Method for transmitting information, network device, and terminal device

By transmitting indicator information in 5G network, the security risks of data transmission between NR and LTE are solved, and the security and success rate of data transmission are improved.

CN111279732BActive Publication Date: 2025-06-17GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN201780096334.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2017-11-10
Publication Date
2025-06-17
Estimated Expiration
2037-11-10

AI Technical Summary

Technical Problem

In 5G networks, data transmission between NR and LTE poses a security risk, because if the IP verification of data integrity protection fails, it may lead to data being attacked or maliciously tampered, thereby reducing the success rate of data transmission.

Method used

By transmitting indication information between network devices, it is instructed that when the IP verification of data on the DRB fails, the terminal device's secret key or the RRC connection is released, thereby eliminating security risks and ensuring communication security.

Benefits of technology

Effectively eliminate security risks, improve the success rate of data transmission, and ensure communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN111279732B_ABST
    Figure CN111279732B_ABST
Patent Text Reader

Abstract

A method for transmitting information, a network device, and a terminal device are provided. The method includes: a first network device obtains indication information, where the indication information is used to indicate that an integrity protection IP check of data on a data radio bearer (DRB) fails; the first network device sends the indication information to a second network device. In an embodiment of the present invention, through the indication information, when the IP check of the data on the DRB fails, the second network device can update the secret key of the terminal device, or the second network device can release the radio resource control (RRC) connection where the DRB is located. Thereby, potential security risks are eliminated, communication security is ensured, and further the success rate of data transmission is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of communications, and more particularly, to methods for transmitting information, network devices, and terminal devices. Background Art

[0002] With the pursuit of rate, latency, high-speed mobility, and energy efficiency by people, as well as the diversity and complexity of services in future life, the 3rd Generation Partnership Project (3GPP) international standards organization has started to research the fifth-generation mobile communication technology (5G). In the early deployment of New Radio (NR), it is difficult to obtain complete NR coverage. Therefore, typical network coverage is a wide-area Long Term Evolution (LTE) coverage and an NR island coverage mode. Moreover, since a large number of LTEs are deployed below 6 gigahertz (GHz), there is little spectrum below 6 GHz available for 5G. Therefore, NR must study spectrum applications above 6 GHz, but the coverage of high-frequency bands is limited and the signal fades quickly.

[0003] In the prior art, in order to protect the previous investment of mobile operators in LTE, a working mode of tight interworking between LTE and NR has been proposed. Specifically, data is transmitted by supporting LTE-NR dual connection (DC) through bandwidth combination to improve system throughput.

[0004] In LTE, there is no need for integrity protection for data radio bearers (DRBs), but in NR, there is an increased need for integrity protection of data on DRBs. For this purpose, each Packet Data Convergence Protocol (PDCP) service data unit (SDU) has to additionally carry a Media Access Control (MAC)-I part for integrity protection (IP) checksum.

[0005] However, if the IP checksum fails, it is very likely that the data has been attacked or maliciously modified (there is a security risk), and the maliciously modified data will be discarded, reducing the success rate of data transmission. Summary of the Invention

[0006] A method for transmitting information, a network device, and a terminal device are provided, which can effectively eliminate security risks and ensure communication security.

[0007] In a first aspect, a method for transmitting information is provided, including:

[0008] A first network device obtains indication information, where the indication information is used to indicate that the integrity protection IP check of data on a data radio bearer (DRB) fails;

[0009] The first network device sends the indication information to a second network device.

[0010] In an embodiment of the present invention, through this indication information, when the IP check of the data on the DRB fails, the second network device can update the secret key of the terminal device, or the second network device can release the radio resource control (RRC) connection where the DRB is located. Thereby, security risks are eliminated, communication security is ensured, and the success rate of data transmission is further improved.

[0011] In some possible implementation manners, the indication information includes at least one of the following information:

[0012] The identification information of the DRB, the cell identification of the data packet whose IP check fails on the DRB, the location information of the terminal device when the IP check of the data packet on the DRB fails, and the time information of the terminal device when the IP check of the data packet on the DRB fails.

[0013] In some possible implementation manners, before the first network device obtains the indication information, the method further includes:

[0014] The first network device receives first uplink data sent by a terminal device on the DRB; the packet data convergence protocol (PDCP) layer of the first network device checks the integrity protection IP of the first uplink data; where the first network device obtains the indication information, including:

[0015] When the IP check of the first uplink data fails, the first network device generates the indication information.

[0016] In some possible implementation manners, the first network device obtains the indication information, including:

[0017] The first network device receives the indication information sent by the terminal device.

[0018] In some possible implementation manners, the first network device receives the indication information sent by the terminal device, including:

[0019] The first network device receives the radio resource control (RRC) signaling sent by the terminal device, and the RRC signaling includes the indication information.

[0020] In some possible implementation manners, the first network device receiving the indication information sent by the terminal device includes:

[0021] The first network device receives the media access control (MAC) control element (CE) sent by the terminal device, and the MAC CE includes the indication information.

[0022] In some possible implementation manners, the first network device receiving the indication information sent by the terminal device includes:

[0023] The first network device receives the PDCP status report sent by the terminal device, and the PDCP status report includes the indication information.

[0024] In some possible implementation manners, the first network device sending the indication information to the second network device includes:

[0025] The first network device sends an X2 / Xn message to the second network device, and the X2 / Xn message includes the indication information.

[0026] In a second aspect, a method for transmitting information is provided, including:

[0027] The second network device determines whether the integrity protection IP of the data on the data radio bearer (DRB) fails the check.

[0028] When the IP check of the data on the DRB fails, the second network device updates the secret key of the terminal device, or the second network device releases the radio resource control (RRC) connection where the DRB is located.

[0029] In some possible implementation manners, before the second network device determines whether the integrity protection IP of the data on the data radio bearer (DRB) fails the check, the method further includes:

[0030] The second network device receives second uplink data sent by the terminal device on the DRB; the packet data convergence protocol (PDCP) layer of the second network device checks the integrity protection IP of the second uplink data; wherein, the second network device determining whether the integrity protection IP of the data on the data radio bearer (DRB) fails the check includes:

[0031] The second network device determines whether the integrity protection IP check of the data on the DRB fails according to the check result of the second uplink data.

[0032] In some possible implementations, before the second network device determines whether the integrity protection IP for the data on the data radio bearer (DRB) fails, the method further includes:

[0033] The second network device receives indication information sent by the first network device or the terminal device, where the indication information is used to indicate that the integrity protection IP for the data on the DRB fails; where determining whether the integrity protection IP for the data on the data radio bearer (DRB) fails by the second network device includes:

[0034] The second network device determines whether the integrity protection IP check for the data on the DRB fails according to the indication information.

