application include specific features, structures, or characteristics described with reference to such examples. Accordingly, expressions such as “in one example,” “in some examples,” “in another example,” “in another example,” etc., disclosed in various places in this specification do not necessarily refer to the same example. Instead, unless specifically emphasized otherwise, the statement means “one or more of the examples, but not all of them.” The terms “include,” “contain,” “have,” and their derivatives all mean “include but not limited thereto,” unless specifically emphasized otherwise.

[0356] The device provided in the embodiment of the present application is described in detail below with reference to FIGS. 10 and FIGS. 11. It should be understood that the description of the device embodiment corresponds to the description of the method embodiment. Accordingly, for parts not specifically described, the method embodiment described above is referenced.

[0357] FIG. 10 is a schematic block diagram of a device (1000) according to one embodiment of the present application, and the device (1000) is configured to implement the function of a first device or a second device in the method embodiment described above. For example, the device may be a software module or a chip system. The chip system may include a chip or may include a chip and other individual components. The device (1000) includes a processing unit (1001) and a communication unit (1002). The communication unit (1002) is configured to communicate with another device and may be referred to as a communication interface, a transceiver unit, an input / output interface, etc.

[0358] In some embodiments, the device (1000) may be configured to implement the function of the first device in the method described above. The device (1000) may be the first device or may be a chip, circuit, etc. configured in the first device. The processing unit (1001) may be configured to perform processing-related operations of the first device in the method embodiment described above, and the communication unit (1002) may be configured to direct transmission-reception-related operations of the first device in the method embodiment described above.

[0359] For example, the processing unit (1001) is configured to obtain a second key used for communication authentication with a second node, wherein the second key is different from a pre-configured first key. The communication unit (1002) is configured to receive a request to release a first communication connection from the second node, wherein the first key is used for communication authentication for the first communication connection. The communication unit (1002) is further configured to send a connection establishment request to the second node, and the connection establishment request is used to request the establishment of a connection based on the second key.

[0360] Optionally, a connection establishment request used to request the establishment of a connection based on a second key includes the following: a connection establishment request used to request the execution of an authentication and security context negotiation procedure based on a second key.

[0361] Optionally, the communication unit (1002) is further configured to receive authentication information based on the second key and coming from the second node, and the authentication information is used to verify the identity of the second node.

[0362] Optionally, the use of authentication information to verify the identity of the second node includes the use of authentication information to verify whether the second communication connection to the second node was established based on the second key.

[0363] Optionally, the communication unit (1002) is further configured to transmit an authentication response based on a second key to a second node, wherein the authentication response is used to verify the identity of the first node.

[0364] Optionally, the authentication response used to verify the identity of the first node includes the following: the authentication response is used to verify whether the second node establishes a second communication connection to the first node based on the second key.

[0365] Optionally, the release request includes request cause information, and the request cause information indicates that the key used for communication authentication is updated.

[0366] Optionally, the second key is valid within the first period, and the first period is defined by a timer or timestamp.

[0367] Optionally, the second key is valid within a first period starting from a first point in time, where the first point in time is when the first communication connection is released or when a connection establishment request is transmitted.

[0368] Optionally, the processing unit (1001) is further configured to perform information transmission with the third node using a backhaul link between the second node and the third node within the validity period of the second key.

[0369] Optionally, the first key is a key derived (or negotiated) based on a first communication system, and / or the second key is a key derived (or negotiated) based on a second communication system, and the first communication system is different from the second communication system.

[0370] In some other embodiments, the device (1000) may be configured to implement the function of the second device in the aforementioned method embodiment. The device (1000) may be the second device or may be a chip, circuit, etc. configured in the second device. The processing unit (1001) may be configured to perform processing-related operations of the second device in the aforementioned method embodiment, and the communication unit (1002) may be configured to direct transmission-related operations of the second device in the aforementioned method embodiment.

[0371] For example, the processing unit (1001) is configured to acquire a second key used for communication authentication with the first node, wherein the second key is different from the pre-configured first key. The communication unit (1002) is configured to send a request to release the first communication connection to the first node, and the first key is used for communication authentication for the first communication connection. The communication unit (1002) is further configured to receive a connection establishment request sent by the first node, and the connection establishment request is used to request the establishment of a connection based on the second key.

[0372] Optionally, a connection establishment request used to request the establishment of a connection based on a second key includes the following: a connection establishment request used to request the execution of an authentication and security context negotiation procedure based on a second key.

