Key reuse method and device

By using key reuse indication information and security context information in device-to-device communication and direct vehicle network communication to directly establish a direct link, the problem of excessive signaling interaction during key reuse is solved, and resources are saved and communication efficiency is improved.

CN114007205BActive Publication Date: 2025-09-05HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202010738272.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-07-28
Publication Date
2025-09-05
Estimated Expiration
2040-07-28

AI Technical Summary

Technical Problem

In device-to-device communication and IoV direct communication, the key reuse process between UEs in the existing technology leads to redundant signaling interactions, consuming air interface resources and UE computing resources.

Method used

By establishing key reuse indication information between UEs and using the maintained security context information to directly establish a direct link, the signaling interaction of mutual authentication and key negotiation between user equipments is reduced.

Benefits of technology

The consumption of air interface resources and user equipment computing resources is reduced, and communication efficiency is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114007205B_ABST
    Figure CN114007205B_ABST
Patent Text Reader

Abstract

The embodiment of the present application provides a key reuse method and device for realizing key reuse, reducing the signaling interaction of mutual authentication and key negotiation between user devices, thereby reducing the consumption of air interface resources and user device computing resources. The technical solution provided by the embodiment of the present application is applied to a direct communication system, which includes at least two UEs. In this embodiment, a first UE and a second UE are used as counterparts for explanation: the first UE and the second UE both obtain first key reuse indication information in the process of establishing a first direct link, and obtain corresponding keys and other security context information related to the first direct link according to the first key reuse indication information; finally, the first UE and the second UE establish the first direct link according to the key and other security context information related to the first direct link.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communications, and in particular to a key reuse method and device. Background Art

[0002] In traditional cellular network communications, any instruction sent between user equipment (UE) must first be processed and forwarded by the base station, and different UEs cannot communicate directly with each other. However, to meet the needs of device-to-device (D2D) and vehicle-to-everything (V2X) direct communication, D2D technology provides a PC5 interface based on direct communication between UEs. The PC5 interface supports direct links between UEs, meaning that data and signaling transmission between UEs no longer needs to be relayed by the base station.

[0003] Currently, in PC5 direct unicast communication, the UEs at both ends are divided into the initial UE (initiating UE) and the peer UE (peer UE) according to who initiates the connection establishment. The keys held by the UEs at both ends are divided into four layers. When the UEs establish a PC5 unicast connection, they use long-term authentication information (long term credentials) to generate the K keys at both ends. NRP , where NRP is the new radio PC5 interface (new radio PC5, NRP), and then the UEs at both ends use the parameters negotiated in the security parameter negotiation process to pass K NRP Generate K NRP-sess (Use K NRP ID and K NRP-sess ID to identify), and then UE will use K NRP-sess Generate the corresponding encryption key NRPEK and security key NRPIK.

[0004] Based on the above method, if multiple PC5 unicast connections between two UEs use different keys, the inter-node authentication and key establishment process needs to be repeated multiple times when establishing the connection. This process usually involves multiple signaling interactions between UEs, resulting in redundant signaling interactions and consuming air interface resources and UE computing resources. Summary of the Invention

[0005] The embodiments of the present application provide a key reuse method and apparatus for implementing key reuse, reducing signaling interactions for mutual authentication and key negotiation between user devices, thereby reducing the consumption of air interface resources and user device computing resources.

[0006] In the first aspect, an embodiment of the present application provides a key reuse method, which is applied to a direct communication system, which includes at least two UEs. In this embodiment, a first UE and a second UE are used as counterparts for explanation: the first UE and the second UE both obtain first key reuse indication information during the process of establishing a first direct link, and obtain the corresponding key and other security context information related to the first direct link based on the first key reuse indication information; finally, the first UE and the second UE establish the first direct link based on the key and the security context information.

[0007] In this embodiment, during the process of establishing a direct link, the first UE and the second UE directly establish a direct link based on reusing the maintained security context information, thereby reducing the signaling interaction of mutual authentication and key negotiation between user devices, thereby reducing the consumption of air interface resources and user device computing resources.

[0008] Optionally, the first UE and the second UE may maintain a reusable key and security context information after establishing the first direct link. The specific process is as follows:

[0009] The first UE obtains policy information for indicating the security relevance between services; then the first UE establishes an initial direct link with the second UE, and negotiates with the second UE to determine the first key reuse indication information based on the policy information; finally, the first UE maintains the first key reuse indication information and the reusable security context information indicated by the first key reuse indication information. The policy information for indicating the security relevance between services specifically refers to whether different services have the same security requirements. If the security requirements between the two services are the same, the policy information for indicating the security relevance between the services is the reusable security context information between the two services. Specifically, the same security requirements include the same integrity protection requirements and the same confidentiality protection requirements.

[0010] In the embodiment of the present application, the first UE and the second UE are each other's peer devices. When the first UE acts as an initiator and the second UE acts as a receiver, the specific operation of the first UE and the second UE establishing the first direct link according to the first key reuse indication information is as follows:

[0011] The first UE broadcasts a connection request; the first UE receives a connection reply message sent by the second UE, the connection reply message carries the key reuse indication information corresponding to the second UE, and the connection reply message is sent by the second UE after initiating the inter-node authentication and key establishment process; after the first UE verifies that the key reuse indication information corresponding to the second UE is correct, the first UE determines the key reuse indication information corresponding to the first UE based on the key reuse indication information corresponding to the second UE, and the first key reuse indication information includes the key reuse indication information corresponding to the second UE and the key reuse indication information corresponding to the first UE; the first UE sends the key reuse indication information corresponding to the first UE to the second UE; the first UE receives a second key reuse request sent by the second UE, and the second key reuse request is protected by the second UE using the reusable security context information, and the reusable security context is determined by the second UE based on the reusable security context information indicated by the key reuse indication information corresponding to the second UE after verifying that the key reuse indication information corresponding to the first UE is correct. Specifically, the second UE uses the reusable security context information including an integrity protection key and / or a confidentiality protection key, and using the reusable security context information for protection includes using an integrity protection key for integrity protection and / or using a confidentiality protection key for confidentiality protection; the first UE sends a second key reuse confirmation to the second UE; the first UE receives the second connection response sent by the second UE, and establishes the first direct link with the second UE according to the security context information indicated by the first key reuse indication information.

[0012] When the first UE, as the initiator, creates the first key reuse indication information with the second UE, the specific operations are as follows:

[0013] In one possible implementation, when the first UE determines that there is no existing connection with a reusable key, the first UE sends a first direct link request, and the first direct link request does not carry key reuse indication information; the first UE and the second UE complete the inter-node authentication and key establishment process, and the inter-node authentication and key establishment process is initiated by the second UE when it determines that there is no key reuse request based on the fact that the first direct link request does not carry key reuse indication information or there is no reusable key; the first UE receives the fifth key reuse request sent by the second UE and the shared information selected by the second UE; the first UE sends the fifth key reuse confirmation and the shared information selected by the first UE to the second UE, so that the second UE generates the first key reuse indication information based on the shared information selected by the second UE and the shared information selected by the first UE; the first UE generates the first key reuse indication information based on the shared information selected by the second UE and the shared information selected by the first UE.

[0014] In another possible implementation, when the first UE determines that there is no existing connection with a reusable key, the first UE sends a first direct link request; the first UE receives an inter-node authentication and key establishment request sent by the second UE, and the inter-node authentication and key establishment request does not carry the key reuse indication information corresponding to the second UE, and the inter-node authentication and key establishment request is initiated by the second UE when it determines that there is no connection with a reusable key; when the first UE determines that there is no key reuse request based on the absence of the key reuse indication information corresponding to the second UE in the inter-node authentication and key establishment request or the connection without a reusable key, the first UE completes the inter-node authentication and key establishment process with the second UE; the first UE receives the sixth key reuse request sent by the second UE and the shared information selected by the second UE; the first UE sends a sixth key reuse confirmation and the shared information selected by the first UE to the second UE, so that the second UE generates the first key reuse indication information based on the shared information selected by the second UE and the shared information selected by the first UE; the first UE generates the first key reuse indication information based on the shared information selected by the second UE and the shared information selected by the first UE.

[0015] In another possible implementation, when the first UE determines that there is no existing connection with a reusable key, the first UE sends an initial direct link request; the first UE receives an inter-node authentication and key establishment request sent by the second UE, the inter-node authentication and key establishment request carrying a seventh key reuse request and not carrying key reuse indication information corresponding to the second UE, and the inter-node authentication and key establishment request is triggered when the second UE determines that there is no connection with a reusable key and needs to send a key reuse request; when the first UE determines that there is no key reuse request based on the fact that the inter-node authentication and key establishment request does not carry the key reuse indication information corresponding to the second UE or that there is no reusable key, the first UE completes the inter-node authentication and key establishment process with the second UE and sends a seventh key reuse confirmation to the second UE; the first UE receives the shared information selected by the second UE sent by the second UE; the first UE sends the shared information selected by the first UE to the second UE, so that the second UE generates the first key reuse indication information based on the shared information selected by the second UE and the shared information selected by the first UE; the first UE generates the first key reuse indication information based on the shared information selected by the second UE and the shared information selected by the first UE.

[0016] If the first UE serves as a receiver and the second UE serves as an initiator, specific operations for the first UE and the second UE to establish the first direct link according to the first key reuse indication information are as follows:

[0017] In one possible implementation, the first UE receives a connection request, and the connection request carries key reuse indication information corresponding to the second UE; after the first UE verifies that the key reuse indication information corresponding to the second UE is correct, the first UE determines the key reuse indication information corresponding to the first UE based on the key reuse indication information corresponding to the second UE; the first UE sends a third key reuse request to the second UE, and the third key reuse request carries the key reuse indication information corresponding to the first UE, and the first key reuse indication information includes the key reuse indication information corresponding to the second UE and the key reuse indication information corresponding to the first UE; the first UE receives a third key reuse confirmation sent by the second UE, and the third key reuse confirmation is sent by the second UE after verifying that the key reuse indication information corresponding to the first UE is correct; the first UE sends a first direct link response to the second UE, and establishes the first direct link with the second UE based on the security context information indicated by the first key reuse indication information. In this embodiment, the second UE verifies whether the key reuse indication information corresponding to the first UE is correct, specifically including: the second UE verifies whether it stores key reuse indication information that matches the key reuse indication information corresponding to the first UE; or, the second UE verifies whether the key reuse indication information corresponding to the first UE is valid (that is, the "correct" is used to indicate whether the second UE stores the associated key reuse indication information or whether the key reuse indication information is valid). Specifically, the key reuse indication information can be Token information, which is bound to the user identity, or can be bound according to the key reuse request or key reuse confirmation. The validity of the Token can be verified on the UE side through a security algorithm, which is to verify that the key reuse indication information is correct. The key reuse indication information can also be an indicator. The UE only compares it with the internally stored indicator to verify whether the key reuse indication information is valid. The key reuse indication information can also be K NRP ID is used to identify reusable security contexts between UEs, and is not limited here.

