Key update method and apparatus

By using a MAC control unit to transmit the key seed in a wireless communication system, and generating the key on the terminal and network sides, the system overhead and security issues caused by frequent key updates in wireless communication systems are resolved, and fast and secure key updates are achieved.

CN116249105BActive Publication Date: 2026-01-30CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111484386.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-07
Publication Date
2026-01-30
Estimated Expiration
2041-12-07

AI Technical Summary

Technical Problem

The lack of an effective key update mechanism in existing wireless communication systems leads to frequent key switching, resulting in system overhead and security issues.

Method used

The MAC control unit, which contains a key seed, is sent by the network-side device. The terminal and the network side generate the first key based on the key seed, and the key takes effect at the time of the air interface transmission of the confirmation message, thus realizing rapid key update.

Benefits of technology

It enables fast key updates at the MAC layer in wireless communication systems, reducing system overhead and power consumption, improving security, and ensuring lossless transmission of data packets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116249105B_ABST
    Figure CN116249105B_ABST
Patent Text Reader

Abstract

This invention provides a key update method and apparatus, belonging to the field of wireless technology. The key update method, executed by a network-side device, includes: sending a first MAC CE to a terminal, the first MAC CE including a key seed for generating a first key; receiving an acknowledgment message from the terminal in response to the first MAC CE; generating the first key based on the key seed; and using the first key to encrypt and / or decrypt transmitted data. The technical solution of this invention enables rapid MAC key updates.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of wireless technology, in particular to a key update method and device. BACKGROUND

[0002] In a wireless communication system, security is one of the main features of the wireless network. How to realize security in the wireless communication system becomes a problem to be solved.

[0003] The wireless access network itself has a set of key management, distribution and control mechanism. In order to enable the wireless network to have the function of security, new functions need to be added under the existing key mechanism.

[0004] In the prior art, there is no solution to how to realize security in the wireless system. SUMMARY

[0005] The technical problem to be solved by the present application is to provide a key update method and device, which can realize MAC fast key update.

[0006] To solve the above technical problems, the embodiments of the present application provide the technical solutions as follows:

[0007] In one aspect, a key update method is provided, which is executed by a network side device, and includes:

[0008] sending a first medium access control (MAC) control element (CE) to a terminal, wherein the first MAC CE includes a key seed, and is used to generate a first key;

[0009] receiving an acknowledgement message fed back by the terminal for the first MAC CE;

[0010] generating the first key according to the key seed, and using the first key to encrypt and / or decrypt transmission data.

[0011] In some embodiments, the effective time point of the first key is an air interface sending time point of feeding back the acknowledgement message.

[0012] In some embodiments, after receiving the acknowledgement message fed back by the terminal for the first MAC CE, the method further includes:

[0013] emptying all hybrid automatic repeat request (HARQ) process sending buffers.

[0014] In some embodiments, after receiving the acknowledgement message fed back by the terminal for the first MAC CE, the method further includes:

[0015] feeding back a negative acknowledgement message to the terminal for a transmission block that is not correctly received;

[0016] For the successfully received transport blocks, an acknowledgement message is fed back to the terminal.

[0017] In some embodiments, the encryption and / or decryption of the transmission data using the first key comprises:

[0018] For the retransmission required transport blocks fed back to the terminal, a MAC protocol data unit (PDU) is reassembled using the corresponding MAC service data unit (SDU) of the transport block;

[0019] The MAC PDU is encrypted using the first key;

[0020] The encrypted MAC PDU is sent to the terminal.

[0021] In some embodiments, after the encryption and / or decryption of the transmission data using the first key, the method further comprises:

[0022] Determining whether the first key needs to trigger the operation of the upper protocol layer;

[0023] If needed, sending a first request to the upper protocol layer to trigger the reestablishment process of the upper protocol layer.

[0024] In some embodiments, before sending the first MAC CE to the terminal, the method further comprises the step of determining whether the terminal needs to update the key, and determining whether the terminal needs to update the key comprises any of the following:

[0025] Determining whether the key needs to be updated according to the result output by the detection and analysis of the MAC layer;

[0026] Determining whether the key needs to be updated according to the indication from the cloud;

[0027] Determining whether the key needs to be updated according to a preset time period.

[0028] In some embodiments, the parameters used by the MAC layer for detection and analysis comprise at least one of the following:

[0029] Statistical characteristics of terminal data packet reception and transmission, characteristics of terminal application service data packet transmission and reception, terminal mobility characteristics, mobility characteristics and service characteristics of other terminals in the cell, and air interface resource occupation statistical characteristics.

[0030] In some embodiments, the indication of the cloud comprises at least one of the following:

[0031] A key seed;

[0032] Characteristics of the key seed, including timeliness and length;

[0033] Objects or scenarios or services or functions to which the first key is applicable.

[0034] In some embodiments, the preset time period is defined, configured or pre-configured by a protocol.

[0035] In some embodiments, the first MAC CE is identified by a value of a logical channel identifier (LCID), or is identified by a value of an enhanced logical channel identifier (eLCID).

[0036] In some embodiments, if the length of the first MAC CE is variable, the length of the key seed is variable.

[0037] If the length of the first MAC CE is fixed, the length of the key seed is fixed.

[0038] In some embodiments, the key seed is generated in any of the following ways:

[0039] randomly;

[0040] according to an indication of an upper protocol layer;

[0041] according to a preset length of a bit string in an identity of the terminal through a random function;

[0042] according to a preset bit string in a data packet to be encrypted through a random function;

[0043] according to a feature value of the terminal, and through a random function after length expansion or without length expansion;

[0044] according to a position coordinate of a moving track of the terminal, and through a random function after length expansion or without length expansion.