[0373] Optionally, the communication unit (1002) is further configured to transmit authentication information based on a second key to a first node, wherein the authentication information is used to verify the identity of the second node.

[0374] Optionally, the use of authentication information to verify the identity of the second node includes the use of authentication information to verify whether the second communication connection to the second node was established by the first node based on the second key.

[0375] Optionally, the first key is a key derived (or negotiated) based on a first communication system, and / or the second key is a key derived (or negotiated) based on a second communication system, and the first communication system is different from the second communication system.

[0376] Optionally, the communication unit (1002) is further configured to receive an authentication response from the first node based on the second key, and the authentication response is used to verify the identity of the first node.

[0377] Optionally, the authentication response used to verify the identity of the first node includes the following: the authentication response is used to verify whether the second node establishes a second communication connection to the first node based on the second key.

[0378] Optionally, the release request includes request cause information, and the request cause information indicates that the key used for communication authentication is updated.

[0379] Optionally, the second key is valid within the first period, and the first period may be defined by a timer or timestamp.

[0380] Optionally, the second key is valid within a first period starting from a first time point, where the first time point is when the first communication connection is released or when the second node receives a connection establishment request.

[0381] Optionally, the processing unit (1001) is further configured to transmit transmission information from the first node to the third node using a backhaul link between the second node and the third node within the validity period of the second key.

[0382] Optionally, the processing unit (1001) is further configured to pause the backhaul link after releasing the first communication connection to the first node.

[0383] Optionally, the processing unit (1001) is further configured to activate the backhaul link after determining that a second communication connection to the first node has been successfully established, and communication authentication is performed for the second communication connection based on the second key.

[0384] In this embodiment of the present application, division into units is exemplary and is merely a logical functional division. In actual implementations, other division methods may be used. Furthermore, the functional units in this embodiment of the present application may be integrated into a single processor, each unit may exist physically independently, or two or more units may be integrated into a single unit. The integrated module may be implemented in the form of hardware or in the form of a software functional module.

[0385] FIG. 11 is a schematic diagram of a device (1100) according to one embodiment of the present application. The device (1100) may be a node or a component within a node, for example, a chip or an integrated circuit. The device (1100) may include at least one processor (1102) and a communication interface (1104). Additionally, optionally, the device may further include at least one memory (1101). Additionally, optionally, the device may further include a bus (1103). The memory (1101), the processor (1102), and the communication interface (1104) are connected to communicate with each other via the bus (1103).

[0386] The memory (1101) is configured to provide storage space, and the storage space can store data such as an operating system and computer programs. The memory (1101) mentioned in the embodiments of the present application may be volatile memory or non-volatile memory, or may include both volatile memory and non-volatile memory. Non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may be random access memory (RAM) that serves as an external cache. As an example of non-limiting examples, many forms of RAM can be used, such as static random access memory (static RAM, SRAM), dynamic random access memory (dynamic RAM, DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchronous link dynamic random access memory (Synchlink DRAM, SLDRAM), and direct Rambus dynamic random access memory (Direct Rambus RAM, DR RAM).

[0387] Note that the memory described in this specification includes, but is not limited to, these memories and any other suitable type of memory. A processor (1102) is a module for performing arithmetic operations and / or logical operations, and specifically may include a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor unit (MPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), a coprocessor (which supports the central processing unit in completing corresponding processing and applications), and a microcontroller unit (MCU).

[0388] Note that if the processor is a general-purpose processor, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, memory (storage module) may be integrated into the processor.

[0389] The communication interface (1104) may be configured to provide information input or output to at least one processor. Alternatively, the communication interface may be configured to receive data transmitted from the outside and / or transmit data to the outside, and may be a wired link interface including an Ethernet cable, etc., or a wireless link interface (Wi-Fi, Bluetooth, Universal Wireless Transmission, In-vehicle Short-Range Communication Technology, etc.). Optionally, the communication interface (1104) may further include a transmitter (e.g., radio frequency transmitter or antenna), a receiver, etc. connected to the interface.

[0390] In some embodiments, the device (1100) may be the first device in the above-described method embodiment, or a component of the first device, and may be, for example, a chip or an integrated circuit. A processor (1102) in the device (1100) is configured to read a computer program stored in memory (1101) and to control the first device to perform the following operations:

[0391] Acquire a second key used for communication authentication with the second node - the second key is different from the pre-configured first key -, receive a request to release the first communication connection from the second node - the first key is used for communication authentication for the first communication connection -, and send a connection establishment request to the second node - the connection establishment request is used to request the establishment of a connection based on the second key -.

