Communication method and device, user equipment, base station and storage medium
By encrypting the RRC reestablishment message with the NCC within a MAC CE, the method addresses the security vulnerability of RRC reestablishment messages, ensuring secure key updates for User Equipment (UE) in wireless communication systems.
Patent Information
- Application Number
- CN202410052512.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-12
- Publication Date
- 2025-07-15
AI Technical Summary
During the RRC re-establishment process, the RRC re-establishment message has low security and cannot effectively protect the key update process between the UE and the base station, resulting in the message being easily attacked or tampered during transmission.
The security of the key update process is ensured by using the encrypted MAC CE to carry the NCC and the encrypted RRC re-establishment message during the communication between the UE and the base station. The specific steps include after the UE sends an RRC re-establishment request message, the base station sends a MAC CE containing the NCC and the encrypted byte stream, and after the UE receives it, updates the key and performs decryption and integrity verification.
Improve the security of RRC re-establishment messages, ensure the integrity and encryption of the key update process, prevent messages from being illegally tampered with, and improve the security of wireless communications.
Smart Images

Figure CN120321812A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technologies, and particularly relates to a communication method, apparatus, user equipment, base station, and storage medium. Background Art
[0002] Currently, a user equipment (UE) and a base station update the keys used during a radio resource control (RRC) reestablishment process. Specifically, on the UE side, the UE can receive an RRC reestablishment message sent by the base station. The RRC reestablishment message carries a next hop chaining count (NCC). The UE can update the key used by the UE according to the NCC carried in the RRC reestablishment message. Since the UE needs to use the NCC to update the key, the RRC reestablishment message sent by the base station cannot be encrypted. If encrypted, the UE cannot obtain the NCC and thus cannot update the used key. In this way, the security of the RRC reestablishment message is relatively low. Therefore, how to improve the security of the RRC reestablishment message is an urgent problem to be solved in this application. Summary of the Invention
[0003] Embodiments of this application provide a communication method, apparatus, user equipment, base station, and storage medium, which can improve the security of the RRC reestablishment message.
[0004] In a first aspect, a communication method is provided. The method includes: the UE sends an RRC reestablishment request message to the base station; the medium access control (MAC) layer of the UE receives a first medium access control element (MAC CE) from the base station; wherein the first MAC CE includes an NCC and a first byte stream, and the first byte stream includes an encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0005] In a second aspect, a communication method is provided. The method includes: the base station receives an RRC reestablishment request message from the UE; the MAC layer of the base station sends a first MAC CE to the UE; wherein the first MAC CE includes an NCC and a first byte stream, and the first byte stream includes an encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0006] In a third aspect, a communication method is provided, which includes: the UE sends an RRC reestablishment request message to the base station; the UE receives a first signaling from the base station, the first signaling is used to request the UE to update the key used by the UE, the first signaling includes the NCC, and the first signaling is the second MAC CE or the PDCP control PDU; the RRC layer of the UE updates the key used by the UE based on the NCC, and generates a first encryption key and a first integrity protection key based on the updated key; the RRC layer of the UE instructs the Packet Data Convergence Protocol (PDCP) layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption; after the PDCP layer of the UE restores integrity protection and encryption using the first encryption key and the first integrity protection key, the PDCP layer of the UE processes a second PDCP protocol data unit (PDU) from the base station, and the second PDCP PDU includes an integrity-protected and encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0007] In a fourth aspect, a communication method is provided, which includes: the base station receives an RRC reestablishment request message from the UE; the base station sends a first signaling to the UE, the first signaling is used to request the UE to update the key used by the UE, the first signaling includes the NCC, and the first signaling is the second MAC CE or the PDCP control PDU; the base station sends a second PDCP PDU to the UE, and the second PDCP PDU includes an integrity-protected and encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0008] In a fifth aspect, a communication device is provided, which is applied to the UE and includes: a sending module and a receiving module. The sending module is used to send an RRC reestablishment request message to the base station. The receiving module is used to receive a first MAC CE from the base station; wherein, the first MAC CE includes the NCC and a first byte stream, and the first byte stream includes an encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0009] In a sixth aspect, a communication device is provided, which is applied to the base station and includes: a receiving module and a sending module. The receiving module is used to receive an RRC reestablishment request message from the UE. The sending module is used to send a first MAC CE to the UE; wherein, the first MAC CE includes the NCC and a first byte stream, and the first byte stream includes an encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0010] In a seventh aspect, a communication device is provided, which is applied to a UE and includes a sending module, a receiving module, a processing module, and an indicating module. The sending module is configured to send an RRC reestablishment request message to a base station. The receiving module is configured to receive a first signaling from the base station, where the first signaling is used to request the UE to update the key used by the UE, the first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU. The processing module is configured to update the key used by the UE based on the NCC, and generate a first encryption key and a first integrity protection key based on the updated key. The requesting module is configured to instruct the PDCP layer of the UE to restore integrity protection and encryption using the first encryption key and the first integrity protection key generated by the processing module. The processing module is further configured to, after the PDCP layer of the UE restores integrity protection and encryption using the first encryption key and the first integrity protection key, process a second PDCP PDU from the base station, where the second PDCP PDU includes an RRC reestablishment message that is integrity protected and encrypted, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0011] In an eighth aspect, a communication device is provided, which includes a receiving module and a sending module. The receiving module is configured to receive an RRC reestablishment request message from a UE. The sending module is configured to send a first signaling to the UE, where the first signaling is used to request the UE to update the key used by the UE, the first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU; and send a second PDCP PDU to the UE, where the second PDCP PDU includes an RRC reestablishment message that is integrity protected and encrypted, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0012] In a ninth aspect, a UE is provided, which includes a processor and a memory, where the memory stores a program or instruction that can run on the processor, and when the program or instruction is executed by the processor, the steps of the method described in the first aspect are implemented.