[0045] The embodiments of the present application also provide a key updating method, executed by a terminal, comprising:

[0046] receiving a first media access control (MAC) control element (CE) of a network side device, wherein the first MAC CE comprises a key seed, and feeding back a confirmation message to the network side device;

[0047] generating a first key according to the key seed;

[0048] encrypting and / or decrypting transmission data by using the first key.

[0049] In some embodiments, the effective time point of the first key is an air interface sending time point of feeding back the confirmation message.

[0050] In some embodiments, after receiving the first MAC CE of the network side device, the method further comprises:

[0051] emptying all hybrid automatic repeat request (HARQ) process sending buffers.

[0052] In some embodiments, after receiving the first MAC CE of the network side device, the method further comprises:

[0053] feeding back a negative message to the network side device for a transmission block not correctly received;

[0054] feeding back a confirmation message to the network side device for a transmission block successfully received.

[0055] In some embodiments, the encryption and / or decryption of the transmission data by using the first key comprises:

[0056] for a transmission block not successfully sent and a transmission block sent for the first time, reassembling a MAC protocol data unit (PDU) by using a MAC service data unit (SDU) corresponding to the transmission block, encrypting the MAC PDU by using the first key, and sending the encrypted MAC PDU to the network side device.

[0057] In some embodiments, the first MAC CE is identified by a value of a logical channel identifier (LCID), or the first MAC CE is identified by a value of an enhanced logical channel identifier (eLCID).

[0058] In some embodiments, generating the first key according to the key seed comprises:

[0059] inputting the key seed into a key generator to generate the first key.

[0060] In some embodiments, the key generator is configured to the terminal by the network side device, or is pre-configured in the terminal.

[0061] Embodiments of the present application also provide a key updating device applied to a network side device, comprising a transceiver and a processor,

[0062] the transceiver is configured to send a first media access control (MAC) control element (CE) to a terminal, the first MAC CE comprising a key seed for generating a first key, and receive a confirmation message fed back by the terminal for the first MAC CE;

[0063] the processor is configured to generate the first key according to the key seed, and encrypt and / or decrypt transmission data by using the first key.

[0064] In some embodiments, the effective time point of the first key is an air interface sending time point of feeding back the confirmation message.

[0065] In some embodiments, the processor is further configured to clear all hybrid automatic repeat request (HARQ) process sending buffers.

[0066] In some embodiments, the transceiver is also configured to send a denial message to the terminal for a transport block that is not received correctly, and to send an acknowledgment message to the terminal for a transport block that is successfully received.

[0067] In some embodiments, the processor is specifically used to reconstruct a MAC Protocol Data Unit (PDU) using the MAC Service Data Unit (SDU) corresponding to the transport block that needs to be retransmitted as reported by the terminal; and to encrypt the MAC PDU using the first key.

[0068] The transceiver is used to send the encrypted MAC PDU to the terminal.

[0069] In some embodiments, the processor is further configured to determine whether setting the first key requires triggering an operation at the upper protocol layer; if so, to send a first request to the upper protocol layer to trigger the re-establishment process of the upper protocol layer.

[0070] In some embodiments, the processor is further configured to perform a step of determining that the terminal needs to update the key, wherein determining that the terminal needs to update the key includes any of the following:

[0071] Based on the results of the MAC layer's detection and analysis output, it is determined whether the key needs to be updated;

[0072] Based on instructions from the cloud, it was determined that a key update was required;

[0073] The key needs to be updated based on a preset time period.

[0074] In some embodiments, the parameters used by the MAC layer for detection and analysis include at least one of the following:

[0075] Statistical characteristics of terminal data packet reception and transmission, characteristics of terminal-requested service data packet transmission and reception, terminal mobility characteristics, mobility and service characteristics of other terminals in the cell, and statistical characteristics of air interface resource occupancy.

[0076] In some embodiments, the cloud-based instructions include at least one of the following:

[0077] Key seed;

[0078] Key seed characteristics, including timeliness and length;

[0079] The first key applies to the object, scenario, business, or functional unit.

[0080] In some embodiments, the preset time period is defined, configured, or pre-configured by the protocol.

[0081] In some embodiments, the first MAC CE is identified using the value of the Logical Channel Identifier (LCID), or the first MAC CE is identified using the value of the Enhanced Logical Channel Identifier (eLCID).

[0082] In some embodiments, if the length of the first MAC CE is variable, then the length of the key seed is variable;

[0083] If the length of the first MAC CE is fixed, then the length of the key seed is fixed.

[0084] In some embodiments, the key seed is generated in any of the following ways:

[0085] Randomly generated;

[0086] Generated according to the instructions of the upper protocol layer;

[0087] The data is generated using a random function based on a bit string of preset length from the terminal's identifier.

[0088] A preset bit string is extracted from the data packet to be encrypted and generated using a random function;

[0089] The characteristic value of the terminal is calculated, and after either extending or not extending the length, it is generated through a random function.

[0090] Based on the location coordinates of the terminal's movement trajectory, the length is extended or not, and then generated through a random function.

[0091] This invention also provides a key update device for a terminal, including a transceiver and a processor.

[0092] The transceiver is used to receive a first Media Access Control (MAC) control unit (CE) from a network-side device. The first MAC CE includes a key seed and sends an acknowledgment message back to the network-side device.

[0093] The processor is used to generate a first key based on the key seed; and to encrypt and / or decrypt transmitted data using the first key.

[0094] In some embodiments, the effective time of the first key is the time when the air interface sends the confirmation message.

[0095] In some embodiments, the processor is also configured to clear all HARQ process send buffers.

