Lateral link reconstruction method and device, communication equipment and storage medium

When the PC5 link is disconnected, the second key is generated using the link reconstruction request message and the command message to perform two-way authentication and authorization verification, which solves the problem of high delay in the reconstruction process in the prior art and improves the performance of lateral link reconstruction.

CN120050654APending Publication Date: 2025-05-27CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311586282.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-24
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

When the PC5 link is disconnected, the delay in the reconstruction process is high due to the execution of a complete security process, which affects performance.

Method used

By sending link reconstruction request messages and command messages between the remote user terminal and the relay user terminal, a second key is generated using the reserved key and verification parameters for two-way authentication and authorization verification, reducing signaling flow and delay in the reconstruction process.

Benefits of technology

The performance of lateral link reconstruction is improved, the delay in the reconstruction process is reduced, and the communication efficiency between the remote user terminal and the relay user terminal is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050654A_ABST
    Figure CN120050654A_ABST
Patent Text Reader

Abstract

The invention relates to a lateral link reconstruction method and device, communication equipment, a storage medium and a computer program product. The method comprises the following steps: sending a link reconstruction request message to a relay user terminal; the link reestablishment request message comprises a first verification parameter for generating a second key; receiving a command message sent by the relay user terminal; the command message contains a second verification parameter for generating a second key; determining a second secret key according to the reserved first secret key, the first verification parameter and the second verification parameter; the second key is used for bidirectional authentication and authorization verification between the remote user terminal and the relay user terminal. By adopting the method, the performance of lateral link reconstruction can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of mobile communication security, and particularly to a sidelink reconstruction method, apparatus, communication device, storage medium, and computer program product. Background Art

[0002] With the wide design and application of wireless air interface technology based on Sidelink (sidelink) in many network scenarios, such as vehicle-to-everything (V2X), proximity services, ranging and positioning services, etc. The PC5 link is the definition of the cellular sidelink in 3GPP, which enables indirect communication between vehicle terminals or direct communication between a vehicle terminal and the core network. When the PC5 link is disconnected, it is necessary to reconstruct the PC5 link.

[0003] In traditional technologies, when the PC5 link is disconnected, the terminal releases the original PC5 link, and the Remote UE (remote user terminal) and the Relay UE (relay user terminal) re-initiate a PC5 link creation request, interact with the core network to establish a security process between the Remote UE and the Relay UE, perform a complete two-way authentication and authorization authentication between the Remote UE and the Relay UE, and complete the reconstruction of the PC5 link.

[0004] However, currently, the Remote UE and the Relay UE reconstruct the PC5 link by executing a complete security process. Due to the high latency of reconstructing the PC5 link, the performance of the PC5 link for communication between the Remote UE and the Relay UE or with the network relay service is poor. Summary of the Invention

[0005] Embodiments of the present application provide a sidelink reconstruction method, apparatus, communication device, storage medium, and computer program product, which can improve the performance of sidelink reconstruction.

[0006] A sidelink reconstruction method, applied to a remote user terminal, the method includes:

[0007] Sending a link reconstruction request message to a relay user terminal; the link reconstruction request message includes a first verification parameter for generating a second key;

[0008] Receiving a command message sent by the relay user terminal; the command message includes a second verification parameter for generating the second key;

[0009] Determining the second key according to a reserved first key, the first verification parameter, and the second verification parameter; the second key is used for two-way authentication and authorization verification between the remote user terminal and the relay user terminal.

[0010] In one embodiment, the first verification parameter included in the link reconstruction request message includes a first key sequence number, a first random number for generating a second key, and the highest four significant bits of a second key sequence number.

[0011] In one embodiment, the second verification parameter included in the command message includes a second random number for generating the second key and the lowest four significant bits of the second key sequence number.

[0012] In one embodiment, the link reconstruction request message further includes at least one of a relay service code (RSC) and a relay user terminal identifier; at least one of the RSC and the relay user terminal identifier is used to determine a PC5 link security context.

[0013] In one embodiment, the method further includes:

[0014] Checking the validity of the PC5 link security context, and if the check passes, generating a link reconstruction request message;

[0015] Protecting the link reconstruction request message according to a discovery key associated with the RSC, and performing the step of sending the link reconstruction request message to the relay user terminal.

[0016] In one embodiment, after determining the second key according to the reserved first key, the first verification parameter, and the second verification parameter, the method further includes:

[0017] Performing integrity verification on the command message based on the second key to obtain an integrity verification result, and if the integrity verification result is successful, sending a completion message to the relay user terminal; the completion message includes the highest four significant bits for generating a new first key sequence number;

[0018] Receiving a reconstruction success message sent by the relay user terminal, and generating a new first key sequence number according to the highest four significant bits for generating a new first key sequence number and the lowest four significant bits for generating a new first key sequence number in the reconstruction success message.

[0019] A sidelink reconstruction method. Applied to a relay user terminal, the method includes:

[0020] Receiving a link reconstruction request message sent by a remote user terminal; the link reconstruction request message includes a first verification parameter for generating a second key;

[0021] Determine the second key according to the reserved first key, the first verification parameter, and the second verification parameter; the second key is used for two-way authentication and authorization verification between the remote user terminal and the relay user terminal;

[0022] Send a command message to the remote user terminal; the command message includes the second verification parameter for generating the second key.

[0023] In one embodiment, after determining the second key according to the reserved first key, the first verification parameter, and the second verification parameter, the method further includes:

[0024] Receive a completion message sent by the remote user terminal; the completion message includes the highest four significant bits for generating a new first key sequence number;

[0025] Perform integrity verification on the completion message based on the second key to obtain an integrity verification result. If the integrity verification result is successful, send a reconstruction success message to the remote user terminal; the reconstruction success message includes the lowest four significant bits for generating a new first key sequence number;

[0026] Generate a new first key sequence number according to the lowest four significant bits for generating the new first key sequence number and the highest four significant bits for generating the new first key sequence number in the completion message.