[0035] In some possible implementations, the indication information includes at least one of the following:

[0036] The identification information of the DRB, the cell identification of the data packet with IP check failure on the DRB, the location information of the terminal device when the IP check of the data packet on the DRB fails, and the time information of the terminal device when the IP check of the data packet on the DRB fails.

[0037] In some possible implementations, the second network device receiving the indication information sent by the first network device or the terminal device includes:

[0038] The second network device receives an X2 / Xn message sent by the first network device, where the X2 / Xn message includes the indication information.

[0039] In some possible implementations, the second network device receiving the indication information sent by the first network device or the terminal device includes:

[0040] The second network device receives radio resource control (RRC) signaling sent by the terminal device, where the RRC signaling includes the indication information.

[0041] In some possible implementations, the second network device receiving the indication information sent by the first network device or the terminal device includes:

[0042] The second network device receives a media access control (MAC) control element (CE) sent by the terminal device, where the MAC CE includes the indication information.

[0043] In some possible implementations, the second network device receiving the indication information sent by the first network device or the terminal device includes:

[0044] The first network device receives the PDCP status report sent by the terminal device, and the PDCP status report includes the indication information.

[0045] In some possible implementation manners, the second network device updates the key of the terminal device, including:

[0046] The second network device sends an RRC connection reconfiguration message to the terminal device, and the RRC connection reconfiguration message includes the key for update.

[0047] In some possible implementation manners, the second network device releases the radio resource control (RRC) connection where the DRB is located, including:

[0048] The second network device sends an RRC connection release message to the terminal device, and the RRC connection release message includes information for instructing the terminal device to release the RRC connection where the DRB is located.

[0049] In some possible implementation manners, the RRC connection release message further includes:

[0050] Information for instructing the terminal device to initiate a Detach process and an Attach process in sequence, or information for instructing the terminal device to initiate a Tracking Area Update (TAU) process.

[0051] In a third aspect, a method for transmitting information is provided, including:

[0052] The terminal device generates indication information for indicating that the integrity protection IP check of the data on the data radio bearer (DRB) fails;

[0053] The terminal device sends the indication information to a first network device or a second network device, where the first network device and the second network device are different network devices.

[0054] In some possible implementation manners, the indication information includes at least one of the following information:

[0055] The identification information of the DRB, the cell identification of the data packet with an IP check failure on the DRB, the location information of the terminal device when the IP check of the data packet on the DRB fails, and the time information of the terminal device when the IP check of the data packet on the DRB fails.

[0056] In some possible implementation manners, before the terminal device generates the indication information, the method further includes:

[0057] The terminal device receives first downlink data sent by the first network device on the DRB; the Packet Data Convergence Protocol (PDCP) layer of the terminal device checks the integrity protection IP of the first downlink data; wherein, the terminal device generates indication information, including:

[0058] When the IP check of the first downlink data fails, the terminal device generates the indication information.

[0059] In some possible implementation manners, before the terminal device generates the indication information, the method further includes:

[0060] The terminal device receives second downlink data sent by the second network device on the DRB; the Packet Data Convergence Protocol (PDCP) layer of the terminal device checks the integrity protection IP of the second downlink data; wherein, the terminal device generates the indication information, including:

[0061] When the IP check of the second downlink data fails, the terminal device generates the indication information.

[0062] In some possible implementation manners, when the terminal device sends the indication information to the first network device or the second network device, it includes:

[0063] The terminal device sends Radio Resource Control (RRC) signaling to the first network device or the second network device, and the RRC signaling includes the indication information.

[0064] In some possible implementation manners, when the terminal device sends the indication information to the first network device or the second network device, it includes:

[0065] The terminal device sends a Medium Access Control (MAC) control element (CE) to the first network device or the second network device, and the MAC CE includes the indication information.

[0066] In some possible implementation manners, when the terminal device sends the indication information to the first network device or the second network device, it includes:

[0067] The terminal device sends a Packet Data Convergence Protocol (PDCP) status report to the first network device or the second network device, and the PDCP status report includes the indication information.

[0068] In some possible implementation manners, the method further includes:

[0069] The terminal device receives an RRC connection reconfiguration message sent by the second network device, and the RRC connection reconfiguration message includes a key for update.

[0070] In some possible implementations, the method further includes:

[0071] The terminal device receives an RRC connection release message sent by the second network device, where the RRC connection release message includes information for instructing the terminal device to release the RRC connection where the DRB is located.

[0072] In some possible implementations, the RRC connection release message further includes:

[0073] Information for instructing the terminal device to initiate a Detach process and an Attach process in sequence, or information for instructing the terminal device to initiate a Tracking Area Update (TAU) process.

[0074] In a fourth aspect, a network device is provided, including:

[0075] A processing unit, configured to obtain indication information for indicating that the integrity protection IP check of data on a Data Radio Bearer (DRB) fails;

[0076] A transceiver unit, configured to send the indication information to a second network device.

[0077] In a fifth aspect, a network device is provided, including:

[0078] A processor, configured to obtain indication information for indicating that the integrity protection IP check of data on a Data Radio Bearer (DRB) fails;

[0079] A transceiver, configured to send the indication information to a second network device.

[0080] In a sixth aspect, a terminal device is provided, including:

[0081] A generating unit, configured to generate indication information for indicating that the integrity protection IP check of data on a Data Radio Bearer (DRB) fails;

[0082] A transceiver unit, configured to send the indication information to a first network device or a second network device, where the first network device and the second network device are different network devices.

[0083] In a seventh aspect, a terminal device is provided, including:

[0084] A generator, configured to generate indication information for indicating that the integrity protection IP check of data on a Data Radio Bearer (DRB) fails;

[0085] A transceiver for sending the indication information to a first network device or a second network device, where the first network device and the second network device are different network devices.

[0086] In a eighth aspect, a network device is provided, including: a processing unit, where the processing unit is configured to:

[0087] Determine whether the integrity protection IP of the data on a data radio bearer (DRB) fails the verification;

[0088] When the IP verification of the data on the DRB fails, update the secret key of the terminal device, or release the radio resource control (RRC) connection where the DRB is located.

[0089] In a ninth aspect, a network device is provided, including: a processor, where the processor is configured to:

[0090] Determine whether the integrity protection IP of the data on a data radio bearer (DRB) fails the verification;

[0091] When the IP verification of the data on the DRB fails, update the secret key of the terminal device, or release the radio resource control (RRC) connection where the DRB is located.

