A dynamic updating method for wireless communication configuration

By securely encrypting the perceived configuration information of the UE in the RAN device, and using the chain deduction structure of the perceived key, the problem of insufficient security of the wireless communication configuration information in the prior art is solved, and higher user privacy protection and system security are achieved.

CN118678342BActive Publication Date: 2025-05-20威海天拓合创电子工程有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410895815.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-05
Publication Date
2025-05-20
Estimated Expiration
2044-07-05

AI Technical Summary

Technical Problem

In the premise of ensuring user privacy, it is difficult to effectively improve the security of wireless communication configuration information, especially in the transmission of perceived measurement configuration information between multiple user equipment (UE).

Method used

By adopting secure encryption in the RAN device, the perceived configuration information of M UEs is configured one by one, and the chain deduction structure of the perceived key is used to ensure that each UE can safely perform perceived operations after receiving the configuration information.

Benefits of technology

The security of the network side sending configuration information for perceived measurement to the UE is improved, preventing user privacy leakage, and enhancing the security coupling of the overall system through the design of a chain deduction structure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118678342B_ABST
    Figure CN118678342B_ABST
Patent Text Reader

Abstract

The present invention provides a method for dynamically updating wireless communication configuration, which belongs to the field of communication technology and is used to improve the security of configuration information for perception measurement sent by the network side to the UE. It is known that M UEs included in the group access the RAN device, where M is an integer greater than 1, and the method includes: the RAN device obtains the perception configuration information of each of the M UEs, and the perception configuration information of each of the M UEs is used by the UE to perform a perception operation; the RAN device sequentially configures the perception configuration information of each of the M UEs to the M UEs in a secure encryption manner, and each two UEs in the M UEs are configured with the corresponding perception configuration information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to a method for dynamically updating wireless communication configurations. Background Art

[0002] With the continuous development of mobile communication technologies, the functions of user equipment (UE) are becoming more and more powerful. They can not only perform voice communications but also execute various sensing measurement tasks, such as detecting targets, ranging, tracking, etc. The realization of these functions is inseparable from the close cooperation between the UE and the network side. In this cooperation mode, the network side can configure relevant sensing measurement parameters for one or more UEs participating in sensing measurements to ensure that the UEs can accurately complete these tasks. The network side sends the configuration information of the sensing measurement to the UE by multiplexing the communication link (such as the air interface) between the UE and the network through configuration files in formats such as XML and JSON. These configuration information includes the characteristics of the target, the measurement range, the measurement accuracy requirements, the time synchronization accuracy, etc. After receiving these configuration information, the UE adjusts its measurement behavior according to these parameters.

[0003] However, sensing measurements may involve more user privacy. Therefore, ensuring the security of the configuration information distribution is one of the cores to avoid user privacy leakage. Thus, how to ensure its security is also a hot research issue at present. Summary of the Invention

[0004] Embodiments of the present invention provide a method for dynamically updating wireless communication configurations to improve the security of the configuration information sent by the network side to the UE for sensing measurements.

[0005] To achieve the above object, the present invention adopts the following technical solutions:

[0006] In a first aspect, a method for dynamically updating wireless communication configurations is provided, which is applied to a RAN device. M UEs included in a sensing group access the RAN device, where M is an integer greater than 1. The method includes: the RAN device obtains the respective sensing configuration information of the M UEs, and the sensing configuration information of each UE among the M UEs is used for the UE to perform sensing operations; the RAN device sequentially configures the respective sensing configuration information of the M UEs to the M UEs in a secure encryption manner, and the correlation during the process of configuring the respective corresponding sensing configuration information to every two UEs among the M UEs.

[0007] Optionally, i is an integer ranging from 1 to M - 1. The RAN device configures the sensing configuration information of each of the M UEs for the M UEs in sequence through secure encryption, including: The RAN device receives a configuration request #i sent by the i-th UE among the M UEs. The configuration request #i is used by the i-th UE to request the RAN device to perform sensing configuration for the i-th UE. The RAN device sends a sensing configuration ciphertext #i to the i-th UE according to the configuration request #i. The sensing configuration ciphertext #i is obtained by encrypting the sensing configuration information of the i-th UE using the sensing key Ksen_uei of the i-th UE. The sensing key Ksen_uei of the i-th UE is shared and used by the RAN device and the i-th UE. The sensing configuration information of the i-th UE includes the identifier of the (i + 1)-th UE among the M UEs, which is used for the i-th UE to trigger the (i + 1)-th UE to request the RAN device to perform sensing configuration for the (i + 1)-th UE. The RAN device receives a configuration request #i+1 sent by the (i + 1)-th UE. The configuration request #i+1 is used by the (i + 1)-th UE to request the RAN device to perform sensing configuration for the (i + 1)-th UE. The RAN device sends a sensing configuration ciphertext #i+1 to the (i + 1)-th UE according to the configuration request #i+1. The sensing configuration ciphertext #i+1 is obtained by encrypting the sensing configuration information of the (i + 1)-th UE using the sensing key Ksen_uei+1 of the (i + 1)-th UE. The sensing key Ksen_uei+1 of the (i + 1)-th UE is shared and used by the RAN device and the (i + 1)-th UE. If i + 1 = M, the sensing configuration information of the (i + 1)-th UE does not include the identifiers of other UEs among the M UEs except the (i + 1)-th UE.

[0008] Optionally, the configuration request #i includes a random number #i generated by the i-th UE. The method further includes: If i is equal to 1, the RAN device uses the access stratum key KgNB of the i-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE. The access stratum key KgNB of the i-th UE is the key assigned by the network to the RAN device for communication between the RAN device and the i-th UE when the i-th UE registers to the network of the RAN device. If i is greater than 1, the RAN device uses the sensing key Ksen_uei-1 of the (i - 1)-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE. The configuration request #i+1 includes a random number #i+1 generated by the (i + 1)-th UE. The method further includes: The RAN device uses the sensing key Ksen_uei of the i-th UE and the random number #i+1 as input parameters to derive the sensing key Ksen_uei+1 of the (i + 1)-th UE.

[0009] Optionally, the method is also applied to the i-th UE among the M UEs. The method includes: the i-th UE sends a configuration request #i to the RAN device; the i-th UE receives the sensed configuration ciphertext #i returned by the RAN device for the configuration request #i; the i-th UE decrypts the sensed configuration ciphertext #i using the sensing key Ksen_uei of the i-th UE to obtain the sensed configuration information of the i-th UE, and the sensed configuration information of the i-th UE is used by the i-th UE to perform sensing operations; the i-th UE discovers the (i + 1)-th UE by broadcasting the identifier of the (i + 1)-th UE according to the sensed configuration information of the i-th UE including the identifier of the (i + 1)-th UE, and establishes a sidelink secure connection with the (i + 1)-th UE; the i-th UE sends the sensing key Ksen_uei of the i-th UE and the indication information #i to the (i + 1)-th UE through the sidelink secure connection, and the indication information #i indicates that the (i + 1)-th UE needs to request the RAN device to perform sensing configuration for the (i + 1)-th UE.

[0010] Optionally, if i is equal to 1, the i-th UE sending the configuration request #i to the RAN device includes: the i-th UE sends the configuration request #i to the RAN device according to the APP message sent by the AF corresponding to the sensing group to the i-th UE, and the APP message indicates that the sensing operation of the group needs to be performed; correspondingly, the method further includes: the i-th UE derives the sensing key Ksen_uei of the i-th UE using the access layer key KgNB of the i-th UE and the random number #i as input parameters; if i is greater than 1, the i-th UE sending the configuration request #i to the RAN device includes: the i-th UE sends the configuration request #i to the RAN device according to the indication information #i - 1 sent by the (i - 1)-th UE to the i-th UE, and the indication information #i - 1 indicates that the i-th UE needs to request the RAN device to perform sensing configuration for the i-th UE; correspondingly, the method further includes: the i-th UE derives the sensing key Ksen_uei of the i-th UE using the sensing key Ksen_uei - 1 of the (i - 1)-th UE and the random number #i as input parameters, and the sensing key Ksen_uei - 1 of the (i - 1)-th UE is received by the i-th UE through establishing a sidelink secure connection with the (i - 1)-th UE; wherein, the (i + 1)-th UE derives the sensing key Ksen_uei + 1 of the (i + 1)-th UE using the sensing key Ksen_uei of the i-th UE and the random number #i + 1 as input parameters.