[0027] A sidelink reconstruction device. The device includes:

[0028] A first sending module, configured to send a link reconstruction request message to the relay user terminal; the link reconstruction request message includes the first verification parameter for generating the second key;

[0029] A first receiving module, configured to receive the command message sent by the relay user terminal; the command message includes the second verification parameter for generating the second key;

[0030] A first determining module, configured to determine the second key according to the reserved first key, the first verification parameter, and the second verification parameter; the second key is used for two-way authentication and authorization verification between the remote user terminal and the relay user terminal.

[0031] In one embodiment, the first verification parameter included in the link reconstruction request message includes a first key sequence number, a first random number for generating the second key, and the highest four significant bits of a second key sequence number.

[0032] In one embodiment, the second verification parameter included in the command message includes a second random number for generating the second key and the lowest four significant bits of the second key sequence number.

[0033] In one embodiment, the link reconstruction request message further includes at least one of a relay service code (RSC) and a relay user terminal identifier; at least one of the RSC and the relay user terminal identifier is used to determine the PC5 link security context.

[0034] In one embodiment, the apparatus further includes:

[0035] A first generation module, configured to verify the validity of the PC5 link security context, and if the verification passes, generate a link reconstruction request message;

[0036] A protection module, configured to protect the link reconstruction request message according to a discovery key associated with the RSC, and perform the step of sending the link reconstruction request message to the relay user terminal.

[0037] In one embodiment, the apparatus further includes:

[0038] A verification module, configured to perform integrity verification on the command message based on the second key to obtain an integrity verification result, and if the integrity verification result is successful verification, send a completion message to the relay user terminal; the completion message includes the highest four significant bits for generating a new first key sequence number;

[0039] A second generation module, configured to receive a reconstruction success message sent by the relay user terminal, and generate a new first key sequence number according to the highest four significant bits for generating a new first key sequence number and the lowest four significant bits for generating a new first key sequence number in the reconstruction success message.

[0040] A sidelink reconstruction apparatus. The apparatus includes:

[0041] A second receiving module, configured to receive a link reconstruction request message sent by a remote user terminal; the link reconstruction request message includes a first verification parameter for generating a second key;

[0042] A second determination module, configured to determine the second key according to a reserved first key, the first verification parameter, and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal;

[0043] A second sending module, configured to send a command message to the remote user terminal; the command message includes a second verification parameter for generating the second key.

[0044] In one embodiment, the apparatus further comprises:

[0045] a third receiving module, configured to receive a completion message sent by a remote user terminal; the completion message includes the highest four significant bits for generating a new first key sequence number;

[0046] a third sending module, configured to perform integrity verification on the completion message based on the second key to obtain an integrity verification result, and if the integrity verification result is successful, send a reconstruction success message to the remote user terminal; the reconstruction success message includes the lowest four significant bits for generating a new first key sequence number;

[0047] a third generating module, configured to generate a new first key sequence number according to the lowest four significant bits for generating a new first key sequence number and the highest four significant bits for generating a new first key sequence number in the completion message.

[0048] A communication device, comprising: a transmitter, a processor, and a receiver;

[0049] The transmitter is configured to send a link reconstruction request message to a relay user terminal; the link reconstruction request message includes a first verification parameter for generating a second key;

[0050] The receiver is configured to receive a command message sent by the relay user terminal; the command message includes a second verification parameter for generating the second key;

[0051] The processor is configured to determine the second key according to a reserved first key, the first verification parameter, and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal.

[0052] A communication device, comprising: a transmitter, a processor, and a receiver;

[0053] The receiver is configured to receive a link reconstruction request message sent by a remote user terminal; the link reconstruction request message includes a first verification parameter for generating a second key;

[0054] The processor is configured to determine the second key according to a reserved first key, the first verification parameter, and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal;

[0055] The transmitter is configured to send a command message to the remote user terminal; the command message includes a second verification parameter for generating the second key.

[0056] A computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the following steps are implemented:

[0057] Send a link reconstruction request message to a relay user terminal; the link reconstruction request message includes a first verification parameter for generating a second key;

[0058] Receive a command message sent by the relay user terminal; the command message includes a second verification parameter for generating the second key;

[0059] Determine the second key according to the reserved first key, the first verification parameter, and the second verification parameter; the second key is used for mutual authentication and authorization verification between a remote user terminal and the relay user terminal.

[0060] A computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the following steps are implemented:

[0061] Receive a link reconstruction request message sent by a remote user terminal; the link reconstruction request message includes a first verification parameter for generating a second key;

[0062] Determine the second key according to the reserved first key, the first verification parameter, and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal;

[0063] Send a command message to the remote user terminal; the command message includes a second verification parameter for generating the second key.

[0064] A computer program product includes a computer program, and is characterized in that when the computer program is executed by a processor, the sidelink reconstruction method provided by an embodiment of the present application is implemented, and the method may be:

[0065] Send a link reconstruction request message to a relay user terminal; the link reconstruction request message includes a first verification parameter for generating a second key;

[0066] Receive a command message sent by the relay user terminal; the command message includes a second verification parameter for generating the second key;

[0067] Determine the second key according to the reserved first key, the first verification parameter, and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal.

[0068] A computer program product includes a computer program, characterized in that when the computer program is executed by a processor, it implements the sidelink reconstruction method provided by the embodiments of the present application, and the method may be as follows:

[0069] Receive a link reconstruction request message sent by a remote user terminal; the link reconstruction request message includes a first verification parameter for generating a second key;

[0070] Determine the second key according to the reserved first key, the first verification parameter, and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal;

[0071] Send a command message to the remote user terminal; the command message includes a second verification parameter for generating the second key.