[0092] In a tenth aspect, a computer-readable medium is provided for storing a computer program, where the computer program includes instructions for executing the method embodiments of the first aspect or the second aspect or the third aspect above.

[0093] In an eleventh aspect, a computer chip is provided, including: an input interface, an output interface, at least one processor, and a memory, where the processor is configured to execute the code in the memory, and when the code is executed, the processor can implement each process executed by the first network device in the method of transmitting information in the first aspect or the second aspect or the third aspect above.

[0094] In a twelfth aspect, a computer chip is provided, including: an input interface, an output interface, at least one processor, and a memory, where the processor is configured to execute the code in the memory, and when the code is executed, the processor can implement each process executed by the second network device in the method of transmitting information in the first aspect or the second aspect or the third aspect above.

[0095] In a thirteenth aspect, a computer chip is provided, including: an input interface, an output interface, at least one processor, and a memory, where the processor is configured to execute the code in the memory, and when the code is executed, the processor can implement each process executed by the terminal device in the method of transmitting information in the first aspect or the second aspect or the third aspect above.

[0096] In a fourteenth aspect, a communication system is provided, including the aforementioned network device and the aforementioned terminal device. Description of the Drawings

[0097] Figure 1 is an example of the application scenario of the present invention.

[0098] Figure 2 is a schematic block diagram of the method for transmitting information according to an embodiment of the present invention.

[0099] Figure 3 is a schematic block diagram of the network device according to an embodiment of the present invention.

[0100] Figure 4 is a schematic block diagram of another network device according to an embodiment of the present invention.

[0101] Figure 5 is a schematic block diagram of the terminal device according to an embodiment of the present invention.

[0102] Figure 6 is a schematic block diagram of another terminal device according to an embodiment of the present invention. Detailed Embodiments

[0103] Figure 1 is a schematic diagram of the application scenario according to an embodiment of the present invention.

[0104] As Figure 1 shown, the terminal device 110 is connected to the first network device 130 under the first communication system and the second network device 120 under the second communication system. For example, the first network device 130 is a network device under New Radio (NR), and the second network device 120 is a network device under Long-Term Evolution (LTE).

[0105] Wherein, the first network device 130 and the second network device 120 may include multiple cells.

[0106] For ease of understanding, the following takes the first network device 130 as a network device under NR and the second network device 120 as a network device under LTE as an example for illustration.

[0107] In LTE, there is no requirement for integrity protection for data radio bearers (DRBs). However, in NR, the requirement for integrity protection of data on DRBs is added. Therefore, each Packet Data Convergence Protocol (PDCP) service data unit (SDU) needs to additionally carry a Media Access Control (MAC)-I part for integrity protection (IP) verification.

[0108] However, if the IP verification fails, it is very likely that the data has been attacked or maliciously modified (there is a security risk). The maliciously modified data will be discarded, reducing the success rate of data transmission.

[0109] To solve the above problems, in the embodiments of the present invention, a method for transmitting information, a terminal device, and a network device are proposed, which can effectively eliminate security risks, ensure communication security, and thus improve the success rate of data transmission.

[0110] It should be understood that Figure 1 is an example of the scenario of the embodiments of the present invention, and the embodiments of the present invention are not limited to Figure 1 shown.

[0111] For example, the communication system adapted to the embodiments of the present invention may include at least multiple network devices under the first communication system and / or multiple network devices under the second communication system.

[0112] For another example, the first communication system and the second communication system in the embodiments of the present invention may be different or the same.

[0113] For example, the first communication system and the second communication system can be various communication systems, such as: Global System of Mobile communication (GSM) system, Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, General Packet Radio Service (GPRS), Long Term Evolution (LTE) system, LTE Time Division Duplex (TDD), Universal Mobile Telecommunication System (UMTS), etc. Another example is the 5G communication system. Among them, the main application scenarios of 5G can include: Enhance Mobile Broadband (eMBB), Ultra-Reliable and Low Latency Communication (URLLC), massive machine type of communication (mMTC).

[0114] In addition, the present invention describes various embodiments in combination with network devices (the first network device 130 and the second network device 120) and terminal device 110.

[0115] Among them, the network device can refer to any entity on the network side used to send or receive signals. For example, it can be a user equipment of Machine Type Communication (MTC), a Base Transceiver Station (BTS) in GSM or CDMA, a NodeB in WCDMA, an Evolutional Node B (eNB or eNodeB) in LTE, a base station device in a 5G network, etc.

[0116] The terminal device 110 can be any terminal device. Specifically, the terminal device can communicate with one or more core networks via a Radio Access Network (RAN), and can also be referred to as an access terminal, a User Equipment (UE), a user unit, a user station, a mobile station, a mobile phone, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device. For example, it can be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA), a handheld device with wireless communication capabilities, a computing device, or other processing devices connected to a wireless modem, a vehicle-mounted device, a wearable device, and a terminal device in a 5G network, etc.

[0117] Figure 2 It is a schematic flowchart of a method for configuring radio resources according to an embodiment of the present invention.

[0118] 210, the first network device obtains indication information, which is used to indicate that the IP checksum of the data on the DRB fails.

[0119] 220, the first network device sends the indication information to the second network device.

[0120] 230, the second network device updates the secret key of the terminal device according to the indication information, or releases the Radio Resource Control (RRC) connection where the DRB is located.

[0121] It should be understood that the first network device can be the first network device 130 as shown in Figure 1 , the second network device can be the second network device 120 as described in Figure 1 , and the terminal device can be the terminal device 110 as described in Figure 1 , but it should be understood that the embodiments of the present invention are not limited thereto.

[0122] It should also be understood that Figure 1 the second network device shown updates the secret key of the terminal device according to the indication information sent by the first network device, or releases the RRC connection where the DRB is located is exemplary, and the embodiments of the present invention are not limited thereto. For example, the second network device can directly make a judgment according to its own information, or for another example, the second network device can receive the indication information sent by the terminal device, etc.

[0123] In summary, for the second network device, the second network device determines whether the IP of the data on the DRB fails the verification; when the IP of the data on the DRB fails the verification, the second network device can update the secret key of the terminal device, or the second network device can release the RRC connection where the DRB is located. Thereby, potential security risks are eliminated, communication security is ensured, and the success rate of data transmission is further improved.

[0124] Specifically, when the IP of the data on the DRB fails the verification, it indicates that there are potential risks of the data on the DRB being attacked or maliciously tampered with. The second network device can take measures: update the secret key of the terminal device, or re - establish the DRB (release the RRC connection where the DRB is located), eliminate potential security risks, ensure communication security, and further improve the success rate of data transmission.