[0013] In a tenth aspect, a UE is provided, which includes a processor and a communication interface. The communication interface is configured to send an RRC reestablishment request message to a base station; and receive a first MAC CE from the base station. The first MAC CE includes an NCC and a first byte stream, and the first byte stream includes an encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0014] In an eleventh aspect, a base station is provided, which includes a processor and a memory, where the memory stores a program or instruction that can run on the processor, and when the program or instruction is executed by the processor, the steps of the method described in the second aspect are implemented.
[0015] In a twelfth aspect, a base station is provided, including a processor and a communication interface. The communication interface is configured to receive an RRC reestablishment request message from a UE; and send a first MAC CE to the UE. The first MAC CE includes an NCC and a first byte stream, and the first byte stream includes an encrypted RRC reestablishment message, where the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0016] In a thirteenth aspect, a UE is provided. The UE includes a processor and a memory. The memory stores a program or instructions that can be run on the processor. When the program or instructions are executed by the processor, the steps of the method described in the third aspect are implemented.
[0017] In a fourteenth aspect, a UE is provided, including a processor and a communication interface. The communication interface is configured to send an RRC reestablishment request message to a base station; and receive a first signaling from the base station. The first signaling is used to request the UE to update the key used by the UE. The first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU. The processor is configured to update the key used by the UE based on the NCC, generate a first encryption key and a first integrity protection key based on the updated key; and instruct the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption. After the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, process a second PDCP PDU from the base station. The second PDCP PDU includes an RRC reestablishment message that is integrity protected and encrypted, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0018] In a fifteenth aspect, a base station is provided. The base station includes a processor and a memory. The memory stores a program or instructions that can be run on the processor. When the program or instructions are executed by the processor, the steps of the method described in the fourth aspect are implemented.
[0019] In a sixteenth aspect, a base station is provided, including a processor and a communication interface. The communication interface is configured to receive an RRC reestablishment request message from a UE; and send a first signaling to the UE. The first signaling is used to request the UE to update the key used by the UE. The first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU. And send a second PDCP PDU to the UE. The second PDCP PDU includes an RRC reestablishment message that is integrity protected and encrypted, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0020] In a seventeenth aspect, a readable storage medium is provided, on which a program or instructions are stored. When the program or instructions are executed by a processor, the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect, or the steps of the method described in the fourth aspect are implemented.
[0021] In an eighteenth aspect, a wireless communication system is provided, including: a UE and a base station. The UE can be used to execute the steps of the method described in the first aspect, or execute the steps of the method described in the third aspect. The base station can be used to execute the steps of the method described in the second aspect, or execute the steps of the method described in the fourth aspect.
[0022] In a nineteenth aspect, a chip is provided. The chip includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run a program or instructions to implement the method described in the first aspect, or implement the method described in the second aspect, or implement the method described in the third aspect, or implement the method described in the fourth aspect.
[0023] In a twentieth aspect, a computer program / program product is provided. The computer program / program product is stored in a storage medium. The program / program product is executed by at least one processor to implement the steps of the communication method described in the first aspect, or implement the steps of the communication method described in the second aspect, or implement the steps of the communication method described in the third aspect, or implement the steps of the communication method described in the fourth aspect.
[0024] In an embodiment of the present application, the UE sends an RRC reestablishment request message to the base station; the Medium Access Control (MAC) layer of the UE receives a first Medium Access Control Element (MAC CE) from the base station; wherein, the first MAC CE includes an NCC and a first byte stream, and the first byte stream includes an encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection. In this solution, since after the UE sends an RRC reestablishment request message to the base station, the base station can send a first MAC CE including an NCC and a first byte stream to the UE, and the first byte stream includes an encrypted RRC reestablishment message, that is, the base station can carry the NCC outside the encrypted RRC reestablishment message. Therefore, while the UE obtains the NCC update key, the security of the RRC reestablishment message is also improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 is a schematic diagram of the architecture of a wireless communication system provided by an embodiment of the present application;
[0026] Figure 2 It is one of the schematic flowcharts of a communication method provided by an embodiment of the present application;
[0027] Figure 3 It is the second of the schematic flowcharts of a communication method provided by an embodiment of the present application;
[0028] Figure 4 It is one of the schematic structural diagrams of a first MAC CE provided by an embodiment of the present application;
[0029] Figure 5 It is the schematic structural diagram of a first PDCP PDU provided by an embodiment of the present application;
[0030] Figure 6 It is the second of the schematic structural diagrams of a first MAC CE provided by an embodiment of the present application;
[0031] Figure 7 It is the third of the schematic flowcharts of a communication method provided by an embodiment of the present application;
[0032] Figure 8 It is one of the schematic structural diagrams of a communication device provided by an embodiment of the present application;
[0033] Figure 9 It is the second of the schematic structural diagrams of a communication device provided by an embodiment of the present application;
[0034] Figure 10 It is the fourth of the schematic flowcharts of a communication method provided by an embodiment of the present application;
[0035] Figure 11 It is the fifth of the schematic flowcharts of a communication method provided by an embodiment of the present application;
[0036] Figure 12 It is the schematic structural diagram of a PDCP control PDU provided by an embodiment of the present application;
[0037] Figure 13 It is the sixth of the schematic flowcharts of a communication method provided by an embodiment of the present application;
[0038] Figure 14 It is the seventh of the schematic flowcharts of a communication method provided by an embodiment of the present application;
[0039] Figure 15 It is the third of the schematic structural diagrams of a communication device provided by an embodiment of the present application;
[0040] Figure 16 It is the fourth of the schematic structural diagrams of a communication device provided by an embodiment of the present application;
[0041] Figure 17It is a schematic diagram of the hardware structure of a communication device provided by an embodiment of the present application;
[0042] Figure 18 It is a schematic diagram of the hardware structure of a UE provided by an embodiment of the present application;
[0043] Figure 19 It is a schematic diagram of the hardware structure of a base station provided by an embodiment of the present application. Detailed implementation manners
[0044] Next, the technical solutions in the embodiments of the present application will be clearly described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art belong to the scope protected by the present application.
