Key generation method and device

By selecting a secondary base station with IAB donor functionality and generating KIAB1, the KIAB inconsistency issue between the IAB node and the IAB donor is resolved, enabling secure tunnel establishment in NE-DC, NR-DC, or NGEN-DC scenarios, and improving communication security and reliability.

CN116508356BActive Publication Date: 2025-10-14HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202080106763.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-11-06
Publication Date
2025-10-14
Estimated Expiration
2040-11-06

AI Technical Summary

Technical Problem

No KIAB generation scheme is provided between the IAB node and the IAB donor. As a result, the KIAB generated by the IAB node is different from the KIAB generated by the IAB donor, and a secure tunnel cannot be established normally.

Method used

The first access network device selects a second access network device with IAB donor function as the secondary base station, obtains the key input parameters, generates KIAB1 based on the primary base station key, and sends KIAB1 to the IAB node, ensuring that the IAB node and the IAB donor use the same IAB key as the authentication credential to establish a secure tunnel.

Benefits of technology

In dual-connection scenarios such as NE-DC, NR-DC, or NGEN-DC, it ensures that the IAB node and IAB donor can establish a secure tunnel using the same IAB key as the authentication credential, improving communication security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116508356B_ABST
    Figure CN116508356B_ABST
Patent Text Reader

Abstract

The application discloses a key generation method and device, and relates to the technical field of communication, which is used for enabling an IAB donor and an IAB node to use the same K IAB . The key generation method comprises the following steps: a first access network device determines that a first device registered to a 5G core network through the first access network device is an IAB node; in the case where a secondary base station needs to be selected for the first device, the first access network device judges whether the first access network device has an IAB donor function; if the first access network device has the IAB donor function, the first access network device selects a third access network device as the secondary base station of the first device; and the first access network device generates a second IAB key K IAB2 according to a secondary base station key, K IAB2 , which is used for establishing a secure tunnel between the first access network device and the first device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a key generation method and device. Background Art

[0002] In order to reduce the construction burden of wired transmission networks and provide flexible and dense new radio (NR) deployment, the fifth generation (5G) mobile communication system uses integrated access backhaul (IAB) technology. Based on IAB technology, base stations can be divided into IAB nodes (node) and IAB donor base stations (donors). The IAB donor is used to provide a user equipment interface to the core network and support the wireless backhaul function of the IAB node. The IAB node can support wireless access of terminal devices and wireless backhaul of data. Since data can be exchanged between the IAB donor and the IAB node through the wireless backhaul link, there is no need to lay cables between the IAB donor and the IAB node. This makes the deployment of the IAB node more flexible.

[0003] In order to ensure the communication security of the F1 interface between the IAB node and the IAB donor, a secure tunnel (such as an Internet Protocol Security (IPsec) secure tunnel) can be established between the IAB node and the IAB donor. In the process of establishing the secure tunnel, the IAB node and the IAB donor need to use the same IAB key K. IAB as authentication credentials.

[0004] To ensure network coverage and service transmission reliability, the IAB node can be enabled to support dual connectivity (DC) to cope with abnormal situations that may occur in the wireless backhaul link, such as wireless backhaul link interruption or congestion.

[0005] Currently, the industry does not provide K for other dual connectivity types except evolved-universal mobiletelecommunications system terrestrial radio access (EUTRA)-NR dual connection (EN-DC), such as NR-EUTRA dual connection (NE-DC) and NR-DC. IABGeneration scheme. As a result, it can cause the K IAB generated by the IAB donor to be different, so that the IAB node and the IAB donor cannot normally establish a secure tunnel. IAB SUMMARY

[0006] The present application provides a key generation method and device for ensuring that the IAB donor and the IAB node generate the same K IAB .

[0007] In a first aspect, a key generation method is provided, comprising: a first access network device determining that a first device registered to a 5G core network through the first access network device is an IAB node; in a case where a secondary base station needs to be selected for the first device, the first access network device judging whether the first access network device itself has an IAB donor function; if the first access network device does not have the IAB donor function, the first access network device selecting a second access network device having the IAB donor function as the secondary base station of the first device; the first access network device obtaining a first key input parameter associated with the second access network device; the first access network device generating a first IAB key K IAB1 according to a master base station key and the first key input parameter, the master base station key being used for security protection of communication between the master base station (the first access network device) and the first device, K IAB1 being used for establishing a secure tunnel between the second access network device and the first device; and the first access network device sending K IAB1 to the second access network device.

[0008] Based on the above technical solution, after the IAB node (for example, the first device) accesses the 5G core network through the first access network device, the first access network device can select a second access network device having the IAB donor function as the secondary base station for the first device in a case where the first access network device itself does not have the IAB donor function, so as to ensure that there is one access network device as the IAB donor to provide corresponding services for the first device in a dual connectivity scenario. And in a NE-DC, NR-DC or NGEN-DC dual connectivity scenario, the first access network device generates a first IAB key K IAB1 according to a master base station key and a first key input parameter, and sends K IAB1 to the first access network device. In this way, the IAB node and the IAB donor uniformly use the IAB key generated based on the master base station key, so as to ensure that the IAB node and the IAB donor can establish a secure tunnel with the same IAB key as authentication credentials.

[0009] ​In a possible design, the first access network device selects a second access network device with an IAB donor function as a secondary base station of the first device, including: the first access network device sends a first request message to the second device, where the first request message comprises an identifier of the first device; and the first access network device receives a first response message sent by the second device, where the first response message comprises an identifier of the second access network device.

[0010] In a possible design, the first key input parameter comprises a first IP address and a second IP address, the first IP address being an IP address used by the first device to communicate with the IAB donor, and the second IP address being an IP address used by the second access network device to communicate with the IAB node.

[0011] In a possible design, the first access network device obtains the first key input parameter associated with the second access network device, including: the first access network device sends a secondary base station configuration message to the second access network device, where the secondary base station configuration message is used to configure the second access network device as a secondary base station of the first device, and the secondary base station configuration message comprises first indication information and / or second indication information, the first indication information being used to request the first IP address, and the second indication information being used to request the second IP address; and the first access network device receives a secondary base station configuration response message sent by the second access network device, where the secondary base station configuration response message comprises the first IP address and / or the second IP address. Based on this design, in the case that the first IP address is allocated by the second access network device, the first access network device obtains the first key input parameter by multiplexing an existing process, which is beneficial to saving signaling overhead and simplifying an operation process.

[0012] In a possible design, the secondary base station configuration message comprises a secondary base station key derived from a master base station key, and the secondary base station key is used to perform security protection on communication between the secondary base station and the first device.

[0013] In a possible design, the key generation method further includes: the first access network device sends the first IP address to the first device.

[0014] In a possible design, the first access network device acquires the first key input parameter associated with the second access network device, including: the first access network device receiving an IP address notification message sent by the first device, the IP address notification message including a first IP address; the first access network device sending a secondary base station configuration message to the second access network device, the secondary base station configuration message being used for configuring the second access network device as a secondary base station of the first device, and the secondary base station configuration message including second indication information used for requesting a second IP address; and the first access network device receiving a secondary base station configuration response message sent by the second access network device, the secondary base station configuration response message including the second IP address. Based on this design, in a case where the first IP address is allocated by the second device, the first access network device can acquire the first IP address through the first device and acquire the second IP address through the second access network device.

[0015] In a possible design, the key generation method further includes: if the first access network device has an IAB donor function, the first access network device selects a third access network device as a secondary base station of the first device; the first access network device acquires a second key input parameter associated with the first access network device; and the first access network device generates a second IAB key K IAB2 , K IAB2 for establishing a secure tunnel between the first access network device and the first device.

[0016] In a possible design, the second key input parameter includes: a first IP address and a third IP address, the first IP address being an IP address used by the first device to communicate with an IAB donor, and the third IP address being an IP address used by the first access network device to communicate with an IAB node.

[0017] In a possible design, the first access network device acquires the second key input parameter associated with the first access network device, including: the first access network device allocating a first IP address for the first device; and the first access network device acquiring a third IP address from a database.

[0018] In a possible design, the first access network device acquires the second key input parameter associated with the first access network device, including: the first access network device receiving an IP address notification message sent by the first device, the IP address notification message including a first IP address; and the first access network device acquiring a third IP address from a database.

[0019] In a second aspect, a key generation method is provided, including: receiving, by a second access network device, a secondary base station configuration message sent by a first access network device, the secondary base station configuration message being used to configure the second access network device as a secondary base station of the first device; determining, by the second access network device, whether the second access network device has an IAB donor function when the secondary base station configuration message includes third indication information, the third indication information being used to indicate that the first device is an IAB node; obtaining, by the second access network device, a first IAB key K IAB1 from the first access network device when the second access network device has an IAB donor function, the K IAB1 being used to establish a secure tunnel between the second access network device and the first device, and the K IAB1 being generated according to a master base station key, the master base station key being used to securely protect communication between the first access network device and the first device.

[0020] According to the above technical solution, the second access network device with the IAB donor function is configured as the secondary base station of the first device, so that the access network device with the IAB donor function can provide corresponding services for the IAB node (i.e., the first device) in the dual connectivity scenario. The second access network device receives the K IAB1 , so that the IAB node and the IAB donor uniformly use the IAB key generated according to the master base station key, and the IAB node and the IAB donor can establish a secure tunnel using the same IAB key as authentication credentials.

[0021] In a possible design, the K IAB1 is generated according to the master base station key, including: the K IAB1 is generated according to the master base station key and a first key input parameter. The first key input parameter includes a first IP address and a second IP address, the first IP address being an IP address used by the first device to communicate with the IAB donor, and the second IP address being an IP address used by the second access network device to communicate with the IAB node.

[0022] In a possible design, the secondary base station configuration message further includes first indication information and / or second indication information, the first indication information being used to request the first IP address, and the second indication information being used to request the second IP address.

[0023] In a possible design, the key generation method further includes: sending, by the second access network device, a secondary base station configuration response message to the first access network device, the secondary base station configuration response message including the first IP address and / or the second IP address.

[0024] In a possible design, the second access network device obtains the KIAB1 , including: the second access network device receives the secondary base station reconfiguration completion message sent by the first access network device, the secondary base station reconfiguration completion message includes the K IAB1 .

[0025] In one possible design, the second access network device obtains K from the first access network device. IAB1 , including: the second access network device sends a key request message to the first access network device, the key request message is used to request the K IAB1 The second access network device receives a key response message sent by the first access network device, the key response message includes the K IAB1 .

[0026] In one possible design, the key request message also includes the first IP address and / or the second IP address.

[0027] In a third aspect, a key generation method is provided, which is applied to a scenario where a first device is connected to a primary base station and a secondary base station, and the first device has an IAB node function. The key generation method includes: the first device determines the type of dual connection based on the communication standard supported by the primary base station, the communication standard supported by the secondary base station, and the communication standard supported by the core network; when the type of dual connection is NE-DC, NR-DC, or NGEN-DC, the first device generates an IAB key K based on the primary base station key. IAB The master base station key is used to protect the communication security between the first device and the master base station.

[0028] Based on the above technical solution, the IAB node determines the type of dual connectivity, and thus in the NE-DC, NR-DC or NGEN-DC scenario, the IAB node uses the primary base station key to generate the IAB key K IAB , so that the IAB node and IAB donor can uniformly use the IAB key generated by the master base station key, thereby ensuring that the IAB node and IAB donor can use the same IAB key as the authentication credential to establish a secure tunnel.

[0029] In one possible design, the above-mentioned key generation method also includes: the first device receives a broadcast message from the main base station; the first device determines the communication standard supported by the main base station based on the configuration parameters in the broadcast message, and the configuration parameters include one or more of the following: base station identifier, logical cell identifier, physical cell identifier, uplink frequency or downlink frequency.

[0030] In one possible design, the first device determines the communication standard supported by the main base station based on the configuration parameters in the broadcast message, including: when the configuration parameters in the broadcast message belong to the 5G communication system, the first device determines that the main base station supports the 5G communication standard; or, when the configuration parameters in the broadcast message belong to the 4G communication system, the first device determines that the main base station supports the 4G communication standard.

[0031] In one possible design, the above-mentioned key generation method also includes: the first device receives an RRC reconfiguration message sent by the primary base station, the RRC reconfiguration message includes secondary cell group configuration information; the first device determines the communication standard supported by the secondary base station based on the secondary cell group configuration information.

[0032] In one possible design, the first device determines the communication standard supported by the secondary base station based on the RRC reconfiguration message, including: when the secondary cell group configuration information belongs to the 5G communication standard, the first device determines that the secondary base station supports the 5G communication standard; or, when the secondary cell group configuration information belongs to the 4G communication standard, the first device determines that the secondary base station supports the 4G communication standard.

[0033] In one possible design, the above-mentioned key generation method also includes: the first device receives a broadcast message sent by the main base station; the first device determines the communication standard supported by the core network based on the cell configuration information in the broadcast message.

[0034] In one possible design, the first device determines the communication standard supported by the core network based on the cell configuration information in the broadcast message, including: when the cell configuration information belongs to the 5G communication standard, the first device determines that the core network supports the 5G communication standard; or, when the cell configuration information belongs to the 4G communication standard, the first device determines that the core network supports the 4G communication standard.

[0035] In one possible design, the first device determines the type of dual connection based on the communication standard supported by the main base station, the communication standard supported by the secondary base station, and the communication standard supported by the core network, including: when the main base station supports the 5G network standard, the secondary base station supports the 4G network standard, and the core network supports the 5G network standard, the first device determines the dual connection type as NE-DC; or, when the main base station supports the 5G network standard, the secondary base station supports the 5G network standard, and the core network supports the 5G network standard, the first device determines the dual connection type as NR-DC; or, when the main base station supports the 4G network standard, the secondary base station supports the 5G network standard, and the core network supports the 5G network standard, the first device determines the dual connection type as NGEN-DC; or, when the main base station supports the 4G network standard, the secondary base station supports the 5G network standard, and the core network supports the 4G network standard, the first device determines the dual connection type as EN-DC.

[0036] In a fourth aspect, a key generation method is provided, the method comprising: a first access network device determining that a first device registered with a network through the first access network device is an IAB node; if the first access network device has an IAB donor function, the first access network device selecting a third access network device as a secondary base station of the first device; the first access network device generating a second IAB key K according to the secondary base station key IAB2 , K IAB2 The secondary base station key is used to establish a secure tunnel between the first access network device and the first device, and the secondary base station key is used to securely protect communications between the secondary base station and the first device.

[0037] Based on the above technical solution, since the first access network device determines that the first device is an IAB node and the first access network device has the IAB donor function, the first access network device can serve as the IAB donor of the first device. Furthermore, in the dual connection scenario, the first access network device generates K according to the secondary base station key. IAB2 , thereby ensuring that the IAB node and IAB donor use the same IAB key generated by the secondary base station key, and further ensuring that the IAB node and IAB donor can use the same IAB key as the authentication credential to establish a secure tunnel.

[0038] In one possible design, the secondary base station key is derived based on the primary base station key, and the primary base station key is used to securely protect communications between the first access network device and the first device.

[0039] In one possible design, the first access network device generates K according to the secondary base station key. IAB2 Afterwards, the method further includes: the first access network device sending a secondary base station configuration message to the second access network device, the secondary base station configuration message including a secondary base station key; and the first access network device receiving a secondary base station configuration response message sent by the second access network device.

[0040] In one possible design, the first access network device generates K according to the secondary base station key. IAB2 , including: after sending the secondary base station configuration message, the first access network device generates K according to the secondary base station key IAB2 .

[0041] In one possible design, the first access network device generates K according to the secondary base station key. IAB2 , including: after receiving the secondary base station configuration response message, the first access network device generates K according to the secondary base station key IAB2 .

[0042] In one possible design, the above-mentioned key generation method also includes: if the first access network device does not have the IAB donor function, the first access network device selects a second access network device with the IAB donor function as the secondary base station of the first device; the first access network device sends a secondary base station configuration message to the second access network device, and the secondary base station configuration message includes the secondary base station key.

[0043] In a fifth aspect, a key generation method is provided, which is applied to a scenario where a first device is connected to a primary base station and a secondary base station, and the first device has an IAB node function. The key generation method includes: the first device determines the type of dual connection according to the communication standard supported by the primary base station, the communication standard supported by the secondary base station, and the communication standard supported by the core network; when the type of dual connection is NE-DC, NR-DC or NGEN-DC, the first device generates an IAB key K according to the secondary base station key. IAB The secondary base station key is used to protect the communication security between the first device and the secondary base station.

[0044] Based on the above technical solution, the IAB node determines the type of dual connectivity, and thus in the NE-DC, NR-DC or NGEN-DC scenario, the IAB node uses the secondary base station key to generate the IAB key K IAB , so that the IAB node and IAB donor use the same IAB key generated by the secondary base station key, thereby ensuring that the IAB node and IAB donor can use the same IAB key as the authentication credential to establish a secure tunnel.