[0018] In another possible implementation, the first UE receives a connection request; the first UE initiates inter-node authentication and key establishment to the second UE and sends a connection reply message, the connection reply message carrying the key reuse indication information corresponding to the first UE, so that the second UE determines the key reuse indication information corresponding to the second UE according to the key reuse indication information corresponding to the first UE after verifying that the key reuse indication information corresponding to the first UE is correct, and the first key reuse indication information includes the key reuse indication information corresponding to the second UE and the key reuse indication information corresponding to the first UE; the first UE receives a fourth key reuse request sent by the second UE, and the fourth key reuse request carries the key reuse indication information corresponding to the second UE; after the first UE verifies that the key reuse indication information corresponding to the second UE is correct, the first UE determines the key reuse indication information corresponding to the first UE and the reusable security context according to the key reuse indication information corresponding to the second UE; the first UE sends a fourth key reuse confirmation message encrypted by the key to the second UE; the first UE sends a third connection response to the second UE, and establishes the first direct link with the second UE according to the security context information indicated by the first key reuse indication information.

[0019] When the first UE, as the initiator, creates the first key reuse indication information with the second UE, the specific operations are as follows:

[0020] In one possible implementation, the first UE receives a first direct link request sent by the second UE, where the first direct link request is sent by the second UE when determining that there is no existing connection with a reusable key, and the first direct link request carries a first identifier, where the first identifier is used to indicate no key reuse;

[0021] The first UE initiates an inter-node authentication and key establishment request to the second UE when determining that there is no key reuse request based on the first identifier or the connection without a reusable key; the first UE sends an eighth key reuse request and the shared information selected by the first UE to the second UE, so that the second UE generates the first key reuse indication information based on the shared information selected by the second UE and the shared information selected by the first UE; the first UE receives the eighth key reuse confirmation sent by the second UE and the shared information selected by the second UE; the first UE generates the first key reuse indication information based on the shared information selected by the second UE and the shared information selected by the first UE.

[0022] In another possible implementation, the first UE receives a first direct link request sent by the second UE, and the first direct link request is sent by the second UE when it determines that there is no connection with an existing reusable key; when the first UE determines that there is no connection with a reusable key, the first UE sends a node-to-node authentication and key establishment request to the second UE, and the node-to-node authentication and key establishment request carries a second identifier, and the second identifier is used to indicate that there is no key reuse; the first UE sends a ninth key reuse request and the shared information selected by the first UE to the second UE, so that the second UE generates the first key reuse indication information according to the shared information selected by the second UE and the shared information selected by the first UE; the first UE receives the ninth key reuse confirmation sent by the second UE and the shared information selected by the second UE, and the first UE generates the first key reuse indication information according to the shared information selected by the second UE and the shared information selected by the first UE.

[0023] In another possible implementation, the first UE receives a first direct link request sent by the second UE, where the first direct link request is sent by the second UE when it determines that there is no connection with an existing reusable key; when the first UE determines that there is no connection with a reusable key, the first UE sends a node-to-node authentication and key establishment request to the second UE, where the node-to-node authentication and key establishment request carries a second identifier and a tenth key reuse request, where the second identifier is used to indicate no key reuse; the first UE receives a tenth key reuse confirmation sent by the second UE, where the tenth key reuse confirmation is sent by the second UE when it determines that there is no key reuse request based on the second identifier or the connection without a reusable key; the first UE sends the shared information selected by the first UE to the second UE, so that the second UE generates the first key reuse indication information based on the shared information selected by the second UE and the shared information selected by the first UE; the first UE receives the shared information selected by the second UE sent by the second UE; the first UE generates the first key reuse indication information based on the shared information selected by the second UE and the shared information selected by the first UE.

[0024] The above describes scenarios in which various schemes are used between the first UE and the second UE to implement establishment, maintenance, and application of key reuse indication information, so that the direct connection between the first UE and the second UE is flexible and diversified and can adapt to various scenarios.

[0025] Optionally, in an embodiment of the present application, the policy information is generated by a policy control function PCF and sent to the first UE or the second UE by an access and mobility management function AMF; the security correlation is used to indicate the association between the security requirement level corresponding to each service type and the algorithm and key reuse corresponding to each service type.

[0026] Among them, the association relationship includes: if the security requirement levels corresponding to the various service types of the first UE and the second UE do not conflict, and the algorithms corresponding to the various service types do not conflict, then the first UE and the second UE can reuse keys in unicast direct connection; if the security requirement levels corresponding to the various service types of the first UE and the second UE or at least one of the algorithms corresponding to the various service types conflict, then the first UE and the second UE cannot reuse keys in unicast direct connection.

[0027] Optionally, after the first UE and the second UE establish the first direct link, the first UE updates the first key reuse indication information to obtain second key reuse indication information; the first UE maintains the second key reuse indication information and the key and security context information indicated by the second key reuse indication information. It can be understood that the second UE updates the first key reuse indication information to obtain the second key reuse indication information; the first UE maintains the second key reuse indication information and the key and security context information indicated by the second key reuse indication information.

[0028] Optionally, the first UE updates the first key reuse indication information to obtain the second key reuse indication information as follows: the first UE obtains the first shared information selected by itself and the second shared information selected by the second UE, the second shared information is carried in the key reuse request sent by the second UE, and the first shared information and the second shared information are generated after the first direct link is established; the first UE generates the second key reuse indication information based on the first shared information and the second shared information.

[0029] Optionally, when the connections between the first UE and the second UE are released, the first UE and the second UE delete the key reuse indication information and the security context information corresponding to the key reuse indication information, and the key reuse indication information includes the first key reuse indication information and the second key reuse indication information.

[0030] In a second aspect, an embodiment of the present application provides a terminal device having a function of implementing the first UE behavior described in the first aspect. The function may be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-mentioned function.

[0031] In one possible implementation, the terminal device includes a unit or module for performing each step of the first aspect above. For example, the terminal device includes: an acquisition module for acquiring first key reuse indication information, where the first key reuse indication information is used to indicate reusable security context information;

[0032] A processing module is used to establish a first direct link with the second UE according to the reusable key and the security context information when the first UE and the second UE verify that the first key reuse indication information is correct.

[0033] Optionally, a storage module is also included for storing necessary program instructions and data of the terminal device.

[0034] In one possible implementation, the terminal device includes: a processor and a transceiver, wherein the processor is configured to support a first UE in executing the corresponding functions of the method provided in the first aspect. The transceiver is configured to instruct communication between the first UE and a second UE and to send information or instructions involved in the method to the second UE. Optionally, the device may further include a memory, coupled to the processor, that stores program instructions and data necessary for the first UE.

[0035] In one possible implementation, when the terminal device is a chip within the first UE, the chip includes: a processing module and a transceiver module, the processing module may be, for example, a processor, and the processor is configured to establish a first direct link with the second UE based on the reusable key and the security context information when the first UE and the second UE verify that the first key reuse indication information is correct. The transceiver module may be, for example, an input / output interface, a pin, or a circuit on the chip, which transmits the relevant information instructions generated by the processor to other chips or modules coupled to the chip. The processing module may execute computer-executable instructions stored in the storage unit to support the first UE in executing the method provided in the first aspect above. Optionally, the storage unit may be a storage unit within the chip, such as a register, a cache, etc., or a storage unit located outside the chip, such as a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM), etc.

[0036] In one possible implementation, the device includes a processor, a baseband circuit, a radio frequency circuit, and an antenna. The processor controls the functions of each circuit component, and the baseband circuit generates a data packet containing signaling information. After analog-to-analog conversion, filtering, amplification, and up-conversion are performed by the radio frequency circuit, the data packet is transmitted via the antenna to the second UE. Optionally, the device also includes a memory that stores program instructions and data necessary for the first UE.

[0037] Among them, the processor mentioned in any of the above places can be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits used to control the execution of programs of the above-mentioned key reuse methods.

[0038] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer storage medium stores computer instructions, and the computer instructions are used to execute the method described in any possible implementation method of the first aspect above.

[0039] In a fourth aspect, an embodiment of the present application provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute the method described in any one of the above aspects.

[0040] In a fifth aspect, the present application provides a chip system, which includes a processor for supporting a terminal device to implement the functions involved in the above aspects, such as generating or processing the data and / or information involved in the above methods. In one possible design, the chip system also includes a memory, which is used to store the necessary program instructions and data of the terminal device to implement the functions of any of the above aspects. The chip system can be composed of a chip, or it can include a chip and other discrete devices.

[0041] In a sixth aspect, an embodiment of the present application provides a communication system, which includes the first UE and the second UE described in the above aspects. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 This is an exemplary structural diagram of a user equipment in an embodiment of the present application;

[0043] Figure 2 This is an exemplary scenario diagram of direct link communication between user equipments in an embodiment of the present application;

[0044] Figure 3 This is an example diagram of an embodiment of the key reuse method in the embodiment of the present application;

[0045] Figure 4 This is a schematic diagram of a first generation process of key reuse indication information in an embodiment of the present application;

[0046] Figure 5 This is another schematic diagram of the first generation process of key reuse indication information in an embodiment of the present application;

[0047] Figure 6 This is another schematic diagram of the first generation process of key reuse indication information in an embodiment of the present application;

[0048] Figure 7 This is a schematic diagram of a reuse acquisition process of key reuse indication information in an embodiment of the present application;

[0049] Figure 8 This is another schematic diagram of a reuse acquisition process of key reuse indication information in an embodiment of the present application;

[0050] Figure 9 This is a schematic diagram of a process for establishing a first direct link in an embodiment of the present application;

[0051] Figure 10 This is another schematic diagram of the process of establishing the first direct link in an embodiment of the present application;

[0052] Figure 11 A schematic diagram of an update process of key reuse indication information in an embodiment of the present application;

[0053] Figure 12 This is another schematic diagram of the update process of the key reuse indication information in an embodiment of the present application;

[0054] Figure 13 This is another example diagram of a key reuse method in an embodiment of the present application;

[0055] Figure 14 This is an exemplary schematic diagram of a user terminal in an embodiment of the present application;

[0056] Figure 15 This is a schematic diagram of another embodiment of a user terminal in an embodiment of the present application. DETAILED DESCRIPTION

[0057] In order to make the purpose, technical solutions and advantages of this application more clearly understood, the following describes the embodiments of this application in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this application, rather than all the embodiments. It is known to those skilled in the art that with the emergence of new application scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0058] The terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate so that the embodiments described herein can be implemented in a sequence other than that illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or modules is not necessarily limited to those steps or modules clearly listed, but may include other steps or modules that are not clearly listed or that are inherent to these processes, methods, products or devices. The naming or numbering of steps in this application does not mean that the steps in the method flow must be executed in the time / logical sequence indicated by the naming or numbering. The process steps that have been named or numbered can be changed in the execution order according to the technical purpose to be achieved, as long as the same or similar technical effects can be achieved. The division of units in this application is a logical division. In actual application, there may be other division methods. For example, multiple units can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between each other shown or discussed can be through some interfaces, and the indirect coupling or communication connection between units can be electrical or other similar forms, which are not limited in this application. Moreover, the units or sub-units described as separate components may or may not be physically separated, may or may not be physical units, or may be distributed into multiple circuit units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this application.