[0045] The terms "first", "second", etc. in the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are usually of the same category, and the number of objects is not limited. For example, the first object can be one or multiple. In addition, the "or" in the present application means at least one of the connected objects. For example, "A or B" covers three scenarios, namely, Scenario 1: including A and not including B; Scenario 2: including B and not including A; Scenario 3: including both A and B. The character " / " generally indicates that the associated objects before and after are in an "or" relationship.
[0046] The term "indicate" in the present application can be either a direct indication (or an explicit indication) or an indirect indication (or an implicit indication). Among them, a direct indication can be understood as that the sender clearly informs the receiver of specific information, operations to be performed, or request results, etc. in the sent indication; an indirect indication can be understood as that the receiver determines the corresponding information according to the indication sent by the sender, or makes a judgment and determines the operations to be performed or request results, etc. according to the judgment result.
[0047] The terms "at least one (item)", "at least one of", etc. in the present application refer to any one, any two, or a combination of two or more of the included objects. For example, at least one (item) of a, b, and c can represent: "a", "b", "c", "a and b", "a and c", "b and c", and "a, b, and c", where a, b, and c can be single or multiple. Similarly, "at least two (items)" refers to two or more, and its meaning is similar to that of "at least one (item)".
[0048] It should be noted that the technology described in the embodiments of this application is not limited to the Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, and can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), or other systems. The terms "system" and "network" in the embodiments of this application are often used interchangeably, and the described technology can be used in the systems and radio technologies mentioned above, as well as in other systems and radio technologies. The following description describes the New Radio (NR) system for example purposes, and the NR terminology is used in most of the following descriptions, but these technologies can also be applied to systems other than the NR system, such as the 6th Generation (6G) communication system. th Generation, 6G) communication system.
[0049] Figure 1A block diagram of a wireless communication system to which embodiments of the present application can be applied is shown. The wireless communication system includes a terminal 11 and a network-side device 12. Among them, the terminal 11 can be a UE, a mobile phone, a tablet personal computer, a laptop computer, a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), an augmented reality (AR), a virtual reality (VR) device, a robot, a wearable device, a flight vehicle, a vehicle user equipment (VUE), a shipborne device, a pedestrian user equipment (PUE), a smart home (home appliances with wireless communication functions, such as refrigerators, TVs, washing machines, or furniture, etc.), a game console, a personal computer (PC), a teller machine, or a self-service machine, etc. Wearable devices include: smart watches, smart bracelets, smart earphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart ankle chains, etc.), smart wristbands, smart clothing, etc. Among them, the vehicle user equipment can also be referred to as a vehicle terminal, a vehicle controller, a vehicle module, a vehicle component, a vehicle chip, or a vehicle unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiments of the present application. The network-side device 12 can include an access network device or a core network device. Among them, the access network device can also be referred to as a radio access network (RAN) device, a radio access network function, or a radio access network unit. The access network device can include a base station, a wireless local area network (WLAN) access point (AP), or a wireless fidelity (WiFi) node, etc.Among them, the base station can be referred to as Node B (NB), Evolved Node B (eNB), the next generation Node B (gNB), New Radio Node B (NR Node B), access point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), home Node B (HNB), home evolved Node B, Transmission Reception Point (TRP), or some other suitable term in the art. As long as the same technical effect is achieved, the base station is not limited to specific technical terms. It should be noted that in the embodiments of this application, only the base station in the NR system is taken as an example for introduction, and the specific type of the base station is not limited.
[0050] Some concepts and / or terms involved in the communication method provided in the embodiments of this application are explained below.
[0051] 1. RRC Reestablishment: When the UE is in the RRC connected state, but the UE experiences a radio link failure, or an integrity check failure, etc., the UE can perform a cell selection process to select a target cell and initiate the RRC reestablishment process, and send an RRC Reestablishment Request to the base station where the target cell is located through SRB0.
[0052] 2. Radio interface control plane protocol stack: The radio interface control plane protocol stack from top to bottom is: RRC layer, PDCP layer, RLC layer, MAC layer, and PHY layer.
[0053] 3. The PDUs of the PDCP layer are divided into two types: Data PDUs and Control PDUs. Among them, Data PDUs are used to transmit data of the user plane and the control plane, as well as the digital signature MAC-I generated by integrity protection. Control PDUs are generated by the PDCP layer itself and are used to transmit, for example, the status reports of the PDCP layer and the decompression feedback messages generated by the compression / decompression module. The data packets received by the PDCP layer from the upper layer are called PDCP service data units (SDUs). After being processed by the PDCP layer, PDCP Data PDUs are generated and then delivered to the next layer for processing.
[0054] The following will, in conjunction with the accompanying drawings, elaborate on the communication method provided by the embodiments of the present application through some embodiments and their application scenarios.