[0011] Optionally, i is an integer ranging from 1 to M - 2. The RAN device configures the sensing configuration information of each of the M UEs for the M UEs in sequence through secure encryption, including: The RAN device receives the configuration request #i sent by the i-th UE among the M UEs. The configuration request #i is used by the i-th UE to request the RAN device to perform the sensing configuration for the i-th UE. The RAN device sends the sensing configuration ciphertext #i to the i-th UE according to the configuration request #i. The sensing configuration ciphertext #i is obtained by encrypting the sensing configuration information of the i-th UE using the sensing key Ksen_uei of the i-th UE. The sensing key Ksen_uei of the i-th UE for encryption is shared and used by the RAN device and the i-th UE. The sensing configuration information of the i-th UE contains the identifiers of the (i + 1)-th UE and the (i + 2)-th UE among the M UEs, for the i-th UE to trigger the (i + 1)-th UE and the (i + 2)-th UE to respectively request the RAN device to perform the sensing configuration for themselves. The RAN device receives the configuration request #i+1 sent by the (i + 1)-th UE and the configuration request #i+2 sent by the (i + 2)-th UE. The configuration request #i+1 is used by the (i + 1)-th UE to request the RAN device to perform the sensing configuration for the (i + 1)-th UE, and the configuration request #i+2 is used by the (i + 2)-th UE to request the RAN device to perform the sensing configuration for the (i + 2)-th UE. The RAN device sends the sensing configuration ciphertext #i+1 to the (i + 1)-th UE according to the configuration request #i+1 and sends the sensing configuration ciphertext #i+2 to the (i + 2)-th UE according to the configuration request #i+2. The sensing configuration ciphertext #i+1 is obtained by encrypting the sensing configuration information of the (i + 1)-th UE using the sensing key Ksen_uei+1 of the (i + 1)-th UE. The sensing key Ksen_uei+1 of the (i + 1)-th UE for encryption is shared and used by the RAN device and the (i + 1)-th UE. The sensing configuration ciphertext #i+2 is obtained by encrypting the sensing configuration information of the (i + 2)-th UE using the sensing key Ksen_uei+2 of the (i + 2)-th UE. The sensing key Ksen_uei+1 of the (i + 2)-th UE for encryption is shared and used by the RAN device and the (i + 2)-th UE. If i + 2 = M, the sensing configuration information of the (i + 1)-th UE does not contain the identifiers of other UEs in the M UEs except the (i + 1)-th UE, and the sensing configuration information of the (i + 2)-th UE does not contain the identifiers of other UEs in the M UEs except the (i + 2)-th UE.

[0012] Optionally, the configuration request #i includes a random number #i generated by the i-th UE. The method further includes: if i is equal to 1, the RAN device uses the access stratum key KgNB of the i-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE. The access stratum key KgNB of the i-th UE is the key allocated by the network to the RAN device for communication between the RAN device and the i-th UE when the i-th UE registers to the network of the RAN device. If i is greater than 1, the RAN device uses the sensing key Ksen_uei-1 of the (i - 1)-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE. The configuration request #i+1 includes a random number #i+1 generated by the (i + 1)-th UE, and the configuration request #i+2 includes a random number #i+2 generated by the (i + 2)-th UE. The method further includes: the RAN device uses the random number #i+2, the sensing key Ksen_uei of the i-th UE, and the sensing key Ksen_uei+1 of the (i + 1)-th UE as input parameters to derive the sensing key Ksen_uei+2 of the (i + 2)-th UE.

[0013] Optionally, the method is further applied to the i-th UE among M UEs. The method includes: the i-th UE sends a configuration request #i to the RAN device; the i-th UE receives the sensing configuration ciphertext #i returned by the RAN device in response to the configuration request #i; the i-th UE decrypts the sensing configuration ciphertext #i using the sensing key Ksen_uei of the i-th UE to obtain the sensing configuration information of the i-th UE, and the sensing configuration information of the i-th UE is used for the i-th UE to perform sensing operations; based on the sensing configuration information of the i-th UE including the identifier of the (i + 1)-th UE and the identifier of the (i + 2)-th UE, the i-th UE discovers the (i + 1)-th UE by broadcasting the identifier of the (i + 1)-th UE and establishes a sidelink secure connection with the (i + 1)-th UE; the i-th UE sends the sensing key Ksen_uei of the i-th UE, the identifier of the (i + 2)-th UE, and the indication information #i to the (i + 1)-th UE through the sidelink secure connection. The i-th UE sends the identifier of the (i + 2)-th UE to the (i + 1)-th UE to indicate that: the (i + 1)-th UE needs to trigger the (i + 2)-th UE to request the RAN device to perform sensing configuration for the (i + 2)-th UE, and the (i + 1)-th UE needs to provide the sensing key Ksen_uei of the i-th UE to the (i + 2)-th UE; the indication information #i indicates that the (i + 1)-th UE needs to request the RAN device to perform sensing configuration for the (i + 1)-th UE.

[0014] Optionally, if i equals 1, the i-th UE sends a configuration request #i to the RAN device, including: the i-th UE sends the configuration request #i to the RAN device according to the APP message sent by the AF corresponding to the sensing group, and the APP message indicates that the sensing operation of the group needs to be performed; correspondingly, the method further includes: the i-th UE uses the access layer key KgNB of the i-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE; if i is greater than 1, the i-th UE sends a configuration request #i to the RAN device, including: the i-th UE sends the configuration request #i to the RAN device according to the indication information #i-1 sent by the (i-1)-th UE to the i-th UE, and the indication information #i-1 indicates that the i-th UE needs to request the RAN device to perform the sensing configuration for the i-th UE; correspondingly, the method further includes: the i-th UE uses the sensing key Ksen_uei-1 of the (i-1)-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE, and the sensing key Ksen_uei-1 of the (i-1)-th UE is received by the i-th UE through establishing a sidelink secure connection with the (i-1)-th UE; wherein, the (i + 1)-th UE uses the sensing key Ksen_uei of the i-th UE and the random number #i+1 as input parameters to derive the sensing key Ksen_uei+1 of the (i + 1)-th UE, and the (i + 2)-th UE uses the sensing key Ksen_uei of the i-th UE, the sensing key Ksen_uei+1 of the (i + 1)-th UE and the random number #i+2 as input parameters to derive the sensing key Ksen_uei+2 of the (i + 2)-th UE.

[0015] Optionally, the RAN device obtains the sensing configuration information of each of the M UEs, including: the RAN device receives the sensing configuration information of each of the M UEs provided by a third-party AF, and the AF determines that the M UEs access the RAN device by requesting the network where the RAN device is located to open the location information of the M UEs.

[0016] In a second aspect, a dynamic update system for wireless communication configuration is provided. The system includes a RAN device, and M UEs included in a sensing group access the RAN device, where M is an integer greater than 1. The system is configured to: the RAN device obtains the sensing configuration information of each of the M UEs, and the sensing configuration information of each UE in the M UEs is used for the UE to perform a sensing operation; the RAN device sequentially configures the sensing configuration information of each of the M UEs to the M UEs in a secure encryption manner, and correlates the relevant associations in the process of configuring the corresponding sensing configuration information for every two UEs in the M UEs.

[0017] Optionally, i is an integer ranging from 1 to M - 1. The RAN device configures the sensing configuration information of each of the M UEs for the M UEs in sequence through secure encryption, including: The RAN device receives a configuration request #i sent by the i-th UE among the M UEs. The configuration request #i is used by the i-th UE to request the RAN device to perform sensing configuration for the i-th UE. The RAN device, according to the configuration request #i, sends a sensing configuration ciphertext #i to the i-th UE. The sensing configuration ciphertext #i is obtained by encrypting the sensing configuration information of the i-th UE using the sensing key Ksen_uei of the i-th UE. The sensing key Ksen_uei of the i-th UE is shared and used by the RAN device and the i-th UE. The sensing configuration information of the i-th UE contains the identifier of the (i + 1)-th UE among the M UEs, for the i-th UE to trigger the (i + 1)-th UE to request the RAN device to perform sensing configuration for the (i + 1)-th UE. The RAN device receives a configuration request #i+1 sent by the (i + 1)-th UE. The configuration request #i+1 is used by the (i + 1)-th UE to request the RAN device to perform sensing configuration for the (i + 1)-th UE. The RAN device, according to the configuration request #i+1, sends a sensing configuration ciphertext #i+1 to the (i + 1)-th UE. The sensing configuration ciphertext #i+1 is obtained by encrypting the sensing configuration information of the (i + 1)-th UE using the sensing key Ksen_uei+1 of the (i + 1)-th UE. The sensing key Ksen_uei+1 of the (i + 1)-th UE is shared and used by the RAN device and the (i + 1)-th UE. If i + 1 = M, the sensing configuration information of the (i + 1)-th UE does not contain the identifiers of other UEs among the M UEs except the (i + 1)-th UE.

[0018] Optionally, the configuration request #i includes a random number #i generated by the i-th UE. The system is configured as follows: If i is equal to 1, the RAN device uses the access stratum key KgNB of the i-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE. The access stratum key KgNB of the i-th UE is: when the i-th UE registers to the network of the RAN device, the key allocated by the network for the RAN device and the i-th UE to communicate with each other. If i is greater than 1, the RAN device uses the sensing key Ksen_uei-1 of the (i - 1)-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE. The configuration request #i+1 includes a random number #i+1 generated by the (i + 1)-th UE. The system is configured as follows: The RAN device uses the sensing key Ksen_uei of the i-th UE and the random number #i+1 as input parameters to derive the sensing key Ksen_uei+1 of the (i + 1)-th UE.

[0019] Optionally, the system further includes M UEs. For the i-th UE among the M UEs, the system is configured as follows: the i-th UE sends a configuration request #i to the RAN device; the i-th UE receives the sensed configuration ciphertext #i returned by the RAN device for the configuration request #i; the i-th UE decrypts the sensed configuration ciphertext #i using the sensed key Ksen_uei of the i-th UE to obtain the sensed configuration information of the i-th UE, and the sensed configuration information of the i-th UE is used for the i-th UE to perform sensing operations; the sensed configuration information of the i-th UE includes the identifier of the (i + 1)-th UE, and the (i + 1)-th UE is discovered by broadcasting the identifier of the (i + 1)-th UE, and a sidelink secure connection is established with the (i + 1)-th UE; the i-th UE sends the sensed key Ksen_uei of the i-th UE and indication information #i to the (i + 1)-th UE through the sidelink secure connection, and the indication information #i indicates that the (i + 1)-th UE needs to request the RAN device to perform sensed configuration for the (i + 1)-th UE.