[0125] For example, the terminal device can receive the RRC connection re - configuration message sent by the second network device, and the RRC connection re - configuration message includes the secret key for update.

[0126] For another example, the terminal device can receive the RRC connection release message sent by the second network device, and the RRC connection release message includes information for instructing the terminal device to release the RRC connection where the DRB is located.

[0127] Furthermore, the RRC connection release message may further include:

[0128] Information for instructing the terminal device to initiate a Detach process and an Attach process in sequence, or information for instructing the terminal device to initiate a tracking area update (TAU) process. Thereby, the secret key of the non - access stratum (NAS) of the terminal device can be changed.

[0129] It should be understood that the Attach process includes completing the registration process of the terminal device in the network and completing the establishment process of the default bearer of the terminal device by the core network (EPC). The Detach process completes the logout process of the terminal device on the network side and the deletion process of all EPS bearers.

[0130] Even further, the indication information may further include at least one of the following information:

[0131] The identification information of the DRB, the cell identification of the data packet whose IP verification fails on the DRB, the location information of the terminal device when the IP of the data packet on the DRB fails the verification, and the time information of the terminal device when the IP of the data packet on the DRB fails the verification.

[0132] Thus, the second network device can determine relevant information when the terminal device is attacked according to the indication information and perform relevant processing.

[0133] For example, the second network device can determine the DRB under attack according to the indication information, and then determine whether to release and update the secret key of the terminal device or re - establish the DRB.

[0134] For another example, the second network device can determine the DRB under attack according to the indication information, and then determine the time and / or location when the terminal device is attacked. Thus, the location of the attacker or the attack time period can be analyzed, and subsequent processing can be performed. For example, regularly change the secret key at the location or time period where the attacker frequently attacks.

[0135] In the embodiments of the present invention, it should be noted that when the second network device determines that the IP check of the data on the DRB fails, the second network device can update the secret key of the terminal device, or the second network device can release the RRC connection where the DRB is located. However, the specific implementation manner for the second network device to determine whether the IP check of the data on the DRB fails is not limited.

[0136] The following is an exemplary description.

[0137] In one embodiment, the indication information is generated by the first network device.

[0138] Specifically, the first network device can receive the first uplink data sent by the terminal device on the DRB; the Packet Data Convergence Protocol (PDCP) layer of the first network device checks the IP of the first uplink data; when the IP check of the first uplink data fails, the first network device generates the indication information.

[0139] That is to say, the first network device can generate indication information by checking the IP of the first uplink data, and then send it to the second network device by the first network device. So that the second network device can update the secret key of the terminal device according to the indication information, or release the RRC connection where the DRB is located

[0140] In another embodiment, the indication information can be generated by the terminal device.

[0141] Specifically, before the second network device determines whether the integrity - protected IP of the data on the DRB fails, it receives the indication information sent by the terminal device or the first network device, and the indication information is used to indicate that the IP check of the data on the DRB fails; so that the second network device can determine whether the IP check of the data on the DRB fails according to the indication information.

[0142] Optionally, the terminal device may send the indication information to a first network device, and then the first network device forwards it to the second network device.

[0143] For example, the first network device receives RRC signaling sent by the terminal device, and the RRC signaling includes the indication information.

[0144] For another example, the first network device receives a Media Access Control (MAC) Control Element (CE) sent by the terminal device, and the MAC CE includes the indication information.

[0145] For yet another example, the first network device receives a PDCP status report sent by the terminal device, and the PDCP status report includes the indication information.

[0146] For yet another example, the first network device sends an X2 / Xn message to the second network device, and the X2 / Xn message includes the indication information. Among them, the X2 interface is an interconnection interface between evolved Node Bs (e-NodeBs) and supports direct transmission of data and signaling. The Xn interface is an interface between 5G Radio Access Networks (RANs).

[0147] Optionally, the terminal device may also directly send the indication information to the second network device.

[0148] For example, the second network device receives RRC signaling sent by the terminal device, and the RRC signaling includes the indication information.

[0149] For another example, the second network device receives a MAC CE sent by the terminal device, and the MAC CE includes the indication information.

[0150] For yet another example, the second network device receives a PDCP status report sent by the terminal device, and the PDCP status report includes the indication information.

[0151] For yet another example, the second network device sends an X2 / Xn message to the second network device, and the X2 / Xn message includes the indication information.

[0152] In another embodiment, the second network device may directly determine whether the IP of the data on the DRB fails the check.

[0153] Specifically, the second network device may receive second uplink data sent by the terminal device on the DRB; the PDCP layer of the second network device verifies the IP of the second uplink data; the second network device determines whether the integrity protection IP verification of the data on the DRB fails according to the verification result of the second uplink data.

[0154] The implementation manner for the terminal device to determine the indication information in the embodiments of the present invention will be described below.

[0155] In one embodiment, the terminal device receives first downlink data sent by the first network device on the DRB; the PDCP layer of the terminal device verifies the IP of the first downlink data; when the IP verification of the first downlink data fails, the terminal device generates the indication information.

[0156] In another embodiment, the terminal device receives second downlink data sent by the second network device on the DRB; the PDCP layer of the terminal device verifies the IP of the second downlink data; when the IP verification of the second downlink data fails, the terminal device generates the indication information.

[0157] It should be understood that in the embodiments of the present invention, it is intended that when the second network device determines that the IP verification of the data on the DRB fails, a key replacement process is initiated (for example, only changing the key of the terminal device, or directly changing the key by releasing the RRC connection), but the embodiments of the present invention do not specifically limit the manner in which the second network device determines that the IP verification of the data on the DRB fails.

[0158] In addition, for the first network device and the terminal device, it is intended that the indication information for indicating that the IP verification of the data on the DRB fails is sent to the second network device, so that the second network device initiates a key replacement process according to the indication information (for example, only changing the key of the terminal device, or directly changing the key by releasing the RRC connection), but the embodiments of the present invention do not specifically limit the sending manner of the terminal device and the first network device.

[0159] Figure 3 It is a schematic block diagram of the first network device or the second network device in the embodiments of the present invention.

[0160] Specifically, a network device is provided, as Figure 3 shown. The network device 300 includes:

[0161] A processing unit 310, configured to obtain indication information, where the indication information is used to indicate that the integrity protection IP verification of the data on the data radio bearer DRB fails;

[0162] A transceiver unit 320, configured to send the indication information to a second network device.