[0055] Currently, the UE and the base station will update the keys used during the RRC reestablishment process. Specifically, on the UE side, the UE can receive the RRC reestablishment message sent by the base station. The NCC is carried in this RRC reestablishment message, and the UE can update the key used by the UE according to the NCC carried in this RRC reestablishment message. Since the UE needs to use the NCC to update the key, the RRC reestablishment message sent by the base station cannot be encrypted. If it is encrypted, the UE cannot obtain the NCC and thus cannot update the key used. Specifically, on the base station side, if the NCC corresponding to the current key is the same as the NCC saved in the UE context of this UE, the update is performed based on the current key. Otherwise, the key is updated based on the next hop (NH) corresponding to the NCC saved in the UE context of this UE, and the encryption key and integrity protection key are generated based on the updated key, and the PDCP layer is configured to use the new integrity protection key to restore integrity protection. The NCC saved in the UE context and its corresponding NH may be sent by the core network to the base station during the previous handover process. The RRC layer generates the RRC message RRC Reestablishment. The NCC is carried in the RRC Reestablishment message and is delivered to the PDCP entity corresponding to SRB1 as a PDCP SDU. The PDCP entity performs integrity protection using the new integrity protection key but does not perform encryption operations, and then generates a PDCP PDU, and delivers the generated PDCP PDU to the Radio Link Control (RLC) layer to be sent to the UE. It can be seen that the RRC Reestablishment message is integrity protected but not encrypted. Further, the base station configures the PDCP layer to restore encryption using the new encryption key. On the UE side, after receiving the RRC Reestablishment message, the UE updates the key according to the NCC carried in this message, generates a new encryption key and integrity protection key, and then requests the PDCP layer to verify this message based on this new integrity protection key. If the verification is successful, the PDCP layer is configured to use the new integrity protection key and encryption key to restore integrity protection and encryption. Thus, it can be seen that since the UE needs to use the NCC to update the key, the RRC Reestablishment message can only be integrity protected and cannot be encrypted. Otherwise, the UE cannot decrypt the RRC Reestablishment and cannot obtain the NCC, further resulting in the inability to update the key. In this way, the security of the RRC reestablishment message is relatively low. Therefore, how to improve the security of the RRC reestablishment message is an urgent problem to be solved in this application.
[0056] In an embodiment of the present application, after the UE sends an RRC reestablishment request message to the base station, the base station may send a first MAC CE including an NCC and a first byte stream to the UE. The first byte stream includes the encrypted RRC reestablishment message, that is, the base station may carry the NCC outside the encrypted RRC reestablishment message. Therefore, while the UE obtains the NCC update key, the security of the RRC reestablishment message is also improved.
[0057] An embodiment of the present application provides a communication method. Figure 2 The flowchart of a communication method provided by an embodiment of the present application is shown. As Figure 2 shown, the communication method provided by the embodiment of the present application may include the following steps 201 and 202.
[0058] Step 201: The UE sends an RRC reestablishment request message to the base station.
[0059] In some embodiments of the present application, when the UE is in the RRC connected state, but the RRC connection needs to be reestablished. For example, when a radio link failure or an integrity check failure occurs to the connected UE, the UE may perform a cell selection process to select a target cell to initiate an RRC reestablishment process, and send an RRCReestablishment Request, that is, an RRC reestablishment request message, to the base station where the target cell is located through SRB0.
[0060] Step 202: The MAC layer of the UE receives a first MAC CE from the base station.
[0061] In an embodiment of the present application, the above first MAC CE includes an NCC and a first byte stream. The first byte stream includes the encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0062] In some embodiments of the present application, the NCC is used to instruct the UE how to update the key used by the UE. Specifically, reference can be made to Figure 6 .9.2.1.1-1 in 3GPP TS33.501 protocol for description: If the NCC corresponding to the current key (i.e., a certain KgNB in the figure) is the same as the received NCC, a new key is generated based on the current key, that is, the horizontal derivation in the figure; if the NCC corresponding to the current key is different from the received NCC, a new key is generated based on the NH corresponding to the received NCC, that is, the vertical derivation in the figure. Further, the UE generates a first encryption key and a first integrity protection key based on the updated key.
[0063] In some embodiments of the present application, the UE may use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0064] It can be understood that after the base station receives the RRC reestablishment request sent by the UE, the base station can send a first MAC CE to the UE, so that the UE can update the key used by the UE based on the NCC in the first MAC CE, generate a first encryption key and a first integrity protection key based on the updated key, and reestablish the RRC connection based on the first byte stream in the first MAC CE.
[0065] An embodiment of the present application provides a communication method. Since after the UE sends an RRC reestablishment request message to the base station, the base station can send a first MAC CE including an NCC and a first byte stream to the UE, and the first byte stream includes an encrypted RRC reestablishment message, that is, the base station can carry the NCC outside the encrypted RRC reestablishment message. Therefore, while the UE obtains the NCC update key, the security of the RRC reestablishment message is also improved.
[0066] In some embodiments of the present application, after the above step 202, the communication method provided by the embodiment of the present application further includes the following steps 203 to 207.
[0067] Step 203: The MAC layer of the UE parses the first MAC CE to obtain the NCC and the first byte stream.
[0068] Step 204: The MAC layer of the UE passes the NCC and the first byte stream to the RRC layer of the UE.
[0069] It can be understood that after the MAC layer of the UE receives the first MAC CE, it can parse the first MAC CE to obtain the NCC and the first byte stream, and pass the NCC and the first byte stream to the RRC layer of the UE through inter-layer interaction.
[0070] In some embodiments of the present application, if the first MAC CE also carries a first information or other message integrity authentication code MAC-I, the MAC layer of the UE can pass it to the RRC layer of the UE together.
[0071] Step 205: The RRC layer of the UE updates the key used by the UE based on the NCC, and generates a first encryption key and a first integrity protection key based on the updated key.
[0072] In some embodiments of the present application, when the NCC corresponding to the current key is the same as the NCC in the first MAC CE, the RRC layer of the UE can update the key used by the UE based on the current key, otherwise it can update the key used by the UE based on the NH corresponding to the NCC in the first MAC CE.
[0073] Step 206, the RRC layer of the UE requests the PDCP layer of the UE to process the first byte stream based on the first encryption key and the first integrity protection key.