[0059] In the embodiment of the present application, the first UE and the second UE are two different electronic devices with the same function. The electronic device 100 in the embodiment of the present application is introduced below. Figure 1 A schematic structural diagram of the electronic device 100 is shown.

[0060] The electronic device 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, an air pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.

[0061] It should be understood that the structures illustrated in the embodiments of the present application do not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0062] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors.

[0063] The controller can generate operation control signals according to the instruction operation code and timing signal to complete the control of instruction fetching and execution.

[0064] Processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in processor 110 is a cache memory. This memory can store instructions or data that have just been used or are being recycled by processor 110. If processor 110 needs to use the same instruction or data again, it can directly access the memory. This avoids duplicate accesses, reduces processor 110 latency, and thus improves system efficiency.

[0065] In some embodiments, the processor 110 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuits sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface.

[0066] In an embodiment of the present application, the processor 110 may be configured to determine whether the electronic device 100 determines that the first UE stores the reusable key information and security context information. In some embodiments, the processor 110 may also be configured to, after determining that the reusable key information and security context information are stored, establish a first direct link with the second UE using the key information and security context information.

[0067] The I2C interface is a bidirectional synchronous serial bus that includes a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 110 may include multiple I2C bus lines. The processor 110 may be coupled to the touch sensor 180K, the charger, the flash, the camera 193, and the like via different I2C bus interfaces. For example, the processor 110 may be coupled to the touch sensor 180K via the I2C interface, enabling communication between the processor 110 and the touch sensor 180K via the I2C bus interface, thereby implementing the touch function of the electronic device 100.

[0068] The I2S interface can be used for audio communication. In some embodiments, the processor 110 can include multiple I2S buses. The processor 110 can be coupled to the audio module 170 via the I2S bus to enable communication between the processor 110 and the audio module 170. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the I2S interface, enabling the function of answering calls through a Bluetooth headset.

[0069] The PCM interface can also be used for audio communication, sampling, quantizing, and encoding analog signals. In some embodiments, the audio module 170 and the wireless communication module 160 can be coupled via a PCM bus interface. In some embodiments, the audio module 170 can also transmit audio signals to the wireless communication module 160 via the PCM interface, enabling the function of answering calls via a Bluetooth headset. Both the I2S interface and the PCM interface can be used for audio communication.

[0070] The UART interface is a universal serial data bus used for asynchronous communication. This bus can be a bidirectional communication bus. It converts the data to be transmitted between serial communication and parallel communication. In some embodiments, the UART interface is typically used to connect the processor 110 and the wireless communication module 160. For example, the processor 110 communicates with the Bluetooth module in the wireless communication module 160 via the UART interface to implement Bluetooth functionality. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the UART interface, enabling the function of playing music through Bluetooth headphones.

[0071] The MIPI interface can be used to connect the processor 110 to peripheral devices such as the display 194 and the camera 193. MIPI interfaces include the camera serial interface (CSI) and the display serial interface (DSI). In some embodiments, the processor 110 and the camera 193 communicate via the CSI interface to implement the camera function of the electronic device 100. The processor 110 and the display 194 communicate via the DSI interface to implement the display function of the electronic device 100.

[0072] The GPIO interface can be configured via software. The GPIO interface can be configured as either a control signal or a data signal. In some embodiments, the GPIO interface can be used to connect the processor 110 to the camera 193, display 194, wireless communication module 160, audio module 170, sensor module 180, etc. The GPIO interface can also be configured as an I2C interface, an I2S interface, a UART interface, a MIPI interface, etc.

[0073] The USB interface 130 is an interface that complies with USB standards and may be a Mini USB interface, a Micro USB interface, a USB Type-C interface, or the like. The USB interface 130 can be used to connect a charger to charge the electronic device 100, or to transfer data between the electronic device 100 and peripheral devices. It can also be used to connect headphones to play audio. This interface can also be used to connect other electronic devices, such as augmented reality devices.

[0074] It is understood that the interface connection relationship between the modules illustrated in the embodiments of the present application is merely an illustrative illustration and does not constitute a structural limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may also adopt different interface connection methods from the above embodiments, or a combination of multiple interface connection methods.

[0075] The charging management module 140 is configured to receive charging input from a charger. The charger can be either a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 can receive charging input from the wired charger via the USB interface 130. In some wireless charging embodiments, the charging management module 140 can receive wireless charging input via the wireless charging coil of the electronic device 100. While charging the battery 142, the charging management module 140 can also provide power to the electronic device via the power management module 141.

[0076] The power management module 141 is used to connect the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140, and provides power to the processor 110, the internal memory 121, the display 194, the camera 193, and the wireless communication module 160. The power management module 141 can also be used to monitor parameters such as battery capacity, battery cycle count, and battery health status (leakage, impedance). In some other embodiments, the power management module 141 can also be set in the processor 110. In other embodiments, the power management module 141 and the charging management module 140 can also be set in the same device.

[0077] The wireless communication function of the electronic device 100 can be implemented through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor and the baseband processor.

[0078] Antenna 1 and Antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in conjunction with a tuning switch.

[0079] The mobile communication module 150 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied to the electronic device 100. The mobile communication module 150 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves from the antenna 1, and filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the processor 110. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the same device as at least some of the modules of the processor 110.

[0080] The modem processor may include a modulator and a demodulator. The modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is passed to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 170A, the receiver 170B, etc.) or displays an image or video through the display screen 194. In some embodiments, the modem processor may be an independent device. In other embodiments, the modem processor may be independent of the processor 110 and be set in the same device as the mobile communication module 150 or other functional modules.

[0081] The wireless communication module 160 can provide wireless communication solutions including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) network), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc. applied to the electronic device 100. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, frequency modulates and filters the electromagnetic wave signal, and sends the processed signal to the processor 110. The wireless communication module 160 can also receive the signal to be sent from the processor 110, frequency modulate it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.

[0082] In some embodiments, the antenna 1 of the electronic device 100 is coupled to the mobile communication module 150, and the antenna 2 is coupled to the wireless communication module 160, so that the electronic device 100 can communicate with a network and other devices through wireless communication technologies. The wireless communication technologies may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology. The GNSS may include a global positioning system (GPS), a global navigation satellite system (GLONASS), a Beidou navigation satellite system (BDS), a quasi-zenith satellite system (QZSS) and / or a satellite based augmentation system (SBAS).

[0083] Electronic device 100 implements display functionality through a GPU, display screen 194, and an application processor. A GPU is a microprocessor for image processing that connects display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. Processor 110 may include one or more GPUs that execute program instructions to generate or modify display information.

[0084] Display screen 194 is used to display images, videos, etc. Display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a MiniLED, a MicroLED, a Micro-oLed, or a quantum dot light-emitting diode (QLED). In some embodiments, electronic device 100 may include one or N display screens 194, where N is a positive integer greater than one.

[0085] The electronic device 100 can implement a shooting function through an ISP, a camera 193, a video codec, a GPU, a display screen 194, and an application processor.

[0086] The ISP processes data fed back by camera 193. For example, when taking a photo, the shutter is opened, and light is transmitted through the lens to the camera's photosensitive element. The light signal is converted into an electrical signal, which is then passed to the ISP for processing and converted into a visible image. The ISP can also perform algorithmic optimization on image noise, brightness, and skin tone. It can also optimize parameters such as exposure and color temperature of the captured scene. In some embodiments, the ISP can be located within camera 193.

[0087] The camera 193 is used to capture still images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, and then passes the electrical signal to the ISP for conversion into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV or other format. In some embodiments, the electronic device 100 may include 1 or N cameras 193, where N is a positive integer greater than 1.

[0088] The digital signal processor is used to process digital signals. In addition to processing digital image signals, it can also process other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy.

[0089] Video codecs are used to compress or decompress digital video. Electronic device 100 may support one or more video codecs. This allows electronic device 100 to play or record videos in various encoding formats, such as Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, and MPEG4.

[0090] The NPU is a neural network (NN) computing processor. Drawing on the structure of biological neural networks, such as the transmission patterns between neurons in the human brain, it rapidly processes input information and can continuously self-learn. The NPU can enable intelligent cognitive applications in electronic device 100, such as image recognition, face recognition, speech recognition, and text comprehension.

[0091] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 via the external memory interface 120 to implement data storage functions. For example, files such as music and videos can be stored on the external memory card.

[0092] The internal memory 121 can be used to store computer executable program codes, which include instructions. The internal memory 121 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc. The data storage area may store data created during the use of the electronic device 100 (such as audio data, a phone book, etc.), etc. In addition, the internal memory 121 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc. The processor 110 executes various functional applications and data processing of the electronic device 100 by running instructions stored in the internal memory 121 and / or instructions stored in a memory provided in the processor.

[0093] The electronic device 100 can implement audio functions such as music playback and recording through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the headphone jack 170D, and the application processor.

[0094] The audio module 170 is used to convert digital audio information into analog audio signal output, and is also used to convert analog audio input into digital audio signals. The audio module 170 can also be used to encode and decode audio signals. In some embodiments, the audio module 170 can be provided in the processor 110, or some functional modules of the audio module 170 can be provided in the processor 110.

[0095] The speaker 170A, also called a "speaker", is used to convert audio electrical signals into sound signals. The electronic device 100 can listen to music or listen to hands-free calls through the speaker 170A.

[0096] The receiver 170B, also called a "handset", is used to convert audio electrical signals into sound signals. When the electronic device 100 receives a call or a voice message, the user can place the receiver 170B close to the ear to hear the voice.

[0097] Microphone 170C, also known as "microphone" or "microphone", is used to convert sound signals into electrical signals. When making a call or sending a voice message, the user can speak by putting their mouth close to the microphone 170C to input the sound signal into the microphone 170C. The electronic device 100 can be provided with at least one microphone 170C. In other embodiments, the electronic device 100 can be provided with two microphones 170C, which can not only collect sound signals but also realize noise reduction function. In other embodiments, the electronic device 100 can also be provided with three, four or more microphones 170C to collect sound signals, reduce noise, identify the source of sound, realize directional recording function, etc.