[0045] In one possible design, the above-mentioned key generation method also includes: the first device receives a broadcast message from the main base station; the first device determines the communication standard supported by the main base station based on the configuration parameters in the broadcast message, and the configuration parameters include one or more of the following: base station identifier, logical cell identifier, physical cell identifier, uplink frequency or downlink frequency.

[0046] In one possible design, the first device determines the communication standard supported by the main base station based on the configuration parameters in the broadcast message, including: when the configuration parameters in the broadcast message belong to the 5G communication system, the first device determines that the main base station supports the 5G communication standard; or, when the configuration parameters in the broadcast message belong to the 4G communication system, the first device determines that the main base station supports the 4G communication standard.

[0047] In one possible design, the above-mentioned key generation method also includes: the first device receives an RRC reconfiguration message sent by the primary base station, the RRC reconfiguration message includes secondary cell group configuration information; the first device determines the communication standard supported by the secondary base station based on the secondary cell group configuration information.

[0048] In a possible design, the first device determines the communication mode supported by the secondary base station according to the RRC reconfiguration message, including: when the secondary cell group configuration information belongs to a 5G communication mode, the first device determines that the secondary base station supports the 5G communication mode; or when the secondary cell group configuration information belongs to a 4G communication mode, the first device determines that the secondary base station supports the 4G communication mode.

[0049] In a possible design, the key generation method further includes: the first device receives a broadcast message sent by the primary base station; and the first device determines the communication mode supported by the core network according to cell configuration information in the broadcast message.

[0050] In a possible design, the first device determines the communication mode supported by the core network according to the cell configuration information in the broadcast message, including: when the cell configuration information belongs to a 5G communication mode, the first device determines that the core network supports the 5G communication mode; or when the cell configuration information belongs to a 4G communication mode, the first device determines that the core network supports the 4G communication mode.

[0051] In a possible design, the first device determines the type of the dual connectivity according to the communication mode supported by the primary base station, the communication mode supported by the secondary base station, and the communication mode supported by the core network, including: when the primary base station supports a 5G network mode, the secondary base station supports a 4G network mode, and the core network supports the 5G network mode, the first device determines that the type of the dual connectivity is NE-DC; or when the primary base station supports the 5G network mode, the secondary base station supports the 5G network mode, and the core network supports the 5G network mode, the first device determines that the type of the dual connectivity is NR-DC; or when the primary base station supports a 4G network mode, the secondary base station supports the 5G network mode, and the core network supports the 5G network mode, the first device determines that the type of the dual connectivity is NGEN-DC; or when the primary base station supports the 4G network mode, the secondary base station supports the 5G network mode, and the core network supports the 4G network mode, the first device determines that the type of the dual connectivity is EN-DC.

[0052] In a sixth aspect, a key generation method is provided, which is applied to a scenario where a first device connects a primary base station and a secondary base station, and the first device has an IAB node function. The key generation method includes: the first device learns that the primary base station or the secondary base station is an IAB donor; when the primary base station is the IAB donor, the first device generates an IAB key according to a primary base station key and a key input parameter, the IAB key is used to establish a secure tunnel between the IAB node and the IAB donor, and the primary base station key is used to protect the communication between the first device and the primary base station; or when the secondary base station is the IAB donor, the first device generates the IAB key according to a secondary base station key and the key input parameter, and the secondary base station key is used to protect the communication between the first device and the secondary base station.

[0053] Based on the above technical solutions, in the case of the master base station as the IAB donor, the IAB node and the IAB donor are ensured to generate the IAB key by using the master base station key. In the case of the secondary base station as the IAB donor, the IAB node and the IAB donor are ensured to generate the IAB key by using the secondary base station key. In this way, in the dual-connection scenario, the IAB donor and the IAB node can establish a secure tunnel by using the same IAB key as authentication credentials.

[0054] In a possible design, the first device learns that the master base station or the secondary base station is the IAB donor, including: when the first device receives fourth indication information, the first device learns that the master base station is the IAB donor, the fourth indication information being used to indicate that the master base station is the IAB donor; or when the first device receives fifth indication information, the first device learns that the secondary base station is the IAB donor, the fifth indication information being used to indicate that the secondary base station is the IAB donor.

[0055] In a possible design, the first device learns that the master base station or the secondary base station is the IAB donor, including: when the first device establishes a wireless backhaul link with the master base station, the first device learns that the master base station is the IAB donor; or when the first device establishes a wireless backhaul link with the secondary base station, the first device learns that the secondary base station is the IAB donor.

[0056] In a possible design, the first device learns that the master base station or the secondary base station is the IAB donor, including: the first device acquires a frequency band supported by the master base station and a frequency band supported by the secondary base station; when the frequency band supported by the master base station is higher than the frequency band supported by the secondary base station, the first device learns that the master base station is the IAB donor; or when the frequency band supported by the master base station is lower than the frequency band supported by the secondary base station, the first device learns that the secondary base station is the IAB donor.

[0057] In a possible design, the first device learns that the master base station or the secondary base station is the IAB donor, including: when the first device receives sixth indication information broadcast by the master base station, the first device learns that the master base station is the IAB donor; or when the first device receives the sixth indication information broadcast by the secondary base station, the first device learns that the secondary base station is the IAB donor; where the sixth indication information is used to indicate that the base station has the IAB donor function.

[0058] In a seventh aspect, a communication apparatus is provided, which is applied to a first access network device. The communication apparatus comprises a processing module and a communication module. The processing module is configured to determine that a first device registered to a 5G core network is an IAB node; in a case where a secondary base station needs to be selected for the first device, determine whether the first access network device has an IAB donor function; if the first access network device does not have the IAB donor function, select a second access network device having the IAB donor function as the secondary base station of the first device; obtain a first key input parameter associated with the second access network device; generate a first IAB key K IAB1 based on a master base station key and the first key input parameter, the master base station key being used for security protection of communication between the master base station (the first access network device) and the first device, and the first IAB key K IAB1 being used for establishment of a secure tunnel between the second access network device and the first device. The communication module is configured to send the K IAB1 to the second access network device.

[0059] In a possible design, the communication module is further configured to send, to the second device, a first request message, the first request message comprising an identifier of the first device; and receive a first response message sent by the second device, the first response message comprising an identifier of the second access network device.

[0060] In a possible design, the first key input parameter comprises a first IP address and a second IP address, the first IP address being an IP address used by the first device for communication with the IAB donor, and the second IP address being an IP address used by the second access network device for communication with the IAB node.

[0061] In a possible design, the communication module is configured to send, to the second access network device, a secondary base station configuration message, the secondary base station configuration message being used for configuring the second access network device as the secondary base station of the first device, the secondary base station configuration message comprising first indication information and / or second indication information, the first indication information being used for requesting the first IP address, and the second indication information being used for requesting the second IP address; and receive a secondary base station configuration response message sent by the second access network device, the secondary base station configuration response message comprising the first IP address and / or the second IP address.

[0062] In a possible design, the secondary base station configuration message comprises a secondary base station key derived from the master base station key, the secondary base station key being used for security protection of communication between the secondary base station and the first device.

[0063] In a possible design, the communication module is further configured to send, to the first device, the first IP address.

[0064] In one possible design, the communication module is also used to receive an IP address notification message sent by the first device, the IP address notification message includes the first IP address; send a secondary base station configuration message to the second access network device, the secondary base station configuration message is used to configure the second access network device as a secondary base station of the first device, the secondary base station configuration message includes second indication information, and the second indication information is used to request a second IP address; receive a secondary base station configuration response message sent by the second access network device, the secondary base station configuration response message includes the second IP address.

[0065] In one possible design, the processing module is further configured to select a third access network device as a secondary base station of the first device if the processing module itself has an IAB donor function; obtain a second key input parameter associated with the first access network device; and generate a second IAB key K based on the primary base station key and the second key input parameter. IAB2 , K IAB2 Used to establish a secure tunnel between itself and the first device.

[0066] In one possible design, the second key input parameters include: a first IP address and a third IP address, where the first IP address is the IP address used by the first device to communicate with the IAB donor, and the third IP address is the IP address used by the first access network device to communicate with the IABnode.

[0067] In one possible design, the processing module is further used to assign a first IP address to the first device; and obtain a third IP address from a database.

[0068] In one possible design, the communication module is further configured to receive an IP address notification message sent by the first device, the IP address notification message including the first IP address. The processing module is further configured to obtain a third IP address from a database.

[0069] In an eighth aspect, a communication device is provided for use with a second access network device. The communication device includes: a communication module and a processing module. The communication module is configured to receive a secondary base station configuration message sent by the first access network device, where the secondary base station configuration message is used to configure the second access network device as a secondary base station for the first device. The processing module is configured to determine whether the secondary base station itself has an IAB donor function when the secondary base station configuration message includes third indication information, where the third indication information is used to indicate that the first device is an IAB node. The communication module is also configured to obtain a first IAB key K from the first access network device when the secondary base station configuration message includes third indication information. IAB1 , the K IAB1 is used to establish a secure tunnel between the second access network device and the first device, the K IAB1 It is generated based on a master base station key, and the master base station key is used to securely protect the communication between the first access network device and the first device.

[0070] In a possible design, the K IAB1 is generated according to a master base station key, and includes: K IAB1 is generated according to the master base station key and a first key input parameter. The first key input parameter includes a first IP address and a second IP address, the first IP address being an IP address used by the first device to communicate with the IAB donor, and the second IP address being an IP address used by the second access network device to communicate with the IAB node.

[0071] In a possible design, the secondary base station configuration message further includes first indication information and / or second indication information, the first indication information being used to request the first IP address, and the second indication information being used to request the second IP address.

[0072] In a possible design, the communication module is further configured to send, to the first access network device, a secondary base station configuration response message, the secondary base station configuration response message including the first IP address and / or the second IP address.

[0073] In a possible design, the communication module is specifically configured to receive a secondary base station reconfiguration completion message sent by the first access network device, the secondary base station reconfiguration completion message including the K IAB1 .

[0074] In a possible design, the communication module is specifically configured to send, to the first access network device, a key request message, the key request message being used to request the K IAB1 ; and receive a key response message sent by the first access network device, the key response message including the K IAB1 .

[0075] In a possible design, the key request message further includes the first IP address and / or the second IP address.

[0076] In a ninth aspect, a communication apparatus is provided, and is applied to a first device. The communication apparatus includes a processing module. The processing module is configured to determine a type of dual connectivity according to a communication standard supported by a master base station, a communication standard supported by a secondary base station, and a communication standard supported by a core network; and generate a K IAB according to a master base station key and a key input parameter when the type of dual connectivity is NE-DC, NR-DC, or NGEN-DC, the master base station key being used for security protection of communication between the first device and the master base station.

[0077] In a possible design, the communication apparatus further includes a communication module. The communication module is configured to receive a broadcast message of the master base station. The processing module is further configured to determine a communication system supported by the master base station according to a configuration parameter in the broadcast message, the configuration parameter including one or more of the following: a base station identifier, a logical cell identifier, a physical cell identifier, an uplink frequency point, or a downlink frequency point.

[0078] In a possible design, the processing module is specifically configured to determine that the master base station supports a 5G communication system when the configuration parameter in the broadcast message belongs to the 5G communication system, or determine that the master base station supports a 4G communication system when the configuration parameter in the broadcast message belongs to the 4G communication system.

[0079] In a possible design, the communication apparatus further includes a communication module. The communication module is configured to receive an RRC reconfiguration message sent by the master base station, the RRC reconfiguration message including secondary cell group configuration information. The processing module is configured to determine a communication system supported by the secondary base station according to the secondary cell group configuration information.

[0080] In a possible design, the processing module is specifically configured to determine that the secondary base station supports a 5G communication system when the secondary cell group configuration information belongs to the 5G communication system, or determine that the secondary base station supports a 4G communication system when the secondary cell group configuration information belongs to the 4G communication system.

[0081] In a possible design, the communication apparatus further includes a communication module. The communication module is configured to receive a broadcast message sent by the master base station. The processing module is configured to determine a communication system supported by the core network according to cell configuration information in the broadcast message.

[0082] In a possible design, the processing module is specifically configured to determine that the core network supports a 5G communication system when the cell configuration information belongs to the 5G communication system, or determine that the core network supports a 4G communication system when the cell configuration information belongs to the 4G communication system.

[0083] In a possible design, the processing module is specifically configured to determine that the dual connectivity type is NE-DC when the master base station supports a 5G network system, the secondary base station supports a 4G network system, and the core network supports the 5G network system, or determine that the dual connectivity type is NR-DC when the master base station supports the 5G network system, the secondary base station supports the 5G network system, and the core network supports the 5G network system, or determine that the dual connectivity type is NGEN-DC when the master base station supports a 4G network system, the secondary base station supports the 5G network system, and the core network supports the 5G network system, or determine that the dual connectivity type is EN-DC when the master base station supports the 4G network system, the secondary base station supports the 5G network system, and the core network supports the 4G network system.

[0084] In a tenth aspect, a communication apparatus is provided, which is applied to a first access network device. The communication apparatus comprises a processing module. The processing module is configured to determine that a first device registered to a network is an IAB node; determine whether the first access network device has an IAB donor function in a case where a secondary base station needs to be selected for the first device; select a third access network device as the secondary base station of the first device if the first access network device has the IAB donor function; generate an IAB key K IAB , according to a primary base station key, the primary base station key being used for security protection of communication between the first access network device and the first device. IAB , the secondary base station key being used for security protection of communication between the secondary base station and the first device.

[0085] In a possible design of the apparatus, the secondary base station key is derived according to the primary base station key, the primary base station key being used for security protection of communication between the first access network device and the first device.

[0086] In a possible design of the apparatus, the communication apparatus further comprises a communication module. The communication module is configured to send, after the processing module generates K IAB , a secondary base station configuration message to a second access network device, the secondary base station configuration message comprising the secondary base station key; and receive a secondary base station configuration response message sent by the second access network device.

[0087] In a possible design of the apparatus, the processing module is specifically configured to generate K IAB , according to the secondary base station key, after the communication module sends the secondary base station configuration message.

[0088] In a possible design of the apparatus, the processing module is specifically configured to generate K IAB , according to the secondary base station key, after the secondary base station configuration response message is received.

[0089] In a possible design of the apparatus, the processing module is further configured to select a second access network device having the IAB donor function as the secondary base station of the first device if the first access network device does not have the IAB donor function; and send a secondary base station configuration message to the second access network device, the secondary base station configuration message comprising the secondary base station key.

[0090] In an eleventh aspect, a communication apparatus is provided, which is applied to a first device. The communication apparatus comprises a processing module. The processing module is configured to determine a type of dual connectivity according to a communication standard supported by a primary base station, a communication standard supported by a secondary base station, and a communication standard supported by a core network; and generate an IAB key K IAB , according to a secondary base station key, the secondary base station key being used for security protection of communication between the first device and the secondary base station.

[0091] In a possible design, the communication apparatus further includes a communication module. The communication module is configured to receive a broadcast message of the master base station. The processing module is further configured to determine a communication system supported by the master base station according to a configuration parameter in the broadcast message, the configuration parameter including one or more of the following: a base station identifier, a logical cell identifier, a physical cell identifier, an uplink frequency point, or a downlink frequency point.

[0092] In a possible design, the processing module is specifically configured to determine that the master base station supports a 5G communication system when the configuration parameter in the broadcast message belongs to the 5G communication system; or determine that the master base station supports a 4G communication system when the configuration parameter in the broadcast message belongs to the 4G communication system.

[0093] In a possible design, the communication apparatus further includes a communication module. The communication module is configured to receive an RRC reconfiguration message sent by the master base station, the RRC reconfiguration message including secondary cell group configuration information. The processing module is configured to determine a communication system supported by the secondary base station according to the secondary cell group configuration information.

[0094] In a possible design, the processing module is specifically configured to determine that the secondary base station supports a 5G communication system when the secondary cell group configuration information belongs to the 5G communication system; or determine that the secondary base station supports a 4G communication system when the secondary cell group configuration information belongs to the 4G communication system.

[0095] In a possible design, the communication apparatus further includes a communication module. The communication module is configured to receive a broadcast message sent by the master base station. The processing module is configured to determine a communication system supported by the core network according to cell configuration information in the broadcast message.

[0096] In a possible design, the processing module is specifically configured to determine that the core network supports a 5G communication system when the cell configuration information belongs to the 5G communication system; or determine that the core network supports a 4G communication system when the cell configuration information belongs to the 4G communication system.

[0097] In a possible design, the processing module is specifically configured to determine that the dual connectivity type is NE-DC when the master base station supports a 5G network system, the secondary base station supports a 4G network system, and the core network supports the 5G network system; or determine that the dual connectivity type is NR-DC when the master base station supports the 5G network system, the secondary base station supports the 5G network system, and the core network supports the 5G network system; or determine that the dual connectivity type is NGEN-DC when the master base station supports a 4G network system, the secondary base station supports the 5G network system, and the core network supports the 5G network system; or determine that the dual connectivity type is EN-DC when the master base station supports the 4G network system, the secondary base station supports the 5G network system, and the core network supports the 4G network system.