[0096] In some embodiments, the transceiver is also configured to send a denial message to the network-side device for a transport block that is not received correctly, and to send an acknowledgment message to the network-side device for a transport block that is successfully received.

[0097] In some embodiments, the processor is specifically configured to, for transport blocks that were not successfully transmitted and for transport blocks transmitted for the first time, reconstruct MAC protocol data units (PDUs) using the MAC service data units (SDUs) corresponding to the transport blocks; and encrypt the MAC PDUs using the first key;

[0098] The transceiver is used to send the encrypted MAC PDU to the network-side device.

[0099] In some embodiments, the first MAC CE is identified using the value of the Logical Channel Identifier (LCID), or the first MAC CE is identified using the value of the Enhanced Logical Channel Identifier (eLCID).

[0100] In some embodiments, the processor is specifically configured to input the key seed into a key generator to generate the first key.

[0101] In some embodiments, the key generator is configured by the network-side device for the terminal, or pre-configured in the terminal.

[0102] This invention also provides a key update apparatus, including a memory, a processor, and a computer program stored in the memory and executable on the processor; when the processor executes the program, it implements the key update method as described above.

[0103] In some embodiments, the processor is configured to send a first Media Access Control (MAC) control unit (CE) to a terminal, the first MAC CE including a key seed for generating a first key; receive an acknowledgment message from the terminal in response to the first MAC CE; generate the first key based on the key seed; and use the first key to encrypt and / or decrypt transmitted data.

[0104] In some embodiments, the effective time of the first key is the time when the air interface sends the confirmation message.

[0105] In some embodiments, the processor is also configured to clear all HARQ process send buffers.

[0106] In some embodiments, the processor is further configured to send a denial message to the terminal for a transport block that is not received correctly, and to send an acknowledgment message to the terminal for a transport block that is successfully received.

[0107] In some embodiments, the processor is specifically used to reconstruct a MAC Protocol Data Unit (PDU) using the MAC Service Data Unit (SDU) corresponding to the transport block that needs to be retransmitted as reported by the terminal; encrypt the MAC PDU using the first key; and send the encrypted MAC PDU to the terminal.

[0108] In some embodiments, the processor is further configured to determine whether setting the first key requires triggering an operation at the upper protocol layer; if so, to send a first request to the upper protocol layer to trigger the re-establishment process of the upper protocol layer.

[0109] In some embodiments, the processor is further configured to perform a step of determining that the terminal needs to update the key, wherein determining that the terminal needs to update the key includes any of the following:

[0110] Based on the results of the MAC layer's detection and analysis output, it is determined whether the key needs to be updated;

[0111] Based on instructions from the cloud, it was determined that a key update was required;

[0112] The key needs to be updated based on a preset time period.

[0113] In some embodiments, the parameters used by the MAC layer for detection and analysis include at least one of the following:

[0114] Statistical characteristics of terminal data packet reception and transmission, characteristics of terminal-requested service data packet transmission and reception, terminal mobility characteristics, mobility and service characteristics of other terminals in the cell, and statistical characteristics of air interface resource occupancy.

[0115] In some embodiments, the cloud-based instructions include at least one of the following:

[0116] Key seed;

[0117] Key seed characteristics, including timeliness and length;

[0118] The first key applies to the object, scenario, business, or functional unit.

[0119] In some embodiments, the preset time period is defined, configured, or pre-configured by the protocol.

[0120] In some embodiments, the first MAC CE is identified using the value of the Logical Channel Identifier (LCID), or the first MAC CE is identified using the value of the Enhanced Logical Channel Identifier (eLCID).

[0121] In some embodiments, if the length of the first MAC CE is variable, then the length of the key seed is variable;

[0122] If the length of the first MAC CE is fixed, then the length of the key seed is fixed.

[0123] In some embodiments, the key seed is generated in any of the following ways:

[0124] Randomly generated;

[0125] Generated according to the instructions of the upper protocol layer;

[0126] The data is generated using a random function based on a bit string of preset length from the terminal's identifier.

[0127] A preset bit string is extracted from the data packet to be encrypted and generated using a random function;

[0128] The characteristic value of the terminal is calculated, and after either extending or not extending the length, it is generated through a random function.

[0129] Based on the location coordinates of the terminal's movement trajectory, the length is extended or not, and then generated through a random function.

[0130] In some embodiments, the processor is configured to receive a first Media Access Control (MAC) control unit (CE) from a network-side device, the first MAC CE including a key seed, and to send an acknowledgment message to the network-side device; generate a first key based on the key seed; and use the first key to encrypt and / or decrypt transmitted data.

[0131] In some embodiments, the effective time of the first key is the time when the air interface sends the confirmation message.

[0132] In some embodiments, the processor is also configured to clear all HARQ process send buffers.

[0133] In some embodiments, the processor is further configured to send a denial message to the network-side device for a transport block that is not received correctly, and to send an acknowledgment message to the network-side device for a transport block that is successfully received.

[0134] In some embodiments, the processor is specifically configured to, for transport blocks that were not successfully transmitted and transport blocks transmitted for the first time, reconstruct MAC protocol data units (PDUs) using the MAC service data units (SDUs) corresponding to the transport blocks; encrypt the MAC PDUs using the first key; and send the encrypted MAC PDUs to the network-side device.

[0135] In some embodiments, the first MAC CE is identified using the value of the Logical Channel Identifier (LCID), or the first MAC CE is identified using the value of the Enhanced Logical Channel Identifier (eLCID).

[0136] In some embodiments, the processor is specifically configured to input the key seed into a key generator to generate the first key.

[0137] In some embodiments, the key generator is configured by the network-side device for the terminal, or pre-configured in the terminal.

[0138] This invention also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps in the key update method described above.