[0163] Optionally, the indication information includes at least one of the following information:

[0164] The identification information of the DRB, the cell identification of the data packet with IP check failure on the DRB, the location information of the terminal device when the data packet on the DRB has an IP check failure, and the time information of the terminal device when the data packet on the DRB has an IP check failure.

[0165] Optionally, the transceiver unit 320 is further configured to:

[0166] Before obtaining the indication information, receive first uplink data sent by a terminal device on the DRB; wherein, the processing unit 310 is specifically configured to:

[0167] Verify the integrity protection IP of the first uplink data through the Packet Data Convergence Protocol (PDCP) layer of the network device; when the IP check of the first uplink data fails, generate the indication information.

[0168] Optionally, the processing unit 310 is specifically configured to:

[0169] Receive the indication information sent by the terminal device.

[0170] Optionally, the transceiver unit 320 is specifically configured to:

[0171] Receive radio resource control (RRC) signaling sent by the terminal device, where the RRC signaling includes the indication information.

[0172] Optionally, the transceiver unit 320 is specifically configured to:

[0173] Receive a Medium Access Control (MAC) control element (CE) sent by the terminal device, where the MAC CE includes the indication information.

[0174] Optionally, the transceiver unit 320 is specifically configured to:

[0175] Receive a PDCP status report sent by the terminal device, where the PDCP status report includes the indication information.

[0176] Optionally, the transceiver unit 320 is specifically configured to:

[0177] Send an X2 / Xn message to the second network device, where the X2 / Xn message includes the indication information.

[0178] As Figure 3 shown, another network device is further provided in an embodiment of the present invention. The network device 300 includes: a processing unit 310, and the processing unit 310 is configured to:

[0179] Determine whether the integrity protection IP of the data on the data radio bearer DRB fails the verification;

[0180] When the IP verification of the data on the DRB fails, update the key of the terminal device, or release the radio resource control RRC connection where the DRB is located.

[0181] Optionally, the terminal device further includes:

[0182] A transceiver unit 320, configured to receive second uplink data sent by the terminal device on the DRB before determining whether the integrity protection IP of the data on the data radio bearer DRB fails the verification; wherein, the processing unit 310 is specifically configured to:

[0183] Verify the integrity protection IP of the second uplink data through the packet data convergence protocol PDCP layer of the network device; determine whether the integrity protection IP verification of the data on the DRB fails according to the verification result of the second uplink data.

[0184] Optionally, the terminal device further includes:

[0185] A transceiver unit 320, configured to receive indication information sent by a first network device or the terminal device before determining whether the integrity protection IP of the data on the data radio bearer DRB fails the verification, where the indication information is used to indicate that the integrity protection IP of the data on the DRB fails the verification; wherein, the processing unit 310 is specifically configured to:

[0186] Determine whether the integrity protection IP verification of the data on the DRB fails according to the indication information.

[0187] Optionally, the indication information includes at least one of the following information:

[0188] The identification information of the DRB, the cell identification of the data packet whose IP verification fails on the DRB, the location information of the terminal device when the IP of the data packet on the DRB fails the verification, and the time information of the terminal device when the IP of the data packet on the DRB fails the verification.

[0189] Optionally, the transceiver unit 320 is specifically configured to:

[0190] Receive an X2 / Xn message sent by the first network device, where the X2 / Xn message includes the indication information.

[0191] Optionally, the transceiver unit 320 is specifically configured to:

[0192] Receive radio resource control RRC signaling sent by the terminal device, where the RRC signaling includes the indication information.

[0193] Optionally, the transceiver unit 320 is specifically configured to:

[0194] Receive a Media Access Control (MAC) Control Element (CE) sent by the terminal device, where the MAC CE includes the indication information.

[0195] Optionally, the transceiver unit 320 is specifically configured to:

[0196] Receive a Packet Data Convergence Protocol (PDCP) status report sent by the terminal device, where the PDCP status report includes the indication information.

[0197] Optionally, the processing unit 310 is specifically configured to:

[0198] Send a Radio Resource Control (RRC) connection reconfiguration message to the terminal device, where the RRC connection reconfiguration message includes a key for update.

[0199] Optionally, the processing unit 310 is specifically configured to:

[0200] Send an RRC connection release message to the terminal device, where the RRC connection release message includes information for instructing the terminal device to release the RRC connection where the DRB is located.

[0201] Optionally, the RRC connection release message further includes:

[0202] Information for instructing the terminal device to initiate a Detach process and an Attach process in sequence, or information for instructing the terminal device to initiate a Tracking Area Update (TAU) process.

[0203] It should be noted that the processing unit 310 can be implemented by a processor, and the transceiver unit 320 can be implemented by a transceiver. As Figure 4 shown, the network device 400 may include a processor 410, a transceiver 420, and a memory 430. Among them, the memory 430 can be used to store the indication information, and can also be used to store codes, instructions, etc. executed by the processor 410. Each component in the network device 400 is connected through a bus system. Among them, the bus system includes not only a data bus, but also a power bus, a control bus, and a status signal bus.

[0204] Figure 4 The network device 400 shown can implement each process implemented by the first network device or the second network device in the foregoing Figure 2 method embodiment. To avoid repetition, details are not described here again.

[0205] Figure 5 is a schematic block diagram of a terminal device according to an embodiment of the present invention.

[0206] Specifically, as Figure 5 shown, the terminal device 500 includes:

[0207] A generating unit 510, configured to generate indication information for indicating that integrity protection IP check of data on a data radio bearer (DRB) fails.

[0208] A transceiver unit 520, configured to send the indication information to a first network device or a second network device, where the first network device and the second network device are different network devices.

[0209] Optionally, the indication information includes at least one of the following information:

[0210] Identification information of the DRB, a cell identification of a data packet with an IP check failure on the DRB, location information of the terminal device when an IP check of a data packet on the DRB fails, and time information of the terminal device when an IP check of a data packet on the DRB fails.

[0211] Optionally, the transceiver unit 520 is further configured to:

[0212] Before generating the indication information, receive first downlink data sent by the first network device on the DRB; check integrity protection IP of the first downlink data through a packet data convergence protocol (PDCP) layer of the terminal device; where the generating unit 510 is specifically configured to:

[0213] When an IP check of the first downlink data fails, the terminal device generates the indication information.

[0214] Optionally, the transceiver unit 520 is further configured to:

[0215] Before generating the indication information, receive second downlink data sent by the second network device on the DRB; check integrity protection IP of the second downlink data through a packet data convergence protocol (PDCP) layer of the terminal device; where the generating unit 510 is specifically configured to:

[0216] When an IP check of the second downlink data fails, generate the indication information.