[0098] According to a twelfth aspect, a communication apparatus is provided for use with a first device, the first device having IAB node functionality. The communication apparatus includes a processing module. The processing module is configured to determine whether a primary base station or a secondary base station serves as an IAB donor; when the primary base station serves as the IAB donor, generate an IAB key based on the primary base station key and key input parameters. The IAB key is used to establish a secure tunnel between the IAB node and the IAB donor; or, when the secondary base station serves as the IAB donor, generate the IAB key based on the secondary base station key and key input parameters.

[0099] In one possible design, the processing module is specifically configured to, upon receiving fourth indication information, obtain information that the primary base station is an IAB donor, where the fourth indication information is used to indicate that the primary base station is an IAB donor; or, upon receiving fifth indication information, obtain information that the secondary base station is an IAB donor, where the fifth indication information is used to indicate that the secondary base station is an IAB donor.

[0100] In one possible design, the processing module is specifically configured to, when a wireless backhaul link is established between the communication device and the primary base station, determine that the primary base station is an IAB donor; or, when a wireless backhaul link is established between the communication device and the secondary base station, determine that the secondary base station is an IAB donor.

[0101] In one possible design, the processing module is specifically used to obtain the frequency bands supported by the primary base station and the frequency bands supported by the secondary base station; when the frequency band supported by the primary base station is higher than the frequency band supported by the secondary base station, it is determined that the primary base station is an IAB donor; or when the frequency band supported by the primary base station is lower than the frequency band supported by the secondary base station, it is determined that the secondary base station is an IAB donor.

[0102] In one possible design, the processing module is specifically configured to, upon receiving sixth indication information broadcast by the primary base station, obtain information that the primary base station is an IAB donor; or, upon receiving sixth indication information broadcast by the secondary base station, obtain information that the secondary base station is an IAB donor; wherein the sixth indication information is configured to indicate that the base station has the IAB donor function.

[0103] In the thirteenth aspect, a communication device is provided, comprising a processor and a communication port, wherein the processor is used to execute computer program instructions so that the communication device implements the method involved in any one of the designs provided in any one of the first to sixth aspects.

[0104] In the fourteenth aspect, a computer-readable storage medium is provided, which stores instructions. When the instructions are executed on a computer, the computer implements the method involved in any one of the designs provided in any one of the first to sixth aspects.

[0105] In the fifteenth aspect, a computer program product is provided, which includes instructions. When the computer program product is run on a computer, the computer implements the method involved in any one of the designs provided in any one of the first to sixth aspects.

[0106] In the sixteenth aspect, a chip is provided, which includes a processor. When the processor executes computer program instructions, the computer implements the method involved in any one of the designs provided in any one of the first to sixth aspects.

[0107] Among them, the technical effects brought about by any design method in the above-mentioned seventh to sixteenth aspects can be referred to the beneficial effects in the corresponding methods provided above and the technical effects brought about by the same design method, which will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0108] Figure 1 A flowchart of a dual connection configuration provided for related technologies;

[0109] Figure 2 A schematic diagram of an IAB networking scenario provided in an embodiment of the present application;

[0110] Figure 3 A schematic diagram of a user plane protocol stack in an IAB network provided in an embodiment of the present application;

[0111] Figure 4 A schematic diagram of a control plane protocol stack in an IAB network provided in an embodiment of the present application;

[0112] Figure 5 A schematic diagram of an IAB node using the EN-DC mode provided in an embodiment of the present application;

[0113] Figure 6 A flowchart of generating an IAB key in an EN-DC scenario provided in an embodiment of the present application;

[0114] Figure 7 A schematic diagram of an IAB node using NE-DC mode provided in an embodiment of the present application;

[0115] Figure 8 A schematic diagram of an IAB node using the NR-DC mode provided in an embodiment of the present application;

[0116] Figure 9 A schematic diagram of an IAB node using the NGEN-DC mode provided in an embodiment of the present application;

[0117] Figure 10 A flowchart of a key generation method provided in an embodiment of the present application;

[0118] Figure 11 A flowchart of another key generation method provided in an embodiment of the present application;

[0119] Figure 12 A flowchart of another key generation method provided in an embodiment of the present application;

[0120] Figure 13 A flowchart of another key generation method provided in an embodiment of the present application;

[0121] Figure 14 A flowchart of another key generation method provided in an embodiment of the present application;

[0122] Figure 15 A flowchart of another key generation method provided in an embodiment of the present application;

[0123] Figure 16 A flowchart of another key generation method provided in an embodiment of the present application;

[0124] Figure 17 A flowchart of another key generation method provided in an embodiment of the present application;

[0125] Figure 18 A flowchart of another key generation method provided in an embodiment of the present application;

[0126] Figure 19 A flowchart of another key generation method provided in an embodiment of the present application;

[0127] Figure 20 A flowchart of another key generation method provided in an embodiment of the present application;

[0128] Figure 21 A flowchart of another key generation method provided in an embodiment of the present application;

[0129] Figure 22 A flowchart of another key generation method provided in an embodiment of the present application;

[0130] Figure 23 A flowchart of another key generation method provided in an embodiment of the present application;

[0131] Figure 24 A flowchart of another key generation method provided in an embodiment of the present application;

[0132] Figure 25 A flowchart of another key generation method provided in an embodiment of the present application;

[0133] Figure 26 A flowchart of another key generation method provided in an embodiment of the present application;

[0134] Figure 27 A flowchart of another key generation method provided in an embodiment of the present application;

[0135] Figure 28 A schematic diagram of the structure of a communication device provided in an embodiment of the present application;

[0136] Figure 29 A schematic diagram of the hardware structure of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0137] In the description of this application, unless otherwise specified, " / " means "or", for example, A / B can mean A or B. "And / or" in this article is merely a description of the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, "at least one" means one or more, and "a plurality" means two or more. Words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not limit them to be necessarily different.

[0138] It should be noted that, in this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0139] In order to facilitate understanding of the technical solution of this application, some technical terms are introduced below.

[0140] 1. Dual connection

[0141] In the field of wireless communications, dual connectivity (DC) technology has been introduced to improve user throughput. DC allows two or more base stations to simultaneously provide data transmission services to a single terminal device. These base stations include a primary base station and one or more secondary base stations.

[0142] The above-mentioned primary base station can also be called a master node (MN) or a primary access network device, and the above-mentioned secondary base station can also be called a secondary node (SN) or a secondary access network device, which is not limited in the embodiment of the present application.

[0143] The master base station (MBS) and the core network (CN) are connected via the S1 / NG interface. This interface includes at least a control plane connection and may also include a user plane connection. The S1 interface includes S1-U and S1-C. The NG interface includes NG-U and NG-C. S1-U / NG-U represents a user plane connection, while S1-C / NG-C represents a control plane connection.

[0144] There may or may not be a user plane connection between the secondary base station and the core network. When there is no user plane connection between the secondary base station and the core network, the data of the terminal device can be offloaded from the primary base station to the secondary base station at the packet data convergence protocol (PDCP) layer.

[0145] Depending on the communication modes supported by the primary base station, the secondary base station, and the core network to which the primary base station is connected, there may be multiple types of dual connectivity.

[0146] Table 1

[0147] Dual connection type Main base station Secondary base station Core Network EN-DC 4G base station 4G base station 4G core network NE-DC 5G base stations 4G base station 5G core network NR-DC 5G base stations 5G base stations 5G core network NGEN-DC 4G base station 4G base station 5G core network

[0148] In a dual-connectivity scenario, the master base station manages a primary cell (PCell). A primary cell is a cell deployed at the primary frequency point and accessed during the initial connection establishment process or RRC connection re-establishment process initiated by the terminal, or a cell indicated as a primary cell during a handover. Furthermore, in addition to the primary cell, the master base station can also manage one or more secondary cells (SCells). The cells under the master base station that provide services to the terminal, such as the primary cell and the secondary cells under the master base station, can constitute a master cell group (MCG).

[0149] The secondary base station manages a primary secondary cell (PSCell). The primary secondary cell can be a cell accessed by a terminal during a random access process initiated by the terminal to the secondary base station, or a cell on another secondary base station where the terminal skips the random access process to initiate data transmission during a secondary base station change, or a cell on a secondary base station accessed during a random access process when performing a synchronous reconfiguration process. Furthermore, in addition to the primary secondary cell, the secondary base station can also manage one or more secondary cells. The cells on the secondary base station that provide services to the terminal, such as the primary secondary cell and the secondary cell on the secondary base station, can constitute a secondary cell group (SCG).

[0150] In an embodiment of the present application, a terminal device is a device with wireless transceiver capabilities. The terminal device can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on the water (such as a ship, etc.); it can also be deployed in the air (for example, on an airplane, a balloon, and a satellite, etc.). The terminal device can be a user equipment (UE). Among them, the UE includes a handheld device, a vehicle-mounted device, a wearable device, or a computing device with wireless communication capabilities. Exemplarily, the UE can be a mobile phone, a tablet computer, or a computer with wireless transceiver capabilities. The terminal device can also be a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in unmanned driving, a wireless terminal device in telemedicine, a wireless terminal device in a smart grid, a wireless terminal device in a smart city, a wireless terminal device in a smart home, and the like.

[0151] The above-mentioned primary base station and secondary base station can be collectively referred to as network equipment. The network equipment includes but is not limited to: evolved Node B (eNB), radio network controller (RNC), Node B (NB), base station controller (BSC), base transceiver station (BTS), home base station (e.g., home evolved Node B, or home Node B, HNB), baseband unit (BBU), wireless relay node, wireless backhaul node, transmission point (TRP or transmission point, TP), etc., and can also be 5G, such as gNB in ​​new radio (NR) system, or transmission point (TRP or TP), one or a group of antenna panels (including multiple antenna panels) of a base station in a 5G system, or network nodes constituting a gNB or transmission point, such as a baseband unit (BBU), or a distributed unit (DU), a road side unit (RSU) with base station function, etc.

[0152] In an embodiment of the present application, the network device may adopt a centralized unit (CU)-DU architecture. That is, the network device may be composed of a CU and at least one DU. In this case, some functions of the network device are deployed on the CU, and other functions of the network device are deployed on the DU. The CU and DU are functionally divided according to the protocol stack. As an implementation method, the CU is deployed with the RRC layer, the packet data convergence protocol (PDCP) layer, and the service data adaptation protocol (SDAP) layer in the protocol stack; the DU is deployed with the radio link control (RLC) layer, the media access control (MAC) layer, and the physical layer (PHY) in the protocol stack. Therefore, the CU has the processing capabilities of RRC, PDCP, and SDAP. The DU has the processing capabilities of RLC, MAC, and PHY. It will be understood that the above functional division is only an example and does not constitute a limitation on the CU and DU. That is, there may be other ways of functional division between the CU and DU, which will not be described in detail in the embodiment of the present application.

[0153] 2. Dual connection configuration process

[0154] like Figure 1 As shown, a dual connection configuration process provided in the related art includes the following steps:

[0155] S10. The terminal device registers with the network through the primary base station.

[0156] Optionally, after the terminal device registers with the network, the primary base station may send a measurement event to the terminal device, causing the terminal device to report a measurement report to the primary base station. The primary base station may then determine, based on the measurement report, whether to add a secondary base station for the terminal device. If it is determined that a secondary base station is to be added for the terminal device, the primary base station may execute step S11 below.

[0157] S11. The primary base station determines to add a secondary base station for the terminal device.

[0158] S12. The primary base station sends a secondary node addition / modification request message to the secondary base station.

[0159] The SN addition / modification request message includes relevant configuration information of the secondary base station.

[0160] It should be noted that the primary base station can generate a secondary base station key. Subsequently, the SN addition / modification request message sent by the primary base station can carry the secondary base station key. Since the primary base station does not use the secondary base station key, the primary base station can delete the secondary base station key after sending the SN addition / modification request message.

[0161] S13. The secondary base station sends a secondary node addition / modification request acknowledgment message to the primary base station.

[0162] The SN addition / modification request ack message is used to indicate agreement to use the configuration information carried in the SN addition / modification request message.

[0163] S14. The primary base station sends an RRC reconfiguration message to the terminal device.

[0164] The RRC reconfiguration message is used to configure the radio bearer between the terminal device and the secondary base station.

[0165] S15. The terminal device sends an RRC reconfiguration completion message to the master base station.

[0166] S16: The primary base station sends a secondary node reconfiguration complete message to the secondary base station.

[0167] Afterwards, the terminal device and the secondary base station may perform a random access procedure. After the random access procedure, an RRC connection is established between the terminal device and the secondary base station.

[0168] 3. K gNB

[0169] In 5G networks, K gNB The terminal equipment and access and mobility management function (AMF) are respectively based on K AMF AMF deduced K gNB Afterwards, K gNB Sent to the access network device to which the terminal device is connected. In this way, the terminal device and the access network device maintain the same K gNB , so that terminal equipment and access network equipment can use K gNB and the keys derived from them for secure communication.

[0170] 4. K eNB

[0171] In 4G networks, K eNB The terminal equipment and the mobility management entity (MME) are respectively based on K ASME MME deduces K eNB After that, K eNB Sent to the access network device to which the terminal device is connected. In this way, the terminal device and the access network device maintain the same K eNB , so that terminal equipment and access network equipment can use K eNB and the keys derived from them for secure communication.

[0172] 5. Security protection

[0173] Security protection refers to data encryption / decryption, and / or integrity protection / verification to avoid risks such as data leakage or data tampering.

[0174] 1) Encryption / Decryption: This protects the confidentiality of data during transmission (hence, it is also called confidentiality protection). Confidentiality means that the true content cannot be directly revealed. Encryption protection is generally achieved by encrypting data using a key and an encryption algorithm.

[0175] 2) Integrity protection / verification: Determines whether the content of a message has been altered during transmission. It can also be used for authentication to confirm the source of the message.

[0176] 3) Anti-replay protection / verification: Determine whether the message has been replayed to confirm the freshness of the message.

[0177] The above is an introduction to the technical terms involved in the embodiments of this application, which will not be repeated below.

[0178] Compared to 4G mobile communication systems, 5G mobile communication systems impose stricter requirements on all aspects of network performance, including a 1,000-fold increase in capacity, wider coverage requirements, ultra-high reliability, and ultra-low latency.

[0179] On the one hand, to meet the ultra-high capacity requirements of 5G mobile communication systems and given the abundance of high-frequency carrier frequency resources, operators generally utilize high-frequency small cells to build networks in hotspots. However, high-frequency carriers have poor propagation characteristics, suffer severe attenuation due to obstruction, and have limited coverage, necessitating the dense deployment of large numbers of small cells. Providing fiber backhaul for these densely deployed small cells is, accordingly, costly and difficult to implement, necessitating a cost-effective and convenient backhaul solution. On the other hand, to meet the need for wide coverage, providing network coverage in remote areas is challenging and expensive due to the difficulty of deploying fiber, necessitating the design of flexible and convenient access and backhaul solutions.

[0180] Integrated access and backhaul (IAB) technology provides a solution to the above two problems: its access link and backhaul link both use wireless transmission solutions, avoiding fiber optic deployment.

[0181] In the IAB network, the IAB node can provide wireless access services for terminal devices and connect to the IAB host (donor) through a wireless backhaul link to transmit user business data.

[0182] The IAB node is connected to the core network via a wired link via the host node. For example, in a standalone 5G architecture, the IAB node is connected to the 5G core (5GC) via a wired link via the host node. In a non-standalone 5G architecture, the IAB node is connected to the evolved packet core (EPC) via an evolved NodeB (eNB) on the control plane and to the EPC via the host node and eNB on the user plane.

[0183] To ensure the coverage performance and service transmission reliability of the IAB network, the IAB network supports multi-hop IAB node and multi-connection IAB node networking. Therefore, multiple transmission paths may exist between the terminal served by the IAB node and the host node. A single transmission path may include multiple nodes, such as the terminal, one or more IAB nodes, and the host node. There is a defined hierarchical relationship between IAB nodes, as well as between IAB nodes and the host nodes serving them. Each IAB node considers the node providing backhaul services to be its parent node. Accordingly, each IAB node can be considered a child node of its parent node.

[0184] For example, Figure 2As shown, in the IAB standalone networking scenario, the parent node of IAB node 1 is the donor node, IAB node 1 is the parent node of IAB node 2 and IAB node 3, IAB node 2 and IAB node 3 are the parent nodes of IAB node 4, and the parent node of IAB node 5 is IAB node 2. The uplink data packet of the terminal can be transmitted to the donor node through one or more IAB nodes, and then transmitted to the mobile gateway device (such as the user plane function (UPF) network element in the 5G network) by the donor node. The downlink data packet is received by the donor node from the mobile gateway device, and then transmitted to the terminal through one or more IAB nodes.