[0392] Optionally, the processor (1102) in the first device may read a program in memory (1101) and perform a method procedure performed by the first node in S300 to S305 as illustrated in FIG. 3; or perform a method procedure performed by the first node in S400 to S417 as illustrated in FIG. 4; or perform a method procedure performed by the first node in S500 to S519 as illustrated in FIG. 5; or perform a method procedure performed by the first node in S600 to S617 as illustrated in FIG. 6; or perform a method procedure performed by the first node in S700 to S724 as illustrated in FIG. 7; or perform a method procedure performed by the first node in S800 to S819 as illustrated in FIG. 8; or perform a method procedure performed by the first node in S900 to S921 as illustrated in FIG. 9.

[0393] For specific details, refer to the description of the above-described method examples. Details are not described again.

[0394] In some other embodiments, the device (1100) may be the second device in the above-described method embodiment, or a component of the second device, and may be, for example, a chip or an integrated circuit. A processor (1102) within the device (1100) is configured to read a computer program stored in memory (1101) and to control the second device to perform the following operations:

[0395] The method includes the step of obtaining a second key used for communication authentication with a first node—the second key is different from a pre-configured first key—and the step of transmitting a request to release a first communication connection to the first node—the first key is used for communication authentication for the first communication connection—and the step of receiving a connection establishment request transmitted by the first node—the connection establishment request is used to request the establishment of a connection based on the second key.

[0396] Optionally, the processor (1102) in the second device may read a program in memory (1101) and perform a method procedure performed by the second node in S300 to S305 as illustrated in FIG. 3; or perform a method procedure performed by the second node in S400 to S417 as illustrated in FIG. 4; or perform a method procedure performed by the second node in S500 to S519 as illustrated in FIG. 5; or perform a method procedure performed by the second node in S600 to S617 as illustrated in FIG. 6; or perform a method procedure performed by the second node in S700 to S724 as illustrated in FIG. 7; or perform a method procedure performed by the second node in S800 to S819 as illustrated in FIG. 8; or perform a method procedure performed by the second node in S900 to S921 as illustrated in FIG. 9.

[0397] For specific details, refer to the description of the above-described method examples. Details are not described again.

[0398] Embodiments of the present application further provide a terminal. The terminal may be an intelligent terminal such as a smartphone, a laptop computer, or a tablet computer having a short-range communication function, a mouse, a keyboard, a headset, a speaker, a vehicle-mounted playback device, etc. The terminal includes a first device and / or a second device. The first device and the second device may each be a first node and a second node in the embodiment illustrated in FIG. 3. The types of the first device and the second device may be the same or different.

[0399] FIG. 12 is a schematic diagram of a simplified structure of a terminal device. For ease of understanding and illustration, FIG. 12 uses an example where the terminal device is a mobile phone. As illustrated in FIG. 12, the terminal device includes a processor, memory, radio frequency circuitry, an antenna, and input / output devices. The processor is configured to primarily process communication protocols and communication data, control the terminal device, execute software programs, and process data from software programs. The memory is configured to primarily store software programs and data. The radio frequency circuitry is configured to primarily perform conversion between baseband signals and radio frequency signals and to process radio frequency signals. The antenna is configured to primarily receive and transmit radio frequency signals in the form of electromagnetic waves. Input / output devices, such as a touchscreen, display, and keyboard, are primarily configured to receive data input by the user and output the data to the user. Some types of terminal devices may not have input / output devices.

[0400] When it is necessary to transmit data, the processor performs baseband processing on the data to be transmitted and outputs the baseband signal to a radio frequency circuit; the radio frequency circuit performs radio frequency processing on the baseband signal and transmits the radio frequency signal externally in the form of electromagnetic waves through an antenna. When data is transmitted to a terminal device, the radio frequency circuit receives the radio frequency signal through the antenna, converts the radio frequency signal into a baseband signal, and outputs the baseband signal to the processor. The processor converts the baseband signal into data and processes it. For ease of explanation, only one memory and one processor are illustrated in FIG. 12. An actual terminal device product may have one or more processors and one or more memories. The memory may also be referred to as a storage medium, a storage device, etc. The memory may be placed independently of the processor or may be integrated with the processor. This is not limited to the embodiments of the present application.