[0074] Step 207, the PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key.
[0075] In some embodiments of the present application, after the above step 207, the communication method provided by the embodiments of the present application further includes the following step 301 or step 302.
[0076] Step 301, when the integrity protection verification operation executed by the PDCP layer of the UE fails, the UE enters the idle state.
[0077] Step 302, when the integrity protection verification operation executed by the PDCP layer of the UE passes, the PDCP layer of the UE passes the decrypted RRC reestablishment message to the RRC layer of the UE.
[0078] In some embodiments of the present application, after the above step 302, the communication method provided by the embodiments of the present application further includes the following step 303 and step 304.
[0079] Step 303, the RRC layer of the UE reestablishes the RRC connection based on the decrypted RRC reestablishment message.
[0080] It can be understood that the RRC layer of the UE can process the decrypted RRC reestablishment message and reestablish the RRC connection according to the RRC reestablishment message.
[0081] In some embodiments of the present application, the above step 303 can be specifically implemented by the following step 303a.
[0082] Step 303a, when the NCC in the first MAC CE is the same as the NCC in the RRC reestablishment message, the RRC layer of the UE reestablishes the RRC connection according to the decrypted RRC reestablishment message.
[0083] In some embodiments of the present application, when the RRC reestablishment message includes the NCC, the RRC layer of the UE can further verify whether the NCC in the first MAC CE is the same as the NCC in the RRC reestablishment message. If they are different, the verification fails and the UE enters the idle state; if they are the same, the RRC layer of the UE reestablishes the RRC connection according to the decrypted RRC reestablishment message.
[0084] In this way, since the above RRC reestablishment message includes the NCC, it is possible to verify whether the NCC included in the first MAC CE is consistent with the NCC included in the RRC reestablishment message based on the NCC, thereby improving security.
[0085] Step 304: The UE sends an RRC reestablishment complete message to the base station.
[0086] In the embodiments of the present application, the above RRC reestablishment complete message is a message processed by the PDCP layer of the UE through the first encryption key and the first integrity protection key.
[0087] It can be understood that the UE can send an RRC Reestablishment Complete, that is, an RRC reestablishment complete message, which is encrypted and integrity protected and transmitted on SRB1.
[0088] In some embodiments of the present application, the above first byte stream corresponds to a first PDCP PDU, and the first PDCP PDU includes an encrypted first MAC-I, and the encrypted first MAC-I is generated by the PDCP layer of the base station by performing an integrity protection operation on the RRC reestablishment message; the above step 207 can be specifically implemented by the following steps 207a to 207c.
[0089] Step 207a: The PDCP layer of the UE parses the first PDCP PDU to obtain the encrypted RRC reestablishment message and the encrypted first MAC-I.
[0090] Step 207b: The PDCP layer of the UE performs a decryption operation on the encrypted RRC reestablishment message and the encrypted first MAC-I through the first encryption key to obtain the decrypted RRC reestablishment message and the decrypted first MAC-I.
[0091] Step 207c: The PDCP layer of the UE performs an integrity protection verification operation on the decrypted RRC reestablishment message through the first integrity protection key and the decrypted first MAC-I.
[0092] In some embodiments of the present application, when the integrity protection verification operation performed by the PDCP layer of the UE fails, the UE can enter the idle state.
[0093] In some embodiments of the present application, when the integrity protection verification operation performed by the PDCP layer of the UE passes, the PDCP layer of the UE can deliver the decrypted RRC reestablishment message to the RRC layer of the UE, and the RRC layer of the UE configures the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0094] Specifically, the PDCP layer of the UE can parse the first PDCP PDU, obtain "PDCP SN", "Data", and "MAC-I", decrypt the two cells of "Data" and "MAC-I" using the first encryption key, and then use the first integrity protection key and the decrypted "MAC-I" to perform integrity protection verification on the decrypted "Data" cell. If the verification fails, the UE can enter the idle state and the process ends; if the verification passes, the PDCP layer of the UE can return the decrypted "Data" to the RRC layer. Among them, "Data" corresponds to the encrypted RRC reestablishment message, and "MAC-I" corresponds to the encrypted first MAC-I.
[0095] In some embodiments of the present application, the parameters used by the PDCP layer of the UE to perform the decryption operation and the integrity protection verification operation are the first parameter or the first parameter set.
[0096] In some embodiments of the present application, the above-mentioned first parameter or first parameter set includes at least one of the following: the COUNT value is 0, the BEARER is the bearer identifier of the radio signaling bearer SRB1, and the DIRECTION is the downlink direction.
[0097] In some embodiments of the present application, the value of the above-mentioned downlink direction is 1.
[0098] In some embodiments of the present application, the communication method provided by the embodiments of the present application may further include the following step 208.
[0099] Step 208: The PDCP layer of the UE sets the first variable maintained by the PDCP entity corresponding to SRB1 to 1 or increments it by 1.
[0100] In the embodiments of the present application, the above-mentioned first variable is a variable corresponding to the COUNT value of the next expected received PDCP SDU.
[0101] In some embodiments of the present application, the above-mentioned first variable can be understood as the RX_NEXT variable.
[0102] It can be understood that the PDCP entity of the UE's SRB1 considers that it has successfully received a PDCP SDU with a COUNT value of 0. The RRC layer of the UE configures the PDCP layer of the UE to restore integrity protection and encryption using the first encryption key and the first integrity protection key.
[0103] In some embodiments of the present application, the parameters used by the PDCP layer of the UE to perform the decryption operation and the integrity protection verification operation are the second parameter or the second parameter set.
[0104] In some embodiments of the present application, the above second parameter or second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
[0105] It should be noted that the parameters used by the UE to perform the integrity protection verification operation and the decryption operation are the same as the parameters used by the base station to perform the integrity protection operation and the encryption operation.