[0072] In the above sidelink reconstruction method, device, computer device, storage medium, and computer program product, the link reconstruction request message includes a first verification parameter within the validity period of the PC5 link security context. According to the first verification parameter within the validity period of the PC5 link security context, it is possible to avoid executing the complete security process in the PC5 link, and through the first verification parameter generated by the remote user terminal and the second verification parameter received from the relay user terminal, the second key for mutual authentication and authorization authentication can be determined at the remote user terminal, reducing the signaling process and delay impact of re - establishing the same PC5 link, improving the efficiency of determining the second key, and thus improving the performance of reconstructing the PC5 link. Description of the Drawings

[0073] Figure 1 It is an application environment diagram of the sidelink reconstruction method in an embodiment;

[0074] Figure 2 It is a flowchart of the remote user terminal in the sidelink reconstruction method in an embodiment;

[0075] Figure 3 It is a schematic diagram of the user plane key structure in an embodiment;

[0076] Figure 4 It is a schematic diagram of the control plane key structure in an embodiment;

[0077] Figure 5 It is a flowchart of protecting the link re - addition request message in an embodiment;

[0078] Figure 6 It is a flowchart of the remote user terminal updating the first key sequence number in an embodiment;

[0079] Figure 7Schematic diagram of the process of the relay user terminal in the sidelink reconstruction method in an embodiment;

[0080] Figure 8 Schematic diagram of the process of the relay user terminal updating the first key sequence number in an embodiment;

[0081] Figure 9 Schematic diagram of the signaling interaction process of sidelink reconstruction in an embodiment;

[0082] Figure 10 Block diagram of the structure of the sidelink reconstruction device in an embodiment;

[0083] Figure 11 Block diagram of the structure of the sidelink reconstruction device in an embodiment;

[0084] Figure 12 Internal structure diagram of a communication device in an embodiment. Detailed implementation manners

[0085] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0086] Figure 1 Schematic diagram of the application scenario of a sidelink reconstruction method provided by an embodiment of the present application. As Figure 1 shown, in this scenario, there are a first user terminal 100, a second user terminal 200 and an access network device 300. Among them, data is transmitted between the remote user terminal 100 and the relay user terminal 200 through a network, and data is transmitted between the remote user terminal 100 and the access network device 300 through a network.

[0087] Among them, the access network device 300 may be a base transceiver station (BTS) in Global System of Mobile communication (GSM) or Code Division Multiple Access (CDMA), or a Node B (NB) in Wideband Code Division Multiple Access (WCDMA), or an evolved base station (eNB or eNodeB) in LTE, or a relay station or an access point, or a base station in a 5G network, etc., which is not limited herein.

[0088] The remote user terminal 100 and the relay terminal 200 can be wireless terminals. A wireless terminal can be a device that provides voice and / or other service data connectivity to a user, or a handheld device with wireless connection capabilities, or other processing devices connected to a wireless modem. The wireless terminal can communicate with one or more core networks via a Radio Access Network (RAN). The wireless terminal can be a mobile terminal, such as a mobile phone (or a "cellular" phone) and a computer with a mobile terminal. For example, it can be a portable, pocket-sized, handheld, computer-integrated, or vehicle-mounted mobile device that exchanges voice and / or data with the radio access network. The wireless terminal can also be referred to as a system, subscriber unit, subscriber station, mobile station, mobile, remote station, remote terminal, access terminal, user terminal, user agent, user device or user equipment, which is not limited herein.

[0089] Before introducing the specific embodiments of the present invention, the professional terms involved in the present invention are explained first:

[0090] PC5 link security context: A combination of encryption algorithms and integrity check algorithms and security keys specified for use on the PC5 link. For example, encryption algorithms, message integrity check algorithms, root keys, and session keys, etc.

[0091] Root key: A security key used to generate and manage other keys in the PC5 link.

[0092] Session key: A temporary security key used to encrypt and decrypt data during a communication session in the PC5 link.

[0093] Relay service code RSC ((Relay Service Code): Used to identify the connection service provided by a 5G ProSe U2N relay user terminal (Relay UE, Relay User Equipment) to a remote user terminal (Remote UE, Remote User Equipment), and can be used to select relevant security policies or information.. In one embodiment, as Figure 2 shown, a sidelink reconstruction method is provided, and this method is applied to Figure 1Taking the remote user terminal 102 as an example, the method includes the following steps:

[0094] Step 202: Send a link reconstruction request message to the relay user terminal.

[0095] The link reconstruction request message includes a first verification parameter for generating a second key. In the embodiments of the present application, when the PC5 link connection between the remote user terminal and the relay user terminal is interrupted, the remote user terminal deletes the second key and retains the first key, the first key sequence number, and the relay user terminal identifier. Among them, as Figure 3 shown, Figure 3 is the PC5 key structure based on the user plane, and K NRP is the first key, that is, the root key, between the relay user terminal (or network side) and the remote user terminal. When a passive link failure occurs on the PC5 link, the first key is retained locally at the relay user terminal and the remote user terminal, and at the same time, the first key sequence number (K NRP ID) is retained, and only the key structure of the second key (one of the session keys) is deleted. For example, based on the user plane K NRP-SESS . As Figure 4 shown, Figure 4 is the PC5 key structure based on the control plane, and the K NR_ProSe key is the first key, that is, the root key, between the relay user terminal (or network side) and the remote user terminal. When a passive link failure occurs on the PC5 link, it is retained locally at the relay user terminal and the remote user terminal, and at the same time, the first key sequence number (K NR_ProSe ID) is retained, and only the key structure of the second key (one of the session keys) is deleted. For example, K relay-sess . That is, the PC5 link security context may include K NRP , K NRP-SESS , NRPEK, NRPIK based on the user plane, and K NR_ProSe , K relay-sess , K relay-enc , K relay-int based on the control plane.

[0096] When the PC5 link connection is interrupted, and the remote user terminal rediscovers the relay user terminal at the air interface within a short time (within a preset time threshold) when the PC5 link is interrupted. When the remote user terminal determines that the local still retains a valid PC5 security context that can be used to re - establish the same PC5 link as before with the relay user terminal, the remote user terminal generates a link reconstruction request message containing the first verification parameter and sends the link reconstruction request message to the relay user terminal.

[0097] Step 204: Receive a command message sent by the relay user terminal.

[0098] Among them, the command message includes a second verification parameter for generating a second key.

[0099] In the embodiment of the present application, first, the remote user terminal obtains data from the relay user terminal by receiving a command message on the communication link. This command message is sent by the relay user terminal as a response to the link reconstruction request. Then, the remote user terminal parses the received command message and extracts the second verification parameter from the parsed command message.

[0100] Step 206: Determine the second key according to the reserved first key, the first verification parameter, and the second verification parameter.

[0101] Among them, the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal.