[0185] It can be understood that in the IAB network, one or more IAB nodes can be included in a transmission path between the terminal and the donor node. Each IAB node needs to maintain a wireless backhaul link towards the parent node, and also needs to maintain a wireless link with the child node. If an IAB node is the node accessed by the terminal, the wireless access link is between the IAB node and the child node (i.e. the terminal). If an IAB node is the node providing backhaul service for other IAB nodes, the wireless backhaul link is between the IAB node and the child node (i.e. other IAB nodes). For example, see Figure 2 In the path "terminal 1→IAB node 4→IAB node 3→IAB node 1→donor node", terminal 1 accesses IAB node 4 through a wireless access link, IAB node 4 accesses IAB node 3 through a wireless backhaul link, IAB node 3 accesses IAB node 1 through a wireless backhaul link, and IAB node 1 accesses the donor node through a wireless backhaul link.

[0186] The IAB node can include a mobile terminal (MT) and a centralized unit (DU). The MT included in the IAB node has part or all of the functions of the terminal device. When the IAB node faces its parent node, the IAB node can be regarded as a terminal device, i.e. the IAB node plays the role of MT. When the IAB node faces its child node (which can be a terminal or a terminal part of another IAB node), the IAB node can be regarded as a network device, i.e. the IAB node plays the role of DU. In other words, an IAB node can establish a backhaul connection between the MT part and at least one parent node of the IAB node. The DU part of an IAB node can provide access services for the MT part of a terminal device or other IAB node.

[0187] The IAB donor can be a complete entity. Alternatively, the IAB donor can also be a centralized unit

[0188] The Donor-CU can be separated from the centralized unit (CU) (abbreviated herein as Donor-CU, or CU) and the distributed unit (DU) (abbreviated herein as Donor-DU), that is, the IAB host consists of the Donor-CU and the Donor-DU. The Donor-CU can also be separated from the user plane (UP) (abbreviated herein as CU-UP) and the control plane (CP) (abbreviated herein as CU-CP), that is, the Donor-CU consists of the CU-CP and the CU-UP.

[0189] In the embodiment of the present application, the IAB host may have other names, such as host base station, host node, DgNB (i.e., donor gNB), etc., without limitation.

[0190] An F1 interface needs to be established between the IAB node and the IAB host. The F1 interface may also be referred to as the F1* interface, without limitation. The F1 interface supports the user plane protocol F1-U (or F1*-U) and the control plane protocol F1-C (or F1*-C).

[0191] For example, Figure 3 Schematic diagram of the user plane protocol stack in the IAB network provided by the embodiment of the present application. Figure 6 As shown, the user plane protocol stack includes one or more of the following protocol layers: general packet radio service (GPRS) tunneling protocol user plane (GTP-U), user datagram protocol (UDP), internet protocol (IP), backhaul adaptation protocol (BAP), radio link control (RLC), media access control (MAC), and physical layer (PHY layer). Figure 3 In the embodiment, the L2 layer may be a data link layer in an open systems interconnection (OSI) reference model, and the L1 layer may be a physical layer.

[0192] For example, Figure 4 This is a schematic diagram of the control plane protocol stack in the IAB network provided by the embodiment of the present application. Figure 4As shown, the control plane protocol stack includes one or more of the following protocol layers: F1 application protocol (F1AP), stream control transport protocol (SCTP), IP, BAP, RLC, MAC, PHY, etc.

[0193] In order to protect the security of the F1 interface, an Internet Protocol Security (IPSec) secure connection can be established between the IAB node and the IAB host. Among them, the Internet Key Exchange (IKE) V2 protocol supports the use of a pre-shared secret key (PSK) for security authentication. For example, the IAB node and the IAB host can configure the PSK in advance and use it as an authentication credential in the subsequent IPSec establishment process. Currently, in order to save the process of pre-configuring the PSK and realize the plug-and-play of the IAB node and the IAB donor, the IAB node and the IAB donor can calculate the K IAB Come as PSK.

[0194] Currently, in order to ensure network coverage performance and service transmission reliability requirements, the IAB node can be enabled to support dual connectivity (DC) to cope with abnormal situations that may occur in the wireless backhaul link, such as wireless backhaul link interruption or blocking.

[0195] Figure 5 The following is a schematic diagram of an IAB node using the EN-DC mode. Figure 5 As shown in the figure, when the IAB node operates in EN-DC mode, the 4G base station (eNB) serves as the primary base station, and the IAB donor serves as the secondary base station. An LTE Uu air interface connection exists between the MeNB and the IAB node's mobile station. An X2-C interface connects the MeNB to the IAB donor-CU-CP. The MeNB connects to the 4G core network (evolved packet core, EPC) via the S1 interface. Optionally, the IAB donor-CU-UP can connect to the EPC via the S1-U interface, for example, to a serving gateway (SGW).

[0196] Currently, in scenarios where the IAB node adopts the EN-DC mode, such as Figure 6 As shown, IAB node and IAB donor generate K IAB The process includes the following steps:

[0197] S20, the IAB node accesses the core network through the MeNB.

[0198] It should be understood that after the IAB node accesses the core network, both the IAB node and the MeNB store the same K eNB .

[0199] S21, after the MeNB generates the S-Kgnb, the MeNB sends an SN additional / modification request message to the IAB donor.

[0200] The SN additional / modification request message includes the S-Kgnb. The S-Kgnb is derived from the K eNB .

[0201] It can be understood that after the MeNB sends the S-Kgnb to the secondary base station, the MeNB can optionally delete the S-Kgnb. That is, the purpose of the MeNB calculating the S-Kgnb is to send it to the secondary base station for use, and the MeNB does not use the S-Kgnb.

[0202] S22, the IAB donor sends an SN additional / modification request ACK message to the MeNB.

[0203] S23, the MeNB sends an RRC reconfiguration message to the IAB node.

[0204] It should be understood that after receiving the RRC reconfiguration message, the IAB node can derive the S-Kgnb from the K eNB .

[0205] S24, the IAB node sends an RRC reconfiguration complete message to the MeNB.

[0206] S25, the MeNB sends an SN reconfiguration complete message to the IAB donor.

[0207] S26, the IAB node generates an IAB key according to the S-Kgnb.

[0208] S27, the IAB donor generates an IAB key according to the S-Kgnb.

[0209] In EN-DC mode, the IAB donor can and only can be a secondary base station, so the input key for generating the IAB key can be S-Kgnb, that is, the secondary base station uses S-Kgnb to derive the IAB key.

[0210] In this way, the IAB node and the IAB donor can establish a secure tunnel with the same IAB key as authentication credentials.

[0211] However, with the development of communication technology, the IAB node can also use other types of dual connectivity (such as NE-DC, NR-DC, NGEN-DC, etc.).

[0212] Figure 7 A schematic diagram for the IAB node using the NE-DC mode. As shown in Figure 7 When the IAB node works in the NE-DC mode, the IAB donor CU-UP is connected to the user plane network element in the 5G core (5GC) through the NG-U interface, and the IAB donor CU-CP is connected to the control plane network element in the 5GC through the NG-C interface. There is an LTE Uu air interface connection between the SeNB and the MT in the IAB node. There is an X2-C interface between the IAB donor CU-CP and the SeNB.

[0213] Figure 8 A schematic diagram for the IAB node using the NR-DC mode. As shown in Figure 8 When the IAB node works in the NR-DC mode, the IAB node is connected to an IAB donor and a gNB. Among them, the IAB donor CU-UP is connected to the user plane network element in the 5GC through the NG-U interface, and the IAB donor CU-CP is connected to the control plane network element in the 5GC through the NG-C interface. There is an NR Uu interface between the gNB and the MT in the IAB node.

[0214] Figure 9 A schematic diagram for the IAB node using the NGEN-DC mode. As shown in Figure 9 When the IAB node works in the NGEN-DC mode, the primary base station connected by the IAB node is an NG-eNB, and the secondary base station connected by the IAB node is an IAB donor. Among them, the IAB donor CU-UP is connected to the user plane network element in the 5GC through the NG-U interface. There is an LTE Uu interface between the MT in the IAB node and the NG-enB.

[0215] Currently, for other types of dual connections except EN-DC, the industry does not provide a method for IAB node and IABdonor to generate K IAB This may result in the IAB node generating K IAB K generated by IAB donor IAB The IPsec security connection cannot be established normally between the IAB node and the IAB donor.

[0216] For example, assume an IAB node uses NR-DC to access a network where both the primary and secondary base stations are gNBs. The IAB donor can be either the primary or secondary base station. The IAB node establishes a connection with the IAB donor based on its IP address, but does not need to know whether the IAB donor is the primary or secondary base station. Consequently, if the IAB donor is the secondary base station, the IAB donor may use the secondary base station key to calculate the IAB key, while the IAB node may use the primary base station key to calculate the IAB key, resulting in different IAB keys maintained by the IAB donor and the IAB node. Alternatively, if the IAB donor is the primary base station, the IAB donor may use the primary base station key to calculate the IAB key, while the IAB node may use the secondary base station key to calculate the IAB key, resulting in different IAB keys maintained by the IAB donor and the IAB node.

[0217] In order to solve the above technical problems, the present application provides three technical solutions. The ideas of the three technical solutions are first introduced below.

[0218] The idea of ​​technical solution 1 is that in the case of dual connectivity other than EN-DC (such as NE-DC, NR-DC or NGEN-DC), both the IAB donor and the IAB node use the master base station key to calculate K IAB .

[0219] The idea of ​​the second technical solution is that in the case of other types of dual connectivity (such as NE-DC, NR-DC or NGEN-DC) except EN-DC, both the IAB donor and the IAB node use the secondary base station key to calculate K IAB .

[0220] The idea of ​​technical solution 3 is that in the case of dual connectivity other than EN-DC (such as NE-DC, NR-DC or NGEN-DC), both the IAB donor and the IAB node calculate K based on the local key of the IAB donor.IAB If the primary base station is an IAB donor, the local key is the primary base station key; if the secondary base station is an IAB donor, the local key is the secondary base station key.

[0221] The above technical solutions 1 to 3 can ensure that the IAB donor and IAB node maintain the same K IAB It should be understood that in practical applications, any one of the above technical solutions 1 to 3 can be selected for implementation.

[0222] Exemplarily, the master base station key is used to securely protect the communication between the master base station (eg, the first access network device hereinafter) and the first device. For example, the master base station key may be K gNB , K RRCint , K RRCenc , K UPint , or K UPenc Among them, KRRCint, K RRCenc , KUPint and K UPenc All through K gNB Deduced. K RRCint Used to perform integrity protection on the RRC signaling between the master base station and the first device. RRCenc Used to encrypt and protect the RRC signaling between the master base station and the first device. UPint Used to perform integrity protection on user plane data between the primary base station and the first device. K UPenc Used to encrypt and protect user plane data between the master base station and the first device. The master base station key is described uniformly here and will not be repeated below.

[0223] Exemplarily, the secondary base station key is used to securely protect the communication between the secondary base station (eg, the second access network device or the third access network device hereinafter) and the first device. For example, the secondary base station key may be Ksn, SK RRCint SK RRCenc SK UPint , or SK UPenc etc., without limitation. RRCint SK RRCenc SK UPint , or SK UPenc All are derived through Ksn. SK RRCint Used to perform integrity protection on the RRC signaling between the secondary base station and the first device. RRCenc Used to encrypt and protect the RRC signaling between the secondary base station and the first device. UPint Used to perform integrity protection on the user plane data between the secondary base station and the first device.UPenc Used to encrypt and protect user plane data between the secondary base station and the first device. The master base station key is described uniformly here and will not be repeated below.

[0224] The following describes the specific implementation of the three embodiments in detail with reference to the accompanying drawings. It should be noted that the names of the messages / information in the following embodiments are only examples and may be other names in specific implementations, without limitation.

[0225] Technical Solution 1

[0226] In other dual connectivity scenarios besides EN-DC, the network side can refer to Figure 10 To obtain the IAB key, the IAB node can refer to Figure 11 The embodiment shown is used to obtain the IAB key.

[0227] like Figure 10 As shown, a key generation method provided in an embodiment of the present application includes the following steps:

[0228] S101. The first access network device determines that the first device registered with the 5G core network through the first access network device is an IAB node.

[0229] As a possible implementation, the first access network device receives IAB indication information sent by the first device, where the IAB indication information is used to indicate that the first device is an IAB node. Thus, the first access network device can know that the first device is an IAB node according to the IAB indication information.

[0230] Exemplarily, the IAB indication information may be recorded as “IAB-indication”.

[0231] As another possible implementation, the first access network device receives IAB authorization information from a core network element, where the IAB authorization information indicates that the first device has authority to act as an IAB node. Thus, the first access network device can learn that the first device is an IAB node based on the IAB authorization information.

[0232] For example, the IAB authorization information may be recorded as “IAB-authorized”.

[0233] It should be understood that the core network element may proactively send the IAB authorization information to the first access network device. Alternatively, the core network element may verify the contract data of the first device upon request by the first access network device and determine whether to reply the IAB authorization information to the first access network device.

[0234] It should be understood that the first access network device and the first device can obtain the same master base station key in the process of the first device registering to the 5G core network.

[0235] S102, in the case of needing to select a secondary base station for the first device, the first access network device determines whether the first access network device has the IAB donor function.

[0236] As a possible implementation, the first access network device checks whether the identity of the first access network device exists in the IAB donor configuration information. When the identity of the first access network device exists in the IAB donor configuration information, the first access network device determines that the first access network device has the IAB donor function. When the identity of the first access network device does not exist in the IAB donor configuration information, the first access network device determines that the first access network device does not have the IAB donor function.

[0237] The IAB donor configuration information is used to record the identity of one or more access network devices having the IAB donor function. Optionally, the IAB donor configuration information can be configured to the first access network device by an operation administration and maintenance (OAM) system or other devices.

[0238] As another possible implementation, the first access network device can check whether the first access network device stores a donor configuration file. When the first access network device stores the donor configuration file, the first access network device can determine that the first access network device has the IAB donor function. Otherwise, the first access network device determines that the first access network device does not have the IAB donor function.

[0239] It should be understood that the donor configuration file is used to configure the function of the access network device as the IAB donor. The donor configuration file can be locally configured by the first access network device, or configured to the first access network device by the OAM system.

[0240] Optionally, when the first access network device does not have the IAB donor function, the first access network device performs the following steps S103-S106. When the first access network device has the IAB donor function, the first access network device performs the following steps S107-S109.

[0241] S103, in the case of the first access network device not having the IAB donor function, the first access network device selects a second access network device having the IAB donor function as the secondary base station of the first device.

[0242] As a possible implementation, the second device pre-configures the identity of the second access network device for the first access network device. Thus, in the case that a secondary base station needs to be added for the IAB node (e.g., the first device), the first access network device can select the second access network device as the secondary base station according to the identity of the second access network device.

[0243] As a possible implementation, the first access network device sends a first request message to the second device, the first request message including the identity of the first device. The second device can determine the access network device (i.e., the second access network device) that is the IAB donor of the first device according to the first request message. Then, the first access network device receives a first response message sent by the second device, the first response message including the identity of the second access network device. Thus, the first access network device can select the second access network device as the secondary base station of the first device.

[0244] Optionally, the identity of the first device can include a cell-radio network temporary identifier (C-RNTI), a device number, etc., without limitation.

[0245] Optionally, the identity of the second access network device can include an IP address, a device number, etc., without limitation.

[0246] Optionally, the second device can be an OAM system or a core network element, without limitation.

[0247] It should be noted that the second device determines the second access network device according to the first request message, which can be in the following two cases:

[0248] Case 1: The second device has pre-stored a mapping relationship between the first device and the second access network device. Thus, the second device can find the identity of the second access network device according to the identity of the first device and the mapping relationship between the first device and the second access network device.

[0249] Case 2: The second device does not store the mapping relationship between the first device and the second access network device. Thus, the second device can determine the second access network device according to topology information and other factors.

[0250] It should be understood that since the second device is responsible for determining the second access network device, the second device can send the IP address of the second access network device used for communication with the IAB node to the first device, so that the first device and the second access network device can communicate according to the IP address.

[0251] In the embodiment of the present application, after selecting the second access network device as the secondary base station, the first access network device will send a secondary base station configuration message to the second access network device, so that the second access network device knows that it is the secondary base station of the first device. Figure 1 FIG. 4 shows an SN addition / modification request message in the dual connectivity configuration process. FIG.

[0252] Optionally, when the first device is an IAB node, the secondary base station configuration message may include third indication information, where the third indication information is used to indicate that the first device is an IAB node. Thus, the second access network device may learn that the first device is an IAB node based on the third indication information.

[0253] For the second access network device, when the secondary base station configuration message includes the third indication information, the second access network device determines whether it has the IAB donor function. When the second access network device determines that it has the IAB donor function, the second access network device needs to obtain K from the first access network device. IAB1 .

[0254] The specific implementation method of the second access network device determining whether it has the IAB donor function can refer to the specific implementation method of the first access network device determining whether it has the IAB donor function described above, which will not be repeated here.