[0217] Optionally, the transceiver unit 520 is specifically configured to:

[0218] Send radio resource control (RRC) signaling to the first network device or the second network device, where the RRC signaling includes the indication information.

[0219] Optionally, the transceiver unit 520 is specifically configured to:

[0220] Send a media access control (MAC) control element (CE) to the first network device or the second network device, where the MAC CE includes the indication information.

[0221] Optionally, the transceiver unit 520 is specifically configured to:

[0222] Send a Packet Data Convergence Protocol (PDCP) status report to the first network device or the second network device, where the PDCP status report includes the indication information.

[0223] Optionally, the transceiver unit 520 is further configured to:

[0224] Receive an RRC connection reconfiguration message sent by the second network device, where the RRC connection reconfiguration message includes a key for update.

[0225] Optionally, the transceiver unit 520 is further configured to:

[0226] Receive an RRC connection release message sent by the second network device, where the RRC connection release message includes information for instructing the terminal device to release the RRC connection where the DRB is located.

[0227] Optionally, the RRC connection release message further includes:

[0228] Information for instructing the terminal device to initiate a Detach process and an Attach process in sequence, or information for instructing the terminal device to initiate a Tracking Area Update (TAU) process.

[0229] It should be noted that the generating unit 510 may be implemented by a processor, and the transceiver unit 520 may be implemented by a transceiver. As Figure 6 shown, the terminal device 600 may include a processor 610, a transceiver 620, and a memory 630. Among them, the memory 630 may be used to store the indication information, and may also be used to store codes, instructions, etc. executed by the processor 610. Each component in the terminal device 600 is connected through a bus system. Among them, the bus system includes, in addition to a data bus, a power bus, a control bus, and a status signal bus.

[0230] Figure 6 The terminal device 600 shown is capable of implementing each process implemented by the terminal device in the foregoing Figure 2 method embodiment. To avoid repetition, it will not be elaborated here.

[0231] It should be understood that the method embodiment in the embodiment of the present invention may be applied to a processor or implemented by a processor.

[0232] In the implementation process, the steps of the method embodiments in the embodiments of the present invention can be completed by the integrated logic circuit of the hardware in the processor or the instructions in the form of software. More specifically, the steps of the method disclosed in combination with the embodiments of the present invention can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by the combination of the hardware and software modules in the decoding processor. The software module can be located in a mature storage medium in the art such as random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.

[0233] Among them, the processor may be an integrated circuit chip with signal processing capabilities, and can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present invention. For example, the above-mentioned processor may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, discrete hardware components, and so on. In addition, the general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0234] In addition, in the embodiments of the present invention, the memory may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. It should be understood that the above description of the memory is exemplary but not restrictive. For example, the memory in the embodiments of the present invention may also be a static RAM (SRAM), a dynamic RAM (DRAM), a synchronous DRAM (SDRAM), a double data rate SDRAM (DDR SDRAM), an enhanced SDRAM (ESDRAM), a synch link DRAM (SLDRAM), and a Direct Rambus RAM (DR RAM), etc. That is to say, the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memories.

[0235] Finally, it should be noted that the terms used in the embodiments of the present invention and the appended claims are only for the purpose of describing specific embodiments and are not intended to limit the embodiments of the present invention.

[0236] For example, the singular forms of "a", "the", and "said" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.

[0237] Again, depending on the context, the phrase "when" as used herein may be interpreted as "if" or "when" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if determined" or "if detected (stated condition or event)" may be interpreted as "when determined" or "in response to determining" or "when detected (stated condition or event)" or "in response to detecting (stated condition or event)".

[0238] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the embodiments of the present invention.

[0239] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0240] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of devices or units can be in electrical, mechanical, or other forms.

[0241] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the objectives of the embodiments of the present invention.

[0242] In addition, the various functional units in the embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0243] If it is implemented in the form of software functional units and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present invention, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories, random access memories, magnetic disks, or optical discs.

[0244] The above content is only the specific implementation manner of the embodiments of the present invention, but the protection scope of the embodiments of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the embodiments of the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the embodiments of the present invention. Therefore, the protection scope of the embodiments of the present invention shall be subject to the protection scope of the claims.

Claims

1. A method for transmitting information, characterized in that, including: A first network device obtains indication information for indicating that integrity protection IP verification of data on a data radio bearer (DRB) fails; The first network device sends the indication information to a second network device; wherein, the second network device updates a secret key of a terminal device according to the indication information, or releases a radio resource control (RRC) connection where the DRB is located; The indication information includes: identification information of the DRB, a cell identification of a data packet with IP verification failure on the DRB, location information of the terminal device when the IP verification of the data packet on the DRB fails, and time information of the terminal device when the IP verification of the data packet on the DRB fails; When the second network device releases the radio resource control (RRC) connection where the DRB is located, it includes: The second network device sends an RRC connection release message to the terminal device, and the RRC connection release message includes information for instructing the terminal device to release the RRC connection where the DRB is located; The RRC connection release message further includes: information for instructing the terminal device to initiate a Detach process and an Attach process in sequence, or information for instructing the terminal device to initiate a Tracking Area Update (TAU) process to change a secret key of the non-access stratum (NAS) of the terminal device.

2. The method according to claim 1, characterized in that, Before the first network device obtains the indication information, the method further includes: The first network device receives first uplink data sent by a terminal device on the DRB; The Packet Data Convergence Protocol (PDCP) layer of the first network device verifies the integrity protection IP of the first uplink data; wherein, the first network device obtains the indication information, including: When the IP verification of the first uplink data fails, the first network device generates the indication information.

3. The method according to claim 1, characterized in that, The first network device obtains the indication information, including: The first network device receives the indication information sent by the terminal device.

4. The method according to claim 3, characterized in that, The first network device receives the indication information sent by the terminal device, including: The first network device receives radio resource control (RRC) signaling sent by the terminal device, and the RRC signaling includes the indication information.

5. The method according to claim 3, characterized in that, The first network device receives the indication information sent by the terminal device, including: The first network device receives a Medium Access Control (MAC) control element (CE) sent by the terminal device, and the MAC CE includes the indication information.

6. The method according to claim 3, characterized in that, The first network device receives the indication information sent by the terminal device, including: The first network device receives a PDCP status report sent by the terminal device, and the PDCP status report includes the indication information.

7. The method according to claim 1 or 2, characterized in that, The first network device sends the indication information to the second network device, including: The first network device sends an X2 / Xn message to the second network device, and the X2 / Xn message includes the indication information.