[0139] The embodiments of the present invention have the following beneficial effects:

[0140] In the above scheme, the network-side device sends a first MAC CE to the terminal. The first MAC CE includes a key seed. Then, the network-side device and the terminal can generate a first key based on the key seed, and use the first key to encrypt and / or decrypt the transmitted data, thereby realizing fast MAC key updates. Attached Figure Description

[0141] Figure 1 A schematic diagram of an endogenous security system;

[0142] Figure 2 and Figure 3 This is a flowchart illustrating the key update method according to an embodiment of the present invention;

[0143] Figure 4 This is a schematic diagram of the key update device according to an embodiment of the present invention;

[0144] Figure 5 This is a schematic diagram of the key update device according to an embodiment of the present invention. Detailed Implementation

[0145] To make the technical problems, technical solutions and advantages of the embodiments of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.

[0146] Currently, a security issue in 5G systems is that encryption keys are bound to Physical Cell IDs (PIDs), requiring key changes when the user terminal (UE) moves. As the density of air interface physical cells continues to increase and the coverage area shrinks, this frequent handover leads to significant system overhead from the key update mechanism. This overhead includes not only the overhead of frequent and reliable signaling, but also the overhead of power consumption and service interruption during UE connection establishment.

[0147] To achieve the concept of intrinsic security, a cloud-based solution based on base stations is proposed, such as... Figure 1 As shown, intrinsic security is achieved by leveraging the computing power of the cloud platform to redefine the network's sensing capabilities and flexible, real-time cryptographic control mechanisms.

[0148] This invention provides a key update method and apparatus that enables MAC to update keys quickly.

[0149] Embodiments of the present invention provide a key update method, executed by a network-side device, such as... Figure 2 As shown, it includes:

[0150] Step 101: Send a first Media Access Control (MAC) control unit CE to the terminal. The first MAC CE includes a key seed for generating a first key.

[0151] Step 102: Receive the confirmation message from the terminal in response to the first MAC CE;

[0152] Step 103: Generate a first key based on the key seed, and use the first key to encrypt and / or decrypt the transmitted data.

[0153] In this embodiment, the network-side device sends a first MAC CE to the terminal. The first MAC CE includes a key seed. Then, the network-side device and the terminal can generate a first key based on the key seed, and use the first key to encrypt and / or decrypt the transmitted data, thereby enabling the MAC key to be updated quickly.

[0154] In some embodiments, the effective time of the first key is the time when the air interface sends the confirmation message.

[0155] In this embodiment, both the terminal side and the network side use the air interface transmission time of the ACK (acknowledgment message) feedback from the first MAC CE as the common effective time of the new key (i.e., the first key) for both parties. After the network-side MAC sends the first MAC CE, upon receiving the ACK from the UE for that first MAC CE, the key immediately becomes effective, and the key generated from the key seed is used to encrypt or decrypt data. In this embodiment, the network-side device triggers the synchronization and re-establishment process of the network-side MAC and the terminal-side MAC through the first MAC CE.

[0156] In some embodiments, after receiving the confirmation message from the terminal in response to the first MAC CE, the method further includes:

[0157] Clear all HARQ process send buffers for Hybrid Automatic Repeat Requests.

[0158] In some embodiments, after receiving the confirmation message from the terminal in response to the first MAC CE, the method further includes:

[0159] For a transport block that is not received correctly, a denial message is sent back to the terminal;

[0160] For successfully received transport blocks, an acknowledgment message is sent back to the terminal.

[0161] In some embodiments, encrypting and / or decrypting transmitted data using the first key includes:

[0162] For the transmission blocks that need to be retransmitted as reported by the terminal, the MAC protocol data unit (PDU) corresponding to the transmission block is reassembled using the MAC service data unit (SDU).

[0163] The MAC PDU is encrypted using the first key;

[0164] The encrypted MAC PDU is sent to the terminal.

[0165] In some embodiments, after encrypting and / or decrypting the transmitted data using the first key, the method further includes:

[0166] Determine whether setting the first key requires triggering an operation at the upper protocol layer;

[0167] If necessary, send the first request to the upper protocol layer to trigger the re-establishment process of the upper protocol layer.

[0168] The MAC of the network-side device determines whether the key reset needs to trigger upper-layer operations. If so, the MAC of the network-side device sends a request to the upper layer, including generating end-to-end RRC signaling (configuring end-to-end functions on the network side and the terminal side), processing of data by various protocol sublayers in the upper layer, and even triggering the upper-layer re-establishment process.

[0169] In some embodiments, before sending the first MAC CE to the terminal, the method further includes a step of determining whether the terminal needs to update the key, wherein determining whether the terminal needs to update the key includes any of the following:

[0170] Based on the results of the MAC layer's detection and analysis output, it is determined whether the key needs to be updated;

[0171] Based on instructions from the cloud, it was determined that a key update was required;

[0172] The key needs to be updated based on a preset time period.

[0173] In some embodiments, the parameters used by the MAC layer for detection and analysis include at least one of the following:

[0174] Statistical characteristics of terminal data packet reception and transmission, characteristics of terminal-requested service data packet transmission and reception, terminal mobility characteristics, mobility and service characteristics of other terminals in the cell, and statistical characteristics of air interface resource occupancy.

[0175] The MAC layer can generate security policies for the UE based on statistical characteristics of UE data packet reception and transmission, characteristics of UE-requested service data packet transmission and reception, UE mobility characteristics, mobility and service characteristics of other UEs in the cell, and statistical characteristics of air interface resource (including power, time-frequency domain resources, etc.) occupancy, using AI algorithms. Taking the characteristics of UE-transmitted data packets as an example: the base station's MAC records the size and frequency of each uplink data packet transmitted by the UE. These characteristics are then compared with the service model corresponding to the UE's service request. If the deviation exceeds the expected threshold (using traditional threshold comparison algorithms), or through AI algorithms (non-linear eigenvalue analysis), it is determined whether an abnormal state exists. If N abnormal states occur within a certain time period, it is determined that the UE's state has a security problem and the key needs to be updated.