[0401] In this embodiment of the present application, an antenna and a radio frequency circuit having transceiver functions may be considered as the transceiver unit of the terminal device, and a processor having processing functions may be considered as the processing unit of the terminal device. As illustrated in FIG. 12, the terminal device includes a transceiver unit (1210) and a processing unit (1220). The transceiver unit may be referred to as a transceiver, a transceiver machine, a transceiver device, etc. The processing unit may be referred to as a processor, a processing board, a processing module, a processing device, etc. Optionally, in the transceiver unit (1210), a component configured to implement a receiving function may be considered as a receiving unit; and in the transceiver unit (1210), a component configured to implement a transmitting function may be considered as a transmitting unit. In other words, the transceiver unit (1210) includes a receiving unit and a transmitting unit. The transceiver unit may often be referred to as a transceiver machine, a transceiver, a transceiver circuit, etc. Often, the receiving unit may be referred to as a receiver machine, receiver, receiving circuit, etc. Often, the transmitting unit may alternatively be referred to as a transmitter machine, transmitter, transmission circuit, etc.

[0402] It should be understood that the transceiver unit (1210) is configured to perform transmission and reception operations at the first node side in the method embodiment illustrated in FIG. 3, and the processing unit (1220) is configured to perform other operations other than transmission and reception operations at the first node side in the method embodiment illustrated in FIG. 3.

[0403] For example, in an embodiment, the transceiver unit (1210) is configured to perform a transceiver step on the terminal device side in the embodiment illustrated in FIG. 3, for example, S303 and S305, and / or is configured to support other processes of the technology described herein. The processing unit (1220) is configured to perform operations on the terminal device side other than the transceiver operation in the embodiment illustrated in FIG. 3, for example, other than S300, and / or is configured to support other processes of the technology described herein.

[0404] In another way, it should be understood that the transceiver unit (1210) is configured to perform transmission and reception operations on the terminal device side in the method embodiment illustrated in FIG. 4, and the processing unit (1220) is configured to perform other operations other than transmission and reception operations on the terminal device side in the method embodiment illustrated in FIG. 4.

[0405] For example, in an embodiment, the transceiver unit (1210) is configured to perform a transceiver step on the terminal device side in, for example, S406, of the embodiment shown in FIG. 4, and / or is configured to support other processes of the technology described herein. The processing unit (1220) is configured to perform operations on the terminal device side other than the transceiver operation in the embodiment shown in FIG. 4, for example, other than S409, and / or is configured to support other processes of the technology described herein.

[0406] In another way, it should be understood that the transceiver unit (1210) is configured to perform transmission and reception operations on the terminal device side in the method embodiment illustrated in FIG. 5, and the processing unit (1220) is configured to perform other operations other than transmission and reception operations on the terminal device side in the method embodiment illustrated in FIG. 5.

[0407] For example, in an embodiment, the transceiver unit (1210) is configured to perform a transceiver step on the terminal device side in the embodiment illustrated in FIG. 5, for example, S508, and / or is configured to support other processes of the technology described herein. The processing unit (1220) is configured to perform operations on the terminal device side other than the transceiver operation in the embodiment illustrated in FIG. 5, for example, other than S511, and / or is configured to support other processes of the technology described herein.

[0408] In another way, it should be understood that the transceiver unit (1210) is configured to perform transmission and reception operations on the terminal device side in the method embodiment illustrated in FIG. 6, and the processing unit (1220) is configured to perform other operations other than transmission and reception operations on the terminal device side in the method embodiment illustrated in FIG. 6.

[0409] For example, in an embodiment, the transceiver unit (1210) is configured to perform a transceiver step on the terminal device side in the embodiment shown in FIG. 6, for example, S606, and / or is configured to support other processes of the technology described herein. The processing unit (1220) is configured to perform operations on the terminal device side other than the transceiver operation in the embodiment shown in FIG. 6, for example, other than S604, and / or is configured to support other processes of the technology described herein.

[0410] In another way, it should be understood that the transceiver unit (1210) is configured to perform transmission and reception operations on the terminal device side in the method embodiment illustrated in FIG. 7, and the processing unit (1220) is configured to perform other operations other than transmission and reception operations on the terminal device side in the method embodiment illustrated in FIG. 7.