[0020] Optionally, if i is equal to 1, the i-th UE sending a configuration request #i to the RAN device includes: the i-th UE sending a configuration request #i to the RAN device according to the APP message sent by the AF corresponding to the sensing group to the i-th UE, and the APP message indicates that the sensing operation of the group needs to be performed; correspondingly, the system is configured as follows: the i-th UE uses the access layer key KgNB of the i-th UE and random number #i as input parameters to derive the sensed key Ksen_uei of the i-th UE; if i is greater than 1, the i-th UE sending a configuration request #i to the RAN device includes: the i-th UE sending a configuration request #i to the RAN device according to the indication information #i - 1 sent by the (i - 1)-th UE to the i-th UE, and the indication information #i - 1 indicates that the i-th UE needs to request the RAN device to perform sensed configuration for the i-th UE; correspondingly, the system is configured as follows: the i-th UE uses the sensed key Ksen_uei - 1 of the (i - 1)-th UE and random number #i as input parameters to derive the sensed key Ksen_uei of the i-th UE, and the sensed key Ksen_uei - 1 of the (i - 1)-th UE is received by the i-th UE through establishing a sidelink secure connection with the (i - 1)-th UE; wherein, the (i + 1)-th UE uses the sensed key Ksen_uei of the i-th UE and random number #i + 1 as input parameters to derive the sensed key Ksen_uei + 1 of the (i + 1)-th UE.

[0021] Optionally, i is an integer that traverses from 1 to M - 2. The RAN device configures the sensing configuration information of each of the M UEs for the M UEs in sequence through secure encryption, including: The RAN device receives the configuration request #i sent by the i-th UE among the M UEs. The configuration request #i is used by the i-th UE to request the RAN device to perform sensing configuration for the i-th UE. The RAN device sends the sensing configuration ciphertext #i to the i-th UE according to the configuration request #i. The sensing configuration ciphertext #i is obtained by encrypting the sensing configuration information of the i-th UE using the sensing key Ksen_uei of the i-th UE. The sensing key Ksen_uei of the i-th UE for encryption is shared by the RAN device and the i-th UE. The sensing configuration information of the i-th UE contains the identifiers of the (i + 1)-th UE and the (i + 2)-th UE among the M UEs, for the i-th UE to trigger the (i + 1)-th UE and the (i + 2)-th UE to respectively request the RAN device to perform sensing configuration for themselves. The RAN device receives the configuration request #i+1 sent by the (i + 1)-th UE, and the configuration request #i+2 sent by the (i + 2)-th UE. The configuration request #i+1 is used by the (i + 1)-th UE to request the RAN device to perform sensing configuration for the (i + 1)-th UE, and the configuration request #i+2 is used by the (i + 2)-th UE to request the RAN device to perform sensing configuration for the (i + 2)-th UE. The RAN device sends the sensing configuration ciphertext #i+1 to the (i + 1)-th UE according to the configuration request #i+1, and sends the sensing configuration ciphertext #i+2 to the (i + 2)-th UE according to the configuration request #i+2. The sensing configuration ciphertext #i+1 is obtained by encrypting the sensing configuration information of the (i + 1)-th UE using the sensing key Ksen_uei+1 of the (i + 1)-th UE. The sensing key Ksen_uei+1 of the (i + 1)-th UE for encryption is shared by the RAN device and the (i + 1)-th UE. The sensing configuration ciphertext #i+2 is obtained by encrypting the sensing configuration information of the (i + 2)-th UE using the sensing key Ksen_uei+2 of the (i + 2)-th UE. The sensing key Ksen_uei+1 of the (i + 2)-th UE for encryption is shared by the RAN device and the (i + 2)-th UE. If i + 2 = M, then the sensing configuration information of the (i + 1)-th UE does not contain the identifiers of other UEs among the M UEs except the (i + 1)-th UE, and the sensing configuration information of the (i + 2)-th UE does not contain the identifiers of other UEs among the M UEs except the (i + 2)-th UE.

[0022] Optionally, the configuration request #i includes a random number #i generated by the i-th UE. The system is configured such that if i equals 1, the RAN device uses the access stratum key KgNB of the i-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE. The access stratum key KgNB of the i-th UE is the key allocated by the network to the RAN device for communication between the RAN device and the i-th UE when the i-th UE registers to the network of the RAN device. If i is greater than 1, the RAN device uses the sensing key Ksen_uei-1 of the (i - 1)-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE. The configuration request #i+1 includes a random number #i+1 generated by the (i + 1)-th UE, and the configuration request #i+2 includes a random number #i+2 generated by the (i + 2)-th UE. The system is configured such that the RAN device uses the random number #i+2, the sensing key Ksen_uei of the i-th UE, and the sensing key Ksen_uei+1 of the (i + 1)-th UE as input parameters to derive the sensing key Ksen_uei+2 of the (i + 2)-th UE.

[0023] Optionally, the system further includes M UEs. For the i-th UE among the M UEs, the system is configured such that the i-th UE sends a configuration request #i to the RAN device; the i-th UE receives the sensing configuration ciphertext #i returned by the RAN device for the configuration request #i; the i-th UE decrypts the sensing configuration ciphertext #i using the sensing key Ksen_uei of the i-th UE to obtain the sensing configuration information of the i-th UE, and the sensing configuration information of the i-th UE is used by the i-th UE to perform sensing operations; based on the sensing configuration information of the i-th UE including the identifier of the (i + 1)-th UE and the identifier of the (i + 2)-th UE, the i-th UE discovers the (i + 1)-th UE by broadcasting the identifier of the (i + 1)-th UE and establishes a sidelink secure connection with the (i + 1)-th UE; the i-th UE sends the sensing key Ksen_uei of the i-th UE, the identifier of the (i + 2)-th UE, and an indication message #i to the (i + 1)-th UE through the sidelink secure connection. The i-th UE sends the identifier of the (i + 2)-th UE to the i-th UE to indicate that the (i + 1)-th UE needs to trigger the (i + 2)-th UE to request the RAN device to perform sensing configuration for the (i + 2)-th UE, and the (i + 1)-th UE needs to provide the sensing key Ksen_uei of the i-th UE to the (i + 2)-th UE; the indication message #i indicates that the (i + 1)-th UE needs to request the RAN device to perform sensing configuration for the (i + 1)-th UE.

[0024] Optionally, if i is equal to 1, the i-th UE sends a configuration request #i to the RAN device, including: the i-th UE sends a configuration request #i to the RAN device according to the APP message sent by the AF corresponding to the sensing group, and the APP message indicates that the sensing operation of the group needs to be performed; correspondingly, the system is configured as: the i-th UE uses the access layer key KgNB of the i-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE; if i is greater than 1, the i-th UE sends a configuration request #i to the RAN device, including: the i-th UE sends a configuration request #i to the RAN device according to the indication information #i-1 sent by the (i-1)-th UE to the i-th UE, and the indication information #i-1 indicates that the i-th UE needs to request the RAN device to perform the sensing configuration for the i-th UE; correspondingly, the system is configured as: the i-th UE uses the sensing key Ksen_uei-1 of the (i-1)-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE, and the sensing key Ksen_uei-1 of the (i-1)-th UE is received by the i-th UE through establishing a sidelink secure connection with the (i-1)-th UE; wherein, the (i + 1)-th UE uses the sensing key Ksen_uei of the i-th UE and the random number #i+1 as input parameters to derive the sensing key Ksen_uei+1 of the (i + 1)-th UE, and the (i + 2)-th UE uses the sensing key Ksen_uei of the i-th UE, the sensing key Ksen_uei+1 of the (i + 1)-th UE and the random number #i+2 as input parameters to derive the sensing key Ksen_uei+2 of the (i + 2)-th UE.

[0025] Optionally, the RAN device obtains the sensing configuration information of each of the M UEs, including: the RAN device receives the sensing configuration information of each of the M UEs provided by a third-party AF, and the AF determines that the M UEs access the RAN device by requesting the network where the RAN device is located to open the location information of the M UEs.

[0026] In a third aspect, a computer-readable storage medium is provided, including: a computer program or instruction; when the computer program or instruction runs on a computer, the computer is caused to execute the method described in the first aspect.

[0027] In a fourth aspect, a computer program product is provided, including a computer program or instruction, when the computer program or instruction runs on a computer, the computer is caused to execute the method described in the first aspect.

[0028] In summary, the above method and system have the following technical effects:

[0029] When the RAN device obtains the perception configuration information of each of the M UEs, the RAN device can sequentially configure the perception configuration information of each of the M UEs in a secure and encrypted manner, and each two UEs in the M UEs are configured with the corresponding perception configuration information in the process of relevant association, so as to improve the security of the configuration information for perception measurement sent by the network side to the UE through secure and sequential correlation configuration. Brief Description of the Figures

[0030] Figure 1 A schematic diagram of the architecture of a dynamic update system for wireless communication configuration provided by an embodiment of the present invention;

[0031] Figure 2 A schematic diagram of a flow chart of a method for dynamically updating a wireless communication configuration provided by an embodiment of the present invention;

[0032] Figure 3 This is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. Specific implementation method

[0033] The present invention will present various aspects, embodiments or features around a system that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc. and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the figures. In addition, combinations of these schemes may also be used.

[0034] In the embodiment of the present invention, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information (such as the first indication information, the second indication information, or the third indication information, etc. described below) is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, directly indicating the information to be indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated may also be indirectly indicated by indicating other information, wherein the other information is associated with the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information may be realized by means of the arrangement order of each piece of information agreed in advance (such as specified by the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information may be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.