[0106] In some embodiments of the present application, the above first MAC CE includes first information, and the first information is MAC-I generated by performing an integrity protection operation on the RRC re-establishment message; the above step 207 can be specifically implemented by the following step 207d and step 207e.
[0107] Step 207d: The PDCP layer of the UE performs a decryption operation on the first byte stream through the first encryption key to obtain the decrypted RRC re-establishment message.
[0108] Step 207e: The PDCP layer of the UE performs an integrity protection verification operation on the decrypted RRC re-establishment message through the first integrity protection key and the first information.
[0109] In some embodiments of the present application, when the integrity protection verification operation performed by the PDCP layer of the UE fails, the UE can enter the idle state.
[0110] In some embodiments of the present application, when the integrity protection verification operation performed by the PDCP layer of the UE passes, the PDCP layer of the UE can pass the decrypted RRC re-establishment message to the RRC layer of the UE and configure the PDCP layer to restore integrity protection and encryption using the first encryption key and the first integrity protection key.
[0111] In some embodiments of the present application, the above first MAC CE includes second information, and the second information is MAC-I generated by performing an integrity protection operation on the NCC and the first byte stream; the above step 207 can be specifically implemented by the following step 207f and step 207g.
[0112] Step 207f: The PDCP layer of the UE performs an integrity protection verification operation on the NCC and the first byte stream through the first integrity protection key and the second information.
[0113] Step 207g: When the integrity protection verification operation performed by the PDCP layer of the UE on the NCC and the first byte stream passes, the PDCP layer of the UE performs a decryption operation on the first byte stream through the first encryption key to obtain the decrypted RRC re-establishment message.
[0114] In some embodiments of the present application, when the integrity protection verification operation performed by the PDCP layer of the UE fails, the UE may enter the idle state.
[0115] In some embodiments of the present application, when the integrity protection verification operation performed by the PDCP layer of the UE passes, the PDCP layer of the UE may deliver the decrypted RRC reestablishment message to the RRC layer of the UE, and configure the PDCP layer to restore integrity protection and encryption using the first encryption key and the first integrity protection key.
[0116] It should be noted that the parameters used by the PDCP layer of the UE in the present application embodiments to perform the decryption operation and the integrity protection verification operation are any one of the following: the first parameter, the first parameter set, the second parameter, and the second parameter set, which are not elaborated in the present application embodiments. Moreover, the parameters used by the UE to perform the integrity protection verification operation and the decryption operation are the same as the parameters used by the base station to perform the integrity protection operation and the encryption operation.
[0117] Embodiments of the present application provide a communication method. Figure 3 The flowchart of a communication method provided by an embodiment of the present application is shown. As Figure 3 shown, the communication method provided by the embodiments of the present application may include the following steps 401 and 402.
[0118] Step 401: The base station receives an RRC reestablishment request message from the UE.
[0119] Step 402: The MAC layer of the base station sends a first MAC CE to the UE.
[0120] In the embodiments of the present application, the above first MAC CE includes an NCC and a first byte stream, and the first byte stream includes an encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0121] In some embodiments of the present application, the above first MAC CE is used to send the NCC and the encrypted RRC reestablishment message to the UE.
[0122] It can be understood that after receiving the RRC reestablishment request sent by the UE, the base station may send a first MAC CE to the UE, so that the UE can update the key used by the UE based on the NCC in the first MAC CE, generate a first encryption key and a first integrity protection key based on the updated key, and reestablish an RRC connection based on the first byte stream in the first MAC CE.
[0123] In some embodiments of the present application, the above-mentioned first MAC CE corresponds to a dedicated logical channel identification (LCID), that is, an LCID is assigned to the first MAC CE. So that after the UE receives the MAC PDU containing the first MAC CE, it can know that it is the first MAC CE through the LCID in the MAC subheader of the MAC PDU.
[0124] An embodiment of the present application provides a communication method. Since after the base station receives the RRC reestablishment request message sent by the UE, it can send the first MAC CE including the NCC and the first byte stream to the UE, and the first byte stream includes the encrypted RRC reestablishment message, that is, the base station can send the NCC to the UE separately without carrying it in the RRC reestablishment message. Therefore, while the UE obtains the NCC update key, the security of the RRC reestablishment message is also improved.
[0125] In some embodiments of the present application, after the above step 401, the communication method provided by the embodiments of the present application further includes the following steps 403 to 405.
[0126] Step 403: The RRC layer of the base station updates the key used by the base station, and generates a first encryption key and a first integrity protection key based on the updated key.
[0127] In some embodiments of the present application, after the RRC layer of the base station receives the RRC reestablishment request message, it can obtain the NCC saved in the UE context of the UE, and update the key used by the base station based on the NCC.
[0128] Step 404: The RRC layer of the base station instructs the PDCP layer of the base station to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0129] Step 405: The RRC layer of the base station generates an RRC reestablishment message, and requests the PDCP layer of the base station to perform security protection on the RRC reestablishment message.
[0130] It can be understood that after the PDCP layer of the base station uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, the RRC layer of the base station can generate an RRC reestablishment message, and request the PDCP layer of the base station to perform security protection on the RRC reestablishment message.
[0131] In some embodiments of the present application, after the above step 405, the communication method provided by the embodiments of the present application further includes the following steps 406 to 408.
[0132] Step 406: The PDCP layer of the base station performs security protection on the RRC re-establishment message, generates a first byte stream, and transfers the first byte stream to the RRC layer of the base station.
[0133] In the embodiments of the present application, the above first byte stream includes the RRC re-establishment message after security protection, and the security protection includes at least one of the following: encryption operation, integrity protection operation.
[0134] Step 407: The RRC layer of the base station transfers the first byte stream and the NCC saved in the UE context of the UE to the MAC layer of the base station.