[0411] For example, in an embodiment, the transceiver unit (1210) is configured to perform a transceiver step on the terminal device side in the embodiment illustrated in FIG. 7, for example, S706, and / or is configured to support other processes of the technology described herein. The processing unit (1220) is configured to perform operations on the terminal device side other than the transceiver operation in the embodiment illustrated in FIG. 7, for example, other than S704, and / or is configured to support other processes of the technology described herein.

[0412] In another way, it should be understood that the transceiver unit (1210) is configured to perform transmission and reception operations on the terminal device side in the method embodiment illustrated in FIG. 8, and the processing unit (1220) is configured to perform other operations other than transmission and reception operations on the terminal device side in the method embodiment illustrated in FIG. 8.

[0413] For example, in an embodiment, the transceiver unit (1210) is configured to perform a transceiver step on the terminal device side in the embodiment illustrated in FIG. 8, for example, S806, and / or is configured to support other processes of the technology described herein. The processing unit (1220) is configured to perform operations on the terminal device side other than the transceiver operation in the embodiment illustrated in FIG. 8, for example, other than S804, and / or is configured to support other processes of the technology described herein.

[0414] In another way, it should be understood that the transceiver unit (1210) is configured to perform transmission and reception operations on the terminal device side in the method embodiment illustrated in FIG. 9, and the processing unit (1220) is configured to perform other operations other than transmission and reception operations on the terminal device side in the method embodiment illustrated in FIG. 9.

[0415] For example, in an embodiment, the transceiver unit (1210) is configured to perform a transmission and reception step on the terminal device side at, for example, S905, in the embodiment illustrated in FIG. 9, and / or is configured to support other processes of the technology described herein. The processing unit (1220) is configured to perform operations on the terminal device side other than the transmission and reception operation in the embodiment illustrated in FIG. 9, for example, other than S915, and / or is configured to support other processes of the technology described herein.

[0416] If the communication device is a chip, the chip includes a transceiver unit and a processing unit. The transceiver unit may be an input / output circuit or a communication interface. The processing unit is a processor, a microprocessor, or an integrated circuit integrated on the chip.

[0417] Embodiments of the present application further provide a computer-readable storage medium comprising instructions. When the instructions are executed on a computer, the computer performs the method described in the above-described embodiment.

[0418] Embodiments of the present application further provide a chip system. The chip system comprises at least one processor and an interface circuit. Additionally, optionally, the chip system may further comprise memory or external memory. The processor is configured to implement the method of the aforementioned method embodiment by executing instruction and / or data interaction through the interface circuit. The chip system may comprise a chip or may comprise a chip and other individual components.

[0419] Embodiments of the present application further provide a computer program product comprising instructions. When the instructions are executed on a computer, the computer performs the method described in the aforementioned embodiments.

[0420] In the embodiments of the present application, the processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component or a coprocessor, and may implement or execute the method, steps and logic block diagram disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed with reference to the embodiments of the present application may be performed directly by a hardware processor or may be performed using a combination of hardware and software modules within the processor.

[0421] In the embodiments of the present application, memory may be non-volatile memory, such as a hard disk drive (HDD) or a solid-state drive (SSD), or volatile memory, such as random access memory (RAM). Memory is any other medium capable of transmitting or storing program code expected in the form of instructions or data structures and accessible by a computer, but is not limited thereto. Memory in the embodiments of the present application may be a circuit or any other device capable of implementing a storage function in other ways and configured to store program instructions and / or data.

[0422] Some or all of the methods of the embodiments of this application may be implemented using software, hardware, firmware, or any combination thereof. Where software is used to implement the embodiments, some or all of the embodiments may be implemented in the form of a computer program product. A computer program product comprises one or more computer instructions. When computer program instructions are loaded into and executed on a computer, the procedure or function according to the embodiments of this application is created in whole or in part. The computer may be a general-purpose computer, a dedicated computer, a computer network, a network device, a user device, or other programmable device. Computer instructions may be stored on a computer-readable storage medium and may be transmitted from a computer-readable storage medium to another computer-readable storage medium. For example, computer instructions may be transmitted from a website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, or digital subscriber line (DSL)) or wireless (e.g., infrared, radio, or microwave). A computer-readable storage medium may be any available medium that can be accessed by a computer or by a data storage device, a server or a data center, etc., and may incorporate one or more available media. Available media may be magnetic media (e.g., floppy disk, hard disk, or magnetic tape), optical media (e.g., digital video disc (DVD)), semiconductor media (e.g., solid-state disk (SSD)), etc.