[0102] In the embodiment of the present application, in the PC5 link re - establishment process, the remote user terminal and the relay user terminal do not execute the complete PC5 link security process. And the remote user terminal and the relay user terminal generate a second key based on the freshly transmitted first verification parameter and second verification parameter in the PC5 link re - establishment process, based on a key derivation algorithm or an encryption algorithm, and derive NRPEK and NRPIK, or K relay-enc and K relay-int , to form a new PC5 security context to protect communication messages. Among them, the key derivation algorithm can be PBKDF2 (Password - Based Key Derivation Function) or HKDF (HMAC - based Extract - and - Expand Key Derivation Function), and the encryption algorithm can be AES (Advanced Encryption Standard) or ECC (Elliptic Curve Cryptography). The embodiment of the present application does not limit the method for generating the second key.

[0103] In the above - mentioned sidelink reconstruction method, the link reconstruction request message includes the first verification parameter within the validity period of the PC5 link security context. According to the first verification parameter within the validity period of the PC5 link security context, it is possible to avoid executing the complete security process in the PC5 link. And through the first verification parameter generated by the remote user terminal and the second verification parameter received from the relay user terminal, the remote user terminal can determine the second key for mutual authentication and authorization authentication, reducing the signaling process and delay impact of re - establishing the same PC5 link, improving the efficiency of determining the second key, and thus improving the performance of re - establishing the PC5 link.

[0104] In one embodiment, the first verification parameter included in the link reconstruction request message includes the first key sequence number, the first random number, and the highest four significant bits of the second key sequence number for generating the second key.

[0105] In an embodiment of the present application, when a connection interruption occurs between a remote user terminal and a relay user terminal, in order to reconstruct the PC5 link, before the remote user terminal sends a link reconstruction request to the relay user terminal, the remote user terminal generates a first random number and the highest four significant bits of a second key sequence number, that is, the highest four significant bits of the session key sequence number (K NRP-SESS ID), and obtains the first key sequence number (K NRP , root key) of the first key through the first key (K NRP ID) reserved by the remote user terminal, and writes the first key sequence number of the first key, the generated first random number, and the highest four significant bits of the second key sequence number into the link reconstruction request message.

[0106] Among them, the first key sequence number (i.e., the root key sequence number) written into the link reconstruction request message, during the process of re-establishing the PC5 link, because there is an associated mapping relationship between the first key, the first key sequence number, and the RSC, therefore, the first key (root key) can be determined through the first key sequence number, and the RSC associated with the determined first key is obtained, and then the RSC associated with the first key is compared with the RSC included in the link reconstruction request, so as to assist the relay user terminal to confirm whether the RSC in the PC5 security context is the same as the RSC in the link reconstruction request message using the first key sequence number.

[0107] In this embodiment, by writing the reserved first key sequence number, the generated first random number, and the highest four significant bits of the second key sequence number into the link reconstruction request message, the second key can be quickly reconstructed through the link reconstruction request message, improving the performance of reconstructing the PC5 link.

[0108] In one embodiment, the second verification parameter included in the command message includes a second random number for generating the second key and the lowest four significant bits of the second key sequence number.

[0109] In an embodiment of the present application, after the remote user terminal receives the command message, the remote user terminal parses the command message and extracts the second random number and the lowest four significant bits of the second key sequence number. The remote user terminal can generate the second key according to the first key reserved locally, the first random number generated locally, the highest four significant bits of the second key sequence number, and the second random number and the lowest four significant bits of the second key sequence number included in the received command message. Among them, the lowest four significant bits and the highest four significant bits of the second key sequence number can be the last four bits and the first four bits respectively in the binary representation of the value of the second key sequence number.

[0110] The remote user terminal and the relay user terminal can generate a second key based on the first random number included in the first verification parameter, the highest four significant bits of the second key sequence number, the second random number included in the second verification parameter, and the lowest four significant bits of the second key sequence number. On the side of the remote user terminal, the remote user terminal can generate a second key, that is, generate a session key, based on the locally generated first random number and the highest four significant bits of the second key sequence number, as well as the second random number and the lowest four significant bits of the second key sequence number included in the received command message.

[0111] In this embodiment, by using the first random number and the second random number as parameters for generating the second key, the risk of the second key being cracked or predicted can be reduced, the security of PC5 link reconstruction can be improved, and by using the lowest four significant bits and the highest four significant bits of the second key sequence number as parameters for generating the second key, the consistency of the second keys generated by the remote user terminal and the relay user terminal can be ensured.

[0112] In one embodiment, the link reconstruction request message further includes at least one of a relay service code RSC and a relay user terminal identifier, and at least one of the RSC and the relay user terminal identifier is used to determine the PC5 link security context.

[0113] In the embodiment of the present application, after the PC5 link between the remote user terminal and the relay user terminal is interrupted, the reserved parameter may further include the RSC. The remote user terminal can use the RSC and the relay user terminal identifier to determine the target relay user terminal according to the RSC. Optionally, the remote user terminal can write the RSC or the relay user terminal identifier into the link reconstruction request message, or write the RSC and the relay user terminal identifier into the link reconstruction request message together.

[0114] In this embodiment, by determining the PC5 link security context through the link reconstruction request message further including at least one of the relay service code RSC and the relay user terminal identifier, it can be used to ensure that the remote user terminal and the relay user terminal retrieve the same PC5 link security context.

[0115] In one embodiment, as Figure 5 shown, the method further includes:

[0116] Step 502, check the validity of the PC5 link security context. If the check passes, generate a link reconstruction request message.

[0117] In the embodiments of the present application, before sending a link reconstruction request message, the remote user terminal may verify the validity of the PC5 link security context. For example, the timeliness of the security context is determined based on the validity period parameter, clock, etc. included or associated in the PC5 link security context, and whether the relevant parameters of the PC5 link security context are complete. For example, whether the first key, the second key, the RSC, or the relay user terminal identifier is complete, etc. A link reconstruction request message is generated when the PC5 link security context is complete and timely.

[0118] Step 504, protect the link reconstruction request message according to the discovery key associated with the RSC, and send the protected link reconstruction request message to the relay user terminal.