[0035] In addition, the specific indication method can also be various existing indication methods, such as, but not limited to, the above-mentioned indication methods and their various combinations, etc. The specific details of various indication methods can refer to the prior art and will not be elaborated herein. As can be seen from the above description, for example, when multiple pieces of information of the same type need to be indicated, there may be a situation where the indication methods of different pieces of information are different. In the specific implementation process, the required indication method can be selected according to specific needs, and the indication method selected in the embodiments of the present invention is not limited. In this way, the indication methods involved in the embodiments of the present invention should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0036] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending periods and / or sending times of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of the present invention. Among them, the sending periods and / or sending times of these sub-information can be predefined, such as predefined according to a protocol, or can be configured by the sending device by sending configuration information to the receiving device.

[0037] "Predefined" or "preconfigured" can be implemented by pre-saving corresponding codes, tables or other ways that can be used to indicate relevant information in the device, and the embodiments of the present invention do not limit its specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be set separately or integrated in an encoder, decoder, processor, or communication device. The one or more memories can also be partially set separately and partially integrated in a decoder, processor, or communication device. The type of the memory can be any form of storage medium, which is not limited in the embodiments of the present invention.

[0038] The "protocol" involved in the embodiments of the present invention can refer to a protocol family in the communication field, a standard protocol similar to the frame structure of a protocol family, or a related protocol applied to a future communication system, and the embodiments of the present invention do not make specific limitations on this.

[0039] In the embodiments of the present invention, descriptions such as "when...", "in the case of...", "if", and "when" all refer to that the device will perform corresponding processing under a certain objective situation, which does not limit time, and does not require the device to have a judgment action when implementing, nor does it mean other limitations.

[0040] In the description of the embodiments of the present invention, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship. For example, A / B may represent A or B. The "and / or" in the embodiments of the present invention is merely a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Also, in the description of the embodiments of the present invention, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of single item (s) or plural items (s). For example, at least one (item) of a, b, and c, or at least one (item) of a, b, or c, may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple. Additionally, for the convenience of clearly describing the technical solutions of the embodiments of the present invention, in the embodiments of the present invention, terms such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and roles. Those skilled in the art can understand that the terms "first", "second", etc. do not limit the quantity and execution order, and the terms "first", "second", etc. do not necessarily mean different. At the same time, in the embodiments of the present invention, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present invention should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific way for easy understanding.

[0041] The network architecture and service scenarios described in the embodiments of the present invention are for more clearly illustrating the technical solutions of the embodiments of the present invention, and do not constitute a limitation on the technical solutions provided by the embodiments of the present invention. Those of ordinary skill in the art know that with the evolution of the network architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of the present invention are equally applicable to similar technical problems.

[0042] To facilitate the understanding of the embodiments of the present invention, first, take Figure 1 the dynamic update system of the wireless communication configuration shown in Figure 1 as an example to detail the control system applicable to the embodiments of the present invention. Exemplarily,

[0043] As Figure 1 shown, the dynamic update system of the wireless communication configuration may include: radio access network (RAN) devices and M terminals.

[0044] A RAN device can be a device that provides access for terminals. For example, a RAN device can include: A RAN device can also include 5G, such as a gNB in a new radio (NR) system, or one or a group (including multiple antenna panels) of antenna panels of a base station in 5G, or it can also be a network node that constitutes a gNB, a transmission and reception point (TRP) or a transmission point (TP), or a transmission measurement function (TMF), such as a building base band unit (BBU), or a centralized unit (CU) or a distributed unit (DU), an RSU with base station functions, or a wired access gateway, or a core network element of 5G. Alternatively, a RAN device can also include an access point (AP) in a wireless fidelity (WiFi) system, a wireless relay node, a wireless backhaul node, various forms of macro base stations, micro base stations (also known as small stations), relay stations, access points, wearable devices, vehicle-mounted devices, and so on. Or, a RAN device can also include a next-generation mobile communication system, such as an access network device for 6G, such as a 6G base station, or in a next-generation mobile communication system, this network device can also have other naming methods, all of which are covered by the protection scope of the embodiments of the present invention, and the present invention makes no limitation thereto.

[0045] The above terminal can be a terminal with transceiver functions, or a chip or chip system that can be set in the terminal. The terminal can also be referred to as a user equipment (UE), access terminal, subscriber unit, user station, mobile station (MS), mobile unit, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user equipment. The terminal in the embodiments of the present invention can be a mobile phone, cellular phone, smart phone, tablet (Pad), wireless data card, personal digital assistant (PDA), wireless modem, handset, laptop computer, machine type communication (MTC) terminal, computer with wireless transceiver functions, virtual reality (VR) terminal, augmented reality (AR) terminal, wireless terminal in industrial control, wireless terminal in self-driving, wireless terminal in remote medical, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, wireless terminal in smart home, in-vehicle terminal, roadside unit (RSU) with terminal functions, etc. The terminal of the present invention can also be an in-vehicle module, in-vehicle module group, in-vehicle component, in-vehicle chip, or in-vehicle unit built into a vehicle as one or more components or units.

[0046] The terminal device is provided with a plurality of antenna panels, such as a first antenna panel and a second antenna panel. Each antenna panel among the plurality of antenna panels can transmit or receive a plurality of beams with different directions, which are called the plurality of beams of the antenna panel.

[0047] A beam refers to a special directional transmission or reception effect formed by the transmitter or receiver of a network device or terminal through an antenna array, similar to the light beam formed by a flashlight converging light to one direction. By transmitting and receiving signals in the form of beams, the transmission distance of the signals can be effectively increased. The beam used for communication between terminals can also be called a sidelink beam.

[0048] The beam can be a wide beam, a narrow beam, or other types of beams. The technology for forming the beam can be beamforming technology or other technologies. The beamforming technology can specifically be digital beamforming technology, analog beamforming technology, or hybrid digital / analog beamforming technology, etc.

[0049] Generally, a beam corresponds to a resource. For example, when performing beam measurement, the network device measures different beams through different resources, and the terminal feeds back the measured resource quality, so that the network device can know the quality of the corresponding beam. During data transmission, the beam can also be indicated by its corresponding resource. For example, the network device indicates a transmission configuration indication - state through the transmission configuration index (TCI) field in the downlink control information (DCI), and the terminal determines the beam corresponding to the reference resource according to the reference resource included in the TCI - state.

[0050] In the communication protocol, the beam can be specifically characterized as a digital beam, an analog beam, a spatial domain vector, a spatial domain filter, a spatial filter, a spatial parameter, a TCI, a TCI - state, etc. The beam used for transmitting signals can be called a transmission beam (or Tx beam), a spatial domain transmission filter, a spatial transmission filter, a spatial domain transmission parameter, a spatial transmission parameter, etc. The beam used for receiving signals can be called a reception beam (or Rx beam), a spatial domain reception filter, a spatial reception filter, a spatial domain reception parameter, a spatial reception parameter, etc.

[0051] It can be understood that in the embodiments of the present invention, the beam is uniformly used for expression, but the beam can be equivalently understood as other concepts, and is not limited to the concepts mentioned above.

[0052] In the embodiments of the present invention, M terminals are referred to as M UEs, where M is an integer greater than 1. The M UEs form a sensing group, and sensing measurements are performed at the group level. For example, the M UEs jointly perform ranging, tracking, etc. on the same target object. The M UEs are connected to the RAN device. The M UEs perform sensing measurements through their respective beams of the M UEs, that is, sensing measurements are achieved by transmitting beams. The specific implementation is in the prior art and will not be elaborated here.

[0053] Next, in combination with Figure 2 , the interaction process between the devices in the above system will be specifically introduced through method embodiments. The method for dynamically updating wireless communication configuration provided by the embodiments of the present invention can be applied to the above control system, and will be specifically introduced below.

[0054] Figure 2 FIG.

[0055] S201, the RAN device obtains the sensing configuration information of each of the M UEs.

[0056] The sensing configuration information of each UE among the M UEs is used for the UE to perform sensing operations. The RAN device can receive the sensing configuration information of each of the M UEs provided by a third-party AF. The AF determines that the M UEs are connected to the RAN device by requesting the network where the RAN device is located to open the location information of the M UEs, and thus provides the sensing configuration information of each of the M UEs to the RAN device.

[0057] S202, the RAN device sequentially configures the sensing configuration information of each of the M UEs to the M UEs in a secure encryption manner, and there is a correlation between every two UEs among the M UEs during the process of being configured with their respective corresponding sensing configuration information.

[0058] Case 1: The configuration can be performed in a manner where one UE is associated with the next UE.

[0059] i is an integer traversing from 1 to M - 1. The i-th UE sends a configuration request #i to the RAN device. For example, if i is equal to 1, the i-th UE sends a configuration request #i to the RAN device according to the APP message sent by the AF corresponding to the sensing group, and the APP message indicates that the sensing operation of the group needs to be performed. Correspondingly, the method further includes: the i-th UE uses the access layer key KgNB of the i-th UE and a random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE. If i is greater than 1, the i-th UE sends a configuration request #i to the RAN device according to the indication information #i-1 sent by the (i - 1)-th UE to the i-th UE, and the indication information #i-1 indicates that the i-th UE needs to request the RAN device to perform sensing configuration for the i-th UE. Correspondingly, the method further includes: the i-th UE uses the sensing key Ksen_uei-1 of the (i - 1)-th UE and a random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE, and the sensing key Ksen_uei-1 of the (i - 1)-th UE is received by the i-th UE through establishing a sidelink secure connection with the (i - 1)-th UE.

[0060] The RAN device can receive the configuration request #i sent by the i-th UE among the M UEs. The configuration request #i is used for the i-th UE to request the RAN device to perform sensing configuration for the i-th UE. The RAN device can send the sensing configuration ciphertext #i to the i-th UE according to the configuration request #i, and the i-th UE receives the sensing configuration ciphertext #i returned by the RAN device for the configuration request #i.