[0135] Step 408: The MAC layer of the base station generates a first MAC CE based on the NCC and the first byte stream.
[0136] In some embodiments of the present application, the above first MAC CE is used to instruct the UE to re-establish an RRC connection, or to send the NCC and the RRC re-establishment message after security protection to the UE.
[0137] It can be understood that after the MAC layer of the base station generates the first MAC CE based on the NCC and the first byte stream, the MAC layer of the base station can send the first MAC CE including the NCC and the first byte stream to the UE.
[0138] Exemplarily, as Figure 4 shown, is a schematic structural diagram of a first MAC CE provided by an embodiment of the present application. The first MAC CE includes R, NCC, and a first byte stream, where R is reserved bits.
[0139] In some embodiments of the present application, the "the PDCP layer of the base station performs security protection on the RRC re-establishment message, generates a first byte stream" in the above step 406 can be specifically implemented by the following step 406a and step 406b.
[0140] Step 406a: The PDCP layer of the base station performs an integrity protection operation on the RRC re-establishment message through a first integrity protection key, and generates a first MAC-I.
[0141] Step 406b: The PDCP layer of the base station performs an encryption operation on the RRC re-establishment message and the first MAC-I through a first encryption key, and generates a first PDCP PDU.
[0142] In the embodiments of the present application, the above first PDCP PDU corresponds to the first byte stream, and the first PDCP PDU includes the encrypted RRC re-establishment message and the first MAC-I.
[0143] In some embodiments of the present application, the above-mentioned first PDCP PDU can be understood as a first byte stream, that is, the first PDCP PDU is the first byte stream.
[0144] It can be understood that in this embodiment, the PDCP layer of the base station performs security protection on the RRC re-establishment message, and the security protection includes an encryption operation and an integrity protection operation.
[0145] Exemplarily, as Figure 5 shown, it is a schematic structural diagram of a first PDCP PDU provided by an embodiment of the present application. The "PDCP SN" cell of the above-mentioned first PDCP PDU is 0, the "Data" cell corresponds to the encrypted RRC re-establishment message, and the "MAC-I" cell corresponds to the encrypted first MAC-I.
[0146] In this way, since the PDCP layer of the base station generates the first MAC-I and then performs an encryption operation on the first MAC-I through the first encryption key, the security is improved.
[0147] In some embodiments of the present application, the parameters used by the PDCP layer of the base station to perform the encryption operation and the integrity protection operation are the first parameter or the first parameter set.
[0148] In some embodiments of the present application, the above-mentioned first parameter or first parameter set includes at least one of the following: the COUNT value is 0, the BEARER is the bearer identifier of the radio signaling bearer SRB1, and the DIRECTION is the downlink direction.
[0149] In some embodiments of the present application, the value of the above-mentioned downlink direction is 1.
[0150] In some embodiments of the present application, the communication method provided by the embodiments of the present application may further include the following step 409.
[0151] Step 409: The PDCP layer of the base station sets the second variable maintained by the PDCP entity corresponding to SRB1 to 1 or increments it by 1.
[0152] In the embodiments of the present application, the above-mentioned second variable is a variable corresponding to the COUNT value of the next PDCP SDU to be sent.
[0153] In some embodiments of the present application, the above-mentioned second variable can be understood as the TX_NEXT variable.
[0154] It can be understood that the PDCP entity of SRB1 allocates a COUNT value (i.e., the value of 0) for the RRC re-establishment message, performs security protection processing, and instead of delivering it to the RLC layer after processing, it returns to the RRC layer. Moreover, the TX_NEXT variable is set to 1 or incremented by 1, thus avoiding the problem of reduced security caused by subsequent RRC messages sent on SRB1 using the same security protection parameters.
[0155] In some embodiments of the present application, the parameters used by the PDCP layer of the above base station to perform the encryption operation and the integrity protection operation are the second parameter or the second parameter set.
[0156] In some embodiments of the present application, the above second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
[0157] In some embodiments of the present application, the above step 406 can be specifically implemented by the following steps 406c to 406e.
[0158] Step 406c: The PDCP layer of the base station performs an encryption operation on the RRC re-establishment message through the first encryption key to generate the first byte stream.
[0159] It can be understood that the above first byte stream includes the encrypted RRC re-establishment message.
[0160] Step 406d: The PDCP layer of the base station performs an integrity protection operation on the RRC re-establishment message through the first integrity protection key to generate the first information.
[0161] In the embodiments of the present application, the above first information is the MAC-I generated by performing an integrity protection operation on the RRC re-establishment message.
[0162] It can be understood that in this embodiment, the PDCP layer of the base station performs security protection on the RRC re-establishment message, and this security protection includes an encryption operation and an integrity protection operation.
[0163] In some embodiments of the present application, the MAC-I generated by the PDCP layer of the base station when performing an integrity protection operation on the RRC re-establishment message using the first parameter or the first parameter set is different from the MAC-I generated by the PDCP layer of the base station when performing an integrity protection operation on the RRC re-establishment message using the second parameter or the second parameter set.
[0164] Step 406e: The PDCP layer of the base station transfers the first byte stream and the first information to the RRC layer of the base station.
[0165] In an embodiment of the present application, a first MAC CE generated by the MAC layer of the base station includes a first byte stream, an NCC, and first information, and the first information is passed from the RRC layer of the base station to the MAC layer of the base station.
[0166] It can be understood that after the RRC layer of the base station requests the PDCP layer of the base station to perform security protection on the RRC reestablishment message, and the PDCP layer of the base station performs encryption operations and integrity protection operations on the RRC reestablishment message to generate a first byte stream and first information, the PDCP layer of the base station can return the first byte stream and first information to the RRC layer of the base station. Then, the RRC layer of the base station can pass the first byte stream, NCC, and first information to the MAC layer of the base station, so that the MAC layer of the base station can generate a first MAC CE based on the NCC, first byte stream, and first information.