[0119] In the embodiments of the present application, the discovery service or system related to the RSC of the remote user terminal generates, manages, and distributes the discovery key. The discovery key can be generated through a key generation algorithm in the initialization stage of the system and stored in the corresponding security module. The distribution of the discovery key can be carried out through a secure channel, using asymmetric key encryption, etc. After constructing the link reconstruction request message, the remote user terminal uses the discovery key to encrypt and protect the link reconstruction request message. Among them, the encryption algorithm can be AES (Advanced Encryption Standard), which is used to encrypt the link reconstruction request message. The encryption process will use the encryption key in the discovery key to encrypt the message content to ensure that only the relay user terminal with the correct key can decrypt the message.

[0120] In an alternative embodiment, before sending the link reconstruction request, the remote user terminal may also use the integrity protection key in the discovery key to perform integrity protection on the link reconstruction request. For example, the remote user terminal uses an encryption algorithm to calculate the checksum of the link reconstruction request message, and this checksum is used to be sent together with the link reconstruction request message to assist the relay user terminal in performing integrity verification on the link reconstruction request message.

[0121] In this embodiment, the remote user terminal can verify the validity of the PC5 link security context and generate a link reconstruction request message with a valid PC5 link security context, which can ensure that the link reconstruction request message is based on a valid PC5 link security context, and protect the link reconstruction request message through the discovery key associated with the RSC, ensuring that only the relay user terminal with the correct discovery key can correctly decrypt and process the encrypted message content, which can guarantee the security of the link reconstruction request message in the PC5 link reconstruction.

[0122] In one embodiment, the remote user terminal and the relay user terminal may generate a new first key sequence number based on the highest four significant bits and the lowest four significant bits of the exchanged first key sequence number. If the remote user terminal and the relay user terminal perform a refresh of the first key sequence number, confidentiality protection needs to be enabled during the communication process between the remote user terminal and the relay user terminal. For example, Figure 6 As shown, after determining the second key according to the reserved first key, the first verification parameter, and the second verification parameter in step 206, the method further includes:

[0123] Step 602, perform integrity verification on the command message based on the second key to obtain an integrity verification result. If the integrity verification result is successful, send a completion message to the relay user terminal.

[0124] Wherein, the completion message includes the highest four significant bits for generating a new first key sequence number.

[0125] In the embodiment of the present application, the remote user terminal may derive the key for integrity verification based on the second key, such as Figure 3 the NRPEK and NRPIK shown, or such as Figure 4 the K shown relay-enc and K relay-int , perform integrity verification on the command message through a preset verification method. The preset verification method may be a message authentication code algorithm (for example, the HMAC algorithm, Hash-based Message Authentication Code, hash message authentication code). By calculating the integrity code of the command message and matching the calculated integrity code with the integrity code in the command message, if the matching result is a match, the integrity verification is successful, indicating that the command message has not been tampered with. Then the remote user terminal generates the highest four significant bits of the first key sequence number, generates a completion message according to the highest four significant bits of the first key sequence number, and sends the completion message including the highest four significant bits of the first key sequence number to the relay user terminal. If the calculated integrity code does not match the integrity code in the command message, the integrity verification result is a verification failure, and the remote user terminal terminates the reconstruction of the PC5 link.

[0126] Optionally, the remote user terminal may perform confidentiality protection on the completion message based on an encryption algorithm and a security policy.

[0127] Step 604, receive the reconstruction success message sent by the relay user terminal, and generate a new first key sequence number according to the highest four significant bits for generating a new first key sequence number and the lowest four significant bits for generating a new first key sequence number in the reconstruction success message.

[0128] Wherein, the new first key sequence number is used for sidelink privacy protection.

[0129] In an embodiment of the present application, the remote user terminal receives the reconstruction success message sent by the relay user terminal, parses and extracts the lowest four significant bits of the first key serial number in the reconstruction success message, generates a new first key serial number by using the highest four significant bits of the first key serial number locally generated and the lowest four significant bits of the first key serial number in the reconstruction success message, and refreshes it as the local first key serial number, thereby completing the update of the local first key serial number.

[0130] Specifically, the remote user terminal generates a new first key serial number according to the highest four significant bits of the first key serial number locally generated and the lowest four significant bits of the first key serial number included in the reconstruction success message.

[0131] In this embodiment, the remote user terminal receives the reconstruction success message sent by the relay user terminal, and generates a new first key serial number by using the highest four significant bits of the first key serial number and the lowest four significant bits of the first key serial number in the reconstruction success message. The generated new first key serial number can be used for sidelink privacy protection.

[0132] In one embodiment, as Figure 7 shown, a sidelink reconstruction method is provided. Taking the method applied to the relay user terminal 104 in Figure 1 as an example for illustration, the method includes the following steps:

[0133] Step 702: Receive the link reconstruction request message sent by the remote user terminal.

[0134] The link reconstruction request message includes the first verification parameter for generating the second key.

[0135] In an embodiment of the present application, the relay user terminal receives the link reconstruction request message from the remote user terminal, and parses and extracts the first verification parameter included in the link reconstruction request message.

[0136] Step 704: Determine the second key according to the reserved first key, the first verification parameter, and the second verification parameter.

[0137] The second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal.

[0138] In an embodiment of the present application, based on the same principle as in step 206, the relay user terminal calculates and generates the second key according to the first key reserved locally in the relay user terminal, the first verification parameter included in the received link reconstruction request message, and the second verification parameter locally generated, and obtains the second key for mutual authentication and authorization authentication with the remote user terminal.

[0139] Step 706, send a command message to the remote user terminal.

[0140] Wherein, the command message includes a second verification parameter for generating a second key.

[0141] In the embodiment of the present application, the relay user terminal writes the second verification parameter into the command message to generate the command message, and sends the command message to the remote user terminal.

[0142] Optionally, if the link reconstruction request message includes the RSC associated with the PC5 link, the relay user terminal uses the first key sequence number of the first key to assist in retrieving the locally stored PC5 link security context. Specifically, the relay user terminal retrieves the corresponding first key in the locally stored PC5 security context according to the first key sequence number in the link reconstruction request message. If there is no valid first key corresponding to the first key sequence number in the link reconstruction request message in the locally stored PC5 security context, or it is retrieved that the first key in the locally stored PC5 security context has no association with the RSC associated with the PC5 link in the link reconstruction request message, it is determined that the validity of the PC5 security context in the link request message is abnormal. Furthermore, the relay user terminal sends a reconstruction rejection message to the remote user terminal, terminates the reconstruction of the PC5 link, and indicates the reason for terminating the reconstruction of the PC5 link.