[0098] The headphone jack 170D is used to connect a wired headphone and can be the USB interface 130 or a 3.5mm open mobile terminal platform (OMTP) standard interface or a cellular telecommunications industry association of the USA (CTIA) standard interface.

[0099] Pressure sensor 180A is used to sense pressure signals and convert them into electrical signals. In some embodiments, pressure sensor 180A can be located on display screen 194. There are many types of pressure sensors 180A, such as resistive, inductive, and capacitive. A capacitive pressure sensor can include at least two parallel plates made of conductive material. When force acts on pressure sensor 180A, the capacitance between the electrodes changes. Electronic device 100 determines the intensity of the pressure based on this change in capacitance. When a touch operation is applied to display screen 194, electronic device 100 detects the touch intensity based on pressure sensor 180A. Electronic device 100 can also calculate the touch location based on the detection signal from pressure sensor 180A. In some embodiments, touch operations applied to the same touch location but with different touch intensities can correspond to different operation instructions. For example, when a touch operation with an intensity less than a first pressure threshold is applied to a short message application icon, a command to view short messages is executed. When a touch operation with an intensity greater than or equal to the first pressure threshold is applied to a short message application icon, a command to create a new short message is executed.

[0100] The gyroscope sensor 180B can be used to determine the motion posture of the electronic device 100. In some embodiments, the angular velocity of the electronic device 100 around three axes (i.e., x, y, and z axes) can be determined by the gyroscope sensor 180B. The gyroscope sensor 180B can be used for anti-shake shooting. For example, when the shutter is pressed, the gyroscope sensor 180B detects the angle of the electronic device 100 shaking, calculates the distance that the lens module needs to compensate based on the angle, and allows the lens to offset the shaking of the electronic device 100 through reverse movement to achieve anti-shake. The gyroscope sensor 180B can also be used for navigation and somatosensory game scenes.

[0101] The air pressure sensor 180C is used to measure air pressure. In some embodiments, the electronic device 100 calculates the altitude using the air pressure value measured by the air pressure sensor 180C to assist in positioning and navigation.

[0102] The magnetic sensor 180D includes a Hall sensor. The electronic device 100 can use the magnetic sensor 180D to detect the opening and closing of the flip case. In some embodiments, when the electronic device 100 is a flip phone, the electronic device 100 can detect the opening and closing of the flip cover based on the magnetic sensor 180D. Based on the detected opening and closing status of the case or flip cover, features such as automatic unlocking of the flip cover can be configured.

[0103] Accelerometer 180E can detect the magnitude of acceleration of electronic device 100 in all directions (generally three axes). It can also detect the magnitude and direction of gravity when electronic device 100 is stationary. It can also be used to identify the electronic device's posture, enabling applications such as switching between landscape and portrait modes and pedometers.

[0104] The distance sensor 180F is used to measure distance. The electronic device 100 can measure distance using infrared or laser. In some embodiments, when shooting a scene, the electronic device 100 can use the distance sensor 180F to measure distance to achieve fast focusing.

[0105] The proximity light sensor 180G may include, for example, a light emitting diode (LED) and a light detector, such as a photodiode. The light emitting diode may be an infrared light emitting diode. The electronic device 100 emits infrared light outward through the light emitting diode. The electronic device 100 uses a photodiode to detect infrared reflected light from nearby objects. When sufficient reflected light is detected, it can be determined that there is an object near the electronic device 100. When insufficient reflected light is detected, the electronic device 100 can determine that there is no object near the electronic device 100. The electronic device 100 can use the proximity light sensor 180G to detect that the user is holding the electronic device 100 close to the ear to talk, so as to automatically turn off the screen to save power. The proximity light sensor 180G can also be used in leather case mode and pocket mode to automatically unlock and lock the screen.

[0106] Ambient light sensor 180L is used to sense ambient light brightness. Electronic device 100 can adaptively adjust the brightness of display screen 194 based on the perceived ambient light. Ambient light sensor 180L can also be used to automatically adjust white balance when taking photos. Ambient light sensor 180L can also work with proximity light sensor 180G to detect whether electronic device 100 is in a pocket to prevent accidental touches.

[0107] The fingerprint sensor 180H is used to collect fingerprints. The electronic device 100 can use the collected fingerprint characteristics to implement fingerprint unlocking, access application locks, fingerprint photography, fingerprint call answering, etc.

[0108] The temperature sensor 180J is used to detect temperature. In some embodiments, the electronic device 100 uses the temperature detected by the temperature sensor 180J to execute a temperature processing strategy. For example, when the temperature reported by the temperature sensor 180J exceeds a threshold, the electronic device 100 reduces the performance of the processor located near the temperature sensor 180J to reduce power consumption and implement thermal protection. In other embodiments, when the temperature is lower than another threshold, the electronic device 100 heats the battery 142 to prevent the electronic device 100 from shutting down abnormally due to low temperature. In other embodiments, when the temperature is lower than another threshold, the electronic device 100 boosts the output voltage of the battery 142 to prevent abnormal shutdown due to low temperature.

[0109] The touch sensor 180K is also called a "touch panel." The touch sensor 180K can be disposed on the display screen 194. The touch sensor 180K and the display screen 194 form a touch screen, also called a "touch screen." The touch sensor 180K is used to detect touch operations applied thereto or in the vicinity thereof. The touch sensor can transmit the detected touch operations to the application processor to determine the type of touch event. Visual output related to the touch operations can be provided via the display screen 194. In other embodiments, the touch sensor 180K can also be disposed on the surface of the electronic device 100, in a location different from that of the display screen 194.

[0110] The bone conduction sensor 180M can obtain vibration signals. In some embodiments, the bone conduction sensor 180M can obtain vibration signals from the vibrating bones of the human body. The bone conduction sensor 180M can also contact the human pulse to receive blood pressure pulse signals. In some embodiments, the bone conduction sensor 180M can also be set in headphones to form bone conduction headphones. The audio module 170 can parse out voice signals based on the vibration signals of the vibrating bones of the human body obtained by the bone conduction sensor 180M to implement voice functions. The application processor can parse heart rate information based on the blood pressure pulse signals obtained by the bone conduction sensor 180M to implement heart rate detection functions.

[0111] The buttons 190 include a power button, a volume button, and the like. The buttons 190 may be mechanical buttons or touch buttons. The electronic device 100 may receive key inputs and generate key signal inputs related to user settings and function control of the electronic device 100.

[0112] Motor 191 can generate vibration prompts. Motor 191 can be used for incoming call vibration prompts, and can also be used for touch vibration feedback. For example, touch operations acting on different applications (such as taking pictures, audio playback, etc.) can correspond to different vibration feedback effects. For touch operations acting on different areas of the display screen 194, motor 191 can also correspond to different vibration feedback effects. Different application scenarios (for example: time reminders, receiving messages, alarm clocks, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also support customization.

[0113] The indicator 192 may be an indicator light, which may be used to indicate the charging status, power level changes, messages, missed calls, notifications, etc.

[0114] The SIM card interface 195 is used to connect a SIM card. The SIM card can be connected to or disconnected from the electronic device 100 by inserting it into or removing it from the SIM card interface 195. The electronic device 100 can support 1 or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, and the like. Multiple cards can be inserted into the same SIM card interface 195 at the same time. The types of the multiple cards can be the same or different. The SIM card interface 195 can also be compatible with different types of SIM cards. The SIM card interface 195 can also be compatible with external memory cards. The electronic device 100 interacts with the network through the SIM card to implement functions such as calls and data communications. In some embodiments, the electronic device 100 uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the electronic device 100 and cannot be separated from the electronic device 100.

[0115] In the embodiment of the present application, the first UE and the second UE are applied to Figure 2 In the direct link communication scenario shown, the first UE and the second UE can communicate directly through the PC5 interface, that is, the data and signaling transmission between the UEs no longer need to be interrupted by the base station. In direct communication, key authentication is required for two UEs to establish a PC5 unicast connection. If multiple PC5 unicast connections between two UEs use different keys, the inter-node authentication and key negotiation process needs to be repeated multiple times when establishing the connection, and this process usually involves multiple signaling interactions between UEs, resulting in redundant signaling interactions and consuming air interface resources and UE computing resources. In order to solve the above problem, an embodiment of the present application provides the following technical solution: if the first UE and the second UE are opposite ends to each other, the first UE and the second UE both obtain first key reuse indication information during the process of establishing the first direct link, and obtain the corresponding key and security context information related to establishing the first direct link based on the first key reuse indication information; finally, the first UE and the second UE establish the first direct link based on the key and the security context information.

[0116] Please refer to the following for details: Figure 3 As shown, taking the first UE as the initiator as an example, an embodiment of the key reuse method in the embodiment of the present application is described, which specifically includes:

[0117] 301. The first UE obtains policy information, where the policy information is used to indicate an association between a security requirement level corresponding to each service type and an algorithm corresponding to each service type and key reuse.

[0118] The first UE obtains policy information from the core network, wherein the policy information is used to indicate the security-related logic between different service types and whether keys can be reused between server types. The security-related logic is used to indicate the association between the security requirement level corresponding to each service type and the algorithm and key reuse corresponding to each server. Specifically, the association includes: if the security requirement level corresponding to each service type of the first UE and the second UE does not conflict, and the algorithm corresponding to each service type does not conflict, then the first UE and the second UE can reuse keys in a unicast direct connection; if the security requirement level corresponding to each service type of the first UE and the second UE or at least one of the algorithms corresponding to each service type conflicts, then the first UE and the second UE cannot reuse keys in a unicast direct connection. For example, the security level used by the user plane for bearer services is divided into three categories: REQUIRED: security is mandatory; PREFERRED: security can be enabled or not; NOT NEEDED: security is mandatory not enabled. During direct link establishment, if the UE determines that a new service requires security to be disabled, but the service in the established direct link requires security to be enabled, there will be a conflict and keys cannot be reused. Naturally, if both direct links require security to be enabled, or if one end requires security to be enabled and the other end requires security to be enabled, keys can be reused. Alternatively, the security dependency logic obtained by the UE can indicate which algorithms a service requires and which algorithms cannot be used with it. For example, if one service requires the ZUC algorithm and another service requires AES, keys cannot be reused.

[0119] In this embodiment, the policy information can be generated by a policy control function (PCF), then sent to an access and mobility management function (AMF), and finally sent to each UE by the AMF.

[0120] 302. The first UE establishes an initial direct link with the second UE, and negotiates with the second UE to determine the first key reuse indication information according to the policy information. The second UE is a peer user equipment for establishing a direct link with the first UE.