[0255] S104. The first access network device obtains a first key input parameter associated with the second access network device.

[0256] The first key input parameter includes: a first IP address and / or a second IP address.

[0257] The first IP address is an IP address used by the first device to communicate with the IAB donor. Since the first device acts as an IAB node, the first IP address may also be referred to as the IP address of the IAB node, or the IP address of the MT in the IAB node.

[0258] The second IP address is an IP address used by the second access network device to communicate with the IAB node. Since the second access network device serves as the IAB donor of the first device, the second IP address can also be called the IP address of the IAB donor or the IP address of the CU in the IAB donor.

[0259] Optionally, the first access network device may obtain the first IP address by using any one of the following implementations 1-1 or 1-2:

[0260] Implementation method 1-1: The first access network device obtains the first IP address from the second device.

[0261] For example, when the IP address of the first device is allocated by the second device, the first response message sent by the second device to the first access network device may further include the first IP address.

[0262] Implementation method 1-2: The first access network device obtains the first IP address from the second access network device.

[0263] For example, the first access network device sends first indication information to the second access network device, where the first indication information is used to request a first IP address. Afterwards, the first access network device receives the first IP address sent by the second access network device.

[0264] Exemplarily, the first indication information may be carried in newly added signaling. Alternatively, the first indication information may be carried in existing signaling, such as an SN addition / modification request message.

[0265] Exemplarily, the first IP address sent by the second access network device may be carried in newly added signaling. Alternatively, the first IP address sent by the second access network device may be carried in existing signaling, such as an SN addition / modification request ACK message.

[0266] Optionally, the first access network device may obtain the second IP address by adopting any one of the following implementations 2-1 to 2-3:

[0267] Implementation method 2-1: The first access network device obtains the second IP address from the second device.

[0268] For example, if the second device stores the IP addresses of each access network device having the IAB donor function, the second device stores the second IP address. Therefore, the first response message sent by the second device to the first access network device may also include the second IP address.

[0269] Implementation method 2-2: The first access network device may use the IP address of the Xn interface of the second access network device as the second IP address.

[0270] It should be understood that implementation 2-2 is generally based on the communication system's default assumption that the IP address of the Xn interface of the access network device is the IP address of the access network device when it serves as an IAB donor.

[0271] Implementation method 2-3: The first access network device obtains the second IP address from the second access network device.

[0272] For example, the first access network device sends second indication information to the second access network device, where the second indication information is used to request a second IP address. The first access network device receives the second IP address sent by the second access network device.

[0273] Exemplarily, the second indication information may be carried in newly added signaling, or the second indication information may be carried in existing signaling, such as an SN addition / modification request message.

[0274] It should be understood that the second indication information and the first indication information can be carried in the same signaling or in different signaling. When the second indication information and the first indication information are carried in the same signaling, the second indication information and the first indication information can be integrated into one indication information, such as a parameter request indication information (para_request_indicator). Thus, the parameter request indication information is used to request the IP address of the IAB donor and the IP address of the IAB node.

[0275] Exemplarily, the second IP address sent by the second access network device may be carried in newly added signaling. Alternatively, the second IP address sent by the second access network device may be carried in existing signaling, such as an SN addition / modification request ACK message.

[0276] S105: The first access network device generates a first IAB key K according to the first key input parameter and the master base station key. IAB1 .

[0277] Among them, K IAB1 Used to establish a secure tunnel between the second access network device and the first device.

[0278] S106: The first access network device sends K to the second access network device. IAB1 .

[0279] In one possible design, K IAB1 Can be carried in a new message. Figure 1 The dual connection configuration process shown in the figure is used as an example to illustrate the new IAB1 The message may be sent after the SNadditional / modification request ACK message or after the SN reconfigurationcomplete message.

[0280] In another possible design, K IAB1 Can be carried in existing messages. Figure 1 The dual connection configuration process shown in FIG is used as an example to illustrate that the first access network device can send an SN reconfiguration complete message to the second access network device. The SN reconfiguration complete message includes K IAB1 .

[0281] It should be understood that the second access network device receives K IAB1 Afterwards, K will be saved IAB1 .

[0282] Based on the above steps S103-S106, when the secondary base station (i.e., the second access network device) serves as the IAB donor, the primary base station (i.e., the first access network device) can actively generate K using the primary base station key. IAB , and the K IAB Sent to the secondary base station to ensure that the IAB donor and IAB node maintain the same K IAB .

[0283] S107: When the first access network device has an IAB donor function, the first access network device selects a third access network device as a secondary base station of the first device.

[0284] In one possible implementation, the first access network device selects a suitable access network device (ie, a third access network device) as a secondary base station for the first device from surrounding access network devices based on factors such as the location of the first device and a measurement report of the first device.

[0285] It should be understood that the embodiment of the present application does not limit whether the third access network device has the IAB donor function. That is, the third access network device may have the IAB donor function or may not have the IAB donor function.

[0286] In this case, the first access network device having the IAB donor function serves as the IAB donor of the first device.

[0287] S108. The first access network device obtains a second key input parameter associated with the first access network device.

[0288] The second key input parameters include the first IP address and the third IP address.

[0289] The third IP address is an IP address used by the first access network device to communicate with the IAB node.

[0290] It should be understood that the first access network device can obtain the third IP address locally (ie, a database of the first access network device).

[0291] In one possible design, the first access network device, serving as an IAB donor, allocates a first IP address to the first device. Based on this design, the first access network device also needs to send the first IP address to the first device.

[0292] In another possible design, when the second device allocates the first IP address to the first device, the first access network device can obtain the first IP address from the second device or the first device.

[0293] Exemplarily, the first access network device sends an IP address request message to the first device. Afterwards, the first access network device receives an IP address notification message sent by the first device, where the IP address notification message includes the first IP address.

[0294] S109: The first access network device generates a second IAB key K according to the second key input parameter and the master base station key. IAB2 .

[0295] Among them, K IAB2 Used to establish a secure tunnel between the first access network device and the first device.

[0296] It should be understood that the first access network device generates K IAB2 Afterwards, the K IAB2 .

[0297] Based on the above steps 107-S109, when the primary base station (ie, the first access network device) acts as the IAB donor, the primary base station actively generates K using the primary base station key. IAB , to ensure that IAB donor and IAB node maintain the same K IAB .

[0298] like Figure 11 As shown, a key generation method provided in an embodiment of the present application is applied in a scenario where a first device (IAB node) is connected to a primary base station and a secondary base station. The method includes the following steps:

[0299] S201. The IAB node determines a type of dual connectivity according to a communication standard supported by a primary base station, a communication standard supported by a secondary base station, and a communication standard supported by a core network.

[0300] Optionally, the IAB node determines the communication standard supported by the master base station, which can be specifically implemented as: the supported communication standard. The configuration parameters in the broadcast message include one or more of the following: base station identifier, logical cell identifier, physical cell identifier, uplink frequency band or downlink frequency band. It should be understood that when the configuration parameters in the broadcast message belong to the configuration parameters of the 5G communication system, the IAB node can determine that the master base station supports the 5G communication standard. Alternatively, when the configuration parameters in the broadcast message belong to the configuration parameters of the 4G communication system, the IAB node can determine that the master base station supports the 4G communication standard.

[0301] For example, assuming that the 4G frequency points are A1, A2, and A3, and the 5G frequency points are B1, B2, and B3. When the broadcast message sent by the master base station has a frequency point B1, the IAB node can determine that the master base station supports the 5G communication standard.

[0302] Optionally, the IAB node determines the communication standard supported by the secondary base station, which can be specifically implemented as: the IAB node receives the RRC reconfiguration message sent by the master base station, the RRC reconfiguration message is used to configure the radio bearer between the IAB node and the secondary base station, and the RRC reconfiguration message includes secondary cell group configuration information. The IAB node determines the communication standard supported by the secondary base station according to the secondary cell group configuration information. It should be understood that when the secondary cell group configuration information belongs to the 5G communication standard, the IAB node can determine that the secondary base station supports the 5G communication standard. Alternatively, when the secondary cell group configuration information belongs to the 4G communication standard, the IAB node can determine that the secondary base station supports the 4G communication standard.

[0303] For example, the secondary cell group configuration information belonging to the 5G communication standard can be denoted as nr-SecondaryCellGroupConfig or sourceSCG-NR-Config. The secondary cell group configuration information belonging to the 4G communication standard can be denoted as sourceSCG-EUTRA-Config.

[0304] Optionally, the IAB node determines the communication standard supported by the core network, which can be specifically implemented as: the IAB node receives the broadcast message sent by the master base station. The IAB node determines the communication standard supported by the core network according to the cell configuration information in the broadcast message. It should be understood that if the cell configuration information in the broadcast message belongs to the 5G communication standard, the IAB node determines that the core network supports the 5G communication standard. If the cell configuration information in the broadcast message belongs to the 4G communication standard, the IAB node determines that the core network supports the 4G communication standard.

[0305] Exemplarily, the cell configuration information can comprise cell access related information (cellAccessRelatedInfo). The cell access related information belonging to the 5G communication system can be denoted as cellAccessRelatedInfo-5GC. The cell access related information belonging to the 4G communication system can be denoted as cellAccessRelatedInfo-EUTRA-EPC.

[0306] Optionally, the IAB node determines the type of the dual connectivity, including one of the following cases:

[0307] Case 1: When the master base station supports the 5G communication system, the secondary base station supports the 4G communication system, and the core network supports the 5G communication system, the IAB node determines the type of the dual connectivity as NE-DC.

[0308] Case 2: When the master base station supports the 4G communication system, the secondary base station supports the 5G communication system, and the core network supports the 5G communication system, the IAB node determines the type of the dual connectivity as NGEN-DC.

[0309] Case 3: When the master base station supports the 5G communication system, the secondary base station supports the 5G communication system, and the core network supports the 5G communication system, the IAB node determines the type of the dual connectivity as NR-DC.

[0310] Case 4: When the master base station supports the 4G communication system, the secondary base station supports the 5G communication system, and the core network supports the 4G communication system, the IAB node determines the type of the dual connectivity as EN-DC.

[0311] S202: When the type of the dual connectivity is NE-DC, NR-DC or NGEN-DC, the IAB node generates K IAB .

[0312] As a possible implementation manner, the IAB node generates K IAB .

[0313] The key input parameter comprises an IP address of the IAB donor and an IP address of the IAB node.

[0314] Optionally, the IAB node can obtain the IP address of the IAB donor from a second device. Exemplarily, the second device can be an OAM system or a core network element.

[0315] Alternatively, if the IP address of the IAB node is allocated by the second device, the IAB node may obtain the IP address of the IAB node from the second device. In this case, the second device may encapsulate the IP address of the IAB node and the IP address of the IAB donor into a message and send the message to the IAB node.

[0316] Optionally, in the case that the IP address of the IAB node is allocated by an IAB donor, the IAB node may obtain the IP address of the IAB node from the primary base station or the secondary base station.

[0317] For example, the primary base station serves as an IAB donor and allocates an IP address to an IAB node. The IAB node then sends an IP address request message to the primary base station, and then receives an IP address notification message from the primary base station, which includes the IP address of the IAB node.

[0318] For another example, the primary base station serves as an IAB donor and allocates an IP address to the IAB node. Thus, the IAB node receives an RRC reconfiguration message sent by the primary base station, and the RRC reconfiguration message includes the IP address of the IAB node.

[0319] For another example, the secondary base station serves as an IAB donor and allocates an IP address to the IAB node. Thus, the IAB node can send an IP address request message to the secondary base station; then, the IAB node receives an IP address notification message sent by the secondary base station, which includes the IP address of the IAB node.

[0320] It should be understood that the IAB node generates K IAB Afterwards, K will be saved IAB .

[0321] based on Figure 11 In the embodiment shown, the IAB node can accurately determine the type of dual connectivity used by the IAB node based on the communication standards supported by the primary base station, the communication standards supported by the secondary base station, and the communication standards supported by the core network. Furthermore, when the type of dual connectivity is NE-DC, NR-DC, or NGEN-DC, the IAB node can generate K based on the primary base station key. IAB , to ensure that IAB donor and IAB node maintain the same K IAB .

[0322] It should be understood that when the type of dual connectivity is EN-DC, the IAB node generates K IAB .

[0323] The technical solution one will be described in detail in the form of examples in combination with specific application scenarios.

[0324] Scenario 1: The first device (i.e., the IAB node) registers to the network through the first access network device without the IAB donor function. Then, the first access network device selects the second access network device with the IAB donor function as the secondary base station for the first device, and the second access network device is responsible for allocating the IP address of the IAB node for the first device.

[0325] Based on scenario 1, as shown in Figure 12 , a key generation method provided by the embodiment of the application includes the following steps:

[0326] S301: The first device registers to the network through the first access network device.

[0327] In the process of registering to the network, the first device can perform authentication, security context negotiation and the like.

[0328] In the registration process of the first device, the first device and the first access network device obtain the same AS layer key. The AS layer key between the first device and the first access network device is used for security protection of the AS layer communication between the first device and the first access network device. In the dual connectivity scenario, since the first access network device serves as the primary base station of the first device, the AS layer key between the first device and the first access network device can be referred to as the primary base station key.

[0329] S302: The first access network device determines that the first device is an IAB node.

[0330] S303: In the case where it is necessary to select a secondary base station for the first device, the first access network device judges whether it has the IAB node function.

[0331] S304: In the case where the first access network device does not have the IAB node function, the first access network device selects the second access network device with the IAB donor function as the secondary base station for the first device.

[0332] S305: The first access network device sends an SN addition / modification request message to the second access network device.

[0333] The SN addition / modification request message includes third indication information. The third indication information is used to indicate that the first device is an IAB node.

[0334] In this way, the second access network device can learn that the first device is an IAB node based on the third indication information. Furthermore, since the second access network device has an IAB donor function, the second access network device can serve as an IAB donor of the first device and allocate an IP address of an IAB node to the first device. It should be understood that the IP address of the IAB node here is the first IP address in the embodiment shown. Figure 10

[0335] Optionally, in addition to the related information elements in the prior art, the SN addition / modification request message can also include the first indication information and the second indication information.

[0336] S306, the first access network device receives the SN addition / modification request ACK message sent by the second access network device.

[0337] Optionally, in the case where the SN addition / modification request message includes the first indication information and the second indication information, the SN addition / modification request ACK message includes the IP address of the IAB donor and the IP address of the IAB node.

[0338] S307, the first access network device generates K IAB based on the master base station key, the IP address of the IAB donor, and the IP address of the IAB node.

[0339] S308, the first access network device sends an RRC reconfiguration message to the first device.

[0340] The RRC reconfiguration message includes the IP address of the IAB node.

[0341] S309, the first access network device receives an RRC reconfiguration complete message sent by the first device.

[0342] S310, the first access network device sends an SN reconfiguration complete message to the second access network device.

[0343] The SN reconfiguration complete message includes K​IAB .

[0344] It should be understood that the second access network device obtains the K IAB from the SN reconfiguration complete message. IAB .

[0345] S311, the first device receives an IP address notification message sent by the second device.

[0346] The IP address notification message includes an IP address of the IAB donor.

[0347] It should be understood that the execution timing of step S311 is only after step S304, and the specific execution timing of step S312 is not limited. For example, the execution timing of step S311 can be before step S310.

[0348] S312, the first device determines the type of dual connectivity.

[0349] S313, when the type of dual connectivity is NE-DC, NR-DC or NGEN-DC, the first device generates K IAB based on the master base station key, the IP address of the IAB donor and the IP address of the IAB node.

[0350] The specific implementation details of steps S312-S313 can refer to the embodiments shown in Figure 11 , which will not be described here. In addition, steps S312-S313 can be executed at any time after step S308, and the embodiments of the present application do not limit this.

[0351] S314, the first device and the second access network device establish a secure tunnel using K IAB .

[0352] Based on the embodiments shown in Figure 12 , in the case of the secondary base station as the IAB donor, the master base station generates K IAB based on the master base station key, and sends K IAB to the secondary base station. The IAB node generates K IAB based on the master base station key. Thus, the IAB node and the IAB donor maintain the same K IAB , so as to facilitate the IAB node and the IAB donor to establish a secure tunnel based on K IAB , which is conducive to the IAB node to adopt a dual connectivity mode for networking.

[0353] In scenario 2, a first device (also known as an IAB node) registers with the network through a first access network device that doesn't have IAB donor functionality. The first access network device then selects a second access network device that does have IAB donor functionality as a secondary base station for the first device. The second device is responsible for allocating an IAB node IP address to the first device.

[0354] Based on scenario 2, Figure 13 As shown, a key generation method provided in an embodiment of the present application includes the following steps:

[0355] S401-S404 are the same as steps S301-S304, and their detailed description can be found in Figure 12 The embodiments shown are not described in detail here.

[0356] S405. The first device receives the first IP address notification message sent by the second device.