[0143] Optionally, the link reconstruction request message may further include the relay user terminal identifier. The relay user terminal can perform the validity verification of the PC5 security context based on the same principle of using the RSC to verify the validity of the PC5 security context, according to the locally stored relay user terminal identifier and the relay user terminal identifier included in the link reconstruction request message.

[0144] For the above sidelink reconstruction method, the link reconstruction request message includes the first verification parameter within the validity period of the PC5 link security context. According to the first verification parameter within the validity period of the PC5 link security context, it is possible to avoid performing the complete security process in the PC5 link. By receiving the first verification parameter sent by the remote user terminal and the second verification parameter generated by the relay user terminal, the relay user terminal can determine the second key for mutual authentication and authorization authentication, reducing the signaling process and delay impact of re - establishing the same PC5 link, improving the efficiency of determining the second key, and thus improving the performance of reconstructing the PC5 link.

[0145] In one embodiment, as Figure 8 shown, after step 706 determines the second key according to the reserved first key, the first verification parameter, and the second verification parameter, the method further includes:

[0146] Step 802, receive a completion message sent by the remote user terminal.

[0147] Among them, the completion message includes the highest four significant bits for generating a new first key sequence number.

[0148] In an embodiment of the present application, the relay user terminal receives a completion message sent by the remote user terminal, and the completion message contains the highest four significant bits of the first key sequence number.

[0149] Step 804, perform integrity verification on the completion message based on the second key to obtain an integrity verification result. If the integrity verification result is successful, send a reconstruction success message to the remote user terminal.

[0150] Among them, the reconstruction success message includes the lowest four significant bits for generating a new first key sequence number.

[0151] In an embodiment of the present application, the relay user terminal can perform integrity verification on the completion message through the second key in the same way as performing integrity verification on the command message through the second key in step 602. The process of integrity verification in this embodiment will not be elaborated here. When the integrity verification result of the completion message is successful, the relay user terminal generates the lowest four significant bits of the first key sequence number, generates a reconstruction success message according to the lowest four significant bits of the first key sequence number, and sends the reconstruction success message including the lowest four significant bits of the first key sequence number to the remote user terminal. If the integrity verification result of the completion message is failed, the relay user terminal terminates the reconstruction of the PC5 link.

[0152] Step 806, generate a new first key sequence number according to the lowest four significant bits for generating a new first key sequence number and the highest four significant bits for generating a new first key sequence number in the completion message.

[0153] Among them, the new first key sequence number is used for sidelink privacy protection.

[0154] In an embodiment of the present application, the relay user terminal generates a new first key sequence number according to the highest four significant bits of the first key sequence number in the completion message sent by the remote user terminal and the lowest four significant bits of the first key sequence number locally generated by the relay user terminal, and refreshes the new first key sequence number as the local first key sequence number to complete the update of the local first key sequence number.

[0155] In this embodiment, the relay user terminal receives the completion message sent by the remote user terminal. The new first key sequence number generated according to the lowest four significant bits and the highest four significant bits of the first key sequence number can be used for subsequent security authentication and authorization verification, which can ensure the security and credibility of communication, and further improve the security of the PC5 link.

[0156] In one embodiment, Figure 9 a signaling interaction flowchart for sidelink reconstruction is provided. As Figure 9 shown, the method includes the following steps:

[0157] Step 901, the remote user terminal sends a link reconstruction request message to the relay user terminal;

[0158] Step 902, the relay user terminal directly connects and refuses to reconstruct, and indicates the reason to the remote user terminal;

[0159] Step 903, the relay user terminal sends a command message to the remote user terminal;

[0160] Step 904, the remote user terminal sends a completion message to the relay user terminal;

[0161] Step 905, the relay user terminal sends a reconstruction success message to the remote user terminal.

[0162] It should be understood that although Figure 9 the steps in the flowchart are shown in sequence according to the indication of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, the execution of these steps has no strict order restriction, and these steps can be executed in other orders. Moreover, Figure 9 at least a part of the steps in

[0163] In one embodiment, as Figure 10 shown, a sidelink reconstruction apparatus 1000 is provided, including: a first sending module 1001, a first receiving module 1002, and a first determining module 1003, where:

[0164] The first sending module 1001 is configured to send a link reconstruction request message to the relay user terminal; the link reconstruction request message includes a first verification parameter for generating a second key;

[0165] The first receiving module 1002 is configured to receive a command message sent by the relay user terminal; the command message includes a second verification parameter for generating a second key;

[0166] The first determining module 1003 is configured to determine a second key according to the reserved first key, the first verification parameter, and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal.

[0167] In one embodiment, the first verification parameter included in the link reconstruction request message includes a first key sequence number, a first random number for generating a second key, and the highest four significant bits of a second key sequence number.

[0168] In one embodiment, the second verification parameter included in the command message includes a second random number for generating a second key and the lowest four significant bits of a second key sequence number.

[0169] In one embodiment, the link reconstruction request message further includes at least one of a relay service code RSC and a relay user terminal identifier; at least one of the RSC and the relay user terminal identifier is used to determine the PC5 link security context.

[0170] In one embodiment, the apparatus 1000 further includes:

[0171] A first generation module, configured to verify the validity of the PC5 link security context, and if the verification passes, generate a link reconstruction request message;

[0172] A protection module, configured to protect the link reconstruction request message according to a discovery key associated with the RSC, and perform the step of sending the link reconstruction request message to a relay user terminal.

[0173] In one embodiment, the apparatus 1000 further includes:

[0174] A verification module, configured to perform integrity verification on the command message based on a second key to obtain an integrity verification result, and if the integrity verification result is successful, send a completion message to the relay user terminal; the completion message includes the highest four significant bits for generating a new first key sequence number;

[0175] A second generation module, configured to receive a reconstruction success message sent by the relay user terminal, and generate a new first key sequence number according to the highest four significant bits for generating a new first key sequence number and the lowest four significant bits for generating a new first key sequence number in the reconstruction success message.