[0061] Among them, the sensing configuration ciphertext #i is obtained by encrypting the sensing configuration information of the i-th UE using the sensing key Ksen_uei of the i-th UE. The encryption of the sensing key Ksen_uei of the i-th UE is shared and used by the RAN device and the i-th UE. The sensing configuration information of the i-th UE includes the identifier of the (i + 1)-th UE among the M UEs, which is used for the i-th UE to trigger the (i + 1)-th UE to request the RAN device to perform sensing configuration for the (i + 1)-th UE.

[0062] Among them, if i is equal to 1, the RAN device can use the access layer key KgNB of the i-th UE and a random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE. The access layer key KgNB of the i-th UE is: when the i-th UE registers to the network of the RAN device, the network assigns a key for the RAN device to communicate with the i-th UE; if i is greater than 1, the RAN device uses the sensing key Ksen_uei-1 of the (i - 1)-th UE and a random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE.

[0063] The configuration request #i+1 includes the random number #i+1 generated by the (i+1)-th UE. The method further includes:

[0064] The RAN device may use the sensing key Ksen_uei of the i-th UE and the random number #i+1 as input parameters to derive the sensing key Ksen_uei+1 of the (i+1)-th UE.

[0065] Correspondingly, the i-th UE may use the sensing key Ksen_uei of the i-th UE to decrypt the sensing configuration ciphertext #i to obtain the sensing configuration information of the i-th UE. The sensing configuration information of the i-th UE is used by the i-th UE to perform sensing operations. The sensing configuration information of the i-th UE includes the identifier of the (i+1)-th UE. The i-th UE discovers the (i+1)-th UE by broadcasting the identifier of the (i+1)-th UE and establishes a sidelink secure connection with the (i+1)-th UE. Specifically, it may be an existing sidelink connection recommended based on the SSL / TLS protocol, which is prior art and will not be elaborated in the embodiments of the present invention.

[0066] The i-th UE sends the sensing key Ksen_uei of the i-th UE and the indication information #i to the (i+1)-th UE through the sidelink secure connection. The indication information #i indicates that the (i+1)-th UE needs to request the RAN device to perform sensing configuration for the (i+1)-th UE. The (i+1)-th UE uses the sensing key Ksen_uei of the i-th UE and the random number #i+1 as input parameters to derive the sensing key Ksen_uei+1 of the (i+1)-th UE. The (i+1)-th UE may execute a logic similar to that of the i-th UE. Correspondingly, the RAN device receives the configuration request #i+1 sent by the (i+1)-th UE. The configuration request #i+1 is used by the (i+1)-th UE to request the RAN device to perform sensing configuration for the (i+1)-th UE. The RAN device sends the sensing configuration ciphertext #i+1 to the (i+1)-th UE according to the configuration request #i+1. The sensing configuration ciphertext #i+1 is obtained by encrypting the sensing configuration information of the (i+1)-th UE using the sensing key Ksen_uei+1 of the (i+1)-th UE. The sensing key Ksen_uei+1 of the (i+1)-th UE is shared and used by the RAN device and the (i+1)-th UE. If i+1 = M, the sensing configuration information of the (i+1)-th UE does not include the identifiers of other UEs except the (i+1)-th UE among the M UEs.

[0067] Based on the above method, it can be seen that the above-mentioned sensing key Ksen_ue is used to safeguard the key for transmitting sensing configuration information, decouple the key encryption for signal implementation and multiplexing communication links, and the security implementation can be more flexible. The above-mentioned sensing key Ksen_ue can also be used to encrypt the signal when the UE performs sensing measurements, making the sensing more secure and reducing the probability of user privacy leakage. Additionally, since the sensing key Ksen_ue of the next UE is derived based on the sensing key Ksen_ue of the previous UE, i.e., a chain derivation structure, an attacker cannot break the sensing of the entire group without the sensing key Ksen_ue of any one of the UEs, achieving secure coupling and better security.

[0068] Case 2: It can be configured in a way that one UE is associated with the next two UEs.

[0069] i is an integer traversing from 1 to M - 2. The i-th UE sends a configuration request #i to the RAN device. For example, if i is equal to 1, the i-th UE sends a configuration request #i to the RAN device according to the APP message sent by the i-th UE corresponding to the sensing group, and the APP message indicates that the sensing operation of the group needs to be performed; correspondingly, the method further includes: the i-th UE uses the access layer key KgNB of the i-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE; if i is greater than 1, the i-th UE sends a configuration request #i to the RAN device according to the indication information #i - 1 sent by the (i - 1)-th UE to the i-th UE, and the indication information #i - 1 indicates that the i-th UE needs to request the RAN device to perform the sensing configuration for the i-th UE; correspondingly, the method further includes: the i-th UE uses the sensing key Ksen_uei - 1 of the (i - 1)-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE, and the sensing key Ksen_uei - 1 of the (i - 1)-th UE is received by the i-th UE through establishing a sidelink secure connection with the (i - 1)-th UE.

[0070] The RAN device receives the configuration request #i sent by the i-th UE among the M UEs, and the configuration request #i is used for the i-th UE to request the RAN device to perform the sensing configuration for the i-th UE. The RAN device sends the sensing configuration ciphertext #i to the i-th UE according to the configuration request #i. The sensing configuration ciphertext #i is obtained by encrypting the sensing configuration information of the i-th UE using the sensing key Ksen_uei of the i-th UE. The sensing key Ksen_uei of the i-th UE is shared and used by the RAN device and the i-th UE. The sensing configuration information of the i-th UE includes the identifiers of the (i + 1)-th UE and the (i + 2)-th UE among the M UEs, and is used for the i-th UE to trigger the (i + 1)-th UE and the (i + 2)-th UE to respectively request the RAN device to perform the sensing configuration for themselves.

[0071] Among them, if i is equal to 1, the RAN device uses the access stratum key KgNB of the i-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE. The access stratum key KgNB of the i-th UE is: when the i-th UE registers to the network of the RAN device, the key allocated by the network for the RAN device to communicate with the i-th UE; if i is greater than 1, the RAN device uses the sensing key Ksen_uei-1 of the (i - 1)-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE;

[0072] Among them, the configuration request #i + 1 includes the random number #i + 1 generated by the (i + 1)-th UE, the configuration request #i + 2 includes the random number #i + 2 generated by the (i + 2)-th UE, and the method further includes: the RAN device uses the random number #i + 2, the sensing key Ksen_uei of the i-th UE, and the sensing key Ksen_uei+1 of the i-th UE as input parameters to derive the sensing key Ksen_uei+2 of the (i + 2)-th UE.

[0073] The i-th UE receives the sensed configuration ciphertext #i returned by the RAN device in response to the configuration request #i; the i-th UE decrypts the sensed configuration ciphertext #i using the sensed key Ksen_uei of the i-th UE to obtain the sensed configuration information of the i-th UE, and the sensed configuration information of the i-th UE is used for the i-th UE to perform sensing operations; the sensed configuration information of the i-th UE includes the identifiers of the (i + 1)-th UE and the (i + 2)-th UE, and the i-th UE discovers the (i + 1)-th UE by broadcasting the identifier of the (i + 1)-th UE and establishes a sidelink secure connection with the (i + 1)-th UE; the i-th UE sends the sensed key Ksen_uei of the i-th UE, the identifier of the (i + 2)-th UE, and the indication message #i to the (i + 1)-th UE through the sidelink secure connection, and the i-th UE sends the identifier of the (i + 2)-th UE to the i-th UE to indicate that: the (i + 1)-th UE needs to trigger the (i + 2)-th UE to request the RAN device to perform sensed configuration for the (i + 2)-th UE, and the (i + 1)-th UE needs to provide the sensed key Ksen_uei of the i-th UE to the (i + 2)-th UE; the indication message #i indicates that the (i + 1)-th UE needs to request the RAN device to perform sensed configuration for the (i + 1)-th UE. Among them, the (i + 1)-th UE uses the sensed key Ksen_uei of the i-th UE and the random number #i + 1 as input parameters to derive the sensed key Ksen_uei+1 of the (i + 1)-th UE, and the (i + 2)-th UE uses the sensed key Ksen_uei of the i-th UE, the sensed key Ksen_uei+1 of the (i + 1)-th UE, and the random number #i + 2 as input parameters to derive the sensed key Ksen_uei+2 of the (i + 2)-th UE.

[0074] The RAN device can receive the configuration request #i + 1 sent by the (i + 1)-th UE and the configuration request #i + 2 sent by the (i + 2)-th UE. The configuration request #i + 1 is used for the (i + 1)-th UE to request the RAN device to perform sensed configuration for the (i + 1)-th UE, and the configuration request #i + 2 is used for the (i + 2)-th UE to request the RAN device to perform sensed configuration for the (i + 2)-th UE;

[0075] The RAN device sends the sensed configuration ciphertext #i + 1 to the (i + 1)-th UE according to the configuration request #i + 1, and sends the sensed configuration ciphertext #i + 2 to the (i + 2)-th UE according to the configuration request #i + 2;

[0076] The perception configuration ciphertext #i+1 is obtained by encrypting the perception configuration information of the i+1th UE using the perception key Ksen_uei+1 of the i+1th UE. The perception key Ksen_uei+1 of the i+1th UE is encrypted and shared by the RAN device and the i+1th UE. The perception configuration ciphertext #i+2 is obtained by encrypting the perception configuration information of the i+2th UE using the perception key Ksen_uei+2 of the i+2th UE. The perception key Ksen_uei+1 of the i+2th UE is encrypted and shared by the RAN device and the i+2th UE. If i+2=M, the perception configuration information of the i+1th UE does not include the identifiers of other UEs among the M UEs except the i+1th UE, and the perception configuration information of the i+2th UE does not include the identifiers of other UEs among the M UEs except the i+2th UE.