[0357] The first IP address notification message includes the IP address of the IAB donor and the IP address of the IAB node.

[0358] It should be understood that the embodiment of the present application does not limit the execution order of step S405 and steps S406-S410. That is, step S405 can be executed before or after any one of steps S406-S410.

[0359] S406: The first access network device sends an SN addition / modification request message to the second access network device.

[0360] The SN addition / modification request message includes third indication information. The third indication information is used to indicate that the first device is an IAB node.

[0361] Optionally, the SN addition / modification request message may include first indication information and second indication information in addition to the related information elements in the prior art.

[0362] S407: The first access network device receives the SN addition / modification request ACK message sent by the second access network device.

[0363] S408. The first access network device sends an RRC reconfiguration message to the first device.

[0364] S409. The first access network device receives an RRC reconfiguration completion message sent by the first device.

[0365] S410. The first access network device sends an SN reconfiguration complete message to the second access network device.

[0366] S411. The first device sends a second IP address notification message to the second access network device.

[0367] The second IP address notification message includes the IP address of the IAB node.

[0368] S412: The second access network device sends an SN key request message to the first access network device.

[0369] Among them, the SN key request message is used to request K IAB .

[0370] The SN key request message includes the IP address of the IAB donor and the IP address of the IAB node.

[0371] S413: The first access network device generates K based on the master base station key, the IP address of the IAB donor and the IP address of the IAB node. IAB .

[0372] S414. The first access network device sends an SN key response message to the second access network device.

[0373] Among them, the SN key response message includes K IAB .

[0374] S415: The first device determines the type of dual connectivity.

[0375] S416: When the dual connectivity type is NE-DC, NR-DC, or NGEN-DC, the first device generates K according to the primary base station key, the IP address of the IAB donor, and the IP address of the IAB node. IAB .

[0376] S417: The first device and the second access network device use K IAB Establish a secure tunnel.

[0377] based on Figure 13 In the embodiment shown, when the secondary base station serves as an IAB donor, the primary base station generates K using the primary base station key. IAB , and K IAB Send to the secondary base station. IAB node generates K with the primary base station key IABTherefore, IAB node and IABdonor maintain the same K IAB , so that the IAB node and IAB donor can communicate based on K IAB Establishing a secure tunnel is beneficial for IABnode to adopt dual connection mode for networking.

[0378] In Scenario 3, a first device (also known as an IAB node) registers with the network through a first access network device with IAB donor functionality. The first access network device then acts as the first device's IAB donor and allocates the IP address of the IAB node to the first device. The first access network device then selects a third access network device as a secondary base station for the first device.

[0379] Based on scenario 3, Figure 14 As shown, a key generation method provided in an embodiment of the present application includes the following steps:

[0380] S501: A first device registers with a network through a first access network device.

[0381] S502: The first access network device determines that the first device is an IAB node.

[0382] S503: When the first access network device has an IAB node function, the first access network device sends a notification message to the second device.

[0383] The notification message is used to indicate that the first device is registered with the network through the first access network device having the IAB donor function. In other words, the notification message is used to indicate that the first access network device serves as the IAB donor for the first device.

[0384] Optionally, the notification message may include an identifier of the first device and an identifier of the first access network device.

[0385] S504: The second device sends an IP address notification message to the first device.

[0386] The IP address notification information includes the IP address of the IAB donor.

[0387] It should be understood that step S504 can be executed at any time before step S513, and this embodiment of the present application does not limit this.

[0388] S505: The first access network device selects a third access network device as a secondary base station of the first device.

[0389] S506: The first access network device sends an SN addition / modification request message to the third access network device.

[0390] S507: The first access network device receives the SN addition / modification request ACK message sent by the third access network device.

[0391] S508. The first access network device sends an RRC reconfiguration message to the first device.

[0392] Since the first access network device, as the IAB donor, is responsible for allocating the IP address of the IAB node to the first device, the RRC reconfiguration message may include the IP address of the IAB node.

[0393] S509. The first access network device receives an RRC reconfiguration completion message sent by the first device.

[0394] S510. The first access network device sends an SN reconfiguration complete message to the third access network device.

[0395] S511, the first access network device generates K according to the master base station key, the IP address of the IAB donor and the IP address of the IAB node. IAB .

[0396] It should be understood that the embodiment of the present application does not limit the execution order of step S511 and steps S504-S510. That is, step S511 can be executed before or after any one of steps S504-S510.

[0397] S512: The first device determines the type of dual connectivity.

[0398] S513: When the dual connectivity type is NE-DC, NR-DC, or NGEN-DC, the first device generates K according to the primary base station key, the IP address of the IAB donor, and the IP address of the IAB node. IAB .

[0399] S514: The first device and the first access network device use K IAB Establish a secure tunnel.

[0400] based on Figure 14 In the embodiment shown, when the master base station serves as the IAB donor, both the master base station and the IAB node generate K using the master base station key. IAB Therefore, IAB node and IAB donor maintain the same K IAB , so that IAB node and IABdonor can communicate based on K IABEstablishing a secure tunnel is beneficial for IAB nodes to adopt dual-connection networking.

[0401] Scenario 4: A first device (also known as an IAB node) registers with the network through a first access network device with IAB donor functionality. The first access network device then acts as the first device's IAB donor. The first access network device selects a third access network device as a secondary base station for the first device. The second device is responsible for allocating the IP address of the IAB node to the first device.

[0402] Based on scenario 4, Figure 15 As shown, a key generation method provided in an embodiment of the present application includes the following steps:

[0403] S601: A first device registers to a network through a first access network device.

[0404] S602: The first access network device determines that the first device is an IAB node.

[0405] S603: When the first access network device has an IAB node function, the first access network device sends a notification message to the second device.

[0406] The notification message is used to indicate that the first device is registered with the network through the first access network device having the IAB donor function. In other words, the notification message is used to indicate that the first access network device serves as the IAB donor for the first device.

[0407] S604: The second device sends a first IP address notification message to the first device.

[0408] The first IP address notification message includes the IP address of the IAB node and the IP address of the IAB donor.

[0409] It should be understood that the embodiment of the present application does not limit the execution order between steps S603-S604 and steps S605-S610. That is, steps S603-S604 can be executed before or after any one of steps S606-S610.

[0410] S605: The first access network device selects a third access network device as a secondary base station of the first device.

[0411] S606: The first access network device sends an SN addition / modification request message to the third access network device.

[0412] S607. The first access network device receives the SN addition / modification request ACK message sent by the third access network device.

[0413] S608. The first access network device sends an RRC reconfiguration message to the first device.

[0414] S609. The first access network device receives an RRC reconfiguration complete message sent by the first device.

[0415] S610. The first access network device sends an SN reconfiguration complete message to the third access network device.

[0416] S611. The first access network device receives a second IP address notification message sent by the first device.

[0417] The second IP address notification message includes an IP address of the IAB node.

[0418] S612. The first access network device generates K IAB based on the master base station key, the IP address of the IAB donor, and the IP address of the IAB node.

[0419] It should be understood that steps S611-S612 can be performed at any time after step S604, and the embodiments of the present application do not limit this.

[0420] S613. The first device determines the type of dual connectivity.

[0421] S614. When the type of dual connectivity is NE-DC, NR-DC, or NGEN-DC, the first device generates K IAB based on the master base station key, the IP address of the IAB donor, and the IP address of the IAB node.

[0422] S615. The first device and the first access network device establish a secure tunnel using K IAB .

[0423] Based on the embodiments shown in Figure 15 , when the master base station is an IAB donor, the master base station and the IAB node both generate K IAB based on the master base station key. Thus, the IAB node and the IAB donor maintain the same K IAB , so that the IAB node and the IAB donor establish a secure tunnel based on K IAB , which facilitates the IAB node to adopt a dual connectivity mode for networking.

[0424] Technical solution two

[0425] In a dual connectivity scenario (for example, a NE-DC, NR-DC, or NGEN-DC scenario), the network side can obtain an IAB key according to Figure 16 The IAB node can obtain an IAB key according to Figure 17 the embodiment shown in the figure.

[0426] As Figure 16 shown, a key generation method provided by the embodiment of the application includes the following steps:

[0427] S701, the first access network device determines that the first device registered to the network through the first access network device is an IAB node.

[0428] S702, in the case where a secondary base station needs to be selected for the first device, the first access network device judges whether it has an IAB node function.

[0429] Among them, steps S701-S702 are similar to steps S101-S102 in Figure 10 , and the specific implementation mode can refer to the description in the embodiment shown in Figure 10 .

[0430] It should be understood that the first access network device can generate a secondary base station key according to the primary base station key and the SN count value.

[0431] Optionally, when the first access network device does not have an IAB donor function, the following steps S703-S705 are executed; when the first access network device has an IAB donor function, the following steps S706-S707 are executed.

[0432] S703, in the case where the first access network device does not have an IAB donor function, the first access network device selects a second access network device having an IAB donor function as a secondary base station of the first device.

[0433] S704, the first access network device sends a secondary base station configuration message to the second access network device.

[0434] Among them, the secondary base station configuration message is used to configure the second access network device as the secondary base station of the first device.

[0435] In the embodiment of the application, the secondary base station configuration message includes third indication information and a secondary base station key. The third indication information is used to indicate that the first device is an IAB node.

[0436] It should be understood that when the secondary base station configuration message includes the third indication information, the second access network device can learn, based on the third indication information, that the first device is an IAB node. Furthermore, the second access network device determines whether it has the IAB donor function. If the second access network device has the IAB donor function, the second access network device may consider itself the IAB donor of the first device, and thus the second access network device may perform the following step S705.

[0437] S705: The second access network device generates K according to the secondary base station key. IAB1 .

[0438] As a possible implementation method, the second access network device generates K according to the secondary base station key and the first key input parameter. IAB1 The first key input parameter includes a first IP address and a second IP address. The first IP address is the IP address used by the first device to communicate with the IAB donor. The second IP address is the IP address used by the second access network device to communicate with the IAB node.

[0439] In this embodiment of the present application, the second access network device can obtain the second IP address from its own database.

[0440] In the embodiment of the present application, the second access network device may determine the first IP address, or the second access network device may obtain the first IP address from the first device or the second device.

[0441] Based on the above steps S703-S705, when the secondary base station (ie, the second access network device) serves as the IAB donor, the secondary base station actively generates K using the secondary base station key. IAB , to ensure that IAB donor and IAB node maintain the same K IAB .

[0442] S706: When the first access network device has an IAB donor function, the first access network device selects a third access network device as a secondary base station of the first device.

[0443] S707: The first access network device generates K according to the secondary base station key. IAB2 .

[0444] As a possible implementation method, the first access network device generates K according to the secondary base station key and the second key input parameters. IAB2The second key input parameter includes a first IP address and a third IP address. The first IP address is an IP address used by the first device to communicate with the IAB donor. The third IP address is an IP address used by the first access network device to communicate with the IAB node.

[0445] In this embodiment of the present application, the first access network device can obtain the third IP address from its own database.

[0446] In the embodiment of the present application, the first access network device may determine the first IP address, or the first access network device may obtain the first IP address from the first device or the second device.

[0447] Based on the above steps S706-S707, when the primary base station (ie, the first access network device) serves as the IAB donor, the primary base station actively generates K using the secondary base station key. IAB , to ensure that IAB donor and IAB node maintain the same K IAB .

[0448] like Figure 17 As shown, a key generation method provided in an embodiment of the present application is applied in a scenario where an IAB node is connected to a primary base station and a secondary base station. The method includes the following steps:

[0449] S801 is the same as step S20, and its detailed description can refer to Figure 11 The embodiments shown are not described in detail here.

[0450] S802: When the dual connectivity type is NE-DC, NR-DC, or NGEN-DC, the IAB node generates K according to the secondary base station key. IAB .

[0451] The IAB node can deduce the secondary base station key based on the primary base station key.

[0452] As a possible implementation method, the IAB node generates K according to the secondary base station key and key input parameters. IAB .

[0453] It should be understood that the specific introduction of key input parameters and how to obtain them can be found in Figure 11 The description of step S202 in the illustrated embodiment will not be repeated here.

[0454] based on Figure 17 In the embodiment shown, in the NE-DC, NR-DC or NGEN-DC scenario, the IAB node is guaranteed to generate K using the secondary base station key. IAB, thereby ensuring that IAB donor and IAB node maintain the same K IAB .

[0455] The following describes the second technical solution in detail by taking examples in combination with specific application scenarios.

[0456] In Scenario 1, a first device (also known as an IAB node) registers with the network through a first access network device that doesn't have IAB donor functionality. The first access network device then selects a second access network device that does have IAB donor functionality as a secondary base station for the first device. The second access network device is responsible for allocating the IP address of the IAB node to the first device.

[0457] Based on scenario 1, Figure 18 As shown, a key generation method provided in an embodiment of the present application includes the following steps:

[0458] S901. A first device registers to a network through a first access network device.

[0459] S902: The first access network device determines that the first device is an IAB node.

[0460] S903: When it is necessary to select a secondary base station for the first device, the first access network device determines whether it has an IAB node function.

[0461] S904: When the first access network device does not have the IAB node function, the first access network device selects a second access network device that has the IAB donor function as a secondary base station of the first device.

[0462] After selecting the secondary base station, the first access network device may deduce the secondary base station key according to the primary base station key and the SN count value.

[0463] S905. The first access network device sends an SN addition / modification request message to the second access network device.

[0464] The SN addition / modification request message includes the secondary base station key and third indication information. The third indication information is used to indicate that the first device is an IAB node.

[0465] If the SN addition / modification request message includes the third indication information, the second access network device can determine whether it has the IAB donor function. If the second access network device has the IAB donor function, the second access network device can be considered an IAB donor for the first device, and the second access network device needs to perform the following step S910.

[0466] S906. The first access network device receives the SN addition / modification request ACK message sent by the second access network device.

[0467] S907. The first access network device sends an RRC reconfiguration message to the first device.

[0468] The RRC reconfiguration message is used to configure a radio bearer between the second access network device and the first device. Thus, based on the RRC reconfiguration message, the first device can learn that the second access network device serves as a secondary base station.

[0469] In addition, the RRC reconfiguration message also includes the SN count value. Therefore, the first device can deduce the secondary base station key according to the primary base station key and the SN count value.

[0470] S908. The first access network device receives an RRC reconfiguration completion message sent by the first device.

[0471] S909. The first access network device sends an SN reconfiguration complete message to the second access network device.

[0472] It should be understood that after receiving the SN reconfiguration complete message, the second access network device may establish an RRC connection with the first device, so that the second access network device and the first device can communicate directly.

[0473] S910: The second access network device generates K according to the secondary base station key, the IP address of the IAB donor and the IP address of the IAB node. IAB .

[0474] It should be understood that the second access network device obtains the IP address of the IAB donor locally and allocates the IP address of the IAB node to the first device.

[0475] It should be understood that step S910 can be executed at any time after step S905, and this embodiment of the present application does not limit this.

[0476] S911. The second access network device sends a first IP address notification message to the first device.

[0477] The first IP address notification message includes the IP address of the IAB node.

[0478] S912. The second device sends a second IP address notification message to the first device.

[0479] The second IP address notification message includes the IP address of the IAB donor.

[0480] It should be understood that step S912 can be executed at any time after step S904, and this embodiment of the present application does not limit this.

[0481] Based on steps S911 and S912 , the first device can obtain the IP address of the IAB donor and the IP address of the IAB node.

[0482] S913: The first device determines the type of dual connectivity.

[0483] S914: When the dual connectivity type is NE-DC, NR-DC, or NGEN-DC, the first device generates K according to the secondary base station key, the IP address of the IAB donor, and the IP address of the IAB node. IAB .

[0484] S915. The first device and the second access network device use K IAB Establish a secure tunnel.

[0485] based on Figure 18 In the embodiment shown, when the secondary base station serves as an IAB donor, the secondary base station generates K using the secondary base station key. IAB , IAB node generates K with the secondary base station key IAB Therefore, IAB node and IAB donor maintain the same K IAB , so that the IAB node and IAB donor can communicate based on K IAB Establishing a secure tunnel is beneficial for IAB nodes to adopt dual-connection networking.

[0486] In scenario 2, a first device (also known as an IAB node) registers with the network through a first access network device that doesn't have IAB donor functionality. The first access network device then selects a second access network device that does have IAB donor functionality as a secondary base station for the first device. The second device is responsible for allocating an IAB node IP address to the first device.

[0487] Based on scenario 2, Figure 19As shown, a key generation method provided in an embodiment of the present application includes the following steps:

[0488] S1001. A first device registers to a network through a first access network device.

[0489] S1002: The first access network device determines that the first device is an IAB node.

[0490] S1003: When it is necessary to select a secondary base station for the first device, the first access network device determines whether it has an IAB node function.

[0491] S1004: When the first access network device does not have an IAB node function, the first access network device selects a second access network device that has an IAB donor function as a secondary base station of the first device.

[0492] S1005. The second device sends a first IP address notification message to the first device.