8. A method for transmitting information, characterized in that, including: A second network device receives indication information sent by a first network device or a terminal device for indicating that integrity protection IP verification of data on a data radio bearer (DRB) fails; The second network device determines whether the integrity protection IP of the data on the DRB fails the verification; When the IP verification of the data on the DRB fails, the second network device updates the secret key of the terminal device, or the second network device releases the radio resource control (RRC) connection where the DRB is located; Among them, the second network device determines whether the integrity protection IP of the data on the data radio bearer (DRB) fails the verification, including: the second network device determines whether the integrity protection IP verification of the data on the DRB fails according to the indication information; The indication information includes: The identification information of the DRB, the cell identification of the data packet whose IP verification fails on the DRB, the location information of the terminal device when the IP verification of the data packet on the DRB fails, and the time information of the terminal device when the IP verification of the data packet on the DRB fails; The second network device releases the radio resource control (RRC) connection where the DRB is located, including: The second network device sends an RRC connection release message to the terminal device, and the RRC connection release message includes information for instructing the terminal device to release the RRC connection where the DRB is located; The RRC connection release message further includes: Information for instructing the terminal device to initiate a Detach process and an Attach process in sequence, or information for instructing the terminal device to initiate a Tracking Area Update (TAU) process to change the secret key of the non-access stratum (NAS) of the terminal device.

9. The method according to claim 8, wherein, Before the second network device determines whether the integrity protection IP of the data on the data radio bearer (DRB) fails the verification, the method further includes: The second network device receives second uplink data sent by the terminal device on the DRB; The packet data convergence protocol (PDCP) layer of the second network device verifies the integrity protection IP of the second uplink data; Among them, the second network device determines whether the integrity protection IP of the data on the data radio bearer (DRB) fails the verification, including: The second network device determines whether the integrity protection IP verification of the data on the DRB fails according to the verification result of the second uplink data.

10. The method according to claim 8, wherein, The second network device receives indication information sent by the first network device or the terminal device, including: The second network device receives an X2 / Xn message sent by the first network device, and the X2 / Xn message includes the indication information.

11. The method according to claim 8, wherein, The second network device receives indication information sent by the first network device or the terminal device, including: The second network device receives radio resource control (RRC) signaling sent by the terminal device, and the RRC signaling includes the indication information.

12. The method according to claim 8, wherein, The second network device receives indication information sent by the first network device or the terminal device, including: The second network device receives a media access control (MAC) control element (CE) sent by the terminal device, and the MAC CE includes the indication information.

13. The method according to claim 8, wherein, The second network device receives indication information sent by the first network device or the terminal device, including: The first network device receives the PDCP status report sent by the terminal device, and the PDCP status report includes the indication information.

14. The method according to claim 8 or 9, wherein, The second network device updates the key of the terminal device, including: The second network device sends an RRC connection reconfiguration message to the terminal device, and the RRC connection reconfiguration message includes the key for update.

15. A method for transmitting information, wherein, Including: The terminal device generates indication information, and the indication information is used to indicate that the integrity protection IP check of the data on the data radio bearer (DRB) fails. The terminal device sends the indication information to the first network device or the second network device, and the first network device and the second network device are different network devices. The terminal device receives the RRC connection release message sent by the second network device, and the RRC connection release message includes information for instructing the terminal device to release the RRC connection where the DRB is located. Wherein, the second network device updates the key of the terminal device according to the indication information, or releases the radio resource control (RRC) connection where the DRB is located. The indication information includes: The identification information of the DRB, the cell identification of the data packet with IP check failure on the DRB, the location information of the terminal device when the IP check of the data packet on the DRB fails, and the time information of the terminal device when the IP check of the data packet on the DRB fails. The RRC connection release message further includes: Information for instructing the terminal device to initiate a Detach process and an Attach process in sequence, or information for instructing the terminal device to initiate a Tracking Area Update (TAU) process to change the key of the non-access stratum (NAS) of the terminal device.

16. The method according to claim 15, wherein, Before the terminal device generates the indication information, the method further includes: The terminal device receives the first downlink data sent by the first network device on the DRB. The packet data convergence protocol (PDCP) layer of the terminal device checks the integrity protection IP of the first downlink data. Wherein, the terminal device generates the indication information, including: When the IP check of the first downlink data fails, the terminal device generates the indication information.

17. The method according to claim 15, wherein Before the terminal device generates the indication information, the method further includes: The terminal device receives the second downlink data sent by the second network device on the DRB. The packet data convergence protocol (PDCP) layer of the terminal device checks the integrity protection IP of the second downlink data. Wherein, the terminal device generates the indication information, including: When the IP check of the second downlink data fails, the terminal device generates the indication information.

18. The method according to any one of claims 15 to 17, wherein The terminal device sends the indication information to the first network device or the second network device, including: The terminal device sends RRC signaling to the first network device or the second network device, and the RRC signaling includes the indication information.

19. The method according to any one of claims 15 to 17, wherein The terminal device sends the indication information to the first network device or the second network device, including: The terminal device sends a Media Access Control (MAC) control element (CE) to the first network device or the second network device, and the MAC CE includes the indication information.

20. The method according to any one of claims 15 to 17, wherein The terminal device sending the indication information to the first network device or the second network device includes: The terminal device sends a Packet Data Convergence Protocol (PDCP) status report to the first network device or the second network device, and the PDCP status report includes the indication information.

21. The method according to any one of claims 15 to 17, wherein The method further includes: The terminal device receives an RRC connection reconfiguration message sent by the second network device, and the RRC connection reconfiguration message includes a key for update.

22. A network device, wherein including: a processing unit, configured to obtain indication information for indicating that integrity protection IP check of data on a Data Radio Bearer (DRB) fails; a transceiver unit, configured to send the indication information to the second network device; wherein, the second network device updates the key of the terminal device according to the indication information, or releases the Radio Resource Control (RRC) connection where the DRB is located; The indication information includes: the identification information of the DRB, the cell identification of the data packet with IP check failure on the DRB, the location information of the terminal device when the IP check of the data packet on the DRB fails, and the time information of the terminal device when the IP check of the data packet on the DRB fails; The second network device releasing the RRC connection where the DRB is located includes: The second network device sends an RRC connection release message to the terminal device, and the RRC connection release message includes information for instructing the terminal device to release the RRC connection where the DRB is located; The RRC connection release message further includes: information for instructing the terminal device to initiate a Detach process and an Attach process in sequence, or information for instructing the terminal device to initiate a Tracking Area Update (TAU) process to change the key of the non-access stratum (NAS) of the terminal device.