[0121] In this embodiment, according to the difference in signaling interaction between the first UE and the second UE, the following possible implementations can be specifically classified:

[0122] Please refer to the following for details: Figure 4 An exemplary scheme is shown:

[0123] S1. When the first UE determines to establish a direct link (also referred to as a PC5 unicast connection), and the first UE confirms that there is no identifier indicating that the first UE has a direct link in which the key can be reused, the first UE sends a first direct link request, wherein the first direct link request does not carry the key reuse indication information corresponding to the first UE.

[0124] S2. The second UE determines that there is no need to reuse the key or there is no reusable key or there is no existing PC5 connection based on the key reuse indication message corresponding to the first UE in the direct link request, and then the second UE initiates a node mutual authentication and key establishment process to the first UE.

[0125] S3. After the first UE and the second UE complete mutual authentication and key establishment, the second UE determines a key reuse requirement based on an internal decision and sends a key reuse request and shared information B1 selected by the second UE to the first UE. The shared information is used to generate the first key reuse indication information.

[0126] S4. The first UE obtains the key reuse request and the shared information B1 selected by the second UE.

[0127] S5. When the first UE determines a key reuse requirement according to an internal decision, the first UE sends a key reuse confirmation and the shared information A1 selected by the first UE to the second UE.

[0128] S6. The second UE obtains the shared information A1 and the key reuse confirmation selected by the first UE, and replies a direct connection acceptance message to the first UE, thereby confirming that the first direct connection link establishment is completed.

[0129] S7. The first UE calculates the first key reuse indication information by using the shared information A1 and the shared information B1, and the second UE calculates the first key reuse indication information by using the shared information A1 and the shared information B1.

[0130] It is understandable that the key reuse indication information can be a Token information, which is bound to the user identity, or can be bound according to the key reuse request or key reuse confirmation. The UE can verify the validity of the Token through a security algorithm. The key reuse indication information can also be an indicator, and the UE only compares it with the indicator stored internally. The key reuse indication information can also be a K NRP ID, used to identify reusable security contexts between UEs. Specific details are not limited here.

[0131] Please refer to the following for details: Figure 5 Another exemplary scheme is shown:

[0132] S1. When the first UE determines to establish a direct link (also referred to as a PC5 unicast connection), and the first UE confirms that there is no identifier indicating that the first UE has a direct link for which a key can be reused, the first UE sends an initial direct link request.

[0133] S2. The second UE confirms that there is no identification indicating that the second UE has a direct link that can reuse the key, and then the second UE initiates a node mutual authentication and key establishment request to the first UE. The node mutual authentication and key establishment request does not carry the key reuse indication information corresponding to the second UE.

[0134] S3. After the first UE and the second UE complete mutual authentication and key establishment, the second UE determines a key reuse requirement based on an internal decision and sends a key reuse request and shared information B1 selected by the second UE to the first UE. The shared information is used to generate the first key reuse indication information.

[0135] S4. The first UE obtains the key reuse request and the shared information B1 selected by the second UE.

[0136] S5. When the first UE determines a key reuse requirement according to an internal decision, the first UE sends a key reuse confirmation and the shared information A1 selected by the first UE to the second UE.

[0137] S6. The second UE obtains the shared information A1 and the key reuse confirmation selected by the first UE, and replies a direct connection acceptance message to the first UE, thereby confirming that the first direct connection link establishment is completed.

[0138] S7. The first UE calculates the first key reuse indication information using the shared information A1 and the shared information B1, and the second UE calculates the first key reuse indication information using the shared information A1 and the shared information B1. It can be understood that the key reuse indication information can be Token information, which is bound to the user identity, or can be bound according to the key reuse request or key reuse confirmation. The validity of the Token can be verified by a security algorithm on the UE side. The key reuse indication information can also be an indicator, and the UE only compares it with the indicator stored internally. The key reuse indication information can also be K NRP ID, used to identify reusable security contexts between UEs. Specific details are not limited here.

[0139] Please refer to the following for details: Figure 6 Another exemplary scheme is shown:

[0140] S1. When the first UE determines to establish a direct link (also referred to as a PC5 unicast connection), and the first UE confirms that there is no direct link with an identifier indicating that the first UE can reuse a key, the first UE sends an initial direct link request.

[0141] S2. The second UE indicates that there is a direct link for reusing the key based on the confirmation that there is no identification. Then the second UE initiates a node mutual authentication and key establishment request to the first UE. The node mutual authentication and key establishment request carries a key reuse request and does not carry a key reuse indication message corresponding to the second UE.

[0142] S3. After the mutual authentication and key establishment process between the first UE and the second UE nodes are completed, the first UE sends a key reuse confirmation and the shared information A1 selected by the first UE to the second UE.

[0143] S4. The first UE obtains the shared information B1 selected by the second UE.

[0144] S5. The first UE calculates the first key reuse indication information using the shared information A1 and the shared information B1, and the second UE calculates the first key reuse indication information using the shared information A1 and the shared information B1. It is understandable that the key reuse indication information can be Token information, which is bound to the user identity, or can be bound according to the key reuse request or key reuse confirmation. The validity of the Token can be verified by a security algorithm on the UE side. The key reuse indication information can also be an indicator, which is only compared with the indicator stored internally by the UE. The key reuse indication information can also be K NRP ID, used to identify reusable security contexts between UEs. Specific details are not limited here.

[0145] 303. The first UE maintains the first key reuse indication information and the reusable security context information indicated by the first key reuse indication information.

[0146] In this embodiment, the first UE also marks the first direct connection link as a direct connection link with a reusable key.

[0147] At the same time, the second UE also maintains the first key reuse indication information and the reusable security context information indicated by the first key reuse indication information, wherein the reusable security context information can be used when the first UE and the second UE establish a direct link for the second time.

[0148] 304. When the first UE establishes a secondary direct link with the second UE, the first UE obtains first key reuse indication information, where the first key reuse indication information is used to indicate reusable security context information.

[0149] When the first UE initiates a direct link establishment request again, the first UE obtains the first key reuse indication information according to the policy information and the marked existing direct link and bearer service for which keys can be reused, or the first UE receives the first key reuse indication information sent by the second UE.

[0150] For details, please refer to Figure 7 As shown, in this embodiment, the first UE, as an initiator, obtains the first key reuse indication information including:

[0151] S1. The first UE broadcasts a connection request, where the connection request carries key reuse indication information corresponding to the first UE.

[0152] S2. After receiving the key reuse indication information corresponding to the first UE, the second UE verifies whether the key reuse indication information corresponding to the first UE is correct, and determines the key reuse indication information corresponding to the second UE after verifying that the key reuse indication information corresponding to the first UE is correct. In this embodiment, the second UE verifies whether the key reuse indication information corresponding to the first UE is correct, specifically including: the second UE verifies whether it has stored key reuse indication information that matches the key reuse indication information corresponding to the first UE; or, the second UE verifies whether the key reuse indication information corresponding to the first UE is valid (i.e., the "correct" is used to indicate whether the second UE has stored the associated key reuse indication information or whether the key reuse indication information is valid). Specifically, the key reuse indication information can be a token information, which is bound to the user identity, or can be bound according to a key reuse request or a key reuse confirmation. The validity of the token can be verified on the UE side through a security algorithm, that is, the key reuse indication information is verified to be correct. The key reuse indication information can also be an indicator. The UE only compares it with the internally stored indicator to verify whether the key reuse indication information is correct. The key reuse indication information can also be K NRP ID is used to identify reusable security contexts between UEs, and is not limited here.

[0153] S3. The second UE sends a key reuse request to the first UE, where the key reuse request carries key reuse indication information corresponding to the second UE.

[0154] S4. The first UE determines the key reuse indication information corresponding to the second UE and the key reuse indication information corresponding to the first UE as the first key reuse indication information. At the same time, the second UE determines the key reuse indication information corresponding to the second UE and the key reuse indication information corresponding to the first UE as the first key reuse indication information.

[0155] For details, please refer to Figure 8 As shown, in this embodiment, the first UE, as an initiator, obtains the first key reuse indication information including:

[0156] S1. The first UE broadcasts a connection request. At this time, the connection request does not carry key reuse related information.

[0157] S2. The second UE sends a connection reply message to the first UE, where the connection reply message carries key reuse indication information corresponding to the second UE.

[0158] S3. After verifying that the key reuse indication information corresponding to the second UE is correct, the first UE determines the key reuse indication information corresponding to the first UE based on the key reuse indication information corresponding to the second UE, and simultaneously sends the key reuse indication information corresponding to the first UE to the second UE.

[0159] S4. The first UE determines the key reuse indication information corresponding to the second UE and the key reuse indication information corresponding to the first UE as the first key reuse indication information. At the same time, the second UE determines the key reuse indication information corresponding to the second UE and the key reuse indication information corresponding to the first UE as the first key reuse indication information.

[0160] 305. When the first UE and the second UE verify that the first key reuse indication information is correct, the first UE establishes a first direct link with the second UE according to the reusable security context information.

[0161] In this embodiment, after the first UE and the second UE verify that the key reuse indication information of the other end and the local end is correct, the first UE and the second UE can obtain the reusable security context information indicated by the first key reuse indication information to establish the first direct link.

[0162] In this embodiment, according to the difference in signaling interaction between the first UE and the second UE, the following possible implementations can be specifically classified:

[0163] Please refer to the following for details: Figure 9 An exemplary scheme is shown:

[0164] S1. After the first UE verifies that the key reuse indication information corresponding to the second UE is correct, the first UE sends a key reuse confirmation to the second UE.

[0165] S2. The second UE sends a direct link response to the first UE;

[0166] S3. The first UE and the second UE establish the first direct link through reusable security context information.

[0167] Please refer to the following for details: Figure 10 An exemplary scheme is shown:

[0168] S1. The first UE sends key reuse indication information corresponding to the first UE to the second UE.

[0169] S2. The second UE verifies the key reuse indication information corresponding to the first UE. After the verification is correct, the second UE sends a key reuse request to the first UE.

[0170] S3. The first UE sends a key reuse confirmation to the second UE.

[0171] S4. The second UE sends a connection response to the first UE, completing the establishment of the first direct link.

[0172] In this embodiment, the first UE and the second UE can also update the first key reuse indication information while establishing the first direct link. At the same time, after all connections between the first UE and the second UE are released, the first UE and the second UE can also delete the key reuse indication information and the reusable security context information indicated by the key reuse indication information. Specifically, the first UE and the second UE regenerate the shared information corresponding to the first UE and the shared information corresponding to the second UE in the process of establishing the first direct link, and then the first UE regenerates a key reuse indication information based on the shared information corresponding to the first UE and the shared information corresponding to the second UE, and the second UE also regenerates a key reuse indication information based on the shared information corresponding to the first UE and the shared information corresponding to the second UE, that is, updates the first key reuse indication information to the second key reuse indication information.