[0493] The first IP address notification message includes the IP address of the IAB node and the IP address of the IAB donor.

[0494] It should be understood that step S1005 can be executed at any time after step S1004 and before step S1011, and this embodiment of the present application does not limit this.

[0495] S1006. The first access network device sends an SN addition / modification request message to the second access network device.

[0496] The SN addition / modification request message includes the secondary base station key and third indication information. The third indication information is used to indicate that the first device is an IAB node.

[0497] If the SN addition / modification request message includes the third indication information, the second access network device can determine whether it has the IAB donor function. If the second access network device has the IAB donor function, the second access network device can be considered an IAB donor for the first device, and the second access network device needs to perform the following step S1012.

[0498] S1007. The first access network device receives an SN addition / modification request ACK message sent by the second access network device.

[0499] S1008. The first access network device sends an RRC reconfiguration message to the first device.

[0500] The RRC reconfiguration message is used to configure a radio bearer between the second access network device and the first device. Thus, based on the RRC reconfiguration message, the first device can learn that the second access network device is a secondary base station.

[0501] In addition, the RRC reconfiguration message further includes an SN count value. Thus, the first device can derive the secondary base station key according to the primary base station key and the SN count value.

[0502] S1009. The first access network device receives an RRC reconfiguration complete message sent by the first device.

[0503] S1010. The first access network device sends an SN reconfiguration complete message to the second access network device.

[0504] It should be understood that after receiving the SN reconfiguration complete message, the second access network device can establish an RRC connection with the first device, so that the second access network device and the first device can directly communicate.

[0505] S1011. The first device sends a second IP address notification message to the second access network device.

[0506] The second IP address notification message includes an IP address of an IAB donor.

[0507] S1012. The second access network device generates K IAB .

[0508] It should be understood that the second access network device obtains the IP address of the IAB donor locally. In addition, the second access network device obtains the IP address of the IAB node according to the above-mentioned second IP address notification message.

[0509] S1013. The first device determines the type of dual connectivity.

[0510] S1014. When the type of dual connectivity is NE-DC, NR-DC or NGEN-DC, the first device generates K IAB .

[0511] It should be understood that steps S1013-S1014 can be performed at any time after step S1008, and the embodiments of the present application do not make any limitation in this regard.

[0512] S1015, the first device and the second access network device use K IAB to establish a secure tunnel.

[0513] Based on Figure 19 In the embodiment shown, in the case of the secondary base station as an IAB donor, the secondary base station generates K IAB with the secondary base station key, and the IAB node generates K IAB with the secondary base station key. Thus, the IAB node and the IAB donor maintain the same K IAB , so as to facilitate the IAB node and the IAB donor to establish a secure tunnel according to K IAB , which is conducive to the IAB node to adopt a dual connectivity mode for networking.

[0514] Scenario 3, the first device (i.e. IAB node) registers to the network through the first access network device with IAB donor function. Thus, the first access network device serves as the IAB donor of the first device, and the first access network device allocates an IP address of the IAB node for the first device. The first access network device selects a third access network device as a secondary base station for the first device.

[0515] Based on scenario 3, as Figure 20 shown, a key generation method provided by the embodiments of the present application includes the following steps:

[0516] S1101-S1110, same as steps S501-S510, and the specific description can refer to the embodiment shown in Figure 14 , which will not be repeated here.

[0517] Among them, after selecting the third access network device as the secondary base station, the first access network device will generate the secondary base station key and send the secondary base station key to the third access network device through the SN addition / modification request message.

[0518] S1111, the first access network device generates K IAB according to the secondary base station key, the IP address of the IAB donor and the IP address of the IAB node.

[0519] It should be understood that step S1111 can be performed at any time after S1105, and the embodiments of the present application do not make any limitation in this regard.

[0520] Optionally, if step S1111 is performed before step S1106, the first access network device may delete the secondary base station key after performing step S1106.

[0521] Optionally, if step S1111 is performed after step S1106, the first access network device needs to save the secondary base station key before completing step S1106 until completing step S1111.

[0522] S1112. The first device determines the type of dual connectivity.

[0523] S1113: When the dual connectivity type is NE-DC, NR-DC, or NGEN-DC, the first device generates K according to the secondary base station key, the IP address of the IAB donor, and the IP address of the IAB node. IAB .

[0524] It should be understood that steps S1112-S1113 can be executed at any time after step S1108, and this embodiment of the present application does not limit this.

[0525] S1114. The first device and the first access network device use K IAB Establish a secure tunnel.

[0526] based on Figure 20 In the embodiment shown, when the primary base station serves as the IAB donor, both the primary base station and the IAB node generate K using the secondary base station key. IAB Therefore, IAB node and IAB donor maintain the same K IAB , so that IAB node and IABdonor can communicate based on K IAB Establishing a secure tunnel is beneficial for IAB nodes to adopt dual-connection networking.

[0527] Scenario 4: A first device (also known as an IAB node) registers with the network through a first access network device with IAB donor functionality. The first access network device then acts as the first device's IAB donor. The first access network device selects a third access network device as a secondary base station for the first device. The second device is responsible for allocating the IP address of the IAB node to the first device.

[0528] Based on scenario 4, Figure 21 As shown, a key generation method provided in an embodiment of the present application includes the following steps:

[0529] S1201-S1211 are the same as steps S601-S611, and their detailed description can be found in Figure 15 The embodiments shown are not described in detail here.

[0530] wherein, after selecting the third access network device as the secondary base station, the first access network device generates the secondary base station key and sends the secondary base station key to the third access network device through the SN addition / modification request message.

[0531] S1212, the first access network device generates K IAB based on the secondary base station key, the IP address of the IAB donor and the IP address of the IAB node.

[0532] It should be understood that step S1211 can be performed at any time after step S1204. Step S1212 can be performed at any time after steps S1205 and S1211.

[0533] Optionally, if step S1212 is performed before step S1206, the first access network device can delete the secondary base station key after performing step S1206.

[0534] Optionally, if step S1212 is performed after step S1206, the first access network device needs to save the secondary base station key until step S1212 is performed before performing step S1206.

[0535] S1213, the first device determines the type of dual connectivity.

[0536] S1214, when the type of dual connectivity is NE-DC, NR-DC or NGEN-DC, the first device generates K IAB based on the secondary base station key, the IP address of the IAB donor and the IP address of the IAB node.

[0537] It should be understood that steps S1213-S1214 can be performed at any time after step S1208, which is not limited by the embodiments of the present application.

[0538] S1215, the first device and the first access network device establish a secure tunnel using K IAB .

[0539] Based on the embodiments shown in Figure 21 , in the case of the primary base station as the IAB donor, the primary base station and the IAB node generate K IAB based on the secondary base station key. Thus, the IAB node and the IAB donor maintain the same K IAB , so as to facilitate the IAB node and the IAB donor to establish a secure tunnel according to K IAB , which is conducive to the IAB node to adopt a dual connectivity mode for networking.

[0540] Technical solution three

[0541] In some dual connectivity scenarios (such as NE-DC, NR-DC, or NGEN-DC scenarios), the IAB node can obtain K Figure 22 as shown in the embodiment. IAB The network side can obtain K Figure 23 as shown in the embodiment. IAB .

[0542] As shown in Figure 22 , a key generation method provided by an embodiment of the present application is applied to a scenario in which a first device (IAB node) connects a primary base station and a secondary base station, and the method comprises the following steps:

[0543] S1301, the IAB node learns that the primary base station or the secondary base station is an IAB donor.

[0544] Optionally, step S1301 can adopt any one of the following implementation manners:

[0545] Implementation manner one, when the IAB node receives fourth indication information, the IAB node learns that the primary base station is an IAB donor, and the fourth indication information is used to indicate that the primary base station is an IAB donor. Or, when the IAB node receives fifth indication information, the IAB node learns that the secondary base station is an IAB donor, and the fifth indication information is used to indicate that the secondary base station is an IAB donor.

[0546] Optionally, the IAB node receiving the fourth indication information can be specifically implemented as: the IAB node receiving the fourth indication information sent by the primary base station. Illustratively, in this case, the fourth indication information can be carried in the RRC reconfiguration message sent by the primary base station to the IAB node.

[0547] Optionally, the IAB node receiving the fifth indication information can be specifically implemented as: the IAB node receiving the fifth indication information sent by the primary base station or the secondary base station. Illustratively, in this case, the fifth indication information can be carried in the RRC reconfiguration message sent by the primary base station to the IAB node. Or, the fifth indication information can be carried in the AS message sent by the secondary base station to the IAB node.

[0548] Implementation manner two, when the IAB node establishes a wireless backhaul link with the primary base station, the IAB node learns that the primary base station is an IAB donor. Or, when the IAB node establishes a wireless backhaul link with the secondary base station, the IAB node learns that the secondary base station is an IAB donor.

[0549] In a third implementation, the IAB node acquires the frequency band supported by the primary base station and the frequency band supported by the secondary base station. When the frequency band supported by the primary base station is higher than the frequency band supported by the secondary base station, the IAB node learns that the primary base station is the IAB donor. Alternatively, when the frequency band of the primary base station is lower than the frequency band supported by the secondary base station, the IAB node learns that the secondary base station is the IAB donor.

[0550] In a fourth implementation, when the IAB node receives the sixth indication information broadcast by the primary base station, the IAB node learns that the primary base station is the IAB donor. Alternatively, when the IAB node receives the sixth indication information broadcast by the secondary base station, the IAB node learns that the secondary base station is the IAB donor. The sixth indication information is used to indicate that the base station has the IAB donor function.

[0551] In S1302, when the primary base station is the IAB donor, the IAB node generates K IAB .

[0552] As a possible implementation, the IAB node generates K IAB .

[0553] The primary base station key is generated by the IAB node in the process of registering to the network through the primary base station.

[0554] In S1303, when the secondary base station is the IAB donor, the IAB node generates K IAB .

[0555] As a possible implementation, the IAB node generates K IAB .

[0556] The secondary base station key is generated by the IAB node according to the primary base station key.

[0557] Based on the embodiments shown in Figure 22 , whether the primary base station is the IAB donor or the secondary base station is the IAB donor, the IAB node can use the local key of the IAB donor to generate K IAB , so as to ensure that the IAB node and the IAB donor maintain the same K IAB .

[0558] As shown in Figure 23 , a key generation method provided by the embodiments of the present application includes the following steps:

[0559] S1401, the first access network device determines that the first device registered to the network through the first access network device is an IAB node.

[0560] S1402, in the case where a secondary base station needs to be selected for the first device, the first access network device judges whether it has an IAB node function.

[0561] The steps S1401-S1402 are similar to the steps S101-S102 in the method shown in Figure 10 , and the specific implementation manners can refer to the descriptions in the embodiments shown in Figure 10 .

[0562] Optionally, when the first access network device does not have an IAB donor function, the following steps S1403-S1405 are executed; when the first access network device has an IAB donor function, the following steps S1406-S1407 are executed.

[0563] S1403, in the case where the first access network device does not have an IAB donor function, the first access network device selects a second access network device having an IAB donor function as a secondary base station of the first device.

[0564] S1404, the first access network device sends a secondary base station configuration message to the second access network device.

[0565] The secondary base station configuration message is used to configure the second access network device as a secondary base station of the first device.

[0566] In the embodiments of the present application, the secondary base station configuration message includes third indication information and a secondary base station key. The third indication information is used to indicate that the first device is an IAB node.

[0567] It should be understood that, in the case where the secondary base station configuration message includes the third indication information, the second access network device can know that the first device is an IAB node. Therefore, the second access network device can judge whether it has an IAB donor function. In the case where the second access network device has an IAB donor function, the second access network device can consider that it is an IAB donor of the first device, and therefore the second access network device can execute the following step S1405.

[0568] S1405, the second access network device generates K IAB1 according to the secondary base station key.

[0569] As a possible implementation manner, the second access network device generates K IAB1The first key input parameter includes a first IP address and a second IP address. The first IP address is the IP address used by the first device to communicate with the IAB donor. The second IP address is the IP address used by the second access network device to communicate with the IAB node.

[0570] In this embodiment of the present application, the second access network device can obtain the second IP address from its own database.

[0571] In the embodiment of the present application, the second access network device may determine the first IP address, or the second access network device may obtain the first IP address from the first device or the second device.

[0572] Based on the above steps S1403-S1405, when the secondary base station (ie, the second access network device) serves as the IAB donor, the secondary base station actively generates K using the secondary base station key. IAB , to ensure that IAB donor and IAB node maintain the same K IAB .

[0573] S1406: When the first access network device has an IAB donor function, the first access network device selects a third access network device as a secondary base station of the first device.

[0574] S1407: The first access network device generates K according to the master base station key. IAB2 .

[0575] As a possible implementation method, the first access network device generates K according to the primary base station key and the second key input parameters. IAB2 The second key input parameter includes a first IP address and a third IP address. The first IP address is an IP address used by the first device to communicate with the IAB donor. The third IP address is an IP address used by the first access network device to communicate with the IAB node.

[0576] In this embodiment of the present application, the first access network device can obtain the third IP address from its own database.

[0577] In the embodiment of the present application, the first access network device may determine the first IP address, or the first access network device may obtain the first IP address from the first device or the second device.

[0578] Based on the above steps S1406-S1407, when the primary base station (ie, the first access network device) serves as the IAB donor, the primary base station actively generates K using the primary base station key. IAB , to ensure that IAB donor and IAB node maintain the same K IAB .

[0579] The third technical solution will be described in detail below by way of example in combination with specific application scenarios.

[0580] Scenario 1: The first device (i.e., an IAB node) is registered to the network through a first access network device without an IAB donor function. Then, the first access network device selects a second access network device with an IAB donor function as a secondary base station for the first device, and the second access network device is responsible for allocating an IP address of the IAB node for the first device.

[0581] Based on scenario 1, as shown in Figure 24 , a key generation method provided by an embodiment of the present application includes the following steps:

[0582] S1501-S1512: Similar to steps S901-S912, the specific description can be referred to the embodiment shown in Figure 18 , which will not be described here again.

[0583] Optionally, different from step S906, in step S1506, the SN addition / modification request ACK message sent by the second access network device can include fifth indication information.

[0584] Optionally, different from step S907, in step S1507, the RRC reconfiguration message sent by the first access network device can include fifth indication information, so that the first device knows that the secondary base station (i.e., the second access network device) is an IAB donor.

[0585] S1513: The first device knows that the second access network device is an IAB donor.

[0586] S1514: The first device generates K IAB according to the secondary base station key, the IP address of the IAB donor, and the IP address of the IAB node.

[0587] S1515: The first device and the second access network device establish a secure tunnel using K IAB .

[0588] Based on the embodiment shown in Figure 24 , in the case where the secondary base station is an IAB donor, the secondary base station generates K IAB using the secondary base station key, and the IAB node generates K IAB using the secondary base station key. Thus, the IAB node and the IAB donor maintain the same K IAB , so that the IAB node and the IAB donor can communicate with each other according to KIAB Establishing the security tunnel is conducive to the IAB node adopting a dual-connection manner for networking.

[0589] In scenario 2, the first device (namely, the IAB node) is registered to the network through the first access network device without the IAB donor function. Then, the first access network device selects the second access network device with the IAB donor function as the secondary base station for the first device. The second device is responsible for allocating the IP address of the IAB node for the first device.

[0590] Based on scenario 2, as shown in Figure 25 The key generation method provided by the embodiment of the present application includes the following steps:

[0591] S1601-S1612, similar to steps S1001-S1012, the specific description can be referred to the embodiment shown in Figure 19 , which will not be repeated here.

[0592] Optionally, different from step S1007, in step S1607, the SN addition / modification request ACK message sent by the second access network device can include the fifth indication information.

[0593] Optionally, different from step S1008, in step S1608, the RRC reconfiguration message sent by the first access network device can include the fifth indication information, so that the first device knows that the secondary base station (namely, the second access network device) is the IAB donor.

[0594] S1613, the first device knows that the second access network device is the IAB donor.

[0595] S1614, the first device generates K IAB based on the secondary base station key, the IP address of the IAB donor, and the IP address of the IAB node.

[0596] S1615, the first device and the second access network device use K IAB to establish a security tunnel.

[0597] Based on the embodiment shown in Figure 25 , in the case that the secondary base station is the IAB donor, the secondary base station generates K IAB based on the secondary base station key, and the IAB node generates K IAB based on the secondary base station key. Thus, the IAB node and the IAB donor maintain the same K IAB , so that the IAB node and the IAB donor can communicate with each other based on K IABEstablishing a secure tunnel is beneficial for IAB nodes to adopt dual-connection networking.

[0598] In Scenario 3, a first device (also known as an IAB node) registers with the network through a first access network device with IAB donor functionality. The first access network device then acts as the first device's IAB donor and allocates the IP address of the IAB node to the first device. The first access network device then selects a third access network device as a secondary base station for the first device.