[0176] In some embodiments, the cloud-based instructions include at least one of the following:

[0177] Key seed;

[0178] Key seed characteristics, including timeliness and length;

[0179] The first key applies to the object, scenario, business, or functional unit.

[0180] In some embodiments, the preset time period is defined, configured, or pre-configured by the protocol. It can be configured by the network-side RRC signaling or defined by the network-side MAC. It can be user-level or bearer-level.

[0181] In some embodiments, the first MAC CE is identified using the value of the Logical Channel Identifier (LCID), or the first MAC CE is identified using the value of the Enhanced Logical Channel Identifier (eLCID).

[0182] This embodiment defines a new MAC CE, namely the first MAC CE, which can be identified by LCID or eLCID.

[0183] If using LCID, select an available LCID value to identify the MAC CE. See Table 1 below.

[0184] Table 1. Values ​​of LCID for DL-SCH (Logical Channel Identifier for Downlink Control Channel)

[0185]

[0186]

[0187]

[0188]

[0189] If eLCID is used, the MAC CE is identified by either a 1-byte (one-octet eLCID) or a 2-byte (two-octet eLCID) available eLCID value, as shown in Tables 2 and 3 below. According to the protocol, the MAC CE type can be determined by both the LCID (an extended eLCID value of 33 or 34) and the eLCID.

[0190] Table 2 Values ​​of two-octet eLCID for DL-SCH

[0191]

[0192] Table 3 Values ​​of one-octet eLCID for DL-SCH

[0193] Codepoint Index LCID values XXX XXX Quick controlling of keys 0to 255 64to 319 reserved

[0194] As shown in Table 4, the first MAC CE sends the seed of the production key, and the receiving end produces the key to be used based on the seed.

[0195] Table 4

[0196]

[0197] The key seed has a length of n bytes, where n = 1, 2, 3, ... The key seed can be either variable or fixed in length, corresponding to a flexible MAC CE and a fixed MAC CE, respectively. If the length of the first MAC CE is variable, then the length of the key seed is variable; if the length of the first MAC CE is fixed, then the length of the key seed is fixed.

[0198] In some embodiments, a long key seed or a short key seed may be used depending on the required encryption level.

[0199] The key seed is the input to the key generator. By inputting the key seed into the key generator, a key that meets the requirements is generated.

[0200] In some embodiments, the key seed is generated in any of the following ways:

[0201] Randomly generated;

[0202] Generated according to the instructions of the upper protocol layer;

[0203] The data is generated using a random function based on a bit string of preset length from the terminal's identifier.

[0204] A preset bit string is extracted from the data packet to be encrypted and generated using a random function;

[0205] The characteristic value of the terminal is calculated, and after either extending or not extending the length, it is generated through a random function.

[0206] Based on the location coordinates of the terminal's movement trajectory, the length is extended or not, and then generated through a random function.

[0207] In this embodiment, rapid MAC key replacement or update can be achieved, enhancing system security; lossless data packet transmission can be achieved, and if MAC is re-established, MAC SDUs can continue to be sent, so data packets already sent from the cloud to the edge do not need to be lost; by re-establishing only the MAC layer on the network side and the terminal, the impact of security key changes on data transmission is reduced.

[0208] This invention also provides a key update method, executed by a terminal, such as... Figure 3 As shown, it includes:

[0209] Step 201: Receive the first Media Access Control (MAC) control unit CE from the network-side device, the first MAC CE including a key seed, and send an acknowledgment message to the network-side device;

[0210] Step 202: Generate a first key based on the key seed;

[0211] Step 203: Encrypt and / or decrypt the transmitted data using the first key.

[0212] In this embodiment, the network-side device sends a first MAC CE to the terminal. The first MAC CE includes a key seed. Then, the network-side device and the terminal can generate a first key based on the key seed, and use the first key to encrypt and / or decrypt the transmitted data, thereby enabling the MAC key to be updated quickly.

[0213] In some embodiments, the first key takes effect at the time of air interface transmission of the acknowledgment message. After the terminal sends an ACK to the first MAC CE, it uses the new key (i.e., the first key) to decrypt or encrypt data after the air interface subframe in which the ACK is sent.

[0214] In some embodiments, after receiving the first MAC CE from the network-side device, the method further includes:

[0215] Clear all HARQ process send buffers for Hybrid Automatic Repeat Requests.

[0216] In some embodiments, after receiving the first MAC CE from the network-side device, the method further includes:

[0217] For any transmission block that is not received correctly, a denial message is sent back to the network-side device;

[0218] For each successfully received transmission block, an acknowledgment message is sent back to the network-side device.

[0219] In some embodiments, encrypting and / or decrypting transmitted data using the first key includes:

[0220] For transport blocks that were not successfully sent and transport blocks sent for the first time, a new MAC protocol data unit (PDU) is constructed using the MAC service data unit (SDU) corresponding to the transport block; the MAC PDU is encrypted using the first key; and the encrypted MAC PDU is sent to the network-side device.

[0221] In some embodiments, the first MAC CE is identified using the value of the Logical Channel Identifier (LCID), or the first MAC CE is identified using the value of the Enhanced Logical Channel Identifier (eLCID).

[0222] In some embodiments, generating a first key based on the key seed includes:

[0223] The key seed is input into the key generator to generate the first key.