[0173] The following describes in detail the updating process of the key reuse indication information in this embodiment based on the different signaling interactions between the first UE and the second UE:

[0174] Please refer to the following for details: Figure 11 An exemplary scheme is shown:

[0175] S1. After the first UE verifies that the key reuse indication information corresponding to the second UE is correct, the first UE sends a key reuse confirmation to the second UE.

[0176] S2. The second UE sends a direct link response to the first UE, where the direct link response carries the shared information B2 selected by the second UE.

[0177] S3. The first UE sends a direct link completion response to the second UE, where the direct link completion response carries the shared information A2 selected by the first UE.

[0178] S4. The first UE generates new key reuse indication information according to the shared information A2 and the shared information B2, and the second UE generates new key reuse indication information according to the shared information A2 and the shared information B2.

[0179] Please refer to the following for details: Figure 12 An exemplary scheme is shown:

[0180] S1. The first UE sends key reuse indication information corresponding to the first UE to the second UE.

[0181] S2. The second UE verifies the key reuse indication information corresponding to the first UE. After the verification is correct, the second UE obtains the key indicated by the key reuse indication information corresponding to the second UE.

[0182] S3. The second UE encrypts a key reuse request according to the key, where the key reuse request carries the shared information B2 selected by the second UE.

[0183] S4: The second UE sends the key reuse request to the first UE.

[0184] S5. The first UE verifies the key reuse indication information corresponding to the second UE. After the verification is correct, the first UE obtains the key indicated by the key reuse indication information corresponding to the first UE.

[0185] S6. The first UE encrypts a key reuse confirmation according to the key, where the key reuse confirmation carries the shared information A2 selected by the first UE.

[0186] S7. The first UE sends a key reuse confirmation to the second UE.

[0187] S8. The first UE generates new key reuse indication information according to the shared information A2 and the shared information B2, and the second UE generates new key reuse indication information according to the shared information A2 and the shared information B2.

[0188] Please refer to the following for details: Figure 13 As shown, another embodiment of the key reuse method in the embodiment of the present application includes:

[0189] 1301. The first UE obtains first key reuse indication information, where the first key reuse indication information is used to indicate reusable security context information.

[0190] When the first UE initiates a direct link establishment request again, the first UE obtains the first key reuse indication information according to the policy information and the marked existing direct link and bearer service for which keys can be reused, or the first UE receives the first key reuse indication information sent by the second UE.

[0191] For details, please refer to Figure 7 As shown, in this embodiment, the first UE, as an initiator, obtains the first key reuse indication information including:

[0192] S1. The first UE broadcasts a connection request, where the connection request carries key reuse indication information corresponding to the first UE.

[0193] S2. After receiving the key reuse indication information corresponding to the first UE, the second UE verifies whether the key reuse indication information corresponding to the first UE is correct, and determines the key reuse indication information corresponding to the second UE after verifying that the key reuse indication information corresponding to the first UE is correct.

[0194] S3. The second UE sends a key reuse request to the first UE, where the key reuse request carries key reuse indication information corresponding to the second UE.

[0195] S4. The first UE determines the key reuse indication information corresponding to the second UE and the key reuse indication information corresponding to the first UE as the first key reuse indication information. At the same time, the second UE determines the key reuse indication information corresponding to the second UE and the key reuse indication information corresponding to the first UE as the first key reuse indication information.

[0196] For details, please refer to Figure 8 As shown, in this embodiment, the first UE, as an initiator, obtains the first key reuse indication information including:

[0197] S1. The first UE broadcasts a connection request. At this time, the connection request does not carry key reuse related information.

[0198] S2. The second UE sends a connection reply message to the first UE, where the connection reply message carries key reuse indication information corresponding to the second UE.

[0199] S3. After verifying that the key reuse indication information corresponding to the second UE is correct, the first UE determines the key reuse indication information corresponding to the first UE based on the key reuse indication information corresponding to the second UE, and simultaneously sends the key reuse indication information corresponding to the first UE to the second UE.

[0200] S4. The first UE determines the key reuse indication information corresponding to the second UE and the key reuse indication information corresponding to the first UE as the first key reuse indication information. At the same time, the second UE determines the key reuse indication information corresponding to the second UE and the key reuse indication information corresponding to the first UE as the first key reuse indication information.

[0201] 1302. When the first UE and the second UE verify that the first key reuse indication information is correct, the first UE establishes a first direct link with the second UE according to the reusable security context information, and the second UE is a peer user equipment of the first UE.

[0202] In this embodiment, after the first UE and the second UE verify that the key reuse indication information of the other end and the local end is correct, the first UE and the second UE can obtain the reusable security context information indicated by the first key reuse indication information to establish the first direct link.

[0203] In this embodiment, according to the difference in signaling interaction between the first UE and the second UE, the following possible implementations can be specifically classified:

[0204] Please refer to the following for details: Figure 9 An exemplary scheme is shown:

[0205] S1. After the first UE verifies that the key reuse indication information corresponding to the second UE is correct, the first UE sends a key reuse confirmation to the second UE.

[0206] S2. The second UE sends a direct link response to the first UE;

[0207] S3. The first UE and the second UE establish the first direct link through reusable security context information.

[0208] Please refer to the following for details: Figure 10 An exemplary scheme is shown:

[0209] S1. The first UE sends key reuse indication information corresponding to the first UE to the second UE.

[0210] S2. The second UE verifies the key reuse indication information corresponding to the first UE. After the verification is correct, the second UE sends a key reuse request to the first UE.

[0211] S3. The first UE sends a key reuse confirmation to the second UE.

[0212] S4. The second UE sends a connection response to the first UE, completing the establishment of the first direct link.

[0213] In this embodiment, the first UE and the second UE can also update the first key reuse indication information while establishing the first direct link. At the same time, after all connections between the first UE and the second UE are released, the first UE and the second UE can also delete the key reuse indication information and the reusable security context information indicated by the key reuse indication information. Specifically, the first UE and the second UE regenerate the shared information corresponding to the first UE and the shared information corresponding to the second UE in the process of establishing the first direct link, and then the first UE regenerates a key reuse indication information based on the shared information corresponding to the first UE and the shared information corresponding to the second UE, and the second UE also regenerates a key reuse indication information based on the shared information corresponding to the first UE and the shared information corresponding to the second UE, that is, updates the first key reuse indication information to the second key reuse indication information.

[0214] The following describes in detail the updating process of the key reuse indication information in this embodiment based on the different signaling interactions between the first UE and the second UE:

[0215] Please refer to the following for details: Figure 11 An exemplary scheme is shown:

[0216] S1. After the first UE verifies that the key reuse indication information corresponding to the second UE is correct, the first UE sends a key reuse confirmation to the second UE.

[0217] S2. The second UE sends a direct link response to the first UE, where the direct link response carries the shared information B2 selected by the second UE.

[0218] S3. The first UE sends a direct link completion response to the second UE, where the direct link completion response carries the shared information A2 selected by the first UE.

[0219] S4. The first UE generates new key reuse indication information according to the shared information A2 and the shared information B2, and the second UE generates new key reuse indication information according to the shared information A2 and the shared information B2.

[0220] Please refer to the following for details: Figure 12 An exemplary scheme is shown:

[0221] S1. The first UE sends key reuse indication information corresponding to the first UE to the second UE.

[0222] S2. The second UE verifies the key reuse indication information corresponding to the first UE. After the verification is correct, the second UE obtains the key indicated by the key reuse indication information corresponding to the second UE.

[0223] S3. The second UE encrypts a key reuse request according to the key, where the key reuse request carries the shared information B2 selected by the second UE.

[0224] S4: The second UE sends the key reuse request to the first UE.

[0225] S5. The first UE verifies the key reuse indication information corresponding to the second UE. After the verification is correct, the first UE obtains the key indicated by the key reuse indication information corresponding to the first UE.

[0226] S6. The first UE encrypts a key reuse confirmation according to the key, where the key reuse confirmation carries the shared information A2 selected by the first UE.

[0227] S7. The first UE sends a key reuse confirmation to the second UE.

[0228] S8. The first UE generates new key reuse indication information according to the shared information A2 and the shared information B2, and the second UE generates new key reuse indication information according to the shared information A2 and the shared information B2.

[0229] The following describes in detail the updating process of the key reuse indication information in this embodiment based on the different signaling interactions between the first UE and the second UE:

[0230] Please refer to the following for details: Figure 11 An exemplary scheme is shown:

[0231] S1. After the first UE verifies that the key reuse indication information corresponding to the second UE is correct, the first UE sends a key reuse confirmation to the second UE.

[0232] S2. The second UE sends a direct link response to the first UE, where the direct link response carries the shared information B2 selected by the second UE.

[0233] S3. The first UE sends a direct link completion response to the second UE, where the direct link completion response carries the shared information A2 selected by the first UE.

[0234] S4. The first UE generates new key reuse indication information according to the shared information A2 and the shared information B2, and the second UE generates new key reuse indication information according to the shared information A2 and the shared information B2.

[0235] Please refer to the following for details: Figure 12 An exemplary scheme is shown:

[0236] S1. The first UE sends key reuse indication information corresponding to the first UE to the second UE.

[0237] S2. The second UE verifies the key reuse indication information corresponding to the first UE. After the verification is correct, the second UE obtains the key indicated by the key reuse indication information corresponding to the second UE.

[0238] S3. The second UE encrypts a key reuse request according to the key, where the key reuse request carries the shared information B2 selected by the second UE.

[0239] S4. The first UE sends a key reuse confirmation to the second UE, where the key reuse confirmation carries the shared information A2 selected by the first UE, wherein the first UE also encrypts the key reuse confirmation according to the key indicated by the key reuse indication information corresponding to the first UE.

[0240] S5. The first UE generates new key reuse indication information according to the shared information A2 and the shared information B2, and the second UE generates new key reuse indication information according to the shared information A2 and the shared information B2.

[0241] In this embodiment, the first UE and the second UE can be peers to each other. The first UE can act as an initiator and the second UE can act as a receiver. Alternatively, the first UE can act as a receiver and the second UE can act as an initiator. However, both the first UE and the second UE have the functions of the user equipment in the above-mentioned solution. The solution in which the first UE acts as a receiver and the second UE acts as an initiator will not be described here in detail.

[0242] The above describes an embodiment of the key reuse method in the embodiment of the present application. The following describes the user equipment in the embodiment of the present application.

[0243] Please refer to the following for details: Figure 14 As shown, the user equipment 1400 in the embodiment of the present application includes: an acquisition module 1401 and a processing module 1402. The user equipment 1400 can be the first UE in the above method embodiment, or one or more chips within the first UE. The user equipment 1400 can be used to perform some or all of the functions of the user equipment in the above method embodiment.