[0423] Those skilled in the art will understand that unit and algorithm steps may be implemented by electronic hardware in combination with the examples described in the embodiments disclosed herein, or by a combination of computer software and electronic hardware. Whether a function is performed by hardware or by software depends on the specific application and design constraint requirements of the technical solution. Those skilled in the art may use various methods to implement the function described for each specific application, but such implementations should not be construed as being outside the scope of this application.

[0424] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the detailed operation processes of the aforementioned systems, devices, and units refer to the corresponding processes in the aforementioned method embodiments. Further details are not described herein.

[0425] The units described as separate parts may or may not be physically separated, and the parts indicated as units may or may not be physical units, and may be located in one location or distributed across multiple network devices. Some or all of the units may be selected based on actual requirements for achieving the purpose of the solution of the embodiment.

[0426] Where a function is implemented in the form of a software function unit and sold or used as an independent product, the function may be stored on a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially a part of the prior art, or some technical solution may be implemented in the form of a software product. The software product is stored on a storage medium and includes several instructions for instructing a computer device (which may be a personal computer, a server, or a network device) to perform some or all of the steps of the methods described in the embodiments of the present application. The aforementioned storage medium may include any medium capable of storing program code, such as a USB flash drive, a removable hard disk, Read-Only Memory (ROM), Random Access Memory (RAM), a magnetic disk, or an optical disk.

[0427] It is evident that those skilled in the art may make various modifications and variations to this application without departing from the scope of the rights of this application. Such modifications and variations fall within the scope of protection defined in the claims of this application and equivalent technologies.

Claims

Claim 1 A communication method applied to a first node, comprising: a step of establishing a first communication connection with a second node that performs communication authentication based on a pre-configured first key; a step of obtaining a second key used for communication authentication with the second node after the first node has established the first communication connection with the second node, wherein the second key is different from the pre-configured first key; a step of receiving a request to release the first communication connection from the second node, wherein the first key is used for communication authentication for the first communication connection; and a step of transmitting a request to establish a connection to the second node, wherein the request to establish a connection is used to request the establishment of a connection based on the second key. Claim 2 A method according to claim 1, wherein the connection establishment request is used to request to establish a connection based on the second key, and wherein the connection establishment request is used to request to perform an authentication and security context negotiation procedure based on the second key. Claim 3 A method according to claim 1, further comprising the step of receiving authentication information coming from the second node based on the second key—the authentication information being used to verify the identity of the second node. Claim 4 A method according to claim 3, further comprising the step of transmitting an authentication response based on the second key to the second node—the authentication response being used to verify the identity of the first node. Claim 5 A method according to claim 1, wherein the release request includes request cause information, and the request cause information indicates that the key used for communication authentication has been updated. Claim 6 A method according to claim 1, wherein the second key is valid within a first period, and the first period is defined by a timer or timestamp. Claim 7 A method according to claim 6, wherein the second key is valid within the first period starting from the first point in time, and the first point in time is the point in time when the first communication connection is released or the point in time when the connection establishment request is transmitted. Claim 8 A method according to claim 1, further comprising the step of performing information transmission with the third node using a backhaul link between the second node and the third node within the validity period of the second key. Claim 9 In claim 1, the first key is a key derived based on a first communication system, and the second key is a key derived based on a second communication system, and the first communication system is different from the second communication system, method. Claim 10 A communication device comprising at least one processor and an interface circuit, wherein the interface circuit provides a program or instruction to the at least one processor, and the at least one processor, by using a logic circuit or executing the program or instruction, causes a device on which the communication device is located to perform any one of claims 1 to 9. Claim 11 A computer-readable storage medium comprising computer instructions, wherein when the computer instructions are executed on a computer, the computer performs a method according to any one of claims 1 to 9. Claim 12 A terminal comprising a first node that performs a method according to any one of paragraphs 1 through 9. Claim 13 delete Claim 14 delete Claim 15 delete Claim 16 delete Claim 17 delete Claim 18 delete Claim 19 delete Claim 20 delete Claim 21 delete Claim 22 delete Claim 23 delete Claim 24 delete Claim 25 delete Claim 26 delete

Citation Information

Patent Citations

  • Communication method, apparatus and system

    EP4387302B1

  • Communication method, apparatus, and system

    JP7717965B2

  • Key update method, device, and storage medium

    EP3793317A1

  • Key generation method, device, and system

    US20170359719A1

  • Key provisioning for broadcast control channel protection in a wireless network

    US20210195563A1