[0077] Based on the above method, it can be known that the above perception key Ksen_ue is a key used to ensure the transmission of perception configuration information. The signal is decoupled from the key encryption of the multiplexed communication link, and the security implementation can be more flexible. The above perception key Ksen_ue can also be used to encrypt the signal when the UE performs perception measurement, so that the perception security is better and the probability of user privacy leakage is reduced. In addition, since the perception keys Ksen_ue of the next two UEs are derived based on the perception key Ksen_ue of the previous UE, that is, a chain derivation structure, an attacker who lacks the perception key Ksen_ue of any of the UEs cannot decipher the perception of the entire group, achieving security coupling and better security.

[0078] In summary, when the RAN device obtains the perception configuration information of each of the M UEs, the RAN device can sequentially configure the perception configuration information of each of the M UEs to the M UEs in a secure and encrypted manner, and the relevant associations in the process of configuring the corresponding perception configuration information of each two UEs in the M UEs can be improved through secure and sequential correlation configuration to improve the security of the configuration information for perception measurement sent by the network side to the UE.

[0079] Combination of the above Figure 2 The method for dynamically updating the wireless communication configuration provided by the embodiment of the present invention is described in detail. The following describes in detail the system for dynamically updating the wireless communication configuration used to execute the method for dynamically updating the wireless communication configuration provided by the embodiment of the present invention.

[0080] The system includes a RAN device, and M UEs included in a sensing group access the RAN device, where M is an integer greater than 1. The system is configured as follows: The RAN device obtains the sensing configuration information of each of the M UEs. The sensing configuration information of each UE among the M UEs is used for the UE to perform a sensing operation; The RAN device sequentially configures the sensing configuration information of each of the M UEs to the M UEs in a secure encryption manner, and there is a relevant association during the process of each two UEs among the M UEs being configured with their respective corresponding sensing configuration information.

[0081] Optionally, i is an integer traversing from 1 to M - 1. The RAN device sequentially configures the sensing configuration information of each of the M UEs to the M UEs in a secure encryption manner, including: The RAN device receives a configuration request #i sent by the i-th UE among the M UEs. The configuration request #i is used for the i-th UE to request the RAN device to perform sensing configuration for the i-th UE; The RAN device sends a sensing configuration ciphertext #i to the i-th UE according to the configuration request #i. The sensing configuration ciphertext #i is obtained by encrypting the sensing configuration information of the i-th UE with the sensing key Ksen_uei of the i-th UE. The sensing key Ksen_uei of the i-th UE is shared and used by the RAN device and the i-th UE. The sensing configuration information of the i-th UE includes the identifier of the (i + 1)-th UE among the M UEs, for the i-th UE to trigger the (i + 1)-th UE to request the RAN device to perform sensing configuration for the (i + 1)-th UE; The RAN device receives a configuration request #i+1 sent by the (i + 1)-th UE. The configuration request #i+1 is used for the (i + 1)-th UE to request the RAN device to perform sensing configuration for the (i + 1)-th UE; The RAN device sends a sensing configuration ciphertext #i+1 to the (i + 1)-th UE according to the configuration request #i+1. The sensing configuration ciphertext #i+1 is obtained by encrypting the sensing configuration information of the (i + 1)-th UE with the sensing key Ksen_uei+1 of the (i + 1)-th UE. The sensing key Ksen_uei+1 of the (i + 1)-th UE is shared and used by the RAN device and the (i + 1)-th UE. If i + 1 = M, the sensing configuration information of the (i + 1)-th UE does not include the identifiers of other UEs among the M UEs except the (i + 1)-th UE.

[0082] Optionally, the configuration request #i includes a random number #i generated by the i-th UE, and the system is configured such that: if i equals 1, the RAN device uses the access stratum key KgNB of the i-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE. The access stratum key KgNB of the i-th UE is the key allocated by the network to the RAN device for communication between the RAN device and the i-th UE when the i-th UE registers to the network of the RAN device; if i is greater than 1, the RAN device uses the sensing key Ksen_uei-1 of the (i - 1)-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE; the configuration request #i+1 includes a random number #i+1 generated by the (i + 1)-th UE, and the system is configured such that: the RAN device uses the sensing key Ksen_uei of the i-th UE and the random number #i+1 as input parameters to derive the sensing key Ksen_uei+1 of the (i + 1)-th UE.

[0083] Optionally, the system further includes M UEs. For the i-th UE among the M UEs, the system is configured such that: the i-th UE sends a configuration request #i to the RAN device; the i-th UE receives the sensing configuration ciphertext #i returned by the RAN device for the configuration request #i; the i-th UE decrypts the sensing configuration ciphertext #i using the sensing key Ksen_uei of the i-th UE to obtain the sensing configuration information of the i-th UE, and the sensing configuration information of the i-th UE is used by the i-th UE to perform sensing operations; the sensing configuration information of the i-th UE includes the identifier of the (i + 1)-th UE, and the i-th UE discovers the (i + 1)-th UE by broadcasting the identifier of the (i + 1)-th UE and establishes a sidelink secure connection with the (i + 1)-th UE; the i-th UE sends the sensing key Ksen_uei of the i-th UE and an indication message #i to the (i + 1)-th UE through the sidelink secure connection, and the indication message #i indicates that the (i + 1)-th UE needs to request the RAN device to perform sensing configuration for the (i + 1)-th UE.

[0084] Optionally, if i is equal to 1, the i-th UE sends a configuration request #i to the RAN device, including: the i-th UE sends a configuration request #i to the RAN device according to the APP message sent by the AF corresponding to the sensing group, and the APP message indicates that the sensing operation of the group needs to be performed; correspondingly, the system is configured as follows: the i-th UE uses the access layer key KgNB of the i-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE; if i is greater than 1, the i-th UE sends a configuration request #i to the RAN device, including: the i-th UE sends a configuration request #i to the RAN device according to the indication information #i-1 sent by the (i-1)-th UE to the i-th UE, and the indication information #i-1 indicates that the i-th UE needs to request the RAN device to perform the sensing configuration for the i-th UE; correspondingly, the system is configured as follows: the i-th UE uses the sensing key Ksen_uei-1 of the (i-1)-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE, and the sensing key Ksen_uei-1 of the (i-1)-th UE is received by the i-th UE through establishing a sidelink security connection with the (i-1)-th UE; wherein, the (i + 1)-th UE uses the sensing key Ksen_uei of the i-th UE and the random number #i+1 as input parameters to derive the sensing key Ksen_uei+1 of the (i + 1)-th UE.

[0085] Optionally, i is an integer ranging from 1 to M - 2. The RAN device configures the sensing configuration information of each of the M UEs for the M UEs in sequence through secure encryption, including: The RAN device receives a configuration request #i sent by the i-th UE among the M UEs. The configuration request #i is used by the i-th UE to request the RAN device to perform sensing configuration for the i-th UE. The RAN device sends a sensing configuration ciphertext #i to the i-th UE according to the configuration request #i. The sensing configuration ciphertext #i is obtained by encrypting the sensing configuration information of the i-th UE using the sensing key Ksen_uei of the i-th UE. The sensing key Ksen_uei of the i-th UE for encryption is shared and used by the RAN device and the i-th UE. The sensing configuration information of the i-th UE includes the identifiers of the (i + 1)-th UE and the (i + 2)-th UE among the M UEs, for the i-th UE to trigger the (i + 1)-th UE and the (i + 2)-th UE to respectively request the RAN device to perform sensing configuration for themselves. The RAN device receives a configuration request #i+1 sent by the (i + 1)-th UE and a configuration request #i+2 sent by the (i + 2)-th UE. The configuration request #i+1 is used by the (i + 1)-th UE to request the RAN device to perform sensing configuration for the (i + 1)-th UE, and the configuration request #i+2 is used by the (i + 2)-th UE to request the RAN device to perform sensing configuration for the (i + 2)-th UE. The RAN device sends a sensing configuration ciphertext #i+1 to the (i + 1)-th UE according to the configuration request #i+1, and sends a sensing configuration ciphertext #i+2 to the (i + 2)-th UE according to the configuration request #i+2. The sensing configuration ciphertext #i+1 is obtained by encrypting the sensing configuration information of the (i + 1)-th UE using the sensing key Ksen_uei+1 of the (i + 1)-th UE. The sensing key Ksen_uei+1 of the (i + 1)-th UE for encryption is shared and used by the RAN device and the (i + 1)-th UE. The sensing configuration ciphertext #i+2 is obtained by encrypting the sensing configuration information of the (i + 2)-th UE using the sensing key Ksen_uei+2 of the (i + 2)-th UE. The sensing key Ksen_uei+1 of the (i + 2)-th UE for encryption is shared and used by the RAN device and the (i + 2)-th UE. If i + 2 = M, then the sensing configuration information of the (i + 1)-th UE does not include the identifiers of other UEs among the M UEs except the (i + 1)-th UE, and the sensing configuration information of the (i + 2)-th UE does not include the identifiers of other UEs among the M UEs except the (i + 2)-th UE.