23. The network device according to claim 22, wherein The transceiver unit is further configured to: before obtaining the indication information, receive first uplink data sent by the terminal device on the DRB; wherein, the processing unit is specifically configured to: verify the integrity protection IP of the first uplink data through the PDCP layer of the network device; when the IP check of the first uplink data fails, generate the indication information.

24. The network device according to claim 22, wherein The processing unit is specifically configured to: receive the indication information sent by the terminal device.

25. The network device according to claim 24, wherein, The transceiver unit is specifically configured to: receive Radio Resource Control (RRC) signaling sent by the terminal device, and the RRC signaling includes the indication information.

26. The network device according to claim 24, wherein, The transceiver unit is specifically configured to: receive a Media Access Control (MAC) control element (CE) sent by the terminal device, and the MAC CE includes the indication information.

27. The network device according to claim 24, wherein, The transceiver unit is specifically configured to: receive a PDCP status report sent by the terminal device, and the PDCP status report includes the indication information.

28. The network device according to any one of claims 22 to 27, wherein, The transceiver unit is specifically configured to: Send an X2 / Xn message to the second network device, where the X2 / Xn message includes the indication information.

29. A network device, wherein, Comprising: A processing unit configured to: Determine whether integrity protection IP for data on a data radio bearer (DRB) fails verification; When the IP verification for data on the DRB fails, update the key of the terminal device or release the radio resource control (RRC) connection where the DRB is located; The network device further comprises: A transceiver unit, configured to receive indication information sent by a first network device or the terminal device before determining whether integrity protection IP for data on a data radio bearer (DRB) fails verification, where the indication information is used to indicate that the integrity protection IP for data on the DRB fails verification; Wherein, the processing unit is specifically configured to: Determine whether integrity protection IP verification for data on the DRB fails according to the indication information; The processing unit is specifically configured to: Send an RRC connection release message to the terminal device, where the RRC connection release message includes information for instructing the terminal device to release the RRC connection where the DRB is located; Wherein, the indication information includes: The identification information of the DRB, the cell identification of the data packet whose IP verification fails on the DRB, the location information of the terminal device when the IP verification of the data packet on the DRB fails, and the time information of the terminal device when the IP verification of the data packet on the DRB fails; The RRC connection release message further includes: Information for instructing the terminal device to initiate a Detach process and an Attach process in sequence, or information for instructing the terminal device to initiate a Tracking Area Update (TAU) process, so as to change the key of the non-access stratum (NAS) of the terminal device.

30. The network device according to claim 29, wherein, The transceiver unit is further configured to: Receive second uplink data sent by the terminal device on the DRB before determining whether integrity protection IP for data on a data radio bearer (DRB) fails verification; Wherein, the processing unit is specifically configured to: Verify the integrity protection IP of the second uplink data through the Packet Data Convergence Protocol (PDCP) layer of the network device; Determine whether integrity protection IP verification for data on the DRB fails according to the verification result of the second uplink data.

31. The network device according to claim 30, wherein, The transceiver unit is specifically configured to: Receive an X2 / Xn message sent by the first network device, where the X2 / Xn message includes the indication information.

32. The network device according to claim 30, wherein, The transceiver unit is specifically configured to: Receive radio resource control (RRC) signaling sent by the terminal device, where the RRC signaling includes the indication information.

33. The network device according to claim 30, wherein The transceiver unit is specifically configured to: Receive a Medium Access Control (MAC) control element (CE) sent by the terminal device, where the MAC CE includes the indication information.

34. The network device according to claim 30, wherein The transceiver unit is specifically configured to: Receive a PDCP status report sent by the terminal device, where the PDCP status report includes the indication information.

35. The network device according to any one of claims 29 to 34, wherein The processing unit is specifically configured to: Send an RRC connection reconfiguration message to the terminal device, where the RRC connection reconfiguration message includes an updated key.

36. A terminal device, wherein Comprising: A generating unit, configured to generate indication information for indicating that integrity protection IP check of data on a data radio bearer (DRB) fails; A transceiver unit, configured to send the indication information to a first network device or a second network device, where the first network device and the second network device are different network devices; The transceiver unit is further configured to: Receive an RRC connection release message sent by the second network device, where the RRC connection release message includes information for indicating that the terminal device releases the RRC connection where the DRB is located; Wherein, the second network device updates a key of the terminal device according to the indication information, or releases a radio resource control (RRC) connection where the DRB is located; The indication information includes: An identification information of the DRB, a cell identification of a data packet whose IP check fails on the DRB, a location information of the terminal device when the IP check of the data packet on the DRB fails, and a time information of the terminal device when the IP check of the data packet on the DRB fails; The RRC connection release message further includes: Information for indicating that the terminal device sequentially initiates a Detach procedure and an Attach procedure, or information for indicating that the terminal device initiates a Tracking Area Update (TAU) procedure, so as to change a key of the non-access stratum (NAS) of the terminal device.

37. The terminal device according to claim 36, wherein The transceiver unit is further configured to: Before generating the indication information, receive first downlink data sent by the first network device on the DRB; Check the integrity protection IP of the first downlink data through a Packet Data Convergence Protocol (PDCP) layer of the terminal device; Wherein, the generating unit is specifically configured to: When the IP check of the first downlink data fails, the terminal device generates the indication information.

38. The terminal device according to claim 36, wherein The transceiver unit is further configured to: Before generating the indication information, receive second downlink data sent by the second network device on the DRB; Check the integrity protection IP of the second downlink data through a Packet Data Convergence Protocol (PDCP) layer of the terminal device; Wherein, the generating unit is specifically configured to: When the IP check of the second downlink data fails, generate the indication information.

39. The terminal device according to any one of claims 36 to 38, wherein The transceiver unit is specifically configured to: Send an RRC signaling to the first network device or the second network device, where the RRC signaling includes the indication information.

40. The terminal device according to any one of claims 36 to 38, wherein The transceiver unit is specifically configured to: Send a Media Access Control (MAC) control element (CE) to the first network device or the second network device, where the MAC CE includes the indication information.

41. The terminal device according to any one of claims 36 to 38, characterized in that, The transceiver unit is specifically configured to: Send a Packet Data Convergence Protocol (PDCP) status report to the first network device or the second network device, where the PDCP status report includes the indication information.

42. The terminal device according to any one of claims 36 to 38, characterized in that, The transceiver unit is further configured to: Receive an RRC connection reconfiguration message sent by the second network device, where the RRC connection reconfiguration message includes an updated key.

Citation Information

Patent Citations

  • Data processing method and system in relay node system

    CN102142942A