[0176] In one embodiment, as Figure 11 shown, a sidelink reconstruction apparatus 1100 is provided, including: a second receiving module 1101, a second determining module 1102, and a second sending module 1103, where:

[0177] The second receiving module 1101 is configured to receive a link reconstruction request message sent by a remote user terminal; the link reconstruction request message includes a first verification parameter for generating a second key;

[0178] A second determination module 1102, configured to determine a second key according to the reserved first key, the first verification parameter, and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal;

[0179] A second sending module 1103, configured to send a command message to the remote user terminal; the command message includes the second verification parameter for generating the second key.

[0180] In one embodiment, the apparatus 1100 further includes:

[0181] A third receiving module, configured to receive a completion message sent by the remote user terminal; the completion message includes the highest four significant bits for generating a new first key sequence number;

[0182] A third sending module, configured to perform integrity verification on the completion message based on the second key to obtain an integrity verification result. If the integrity verification result is successful, send a reconstruction success message to the remote user terminal; the reconstruction success message includes the lowest four significant bits for generating a new first key sequence number;

[0183] A third generation module, configured to generate a new first key sequence number according to the lowest four significant bits for generating the new first key sequence number and the highest four significant bits for generating the new first key sequence number in the completion message.

[0184] For the specific limitations on the sidelink reconstruction apparatus, reference may be made to the limitations on the sidelink reconstruction method in the foregoing text, which will not be elaborated here. Each module in the foregoing sidelink reconstruction apparatus may be implemented in whole or in part by software, hardware, and their combination. The foregoing modules may be embedded in the processor in the computer device in hardware form or independent of the processor, or may be stored in the memory in the computer device in software form, so as to be called by the processor to execute the operations corresponding to the foregoing modules.

[0185] Figure 12 It is a schematic structural diagram of an access network device provided by an embodiment of the present application. The access network device may include a receiver 1201, a memory 1202, a processor 1203, at least one communication bus 1204, and a transmitter 1205. The communication bus 1204 is used to implement communication connections between components. The memory 1202 may include a high-speed RAM memory, and may also include a non-volatile storage NVM, such as at least one disk memory. Various programs may be stored in the memory 1202 to complete various processing functions and implement the method steps of this embodiment.

[0186] In this embodiment, the transmitter 1205 may be a radio frequency processing module or a baseband processing module in the access network device, and the receiver 1201 may also be a radio frequency processing module or a baseband processing module in the access network device. The transmitter 1205 and the receiver 1201 may be integrated together to form a transceiver. Both the transmitter 1205 and the receiver 1201 may be coupled to the processor 1203, and may perform receive or transmit operations under the indication or control of the processor 1203.

[0187] In this embodiment, the transmitter 1205 is configured to send a link reconstruction request message to the relay user terminal; the link reconstruction request message includes a first verification parameter for generating a second key.

[0188] The receiver 1201 is configured to receive a command message sent by the relay user terminal; the command message includes a second verification parameter for generating a second key.

[0189] The processor 1203 is configured to determine a second key according to the reserved first key, the first verification parameter, and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal.

[0190] In one embodiment, the processor 1203 is specifically configured to verify the validity of the PC5 link security context. If the verification passes, generate a link reconstruction request message; protect the link reconstruction request message according to the discovery key associated with the RSC, and send the protected link reconstruction request message to the relay user terminal.

[0191] In one embodiment, the processor 1203 is further configured to perform integrity verification on the command message based on the second key to obtain an integrity verification result. If the integrity verification result is successful, send a completion message to the relay user terminal; the completion message includes the highest four significant bits for generating a new first key sequence number.

[0192] In one embodiment, the receiver 1201 is specifically configured to receive a reconstruction success message sent by the relay user terminal, and generate a new first key sequence number according to the highest four significant bits for generating a new first key sequence number and the lowest four significant bits for generating a new first key sequence number in the reconstruction success message.

[0193] In another embodiment, the receiver 1201 is configured to receive a link reconstruction request message sent by the remote user terminal; the link reconstruction request message includes a first verification parameter for generating a second key.

[0194] The processor 1203 is configured to determine a second key according to the reserved first key, the first verification parameter, and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal.

[0195] A transmitter 1205 for sending a command message to a remote user terminal; the command message includes a second verification parameter for generating a second key.

[0196] In one embodiment, the receiver 1201 is further configured to receive a completion message sent by the remote user terminal; the completion message includes the highest four significant bits for generating a new first key sequence number.

[0197] In one embodiment, the processor 1203 is further configured to perform integrity verification on the completion message based on the second key to obtain an integrity verification result. If the integrity verification result is successful, send a reconstruction success message to the remote user terminal; the reconstruction success message includes the lowest four significant bits for generating a new first key sequence number; generate a new first key sequence number according to the lowest four significant bits for generating a new first key sequence number and the highest four significant bits for generating a new first key sequence number in the completion message.

[0198] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0199] Send a link reconstruction request message to the relay user terminal; the link reconstruction request message includes a first verification parameter for generating a second key;

[0200] Receive a command message sent by the relay user terminal; the command message includes a second verification parameter for generating a second key;

[0201] Determine the second key according to the reserved first key, the first verification parameter, and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal.

[0202] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:

[0203] The first verification parameter included in the link reconstruction request message includes the first key sequence number for generating the second key, the first random number, and the highest four significant bits of the second key sequence number.

[0204] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:

[0205] The second verification parameter included in the command message includes the second random number for generating the second key and the lowest four significant bits of the second key sequence number.

[0206] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:

[0207] The link reconstruction request message further includes at least one of a relay service code (RSC) and a relay user terminal identifier; at least one of the RSC and the relay user terminal identifier is used to determine the PC5 link security context.

[0208] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0209] Verify the validity of the PC5 link security context. If the verification passes, generate a reconstruction request message;

[0210] Protect the link reconstruction request message according to the discovery key associated with the RSC, and perform the step of sending the link reconstruction request message to the relay user terminal.