[0086] Optionally, the configuration request #i includes the random number #i generated by the i-th UE, and the system is configured such that: if i is equal to 1, the RAN device uses the access stratum key KgNB of the i-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE. The access stratum key KgNB of the i-th UE is the key allocated by the network to the RAN device for communication between the RAN device and the i-th UE when the i-th UE registers to the network of the RAN device. If i is greater than 1, the RAN device uses the sensing key Ksen_uei-1 of the (i - 1)-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE. The configuration request #i+1 includes the random number #i+1 generated by the (i + 1)-th UE, and the configuration request #i+2 includes the random number #i+2 generated by the (i + 2)-th UE. The system is configured such that the RAN device uses the random number #i+2, the sensing key Ksen_uei of the i-th UE, and the sensing key Ksen_uei+1 of the (i + 1)-th UE as input parameters to derive the sensing key Ksen_uei+2 of the (i + 2)-th UE.

[0087] Optionally, the system further includes M UEs. For the i-th UE among the M UEs, the system is configured such that: the i-th UE sends the configuration request #i to the RAN device; the i-th UE receives the sensing configuration ciphertext #i returned by the RAN device for the configuration request #i; the i-th UE decrypts the sensing configuration ciphertext #i using the sensing key Ksen_uei of the i-th UE to obtain the sensing configuration information of the i-th UE, and the sensing configuration information of the i-th UE is used by the i-th UE to perform sensing operations; according to the sensing configuration information of the i-th UE including the identifier of the (i + 1)-th UE and the identifier of the (i + 2)-th UE, the i-th UE discovers the (i + 1)-th UE by broadcasting the identifier of the (i + 1)-th UE and establishes a sidelink secure connection with the (i + 1)-th UE; the i-th UE sends the sensing key Ksen_uei of the i-th UE, the identifier of the (i + 2)-th UE, and the indication information #i to the (i + 1)-th UE through the sidelink secure connection. The i-th UE sends the identifier of the (i + 2)-th UE to the (i + 1)-th UE to indicate that: the (i + 1)-th UE needs to trigger the (i + 2)-th UE to request the RAN device to perform sensing configuration for the (i + 2)-th UE, and the (i + 1)-th UE needs to provide the sensing key Ksen_uei of the i-th UE to the (i + 2)-th UE; the indication information #i indicates that the (i + 1)-th UE needs to request the RAN device to perform sensing configuration for the (i + 1)-th UE.

[0088] Optionally, if i equals 1, the i-th UE sends a configuration request #i to the RAN device, including: the i-th UE sends a configuration request #i to the RAN device according to the APP message sent by the AF corresponding to the sensing group, and the APP message indicates that the sensing operation of the group needs to be performed; correspondingly, the system is configured as: the i-th UE uses the access layer key KgNB of the i-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE; if i is greater than 1, the i-th UE sends a configuration request #i to the RAN device, including: the i-th UE sends a configuration request #i to the RAN device according to the indication information #i-1 sent by the (i-1)-th UE to the i-th UE, and the indication information #i-1 indicates that the i-th UE needs to request the RAN device to perform the sensing configuration for the i-th UE; correspondingly, the system is configured as: the i-th UE uses the sensing key Ksen_uei-1 of the (i-1)-th UE and the random number #i as input parameters to derive the sensing key Ksen_uei of the i-th UE, and the sensing key Ksen_uei-1 of the (i-1)-th UE is received by the i-th UE through establishing a sidelink secure connection with the (i-1)-th UE; wherein, the (i + 1)-th UE uses the sensing key Ksen_uei of the i-th UE and the random number #i+1 as input parameters to derive the sensing key Ksen_uei+1 of the (i + 1)-th UE, and the (i + 2)-th UE uses the sensing key Ksen_uei of the i-th UE, the sensing key Ksen_uei+1 of the (i + 1)-th UE and the random number #i+2 as input parameters to derive the sensing key Ksen_uei+2 of the (i + 2)-th UE.

[0089] Optionally, the RAN device obtains the sensing configuration information of each of the M UEs, including: the RAN device receives the sensing configuration information of each of the M UEs provided by a third-party AF, and the AF determines that the M UEs access the RAN device by requesting the network where the RAN device is located to open the location information of the M UEs.

[0090] Figure 3 FIG. is a schematic structural diagram of an electronic device provided in an embodiment of the present invention. Exemplarily, the electronic device may be a terminal device, or a chip (system) or other components or assemblies that can be set in a terminal device. As Figure 3 shown, the electronic device 400 may include a processor 401. Optionally, the electronic device 400 may further include a memory 402 and / or a transceiver 403. Wherein, the processor 401 is coupled to the memory 402 and the transceiver 403, such as being connected through a communication bus. In addition, the electronic device 400 may also be a chip, such as including a processor 401. At this time, the transceiver may be an input / output interface of the chip.

[0091] Next, in combination with Figure 3Specific components of the electronic device 400 will be introduced as follows:

[0092] Among them, the processor 401 is the control center of the electronic device 400, which can be a single processor or a collective term for multiple processing elements. For example, the processor 401 can be one or more central processing units (CPUs), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention, such as one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).

[0093] Optionally, the processor 401 can execute various functions of the electronic device 400 by running or executing software programs stored in the memory 402 and calling data stored in the memory 402. For example, it can execute the Figure 2 dynamic update method of the wireless communication configuration shown above.

[0094] In a specific implementation, as an embodiment, the processor 401 can include one or more CPUs, such as Figure 3 CPU0 and CPU1 shown in

[0095] In a specific implementation, as an embodiment, the electronic device 400 can also include multiple processors. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, the processor can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer programs or instructions).

[0096] Among them, the memory 402 is used to store software programs for implementing the solution of the present invention and is controlled by the processor 401 for execution. The specific implementation can refer to the above method embodiments and will not be elaborated here.

[0097] Optionally, the memory 402 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or may also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 402 may be integrated with the processor 401 or may exist independently and be coupled to the processor 401 through the interface circuit ( Figure 3 not shown) of the electronic device 400. The embodiments of the present invention do not make specific limitations in this regard.

[0098] The transceiver 403 is used for communication with other electronic devices. For example, if the electronic device 400 is a terminal device, the transceiver 403 may be used for communication with a network device or with another terminal device. For another example, if the electronic device 400 is a network device, the transceiver 403 may be used for communication with a terminal device or with another network device.

[0099] Optionally, the transceiver 403 may include a receiver and a transmitter ( Figure 3 not shown separately). Among them, the receiver is used to implement the receiving function, and the transmitter is used to implement the transmitting function.

[0100] Optionally, the transceiver 403 may be integrated with the processor 401 or may exist independently and be coupled to the processor 401 through the interface circuit ( Figure 3 not shown) of the electronic device 400. The embodiments of the present invention do not make specific limitations in this regard.

[0101] It can be understood that Figure 3 the structure of the electronic device 400 shown does not constitute a limitation on the electronic device. The actual electronic device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.

[0102] In addition, the technical effects of the electronic device 400 may refer to the technical effects of the method described in the above method embodiments, which will not be elaborated here.

[0103] It should be understood that the processor in the embodiments of the present invention may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0104] It should also be understood that the memory in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM) or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM) and direct rambus RAM (DR RAM).

[0105] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer program or instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that contains one or more collections of available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, or magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0106] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Additionally, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be understood specifically by referring to the context.

[0107] In the present invention, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0108] It should be understood that in various embodiments of the present invention, the magnitudes of the sequence numbers of the above processes do not imply the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0109] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0110] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0111] In several embodiments provided by the present invention, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0112] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0113] In addition, the functional units in each embodiment of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0114] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0115] As described above, the above are only specific implementation manners of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A method for dynamically updating a wireless communication configuration, characterized in that: Applied to a RAN device, M UEs included in a sensing group access the RAN device, where M is an integer greater than 1, and the method includes: The RAN device acquires the sensing configuration information of each of the M UEs, where the sensing configuration information of each UE in the M UEs is used for the UE to perform a sensing operation; The RAN device sequentially configures the respective perception configuration information of the M UEs to the M UEs in a secure encryption manner, and the process of configuring the corresponding perception configuration information of each two UEs in the M UEs is related and associated; i is an integer ranging from 1 to M-1, and the RAN device sequentially configures the perception configuration information of each of the M UEs to the M UEs in a secure encryption manner, including: The RAN device receives a configuration request #i sent by an i-th UE among the M UEs, where the configuration request #i is used by the i-th UE to request the RAN device to perform perception configuration for the i-th UE; The RAN device sends a perception configuration ciphertext #i to the i-th UE according to the configuration request #i, where the perception configuration ciphertext #i is obtained by encrypting the perception configuration information of the i-th UE using the perception key Ksen_uei of the i-th UE, the perception key Ksen_uei of the i-th UE is shared by the RAN device and the i-th UE, and the perception configuration information of the i-th UE includes an identifier of the i+1th UE among the M UEs, so that the i-th UE triggers the i+1th UE to request the RAN device to perform perception configuration for the i+1th UE; The RAN device receives a configuration request #i+1 sent by the (i+1)th UE, where the configuration request #i+1 is used by the (i+1)th UE to request the RAN device to perform perception configuration for the (i+1)th UE; The RAN device sends a perception configuration ciphertext #i+1 to the i+1th UE according to the configuration request #i+1, where the perception configuration ciphertext #i+1 is obtained by encrypting the perception configuration information of the i+1th UE using the perception key Ksen_uei+1 of the i+1th UE, and the perception key Ksen_uei+1 of the i+1th UE is shared by the RAN device and the i+1th UE. If i+1=M, the perception configuration information of the i+1th UE does not include identifiers of other UEs among the M UEs except the i+1th UE; The configuration request #i includes a random number #i generated by the i-th UE, and the method further includes: If i is equal to 1, the RAN device uses the access layer key KgNB of the i-th UE and the random number #i as input parameters to derive the perception key Ksen_uei of the i-th UE, where the access layer key KgNB of the i-th UE is: when the i-th UE registers to the network of the RAN device, the network allocates the RAN device a key for communication between the RAN device and the i-th UE; if i is greater than 1, the RAN device uses the perception key Ksen_uei-1 of the i-1th UE and the random number #i as input parameters to derive the perception key Ksen_uei of the i-th UE; The configuration request #i+1 includes a random number #i+1 generated by the i+1th UE, and the method further includes: The RAN device uses the perception key Ksen_uei of the i-th UE and the random number #i+1 as input parameters to derive the perception key Ksen_uei+1 of the i+1-th UE.