[0599] Based on scenario 3, Figure 26 As shown, a key generation method provided in an embodiment of the present application includes the following steps:

[0600] S1701-S1711 are similar to steps S501-S511, and their detailed description can be found in Figure 14 The embodiments shown will not be described in detail here.

[0601] Optionally, different from step S508, in step S1708, the RRC reconfiguration message sent by the first access network device may include fourth indication information, so that the first device knows that the primary base station (ie, the first access network device) is the IAB donor.

[0602] S1712: The first device learns that the first access network device is an IAB donor.

[0603] S1713: The first device generates K based on the master base station key, the IP address of the IAB donor, and the IP address of the IAB node. IAB .

[0604] S1714. The first device and the first access network device use K IAB Establish a secure tunnel.

[0605] based on Figure 26 In the embodiment shown, when the master base station serves as the IAB donor, both the master base station and the IAB node generate K using the master base station key. IAB Therefore, IAB node and IAB donor maintain the same K IAB , so that IAB node and IABdonor can communicate based on K IAB Establishing a secure tunnel is beneficial for IAB nodes to adopt dual-connection networking.

[0606] Scenario 4: A first device (also known as an IAB node) registers with the network through a first access network device with IAB donor functionality. The first access network device then acts as the first device's IAB donor. The first access network device selects a third access network device as a secondary base station for the first device. The second device is responsible for allocating the IP address of the IAB node to the first device.

[0607] Based on scenario 4, Figure 27 As shown, a key generation method provided in an embodiment of the present application includes the following steps:

[0608] S1801-S1812 are similar to steps S601-S612, and their detailed description can be found in Figure 15 The embodiments shown will not be described in detail here.

[0609] Optionally, different from step S608, in step S1808, the RRC reconfiguration message sent by the first access network device may include fourth indication information, so that the first device knows that the primary base station (ie, the first access network device) is the IAB donor.

[0610] S1813: The first device learns that the first access network device is an IAB donor.

[0611] S1814: The first device generates K based on the master base station key, the IP address of the IAB donor, and the IP address of the IAB node. IAB .

[0612] S1815. The first device and the first access network device use K IAB Establish a secure tunnel.

[0613] based on Figure 27 In the embodiment shown, when the master base station serves as the IAB donor, both the master base station and the IAB node generate K using the master base station key. IAB Therefore, IAB node and IAB donor maintain the same K IAB , so that IAB node and IABdonor can communicate based on K IAB Establishing a secure tunnel is beneficial for IAB nodes to adopt dual-connection networking.

[0614] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the method. It is understandable that, in order to realize the above functions, the communication device (such as the first device, the first access network device, the second access network device) includes a hardware structure and / or software module corresponding to the execution of each function. In combination with the units and algorithm steps of each example described in the embodiment disclosed in this application, the embodiment of the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the technical solution of the embodiment of the present application.

[0615] The embodiment of the present application can divide the functional units of the communication device according to the above method example. For example, each functional unit can be divided according to each function, or two or more functions can be integrated into one processing unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. It should be noted that the division of units in the embodiment of the present application is schematic and is only a logical functional division. There may be other division methods in actual implementation.

[0616] like Figure 28 As shown, a communication device provided in an embodiment of the present application includes a processing module 101 and a communication module 102.

[0617] In a possible example, taking the communication device as an IAB node as an example, the processing module 101 is used to support the IAB node to execute Figure 11 Steps S201-S202 in Figure 17 Steps S801-S805 in Figure 22 Steps S1301-S1303 in the embodiment of the present application, and / or other processing operations that the IAB node needs to perform. The communication module 102 is used to support the IAB node to perform Figure 12 Steps S308, S309, and S311 in Figure 13 Steps S405, S408, S409, S411, and / or other communication operations that the IAB node needs to perform in the embodiment of the present application.

[0618] In another possible example, taking the communication device as a first access network device as an example, the processing module 101 is used to support the first access network device to execute Figure 10 Steps S101-S105, S107-S109 in Figure 16 Steps S701-S703, S706-S707 in Figure 23 Steps S1401-S1403, S1406-S1407, and / or other processing operations that the first access network device needs to perform in the embodiment of the present application. The communication module 102 is used to support the first access network device to perform Figure 10 Step S106 in Figure 16 Step S704 in Figure 23 Step S1404 in, and / or other communication operations that the first access network device needs to perform in an embodiment of the present application.

[0619] In another possible example, taking the communication device as a second access network device as an example, the processing module 101 is used to support the second access network device to execute Figure 16 Step S705 in Figure 23 The communication module 102 is used to support the second access network device to perform the step S1405 and / or other processing operations that the second access network device needs to perform in the embodiment of the present application. Figure 10 Step S106 in Figure 16 Step S704 in Figure 23 Step S1404 in, and / or other communication operations that the second access network device needs to perform in an embodiment of the present application.

[0620] Optionally, the communication device may further include a storage module 103 for storing program codes and data of the communication device. The data may include but is not limited to original data or intermediate data.

[0621] The processing module 101 may be a processor or controller, such as a CPU, a general-purpose processor, an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. A processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.

[0622] The communication module 102 can be a communication interface, a transceiver or a transceiver circuit, etc., wherein the communication interface is a general term. In a specific implementation, the communication interface can include multiple interfaces, for example, it can include: an interface between a base station and a terminal and / or other interfaces.

[0623] The storage module 103 may be a memory.

[0624] When the processing module 101 is a processor, the communication module 102 is a communication interface, and the storage module 103 is a memory, the communication device involved in the embodiment of the present application can be Figure 29 shown.

[0625] See Figure 29 As shown, the communication device includes: a processor 201, a communication interface 202, and a memory 203. Optionally, the communication device may further include a bus 204. The communication interface 202, the processor 201, and the memory 203 may be interconnected via the bus 204; the bus 204 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus 204 may be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, Figure 29 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0626] Optionally, an embodiment of the present application further provides a computer program product carrying computer instructions, which, when executed on a computer, enables the computer to execute the method described in the above embodiment.

[0627] Optionally, an embodiment of the present application further provides a computer-readable storage medium, which stores computer instructions. When the computer instructions are executed on a computer, the computer executes the method introduced in the above embodiment.

[0628] Optionally, an embodiment of the present application further provides a chip comprising: a processing circuit and transceiver pins, wherein the processing circuit and transceiver pins are used to implement the methods described in the above embodiments. The processing circuit is used to perform the processing actions in the corresponding methods, and the transceiver pins are used to perform the receiving / sending actions in the corresponding methods.

[0629] Those skilled in the art can understand that all or part of the above-mentioned embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (Digital Subscriber Line, DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available media can be magnetic media (such as floppy disk, hard disk, magnetic tape), optical media (such as digital video disc (Digital Video Disc, DVD)), or semiconductor media (such as solid state disk (Solid State Disk, SSD)) and the like.

[0630] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the above-described device embodiments are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, device or unit, and can be electrical or other forms.

[0631] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or they can be distributed on a plurality of devices. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.

[0632] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each functional unit may exist independently, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.

[0633] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus necessary general-purpose hardware, or of course by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a readable storage medium, such as a computer floppy disk, hard disk or optical disk, and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0634] The above is only a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application shall be included in the scope of protection of the present application. Therefore, the scope of protection of the present application shall be based on the scope of protection of the claims.

Claims

1. A key generation method is applied to a scenario where an integrated access backhaul IAB node is connected to a primary base station and a secondary base station, characterized in that: The method comprises the following steps: The IAB node determines the primary base station or the secondary base station as the IAB donor base station; When the master base station serves as the IAB host base station, the IAB node generates the IAB key K according to the master base station key. IAB ;or When the secondary base station serves as the IAB host base station, the IAB node generates K according to the secondary base station key. IAB ; Wherein, the secondary base station key is generated by the IAB node according to the primary base station key; The master base station key is generated by the IAB node during the process of registering with the network through the master base station.

2. The method according to claim 1, characterized in that The determining the primary base station or the secondary base station as the IAB donor base station includes: The IAB node receives fourth indication information from the primary base station; The IAB node determines the primary base station as the IAB donor base station according to the fourth indication information.

3. The method according to claim 2, characterized in that The fourth indication information is carried in an RRC reconfiguration message sent by the primary base station to the IAB node.

4. The method according to claim 1, wherein The determining the primary base station or the secondary base station as the IAB donor base station includes: The IAB node receives fifth indication information from the secondary base station; The IAB node determines, according to the fifth indication information, the secondary base station as the IAB donor base station.

5. The method according to claim 1, wherein The determining the primary base station or the secondary base station as the IAB donor base station includes: When a wireless backhaul link is established between the IAB node and the primary base station, the IAB node learns that the primary base station is the IAB donor base station; or, When a wireless backhaul link is established between the IAB node and the secondary base station, the IAB node learns that the secondary base station is the IAB donor base station.

6. The method according to any one of claims 1 to 5, characterized in that: The method further comprises: The IAB node is based on the K IAB A secure tunnel is established between the IAB node and the IAB host base station.

7. The method according to any one of claims 1 to 5, characterized in that: The master base station key is used to securely protect the communication between the master base station and the IAB node.

8. The method according to any one of claims 1 to 5, characterized in that: The master base station key is K gNB .

9. The method according to any one of claims 1 to 5, characterized in that: The secondary base station key is used to securely protect communications between the secondary base station and the IAB node.

10. The method according to any one of claims 1 to 5, characterized in that: The secondary base station key is K sn .

11. The method according to any one of claims 1 to 5, characterized in that: The primary base station and the secondary base station are both 5G base stations.

12. A key generation method, characterized in that: include: The first access network device determines that the first device is an IAB node, and the first device is registered with the network through the first access network device; The first access network device sends a secondary node addition / adjustment request message to a third access network device; wherein the secondary node addition / adjustment request message includes a secondary base station key, the secondary base station key is generated by the first access network device, and the third access network device is a secondary base station of the first device; The first access network device receives a secondary node addition / adjustment request confirmation message from the third access network device; The first access network sends an RRC reconfiguration message to the first device, wherein the RRC reconfiguration message includes fourth indication information, the first access network device is a primary base station, and the fourth indication information is used to indicate that the first access network device is an IAB host; The first access network device receives an RRC reconfiguration completion message; The first access network device sends a secondary base station reconfiguration completion message to the third access network device; The first access network device generates an IAB key K according to the primary base station key, the IP address of the first access network device and the IP address of the first device. IAB ; Wherein, the master base station key is generated by the IAB node during the process of registering to the network through the master base station; The first access network device uses the K IAB Establish a secure tunnel with the first device.

13. The method according to claim 12, characterized in that The method further comprises: During the process of the first device registering with the network through the first access network device, the first access network device obtains the primary base station key.

14. The method according to claim 12 or 13, characterized in that Also includes: In a case where the first access network device has an IAB host function, the first access network device sends a notification message to the second device, wherein the notification message is used to instruct the first access network device to serve as the IAB host of the first device.

15. The method according to claim 12 or 13, characterized in that Also includes: The first access network device selects the third access network device as a secondary base station of the first device.

16. The method according to claim 12 or 13, characterized in that The method further comprises: The first access network device allocates the IP address of the first device to the first device; wherein the RRC reconfiguration message also includes the IP address of the first device.

17. The method according to claim 12 or 13, characterized in that The first access network device and the third access network device are both 5G base stations.

18. The method according to claim 12 or 13, characterized in that The master base station key is used to securely protect the communication between the first access network device and the first device.

19. The method according to claim 12 or 13, characterized in that The master base station key is K gNB .

20. The method according to claim 12 or 13, characterized in that The secondary base station key is used to securely protect communications between the third access network device and the first device.

21. The method according to claim 12 or 13, characterized in that The secondary base station key is K sn .

22. A key generation method, characterized in that: include: The first access network device determines that the first device is an IAB node, and the first device is registered with the network through the first access network device; The first access network device sends a secondary node addition / adjustment request message to a third access network device; wherein the secondary node addition / adjustment request message includes a secondary base station key, the secondary base station key is generated by the first access network device, and the third access network device is a secondary base station of the first device; The third access network device receives the secondary node addition / adjustment request message; The third access network device sends a secondary node addition / adjustment request confirmation message to the first access network device; The first access network device receives the secondary node addition / adjustment request confirmation message from the third access network device; The first access network sends an RRC reconfiguration message to the first device, wherein the RRC reconfiguration message includes fourth indication information, the first access network device is a primary base station, and the fourth indication information is used to indicate that the first access network device is an IAB host; The first access network device receives an RRC reconfiguration completion message; The first access network device sends a secondary base station reconfiguration completion message to the third access network device; The third access network device receives the secondary base station reconfiguration completion message; The first access network device generates an IAB key K according to the primary base station key, the IP address of the first access network device and the IP address of the first device. IAB ; Wherein, the master base station key is generated by the IAB node during the process of registering to the network through the master base station; The first access network device uses the K IAB Establish a secure tunnel with the first device.

23. The method according to claim 22, characterized in that The method further comprises: During the process of the first device registering with the network through the first access network device, the first access network device obtains the primary base station key.

24. The method according to claim 22 or 23, characterized in that Also includes: In a case where the first access network device has an IAB host function, the first access network device sends a notification message to the second device, wherein the notification message is used to instruct the first access network device to serve as the IAB host of the first device; The second device receives the notification message; The second device sends an IP address notification message to the first device, where the IP address notification information includes the IP address of the first device.

25. The method according to claim 22 or 23, characterized in that Also includes: The first access network device selects the third access network device as a secondary base station of the first device.

26. The method according to claim 22 or 23, characterized in that The method further comprises: The first access network device allocates the IP address of the first device to the first device; wherein the RRC reconfiguration message also includes the IP address of the first device.

27. The method according to claim 22 or 23, characterized in that The method further comprises: The first device is registered with the network through the first access network device; The first device determines, according to the fourth indication information, that the first access network device is an IAB host; The first device generates an IAB key K according to the primary base station key, the IP address of the first access network device and the IP address of the first device. IAB ; The first device uses the K IAB Establish the secure tunnel with the first access network device.

28. The method according to claim 22 or 23, characterized in that The first access network device and the third access network device are both 5G base stations.

29. The method according to claim 22 or 23, characterized in that The master base station key is used to securely protect the communication between the first access network device and the first device.

30. The method according to claim 22 or 23, characterized in that The master base station key is K gNB .

31. The method according to claim 22 or 23, characterized in that The secondary base station key is used to securely protect communications between the third access network device and the first device.

32. The method according to claim 22 or 23, characterized in that The secondary base station key is K sn .

33. A computer-readable storage medium, characterized in that A computer program is stored thereon, which, when executed by a computer, causes the computer to execute the method described in any one of claims 1 to 11; or causes the computer to execute the method described in any one of claims 12 to 21; or causes the computer to execute the method described in any one of claims 22 to 32.

34. A communication system, characterized in that comprising a third access network device, and a first access network device for executing the method according to any one of claims 12 to 21; The third access network device is configured to receive a secondary node addition / adjustment request message; wherein the secondary node addition / adjustment request message includes a secondary base station key, the secondary base station key is generated by the first access network device, and the third access network device is a secondary base station of the first device; The third access network device is further configured to send a secondary node addition / adjustment request confirmation message to the first access network device; The third access network device is further configured to receive a secondary base station reconfiguration completion message.

35. The communication system according to claim 34, wherein: The communication system further includes a second device; The second device is used to receive a notification message; the notification message is used to instruct the first access network device to serve as the IAB host of the first device; The second device is further configured to send an IP address notification message to the first device, wherein the IP address notification information includes the IP address of the first device.

36. The communication system according to claim 34 or 35, characterized in that The communication system further includes a first device; The first device is used to register with the network through the first access network device; The first device is further configured to determine, according to fourth indication information, that the first access network device is an IAB host; The first device is further configured to generate an IAB key K according to the primary base station key, the IP address of the first access network device, and the IP address of the first device. IAB ; The first device is further configured to use the K IAB Establish the secure tunnel with the first access network device.

37. A communication device, characterized in that: The communication device includes a module for executing each step of the method according to any one of claims 1 to 11.

38. A communication device, characterized in that: The communication device includes modules for performing the steps of the method according to any one of claims 12 to 21.

39. A communication device, characterized in that: include: A memory and a processor coupled to the memory, the memory being used to store a program, and the processor being used to execute the program stored in the memory; when the communication device is running, the processor runs the program, causing the communication device to execute the method described in any one of claims 1 to 11; or causing the communication device to execute the method described in any one of claims 12 to 21.

40. A chip, characterized in that: The chip includes: a processor, wherein the processor is configured to execute instructions so that a device including the chip performs the method according to any one of claims 1 to 11; or so that the device including the chip performs the method according to any one of claims 12 to 21.

41. The chip according to claim 40, characterized in that The chip further includes a memory configured to store the instructions.

42. A computer program product, characterized in that The computer program product comprises instructions, which, when run on a computer, causes the computer to implement the method according to any one of claims 1 to 11, or the method according to any one of claims 12 to 21, or the method according to any one of claims 22 to 32.