[0244] For example, the acquisition module 1401 can be used to execute steps 301 and 304 in the above method embodiment, or to execute steps 1301 and 304 in the above method embodiment. Figures 4 to 12 For example, the acquisition module 1401 acquires first key reuse indication information, where the first key reuse indication information is used to indicate reusable security context information.

[0245] The processing module 1402 can be used to execute steps 302 and 303 in the above method embodiment, or to execute steps 1302 and 303 in the above method embodiment. Figures 4 to 12 For example, when the first UE and the second UE verify that the first key reuse indication information is correct, the processing module 1402 establishes a first direct link with the second UE according to the reusable security context information, and the second UE is the opposite user equipment of the first UE.

[0246] Optionally, user device 1400 further includes a storage module, which is coupled to the processing module so that the processing module can execute computer-executable instructions stored in the storage module to implement the functions of the user device in the above-mentioned method embodiment. In one example, the storage module optionally included in user device 1400 can be a storage unit within a chip, such as a register, a cache, etc. The storage module can also be a storage unit located outside the chip, such as a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM), etc.

[0247] It should be understood that the above Figure 14 The processes executed between the modules of the user equipment in the corresponding embodiment are the same as those in the aforementioned Figures 3 to 13 The process executed by the user equipment in the corresponding method embodiment is similar, and the details are not repeated here.

[0248] Figure 15 The following is a schematic diagram illustrating a possible structure of a user device 1500 in the above embodiment. This user device 1500 can be configured as the aforementioned user device. The user device 1500 may include: a processor 1502, a computer-readable storage medium / memory 1503, a transceiver 1504, an input device 1505, an output device 1506, and a bus 1501. The processor, transceiver, computer-readable storage medium, etc. are connected via a bus. The embodiments of this application do not limit the specific connection medium between the above components.

[0249] In an example, the transceiver 1504 obtains first key reuse indication information, where the first key reuse indication information is used to indicate reusable security context information.

[0250] In one example, the processor 1502 may include a baseband circuit, for example, to generate relevant signaling information during the direct link establishment process. The transceiver 1504 may include a radio frequency circuit to modulate and amplify the signaling information before sending it to the peer user equipment.

[0251] In another example, the processor 1502 may run an operating system to control functions between various devices and components. The transceiver 1504 may include a baseband circuit and a radio frequency circuit. For example, relevant signaling information may be processed via the baseband circuit and the radio frequency circuit and then sent to the peer user equipment.

[0252] The transceiver 1504 and the processor 1502 can implement the above Figures 3 to 13 The corresponding steps in any embodiment are not described in detail here.

[0253] It is understandable that Figure 15 Only a simplified design of the user equipment is shown. In actual applications, the user equipment may include any number of transceivers, processors, memories, etc., and all user equipment that can implement the present application are within the scope of protection of the present application.

[0254] The processor 1502 involved in the above-mentioned user equipment 1500 can be a general-purpose processor, such as a general-purpose central processing unit (CPU), a network processor (NP), a microprocessor, etc., or it can be an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application. It can also be a digital signal processor (DSP), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The controller / processor can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like. The processor usually performs logical and arithmetic operations based on program instructions stored in a memory.

[0255] The bus 1501 mentioned above may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 15 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0256] The computer-readable storage medium / memory 1503 mentioned above may also store an operating system and other application programs. Specifically, the program may include program code, and the program code includes computer operating instructions. More specifically, the above-mentioned memory may be a read-only memory (ROM), other types of static storage devices that can store static information and instructions, a random access memory (RAM), other types of dynamic storage devices that can store information and instructions, disk storage, etc. The memory 1503 may be a combination of the above-mentioned storage types. In addition, the above-mentioned computer-readable storage medium / memory may be in the processor, external to the processor, or distributed across multiple entities including a processor or processing circuit. The above-mentioned computer-readable storage medium / memory may be specifically embodied in a computer program product. For example, a computer program product may include a computer-readable medium in packaging material.

[0257] Alternatively, the embodiment of the present application also provides a general processing system, such as a chip, which includes: one or more microprocessors that provide processor functions; and an external memory that provides at least a portion of the storage medium, all of which are connected to other supporting circuits through an external bus architecture. When the instructions stored in the memory are executed by the processor, the processor executes the user device in Figures 3 to 13 The user equipment in the embodiment may use part or all of the steps in the key reuse method, and / or other processes used for the technology described in this application.

[0258] The steps of the method or algorithm described in conjunction with the disclosure of this application can be implemented in hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, which can be stored in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, mobile hard disk, CD-ROM or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and storage medium can be located in an ASIC. In addition, the ASIC can be located in a user device. Of course, the processor and storage medium can also be present in the user device as discrete components.

[0259] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0260] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0261] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of the solution of this embodiment according to actual needs.

[0262] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0263] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0264] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A key reuse method, characterized in that: include: The first electronic device obtains first key reuse indication information, where the first key reuse indication information is used to indicate reusable security context information, where the security context information includes a key; When the first electronic device and the second electronic device verify that the first key reuse indication information is correct, the first electronic device establishes a first direct link with the second electronic device according to the reusable security context information, where the second electronic device is a peer electronic device of the first electronic device; The first electronic device is an initiator, the second electronic device is a receiver, and the first electronic device obtains the first key reuse indication information including: The first electronic device broadcasts a connection request, where the connection request carries key reuse indication information corresponding to the first electronic device; The first electronic device receives a first key reuse request sent by the second electronic device, where the first key reuse request carries key reuse indication information corresponding to the second electronic device; the first key reuse indication information includes key reuse indication information corresponding to the second electronic device and key reuse indication information corresponding to the first electronic device.

2. The method according to claim 1, characterized in that The key reuse instruction information corresponding to the second electronic device is determined by the second electronic device according to the key reuse instruction information corresponding to the first electronic device after verifying that the key reuse instruction information corresponding to the first electronic device is correct; The first electronic device establishing a first direct link with the second electronic device according to the reusable security context information includes: After the first electronic device verifies that the key reuse instruction information corresponding to the second electronic device is correct, the first electronic device sends a first key reuse confirmation to the second electronic device; The first electronic device receives the first direct link response sent by the second electronic device, and establishes the first direct link with the second electronic device according to the reusable security context information indicated by the first key reuse indication information.

3. The method according to any one of claims 1 to 2, characterized in that The method further comprises: The first electronic device obtains policy information, where the policy information is used to indicate the security requirement level corresponding to each service type and the association between the algorithm corresponding to each service type and key reuse; The first electronic device establishes an initial direct link with the second electronic device, and negotiates with the second electronic device to determine the first key reuse indication information based on the policy information, where the second electronic device is the opposite electronic device for establishing the direct link with the first electronic device; The first electronic device maintains the first key reuse indication information and the reusable security context information indicated by the first key reuse indication information.

4. The method according to claim 3, characterized in that The first electronic device establishes an initial direct link with the second electronic device, and negotiates with the second electronic device according to policy information to determine the first key reuse indication information, including: When the first electronic device determines that there is no existing connection with a reusable key, the first electronic device sends an initial direct link request, where the initial direct link request does not carry key reuse indication information corresponding to the first electronic device; The first electronic device and the second electronic device complete an inter-node authentication and key establishment process, wherein the inter-node authentication and key establishment process is initiated by the second electronic device when determining that there is no key reuse request based on the absence of key reuse indication information corresponding to the first electronic device or a connection without a reusable key in the first direct link request; The first electronic device receives the fifth key reuse request sent by the second electronic device and the shared information selected by the second electronic device; The first electronic device sends a fifth key reuse confirmation and the shared information selected by the first electronic device to the second electronic device, so that the second electronic device generates the first key reuse indication information according to the shared information selected by the second electronic device and the shared information selected by the first electronic device; The first electronic device generates the first key reuse indication information according to the shared information selected by the second electronic device and the shared information selected by the first electronic device.

5. The method according to claim 3, characterized in that The first electronic device establishes an initial direct link with the second electronic device, and negotiates with the second electronic device according to the policy information to determine the first key reuse indication information, including: When the first electronic device determines that there is no existing connection with a reusable key, the first electronic device sends a first direct link request; The first electronic device receives an inter-node authentication and key establishment request sent by the second electronic device, where the inter-node authentication and key establishment request does not carry key reuse indication information corresponding to the second electronic device, and the inter-node authentication and key establishment request is initiated by the second electronic device when determining that there is no connection with a reusable key; When the first electronic device determines that there is no key reuse request based on the absence of key reuse indication information corresponding to the second electronic device or the absence of a connection with a reusable key in the inter-node authentication and key establishment request, the first electronic device completes the inter-node authentication and key establishment process with the second electronic device; The first electronic device receives a sixth key reuse request sent by the second electronic device and the shared information selected by the second electronic device; The first electronic device sends a sixth key reuse confirmation and the shared information selected by the first electronic device to the second electronic device, so that the second electronic device generates the first key reuse indication information according to the shared information selected by the second electronic device and the shared information selected by the first electronic device; The first electronic device generates the first key reuse indication information according to the shared information selected by the second electronic device and the shared information selected by the first electronic device.

6. The method according to claim 3, characterized in that The first electronic device establishes an initial direct link with the second electronic device, and negotiates with the second electronic device according to the policy information to determine the first key reuse indication information, including: When the first electronic device determines that there is no existing connection with a reusable key, the first electronic device sends a first direct link request; The first electronic device receives an inter-node authentication and key establishment request sent by the second electronic device, where the inter-node authentication and key establishment request carries the seventh key reuse request and does not carry key reuse indication information corresponding to the second electronic device, and the inter-node authentication and key establishment request is initiated by the second electronic device when determining that there is no connection with a reusable key; When the first electronic device determines that there is no key reuse request based on the fact that the inter-node authentication and key establishment request does not carry the key reuse indication information corresponding to the second electronic device or there is no reusable key, the first electronic device completes the inter-node authentication and key establishment process with the second electronic device and sends a seventh key reuse confirmation to the second electronic device; The first electronic device receives the shared information selected by the second electronic device and sent by the second electronic device; The first electronic device sends the shared information selected by the first electronic device to the second electronic device, so that the second electronic device generates the first key reuse indication information according to the shared information selected by the second electronic device and the shared information selected by the first electronic device; The first electronic device generates the first key reuse indication information according to the shared information selected by the second electronic device and the shared information selected by the first electronic device.

7. The method according to claim 3, characterized in that The policy information is generated by a policy control function PCF and sent to the first electronic device or the second electronic device by an access and mobility management function AMF.

8. The method according to claim 7, characterized in that The association relationship includes: if the security requirement levels corresponding to the service types of the first electronic device and the second electronic device do not conflict, and the algorithms corresponding to the service types do not conflict, then the first electronic device and the second electronic device can reuse keys in the unicast direct connection; If at least one of the security requirement levels corresponding to each service type or the algorithms corresponding to each service type of the first electronic device and the second electronic device conflicts, the first electronic device and the second electronic device cannot reuse keys in a unicast direct connection.