2. The method according to claim 1, characterized in that The method is also applied to an i-th UE among the M UEs, and the method includes: The i-th UE sends the configuration request #i to the RAN device; The i-th UE receives the perception configuration ciphertext #i returned by the RAN device in response to the configuration request #i; The i-th UE decrypts the perception configuration ciphertext #i using the perception key Ksen_uei of the i-th UE to obtain the perception configuration information of the i-th UE, where the perception configuration information of the i-th UE is used for the i-th UE to perform a perception operation; The i-th UE discovers the i+1-th UE by broadcasting the identification of the i+1-th UE according to the perception configuration information of the i-th UE including the identification of the i+1-th UE, and establishes a sidelink security connection with the i+1-th UE; The i-th UE sends the perception key Ksen_uei of the i-th UE and indication information #i to the i+1-th UE through the sidelink security connection, and the indication information #i indicates that the i+1-th UE needs to request the RAN device to perform perception configuration for the i+1-th UE.

3. The method according to claim 2, characterized in that If i is equal to 1, the i-th UE sends the configuration request #i to the RAN device, including: The i-th UE sends the configuration request #i to the RAN device according to the APP message sent by the AF corresponding to the sensing group to the i-th UE, where the APP message indicates that a sensing operation of the group needs to be performed; Accordingly, the method further includes: The i-th UE uses the access layer key KgNB of the i-th UE and the random number #i as input parameters to derive the perception key Ksen_uei of the i-th UE; If i is greater than 1, the i-th UE sends the configuration request #i to the RAN device, including: The i-th UE sends the configuration request #i to the RAN device according to the indication information #i-1 sent by the i-1th UE to the i-th UE, wherein the indication information #i-1 indicates that the i-th UE needs to request the RAN device to perform perception configuration for the i-th UE; Accordingly, the method further includes: The i-th UE uses the perception key Ksen_uei-1 of the i-1th UE and the random number #i as input parameters to derive the perception key Ksen_uei of the i-th UE, where the perception key Ksen_uei-1 of the i-1th UE is received by the i-th UE by establishing a sideline security connection with the i-1th UE; Among them, the i+1th UE uses the perception key Ksen_uei of the i-th UE and the random number #i+1 as input parameters to derive the perception key Ksen_uei+1 of the i+1th UE.

4. The method according to claim 1, characterized in that i is an integer ranging from 1 to M-2, and the RAN device sequentially configures the perception configuration information of each of the M UEs to the M UEs in a secure encryption manner, including: The RAN device receives a configuration request #i sent by an i-th UE among the M UEs, where the configuration request #i is used by the i-th UE to request the RAN device to perform perception configuration for the i-th UE; The RAN device sends a perception configuration ciphertext #i to the i-th UE according to the configuration request #i, where the perception configuration ciphertext #i is obtained by encrypting the perception configuration information of the i-th UE using the perception key Ksen_uei of the i-th UE, the perception key Ksen_uei of the i-th UE is shared by the RAN device and the i-th UE, and the perception configuration information of the i-th UE includes an identifier of an i+1-th UE and an identifier of an i+2-th UE among the M UEs, so that the i-th UE triggers the i+1-th UE and the i+2-th UE to respectively request the RAN device to perform perception configuration for each of them; The RAN device receives a configuration request #i+1 sent by the (i+1)th UE and a configuration request #i+2 sent by the (i+2)th UE, wherein the configuration request #i+1 is used by the (i+1)th UE to request the RAN device to perform a sensing configuration for the (i+1)th UE, and the configuration request #i+2 is used by the (i+2)th UE to request the RAN device to perform a sensing configuration for the (i+2)th UE; The RAN device sends the perception configuration ciphertext #i+1 to the (i+1)th UE according to the configuration request #i+1, and sends the perception configuration ciphertext #i+2 to the (i+2)th UE according to the configuration request #i+2; The perception configuration ciphertext #i+1 is obtained by encrypting the perception configuration information of the i+1th UE using the perception key Ksen_uei+1 of the i+1th UE, and the perception key Ksen_uei+1 of the i+1th UE is shared by the RAN device and the i+1th UE. The perception configuration ciphertext #i+2 is obtained by encrypting the perception configuration information of the i+2th UE using the perception key Ksen_uei+2 of the i+2th UE, and the perception key Ksen_uei+2 of the i+2th UE is shared by the RAN device and the i+2th UE. If i+2=M, the perception configuration information of the i+1th UE does not include the identifiers of other UEs among the M UEs except the i+1th UE, and the perception configuration information of the i+2th UE does not include the identifiers of other UEs among the M UEs except the i+2th UE.

5. The method according to claim 4, characterized in that The configuration request #i includes a random number #i generated by the i-th UE, and the method further includes: If i is equal to 1, the RAN device uses the access layer key KgNB of the i-th UE and the random number #i as input parameters to derive the perception key Ksen_uei of the i-th UE, where the access layer key KgNB of the i-th UE is: when the i-th UE registers to the network of the RAN device, the network allocates the RAN device a key for communication between the RAN device and the i-th UE; if i is greater than 1, the RAN device uses the perception key Ksen_uei-1 of the i-1th UE and the random number #i as input parameters to derive the perception key Ksen_uei of the i-th UE; The configuration request #i+1 includes a random number #i+1 generated by the i+1th UE, the configuration request #i+2 includes a random number #i+2 generated by the i+2th UE, and the method further includes: The RAN device uses the random number #i+2, the perception key Ksen_uei of the i-th UE, and the perception key Ksen_uei+1 of the i+1-th UE as input parameters to derive the perception key Ksen_uei+2 of the i+2-th UE.

6. The method according to claim 5, characterized in that The method is also applied to an i-th UE among the M UEs, and the method includes: The i-th UE sends the configuration request #i to the RAN device; The i-th UE receives the perception configuration ciphertext #i returned by the RAN device in response to the configuration request #i; The i-th UE decrypts the perception configuration ciphertext #i using the perception key Ksen_uei of the i-th UE to obtain the perception configuration information of the i-th UE, where the perception configuration information of the i-th UE is used for the i-th UE to perform a perception operation; The i-th UE discovers the i+1-th UE by broadcasting the identity of the i+1-th UE according to the perception configuration information of the i-th UE including the identity of the i+1-th UE and the identity of the i+2-th UE, and establishes a sideline security connection with the i+1-th UE; The i-th UE sends the perception key Ksen_uei of the i-th UE, the identifier of the i+2-th UE and the indication information #i to the i+1-th UE through the sidelink security connection, and the i-th UE sends the identifier of the i+2-th UE to the i+1-th UE to indicate that: the i+1-th UE needs to trigger the i+2-th UE to request the RAN device to perform perception configuration for the i+2-th UE, and the i+1-th UE needs to provide the perception key Ksen_uei of the i-th UE to the i+2-th UE; The indication information #i indicates that the (i+1)th UE needs to request the RAN device to perform perception configuration for the (i+1)th UE.

7. The method according to claim 6, characterized in that If i is equal to 1, the i-th UE sends the configuration request #i to the RAN device, including: The i-th UE sends the configuration request #i to the RAN device according to the APP message sent by the AF corresponding to the sensing group to the i-th UE, where the APP message indicates that a sensing operation of the group needs to be performed; Accordingly, the method further includes: The i-th UE uses the access layer key KgNB of the i-th UE and the random number #i as input parameters to derive the perception key Ksen_uei of the i-th UE; If i is greater than 1, the i-th UE sends the configuration request #i to the RAN device, including: The i-th UE sends the configuration request #i to the RAN device according to the indication information #i-1 sent by the i-1th UE to the i-th UE, wherein the indication information #i-1 indicates that the i-th UE needs to request the RAN device to perform perception configuration for the i-th UE; Accordingly, the method further includes: The i-th UE uses the perception key Ksen_uei-1 of the i-1th UE and the random number #i as input parameters to derive the perception key Ksen_uei of the i-th UE, where the perception key Ksen_uei-1 of the i-1th UE is received by the i-th UE by establishing a sideline security connection with the i-1th UE; Among them, the i+1th UE uses the perception key Ksen_uei of the i-th UE and the random number #i+1 as input parameters to derive the perception key Ksen_uei+1 of the i+1th UE, and the i+2th UE uses the perception key Ksen_uei of the i-th UE, the perception key Ksen_uei+1 of the i+1th UE and the random number #i+2 as input parameters to derive the perception key Ksen_uei+2 of the i+2th UE.

8. The method according to any one of claims 1 to 7, characterized in that The RAN device obtains the perception configuration information of each of the M UEs, including: The RAN device receives the perception configuration information of each of the M UEs provided by a third-party AF, and the AF determines that the M UEs access the RAN device by requesting the network where the RAN device is located to open the location information of the M UEs.

Citation Information

Patent Citations

  • Perception measurement processing method and equipment

    CN117082439A

  • Base station system information management method and system

    CN117221884A