[0224] In some embodiments, the key generator is configured by the network-side device for the terminal, or pre-configured in the terminal.

[0225] The key generator can be configured by the network side when the UE accesses the network, or it can be pre-embedded in the terminal; the network side and the terminal side use the same or equivalent key generator.

[0226] This invention also provides a key update device, applied to network-side devices, such as... Figure 4 As shown, it includes a transceiver 11 and a processor 12.

[0227] The transceiver 11 is used to send a first Media Access Control (MAC) control unit CE to the terminal, the first MAC CE including a key seed for generating a first key; and to receive an acknowledgment message from the terminal in response to the first MAC CE.

[0228] The processor 12 is used to generate a first key according to the key seed, and to use the first key to encrypt and / or decrypt transmitted data.

[0229] In some embodiments, the effective time of the first key is the time when the air interface sends the confirmation message.

[0230] In some embodiments, the processor 12 is also configured to clear all Hybrid Automatic Repeat Request (HARQ) process send buffers.

[0231] In some embodiments, the transceiver 11 is also configured to send a denial message to the terminal for a transmission block that is not received correctly, and to send an acknowledgment message to the terminal for a transmission block that is successfully received.

[0232] In some embodiments, the processor 12 is specifically used to reconstruct a MAC protocol data unit (PDU) using the MAC service data unit (SDU) corresponding to the transport block that needs to be retransmitted as reported by the terminal; and to encrypt the MAC PDU using the first key.

[0233] The transceiver 11 is used to send the encrypted MAC PDU to the terminal.

[0234] In some embodiments, the processor 12 is further configured to determine whether setting the first key requires triggering an operation at the upper protocol layer; if so, to send a first request to the upper protocol layer to trigger the re-establishment process of the upper protocol layer.

[0235] In some embodiments, the processor 12 is further configured to perform a step of determining that the terminal needs to update the key, wherein determining that the terminal needs to update the key includes any of the following:

[0236] Based on the results of the MAC layer's detection and analysis output, it is determined whether the key needs to be updated;

[0237] Based on instructions from the cloud, it was determined that a key update was required;

[0238] The key needs to be updated based on a preset time period.

[0239] In some embodiments, the parameters used by the MAC layer for detection and analysis include at least one of the following:

[0240] Statistical characteristics of terminal data packet reception and transmission, characteristics of terminal-requested service data packet transmission and reception, terminal mobility characteristics, mobility and service characteristics of other terminals in the cell, and statistical characteristics of air interface resource occupancy.

[0241] In some embodiments, the cloud-based instructions include at least one of the following:

[0242] Key seed;

[0243] Key seed characteristics, including timeliness and length;

[0244] The first key applies to the object, scenario, business, or functional unit.

[0245] In some embodiments, the preset time period is defined, configured, or pre-configured by the protocol.

[0246] In some embodiments, the first MAC CE is identified using the value of the Logical Channel Identifier (LCID), or the first MAC CE is identified using the value of the Enhanced Logical Channel Identifier (eLCID).

[0247] In some embodiments, if the length of the first MAC CE is variable, then the length of the key seed is variable;

[0248] If the length of the first MAC CE is fixed, then the length of the key seed is fixed.

[0249] In some embodiments, the key seed is generated in any of the following ways:

[0250] Randomly generated;

[0251] Generated according to the instructions of the upper protocol layer;

[0252] The data is generated using a random function based on a bit string of preset length from the terminal's identifier.

[0253] A preset bit string is extracted from the data packet to be encrypted and generated using a random function;

[0254] The characteristic value of the terminal is calculated, and after either extending or not extending the length, it is generated through a random function.

[0255] Based on the location coordinates of the terminal's movement trajectory, the length is extended or not, and then generated through a random function.

[0256] This invention also provides a key update device, applied to a terminal, such as... Figure 4 As shown, it includes a transceiver 11 and a processor 12.

[0257] The transceiver 11 is used to receive a first Media Access Control (MAC) control unit CE from the network-side device. The first MAC CE includes a key seed and sends an acknowledgment message back to the network-side device.

[0258] The processor 12 is used to generate a first key according to the key seed; and to encrypt and / or decrypt transmitted data using the first key.

[0259] In some embodiments, the effective time of the first key is the time when the air interface sends the confirmation message.

[0260] In some embodiments, the processor 12 is also configured to clear all Hybrid Automatic Repeat Request (HARQ) process send buffers.

[0261] In some embodiments, the transceiver 11 is further configured to send a denial message to the network-side device for a transmission block that is not received correctly, and to send an acknowledgment message to the network-side device for a transmission block that is successfully received.

[0262] In some embodiments, the processor 12 is specifically configured to, for transport blocks that were not successfully transmitted and transport blocks transmitted for the first time, reconstruct MAC protocol data units (PDUs) using the MAC service data units (SDUs) corresponding to the transport blocks; and encrypt the MAC PDUs using the first key;

[0263] The transceiver 11 is used to send the encrypted MAC PDU to the network-side device.

[0264] In some embodiments, the first MAC CE is identified using the value of the Logical Channel Identifier (LCID), or the first MAC CE is identified using the value of the Enhanced Logical Channel Identifier (eLCID).

[0265] In some embodiments, the processor 12 is specifically configured to input the key seed into a key generator to generate the first key.

[0266] In some embodiments, the key generator is configured by the network-side device for the terminal, or pre-configured in the terminal.

[0267] This invention also provides a key update device, such as... Figure 5 As shown, it includes a memory 21, a processor 22, and a computer program stored on the memory 21 and executable on the processor 22; when the processor 22 executes the program, it implements the key update method as described above.