9. The method according to any one of claims 1 to 2, characterized in that After the first electronic device establishes a first direct link with the second electronic device according to the first key reuse indication information, the method further includes: The first electronic device updates the first key reuse indication information to obtain second key reuse indication information; The first electronic device maintains the second key reuse indication information and the reusable security context information indicated by the second key reuse indication information.

10. The method according to claim 9, characterized in that The first electronic device updating the first key reuse indication information to obtain second key reuse indication information includes: The first electronic device obtains first shared information selected by itself and second shared information selected by the second electronic device, where the second shared information is carried in a key reuse request sent by the second electronic device, and the first shared information and the second shared information are generated after the first direct link is established; The first electronic device generates the second key reuse indication information according to the first shared information and the second shared information.

11. The method according to claim 9, characterized in that The method further comprises: If the connections between the first electronic device and the second electronic device are both released, the first electronic device and the second electronic device delete the key reuse indication information and the reusable security context information indicated by the key reuse indication information, and the key reuse indication information includes the first key reuse indication information and the second key reuse indication information.

12. The method according to claim 9, characterized in that The first key reuse indication information is token information, marking information, or authentication information; The second key reuse indication information is token information, marking information, or authentication information.

13. A key reuse method, characterized in that: include: The first electronic device obtains first key reuse indication information, where the first key reuse indication information is used to indicate reusable security context information, where the security context information includes a key; When the first electronic device and the second electronic device verify that the first key reuse indication information is correct, the first electronic device establishes a first direct link with the second electronic device according to the reusable security context information, where the second electronic device is a peer electronic device of the first electronic device; The first electronic device is an initiator, the second electronic device is a receiver, and the first electronic device obtains the first key reuse indication information including: The first electronic device broadcasts a connection request; The first electronic device receives connection reply information sent by the second electronic device, where the connection reply information carries key reuse indication information corresponding to the second electronic device; After the first electronic device verifies that the key reuse instruction information corresponding to the second electronic device is correct, the first electronic device determines the key reuse instruction information corresponding to the first electronic device according to the key reuse instruction information corresponding to the second electronic device; The first electronic device sends a second key reuse request to the second electronic device, and the second key reuse request carries key reuse indication information corresponding to the first electronic device. The first key reuse indication information includes key reuse indication information corresponding to the second electronic device and key reuse indication information corresponding to the first electronic device.

14. The method according to claim 13, characterized in that The first electronic device establishing a first direct link with the second electronic device according to the first key reuse indication information includes: The first electronic device receives a second key reuse confirmation sent by the second electronic device, where the second key reuse confirmation is sent by the second electronic device after verifying that the key reuse indication information corresponding to the first electronic device is correct; The first electronic device sends a second direct connection response to the second electronic device, and establishes the first direct link with the second electronic device according to the reusable security context information indicated by the first key reuse indication information.

15. A key reuse method, characterized in that: include: The first electronic device obtains first key reuse indication information, where the first key reuse indication information is used to indicate reusable security context information, where the security context information includes a key; When the first electronic device and the second electronic device verify that the first key reuse indication information is correct, the first electronic device establishes a first direct link with the second electronic device according to the reusable security context information, where the second electronic device is a peer electronic device of the first electronic device; The first electronic device is a receiver, the second electronic device is an initiator, and the first electronic device obtains the first key reuse indication information including: The first electronic device receives a connection request, where the connection request carries key reuse indication information corresponding to the second electronic device; After the first electronic device verifies that the key reuse instruction information corresponding to the second electronic device is correct, the first electronic device determines the key reuse instruction information corresponding to the first electronic device according to the key reuse instruction information corresponding to the second electronic device; The first electronic device sends a third key reuse request to the second electronic device, and the third key reuse request carries key reuse indication information corresponding to the first electronic device, and the first key reuse indication information includes key reuse indication information corresponding to the second electronic device and key reuse indication information corresponding to the first electronic device.

16. The method according to claim 15, characterized in that The first electronic device establishing a first direct link with the second electronic device according to the first key reuse indication information includes: The first electronic device receives a third key reuse confirmation sent by the second electronic device, wherein the third key reuse confirmation is sent by the second electronic device after verifying that the key reuse indication information corresponding to the first electronic device is correct; The first electronic device sends a first direct link response to the second electronic device, and establishes the first direct link with the second electronic device according to the reusable security context information indicated by the first key reuse indication information.

17. The method according to any one of claims 15 to 16, characterized in that The method further comprises: The first electronic device obtains policy information, where the policy information is used to indicate the security requirement level corresponding to each service type and the association between the algorithm corresponding to each service type and key reuse; The first electronic device establishes an initial direct link with the second electronic device, and negotiates with the second electronic device to determine the first key reuse indication information based on the policy information, where the second electronic device is the opposite electronic device for establishing the direct link with the first electronic device; The first electronic device maintains the first key reuse indication information and the reusable security context information indicated by the first key reuse indication information.

18. The method according to claim 17, characterized in that The first electronic device establishes an initial direct link with the second electronic device, and negotiates with the second electronic device according to policy information to determine the first key reuse indication information, including: The first electronic device receives a first direct link request sent by the second electronic device, where the first direct link request is sent by the second electronic device when the second electronic device determines that there is no existing connection with a reusable key, and the first direct link request does not carry key reuse indication information corresponding to the second electronic device; The first electronic device initiates an inter-node authentication and key establishment request to the second electronic device when determining that there is no key reuse request based on the absence of key reuse indication information corresponding to the second electronic device or a connection without a reusable key in the first direct link request; The first electronic device sends an eighth key reuse request and the shared information selected by the first electronic device to the second electronic device, so that the second electronic device generates the first key reuse indication information according to the shared information selected by the second electronic device and the shared information selected by the first electronic device; The first electronic device receives, from the second electronic device, an eighth key reuse confirmation and shared information selected by the second electronic device; The first electronic device generates the first key reuse indication information according to the shared information selected by the second electronic device and the shared information selected by the first electronic device.

19. The method according to claim 17, wherein The first electronic device establishes an initial direct link with the second electronic device, and negotiates with the second electronic device according to the policy information to determine the first key reuse indication information, including: The first electronic device receives, from the second electronic device, a first direct link request, the first direct link request being sent by the second electronic device when the second electronic device determines that there is no connection with an existing reusable key; when the first electronic device determines that there is no connection with a reusable key, the first electronic device sends, to the second electronic device, an inter-node authentication and key establishment request, the inter-node authentication and key establishment request not carrying the key reuse indication information corresponding to the first electronic device; The first electronic device sends a ninth key reuse request and the shared information selected by the first electronic device to the second electronic device, so that the second electronic device generates the first key reuse indication information according to the shared information selected by the second electronic device and the shared information selected by the first electronic device; The first electronic device receives, from the second electronic device, a ninth key reuse confirmation and shared information selected by the second electronic device; The first electronic device generates the first key reuse indication information according to the shared information selected by the second electronic device and the shared information selected by the first electronic device.

20. The method according to claim 17, wherein The first electronic device establishes an initial direct link with the second electronic device, and negotiates with the second electronic device according to the policy information to determine the first key reuse indication information, including: The first electronic device receives, by the second electronic device, a first direct link request sent by the second electronic device when the second electronic device determines that there is no connection with an existing reusable key; when the first electronic device determines that there is no connection with a reusable key, the first electronic device sends, to the second electronic device, an inter-node authentication and key establishment request, wherein the inter-node authentication and key establishment request carries a tenth key reuse request and does not carry key reuse indication information corresponding to the second electronic device; The first electronic device receives a tenth key reuse confirmation sent by the second electronic device, the tenth key reuse confirmation being sent by the second electronic device when the second electronic device determines that there is no key reuse request based on the inter-node authentication and key establishment request not carrying key reuse indication information corresponding to the second electronic device or a connection without a reusable key; The first electronic device sends the shared information selected by the first electronic device to the second electronic device, so that the second electronic device generates the first key reuse indication information according to the shared information selected by the second electronic device and the shared information selected by the first electronic device; The first electronic device receives the shared information selected by the second electronic device and sent by the second electronic device; The first electronic device generates the first key reuse indication information according to the shared information selected by the second electronic device and the shared information selected by the first electronic device.

21. A key reuse method, characterized in that: include: The first electronic device obtains first key reuse indication information, where the first key reuse indication information is used to indicate reusable security context information, where the security context information includes a key; When the first electronic device and the second electronic device verify that the first key reuse indication information is correct, the first electronic device establishes a first direct link with the second electronic device according to the reusable security context information, where the second electronic device is a peer electronic device of the first electronic device; The first electronic device is a receiver, the second electronic device is an initiator, and the first electronic device obtains the first key reuse indication information including: The first electronic device receives a connection request; The first electronic device sends a connection reply message to the second electronic device, where the connection reply message carries key reuse indication information corresponding to the first electronic device; The first electronic device receives a fourth key reuse request sent by the second electronic device, where the fourth key reuse request carries key reuse indication information corresponding to the second electronic device, and the first key reuse indication information includes key reuse indication information corresponding to the second electronic device and key reuse indication information corresponding to the first electronic device.

22. The method according to claim 21, characterized in that The key reuse instruction information corresponding to the second electronic device is determined by the second electronic device according to the key reuse instruction information corresponding to the first electronic device after verifying that the key reuse instruction information corresponding to the first electronic device is correct; The first electronic device establishing a first direct link with the second electronic device according to the first key reuse indication information includes: After the first electronic device verifies that the key reuse instruction information corresponding to the second electronic device is correct, the first electronic device determines the key reuse instruction information corresponding to the first electronic device and a reusable security context according to the key reuse instruction information corresponding to the second electronic device; The first electronic device sends a fourth key reuse confirmation message encrypted by the reusable security context to the second electronic device; The first electronic device receives the third connection response sent by the second electronic device, and establishes the first direct link with the second electronic device according to the reusable security context information indicated by the first key reuse indication information.

23. A terminal device, characterized in that: including a processor and a memory; The memory stores computer instructions; The processor calls the computer instructions to cause the terminal device to execute the method according to any one of claims 1 to 22.

24. A computer-readable storage medium, characterized in that Computer instructions are stored, and when the computer instructions are executed on a computer, the computer is caused to execute the method according to any one of claims 1 to 22.

25. A computer program product, characterized in that The invention comprises a program which, when being run on a computer, causes the computer to execute the method according to any one of claims 1 to 22.

26. A communication system comprising the terminal device according to claim 23.

Citation Information

Patent Citations

  • Methods and apparatuses for expression use during D2D communications in a LTE based WWAN

    CN104737616A