[0211] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0212] Perform integrity verification on the command message based on a second key to obtain an integrity verification result. If the integrity verification result is successful, send a completion message to the relay user terminal; the completion message includes the highest four significant bits for generating a new first key sequence number;

[0213] Receive the reconstruction success message sent by the relay user terminal, and generate a new first key sequence number according to the highest four significant bits for generating a new first key sequence number and the lowest four significant bits for generating a new first key sequence number in the reconstruction success message.

[0214] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0215] Receive the link reconstruction request message sent by the remote user terminal; the link reconstruction request message includes a first verification parameter for generating a second key;

[0216] Determine the second key according to the reserved first key, the first verification parameter, and a second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal;

[0217] Send a command message to the remote user terminal; the command message includes a second verification parameter for generating a second key.

[0218] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0219] Receive the completion message sent by the remote user terminal; the completion message includes the highest four significant bits for generating a new first key sequence number;

[0220] Perform integrity verification on the completed message based on the second key pair to obtain an integrity verification result. If the integrity verification result is successful, send a reconstruction success message to the remote user terminal; the reconstruction success message includes the lowest four significant bits for generating a new first key sequence number.

[0221] Generate a new first key sequence number based on the lowest four significant bits for generating a new first key sequence number and the highest four significant bits for generating a new first key sequence number in the completed message.

[0222] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.

[0223] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties.

[0224] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include Read-Only Memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0225] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0226] The above-described embodiments only represent several implementation manners of the present application. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A sidelink reconstruction method, characterized in that, applied to a remote user terminal, the method comprises: sending a link reconstruction request message to a relay user terminal; the link reconstruction request message includes a first verification parameter for generating a second key; receiving a command message sent by the relay user terminal; the command message includes a second verification parameter for generating the second key; determining the second key according to the reserved first key, the first verification parameter and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal.

2. The method according to claim 1, characterized in that, the first verification parameter included in the link reconstruction request message includes a first key sequence number, a first random number for generating the second key, and the highest four significant bits of a second key sequence number.

3. The method according to claim 1, characterized in that, the second verification parameter included in the command message includes a second random number for generating the second key and the lowest four significant bits of the second key sequence number.

4. The method according to claim 1, characterized in that, the link reconstruction request message further includes at least one of a relay service code RSC and a relay user terminal identifier; at least one of the RSC and the relay user terminal identifier is used to determine the PC5 link security context.

5. The method according to claim 4, characterized in that, the method further comprises: checking the validity of the PC5 link security context, if the check passes, generating a link reconstruction request message; protecting the link reconstruction request message according to a discovery key associated with the RSC, and performing the step of sending the link reconstruction request message to the relay user terminal.

6. The method according to claim 1, characterized in that, after determining the second key according to the reserved first key, the first verification parameter and the second verification parameter, the method further comprises: performing integrity verification on the command message based on the second key to obtain an integrity verification result, if the integrity verification result is verification success, sending a completion message to the relay user terminal; the completion message includes the highest four significant bits for generating a new first key sequence number; receiving a reconstruction success message sent by the relay user terminal, and generating a new first key sequence number according to the highest four significant bits for generating the new first key sequence number and the lowest four significant bits for generating the new first key sequence number in the reconstruction success message.

7. A sidelink reconstruction method, characterized in that, applied to a relay user terminal, the method comprises: receiving a link reconstruction request message sent by a remote user terminal; the link reconstruction request message includes a first verification parameter for generating a second key; determining the second key according to the reserved first key, the first verification parameter and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal Send a command message to the remote user terminal; the command message includes a second verification parameter for generating the second key.

8. The method according to claim 7, wherein, after determining the second key according to the reserved first key, the first verification parameter, and the second verification parameter, the method further includes: Receiving a completion message sent by the remote user terminal; the completion message includes the highest four significant bits for generating a new first key sequence number; Performing integrity verification on the completion message based on the second key to obtain an integrity verification result. If the integrity verification result is successful, send a reconstruction success message to the remote user terminal; the reconstruction success message includes the lowest four significant bits for generating a new first key sequence number; Generating a new first key sequence number according to the lowest four significant bits for generating the new first key sequence number and the highest four significant bits for generating the new first key sequence number in the completion message.

9. A sidelink reconstruction device, wherein, the device includes: A first sending module, configured to send a link reconstruction request message to the relay user terminal; the link reconstruction request message includes a first verification parameter for generating a second key; A first receiving module, configured to receive a command message sent by the relay user terminal; the command message includes a second verification parameter for generating the second key; A first determining module, configured to determine the second key according to the reserved first key, the first verification parameter, and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal.

10. A sidelink reconstruction device, wherein, the device includes: A second receiving module, configured to receive a link reconstruction request message sent by the remote user terminal; the link reconstruction request message includes a first verification parameter for generating a second key; A second determining module, configured to determine the second key according to the reserved first key, the first verification parameter, and the second verification parameter; the second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal; A second sending module, configured to send a command message to the remote user terminal; the command message includes a second verification parameter for generating the second key.

11. A communication device, wherein, includes: A transmitter, a processor, and a receiver; The transmitter is configured to send a link reconstruction request message to the relay user terminal; the link reconstruction request message includes a first verification parameter for generating a second key; The receiver is configured to receive a command message sent by the relay user terminal; The command message includes a second verification parameter for generating the second key; The processor is configured to determine the second key according to the reserved first key, the first verification parameter, and the second verification parameter; The second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal.

12. A communication device, wherein, includes: Transmitter, processor, and receiver; The receiver is configured to receive a link reconstruction request message sent by a remote user terminal; the link reconstruction request message includes a first verification parameter for generating a second key; The processor is configured to determine the second key according to a reserved first key, the first verification parameter, and the second verification parameter; The second key is used for mutual authentication and authorization verification between the remote user terminal and the relay user terminal; The transmitter is configured to send a command message to the remote user terminal; The command message includes a second verification parameter for generating the second key.

13. A computer-readable storage medium, on which a computer program is stored, characterized in that, when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 or claims 7 to 8 are implemented.

14. A computer program product, comprising a computer program, characterized in that, when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 or claims 7 to 8 are implemented.