[0268] In some embodiments, the processor 22 is configured to send a first Media Access Control (MAC) control unit CE to the terminal, the first MAC CE including a key seed for generating a first key; receive an acknowledgment message from the terminal in response to the first MAC CE; generate the first key according to the key seed; and use the first key to encrypt and / or decrypt transmitted data.

[0269] In some embodiments, the effective time of the first key is the time when the air interface sends the confirmation message.

[0270] In some embodiments, the processor 22 is also configured to clear all Hybrid Automatic Repeat Request (HARQ) process send buffers.

[0271] In some embodiments, the processor 22 is further configured to send a denial message to the terminal for a transport block that is not received correctly, and to send an acknowledgment message to the terminal for a transport block that is successfully received.

[0272] In some embodiments, the processor 22 is specifically used to reconstruct a MAC Protocol Data Unit (PDU) using the MAC Service Data Unit (SDU) corresponding to the transport block that needs to be retransmitted as reported by the terminal; encrypt the MAC PDU using the first key; and send the encrypted MAC PDU to the terminal.

[0273] In some embodiments, the processor 22 is further configured to determine whether setting the first key requires triggering an operation of the upper protocol layer; if so, to send a first request to the upper protocol layer to trigger the re-establishment process of the upper protocol layer.

[0274] In some embodiments, the processor 22 is further configured to perform a step of determining that the terminal needs to update the key, wherein determining that the terminal needs to update the key includes any of the following:

[0275] Based on the results of the MAC layer's detection and analysis output, it is determined whether the key needs to be updated;

[0276] Based on instructions from the cloud, it was determined that a key update was required;

[0277] The key needs to be updated based on a preset time period.

[0278] In some embodiments, the parameters used by the MAC layer for detection and analysis include at least one of the following:

[0279] Statistical characteristics of terminal data packet reception and transmission, characteristics of terminal-requested service data packet transmission and reception, terminal mobility characteristics, mobility and service characteristics of other terminals in the cell, and statistical characteristics of air interface resource occupancy.

[0280] In some embodiments, the cloud-based instructions include at least one of the following:

[0281] Key seed;

[0282] Key seed characteristics, including timeliness and length;

[0283] The first key applies to the object, scenario, business, or functional unit.

[0284] In some embodiments, the preset time period is defined, configured, or pre-configured by the protocol.

[0285] In some embodiments, the first MAC CE is identified using the value of the Logical Channel Identifier (LCID), or the first MAC CE is identified using the value of the Enhanced Logical Channel Identifier (eLCID).

[0286] In some embodiments, if the length of the first MAC CE is variable, then the length of the key seed is variable;

[0287] If the length of the first MAC CE is fixed, then the length of the key seed is fixed.

[0288] In some embodiments, the key seed is generated in any of the following ways:

[0289] Randomly generated;

[0290] Generated according to the instructions of the upper protocol layer;

[0291] The data is generated using a random function based on a bit string of preset length from the terminal's identifier.

[0292] A preset bit string is extracted from the data packet to be encrypted and generated using a random function;

[0293] The characteristic value of the terminal is calculated, and after either extending or not extending the length, it is generated through a random function.

[0294] Based on the location coordinates of the terminal's movement trajectory, the length is extended or not, and then generated through a random function.

[0295] In some embodiments, the processor 22 is configured to receive a first Media Access Control (MAC) control unit CE from a network-side device, the first MAC CE including a key seed, and to send an acknowledgment message to the network-side device; generate a first key based on the key seed; and use the first key to encrypt and / or decrypt transmitted data.

[0296] In some embodiments, the effective time of the first key is the time when the air interface sends the confirmation message.

[0297] In some embodiments, the processor 22 is also configured to clear all Hybrid Automatic Repeat Request (HARQ) process send buffers.

[0298] In some embodiments, the processor 22 is further configured to send a denial message to the network-side device for a transport block that is not received correctly, and to send an acknowledgment message to the network-side device for a transport block that is successfully received.

[0299] In some embodiments, the processor 22 is specifically configured to, for transport blocks that were not successfully transmitted and transport blocks transmitted for the first time, reconstruct MAC protocol data units (PDUs) using the MAC service data units (SDUs) corresponding to the transport blocks; encrypt the MAC PDUs using the first key; and send the encrypted MAC PDUs to the network-side device.

[0300] In some embodiments, the first MAC CE is identified using the value of the Logical Channel Identifier (LCID), or the first MAC CE is identified using the value of the Enhanced Logical Channel Identifier (eLCID).

[0301] In some embodiments, the processor 22 is specifically configured to input the key seed into a key generator to generate the first key.

[0302] In some embodiments, the key generator is configured by the network-side device for the terminal, or pre-configured in the terminal.

[0303] This invention also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps in the key update method described above.

[0304] Computer-readable media, including both permanent and non-permanent, removable and non-removable media, can store information using any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage, or any other non-transferable medium that can be used to store information accessible to the computer-readable terminal device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0305] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A key update method characterized by comprising: The method is performed by a network side device, comprising: sending a first media access control (MAC) control element (CE) to a terminal, wherein the first MAC CE comprises a key seed, and the key seed is used to generate a first key; receiving an acknowledgement message fed back by the terminal in response to the first MAC CE; generating the first key according to the key seed, and using the first key to encrypt and / or decrypt transmission data; a time point for the first key to take effect is a time point for air interface transmission of the acknowledgement message.

2. The key update method according to claim 1, characterized by, After receiving the acknowledgement message fed back by the terminal in response to the first MAC CE, the method further comprises: emptying all hybrid automatic repeat request (HARQ) process sending buffers.

3. The key update method according to claim 1, characterized by, After receiving the acknowledgement message fed back by the terminal in response to the first MAC CE, the method further comprises: feeding back a negative acknowledgement message to the terminal for a transmission block that is not correctly received; feeding back an acknowledgement message to the terminal for a transmission block that is successfully received.

4. The key update method according to claim 1, characterized by, The step of using the first key to encrypt and / or decrypt transmission data comprises: reconstructing a MAC protocol data unit (PDU) using a MAC service data unit (SDU) corresponding to a transmission block that needs to be retransmitted and fed back by the terminal; encrypting the MAC PDU using the first key; sending the encrypted MAC PDU to the terminal.

5. The key update method according to claim 1, wherein After using the first key to encrypt and / or decrypt transmission data, the method further comprises: judging whether the first key needs to trigger an operation of an upper layer protocol layer; if so, sending a first request to the upper layer protocol layer to trigger a reestablishment process of the upper layer protocol layer.

6. The key update method according to claim 1, wherein Before sending the first MAC CE to the terminal, the method further comprises a step of judging that the terminal needs to update a key, and the step of judging that the terminal needs to update the key comprises any one of the following: judging that the key needs to be updated according to a result output by detection and analysis of a MAC layer; judging that the key needs to be updated according to an indication from a cloud side; judging that the key needs to be updated according to a preset time period.

7. The key update method according to claim 6, wherein The parameters used by the MAC layer for detection and analysis comprise at least one of the following: statistical features of terminal data packet reception and transmission, features of service data packet transmission and reception applied for by the terminal, mobility features of the terminal, mobility features and service features of other terminals in the cell, and air interface resource occupation statistical features.

8. The key update method according to claim 6, wherein The indication from the cloud side comprises at least one of the following: a key seed; a feature of the key seed, including time effectiveness and length; an object or a scenario or a service or a function to which the first key is applicable.

9. The key update method according to claim 6, wherein The preset time period is defined by a protocol, configured or preconfigured.

10. The key update method according to claim 1, wherein A value of a logical channel identifier (LCID) is used to identify the first MAC CE, or a value of an enhanced logical channel identifier (eLCID) is used to identify the first MAC CE.

11. The key update method according to claim 1, wherein: if a length of the first MAC CE is variable, a length of the key seed is variable; if the length of the first MAC CE is fixed, the length of the key seed is fixed.

12. The key update method according to claim 1, wherein The key seed is generated in any one of the following ways: randomly generated; generated according to an indication of an upper layer protocol layer. According to a preset length bit string in the terminal identity, a random function is generated; According to a preset bit string in the intercepted data packet, a random function is generated; According to the terminal feature value, a random function is generated after length expansion or not; According to the position coordinates of the terminal moving track, a random function is generated after length expansion or not.

13. A key update method characterized by comprising: Executed by a terminal, comprising: Receiving a first media access control (MAC) control element (CE) from a network side device, wherein the first MAC CE includes a key seed, and feeding back a confirmation message to the network side device; Generating a first key according to the key seed; Encrypting and / or decrypting transmission data by using the first key; The effective time point of the first key is the air interface sending time point of feeding back the confirmation message.

14. The key update method according to claim 13, wherein After receiving the first MAC CE from the network side device, the method further comprises: Emptying all hybrid automatic repeat request (HARQ) process sending buffers.

15. The key update method according to claim 13, wherein After receiving the first MAC CE from the network side device, the method further comprises: For a transmission block that is not correctly received, feeding back a denial message to the network side device; For a transmission block that is successfully received, feeding back a confirmation message to the network side device.

16. The key update method according to claim 13, wherein Encrypting and / or decrypting transmission data by using the first key comprises: For a transmission block that is not successfully sent and a transmission block that is sent for the first time, reassembling a MAC protocol data unit (PDU) by using a MAC service data unit (SDU) corresponding to the transmission block; encrypting the MAC PDU by using the first key; and sending the encrypted MAC PDU to the network side device.

17. The key update method according to claim 13, wherein The first MAC CE is identified by using a value of a logical channel identifier (LCID), or the first MAC CE is identified by using a value of an enhanced logical channel identifier (eLCID).

18. The key update method according to claim 13, wherein, Generating a first key according to the key seed comprises: Inputting the key seed into a key generator to generate the first key.

19. The key update method according to claim 18, wherein The key generator is configured to the terminal by the network side device, or is pre-configured in the terminal.

20. A key update apparatus characterized by comprising: Applied to a network side device, comprising a transceiver and a processor, The transceiver is configured to send a first media access control (MAC) control element (CE) to a terminal, wherein the first MAC CE includes a key seed, and configured to generate a first key; and receive a confirmation message fed back by the terminal to the first MAC CE; The processor is configured to generate a first key according to the key seed, and encrypt and / or decrypt transmission data by using the first key; The effective time point of the first key is the air interface sending time point of feeding back the confirmation message.

21. A key update apparatus characterized by comprising: Applied to a terminal, comprising a transceiver and a processor, The transceiver is configured to receive a first media access control (MAC) control element (CE) from a network side device, wherein the first MAC CE includes a key seed, and feed back a confirmation message to the network side device; The processor is configured to generate a first key according to the key seed, and encrypt and / or decrypt transmission data by using the first key; The effective time point of the first key is the air interface sending time point of feeding back the confirmation message.

22. A key update apparatus comprising a memory, a processor, and a computer program stored on the memory and executable on the processor; characterized in that, The processor implements the key update method as claimed in any one of claims 1-19 when executing the program.

23. A computer readable storage medium having stored thereon a computer program, characterized in that, The program, when executed by the processor, implements the steps of the key update method as claimed in any one of claims 1-19.

Citation Information

Patent Citations

  • Encryption key updates in wireless communication systems

    US20160021066A1

  • Data transmission method, user equipment and network side device

    WO2017091959A1