[0167] In some embodiments of the present application, when the RRC layer of the base station requests the PDCP layer of the base station to perform security protection on the RRC reestablishment message, the PDCP layer of the base station can only perform encryption operations on the RRC reestablishment message.
[0168] In some embodiments of the present application, the PDCP layer of the base station can only pass the first byte stream to the RRC layer of the base station.
[0169] In some embodiments of the present application, before step 407, the communication method provided by the embodiments of the present application further includes the following steps 407a and 407b.
[0170] Step 407a: The RRC layer of the base station requests the PDCP layer of the base station to perform integrity protection operations on the NCC and the first byte stream.
[0171] In some embodiments of the present application, when the RRC layer of the base station requests the PDCP layer of the base station to perform security protection on the RRC reestablishment message, and the RRC layer of the base station only receives the first byte stream returned by the PDCP layer of the base station, that is, when the PDCP layer of the base station does not perform integrity protection operations on the RRC reestablishment message, the RRC layer of the base station can request the PDCP layer of the base station to perform integrity protection operations on the NCC and the first byte stream.
[0172] In some embodiments of the present application, the RRC layer of the base station can pass the NCC and the first byte stream to the PDCP layer of the base station.
[0173] Step 407b: The PDCP layer of the base station performs integrity protection operations on the NCC and the first byte stream through a first integrity protection key to generate a second MAC-I, and passes the second MAC-I to the RRC layer of the base station.
[0174] In an embodiment of the present application, the first MAC CE generated by the MAC layer of the base station includes a first byte stream, an NCC, and a second MAC-I, and the second MAC-I is passed from the RRC layer of the base station to the MAC layer of the base station.
[0175] It can be understood that when the RRC layer of the base station receives the second MAC-I returned by the PDCP layer of the base station, it can pass the first byte stream, the NCC, and the second MAC-I to the MAC layer of the base station, so that the MAC layer of the base station can generate the first MAC CE based on the NCC, the first byte stream, and the second MAC-I.
[0176] In some embodiments of the present application, the second MAC-I may be second information.
[0177] In some embodiments of the present application, the parameters used by the PDCP layer of the base station to perform integrity protection on the NCC and the first byte stream through the first integrity protection key are the same as the parameters used to perform encryption operations on the RRC reestablishment message through the first encryption key.
[0178] In this way, since the RRC layer of the base station can request the PDCP layer of the base station to perform integrity protection operations on the NCC and the first byte stream, generate the second MAC-I, and then pass the first byte stream, the NCC, and the second MAC-I to the MAC layer of the base station when the PDCP layer of the base station does not perform integrity protection operations on the RRC reestablishment message, the MAC layer of the base station generates the first MAC CE, thus improving the flexibility and reliability of the base station to generate the first MAC CE.
[0179] In some embodiments of the present application, before the above step 408, the communication method provided by the embodiments of the present application further includes the following steps 408a and 408b.
[0180] Step 408a: The MAC layer of the base station requests the PDCP layer of the base station to perform integrity protection operations on the NCC and the first byte stream.
[0181] In some embodiments of the present application, when the MAC layer of the base station only receives the first byte stream and the NCC passed by the RRC layer of the base station, that is, when the PDCP layer of the base station does not perform integrity protection operations on the RRC reestablishment message, the MAC layer of the base station can request the PDCP layer of the base station to perform integrity protection operations on the first byte stream and the NCC.
[0182] In some embodiments of the present application, the MAC layer of the base station can pass the NCC and the first byte stream to the PDCP layer of the base station.
[0183] Step 408b: The PDCP layer of the base station performs integrity protection on the NCC and the first byte stream by using the first integrity protection key, generates a third MAC-I, and passes the third MAC-I to the MAC layer of the base station.
[0184] In an embodiment of the present application, the first MAC CE generated by the MAC layer of the above base station includes the first byte stream, the NCC, and the third MAC-I.
[0185] It can be understood that when the MAC layer of the base station receives the third MAC-I returned by the PDCP layer of the base station, the MAC layer of the base station can generate the first MAC CE based on the NCC, the first byte stream, and the third MAC-I.
[0186] In some embodiments of the present application, the above third MAC-I may be the second information.
[0187] In some embodiments of the present application, the parameters used by the PDCP layer of the base station to perform integrity protection on the NCC and the first byte stream by using the first integrity protection key are the same as the parameters used to perform encryption operations on the RRC re-establishment message by using the first encryption key.
[0188] In this way, since the PDCP layer of the base station does not perform integrity protection operations on the RRC re-establishment message, the MAC layer of the base station can request the PDCP layer of the base station to perform integrity protection operations on the NCC and the first byte stream to generate a third MAC-I. Then, the MAC layer of the base station can generate the first MAC CE based on the NCC, the first byte stream, and the third MAC-I returned by the PDCP layer of the base station. Therefore, the flexibility and reliability of the base station to generate the first MAC CE are improved. Moreover, in addition to the first byte stream, the NCC is also subjected to integrity protection, thereby improving security.
[0189] It should be noted that the parameters used by the PDCP layer of the base station in the embodiments of the present application to perform encryption operations and integrity protection operations are any one of the following: the first parameter, the first parameter set, the second parameter, and the second parameter set.
[0190] Exemplarily, as Figure 6 shown, a schematic structural diagram of a first MAC CE provided by an embodiment of the present application is shown. The first MAC CE includes R, NCC, the first byte stream, and MAC-I, where R is reserved bits.
[0191] In some embodiments of the present application, the RRC reestablishment message is no longer transmitted through SRB1 like a conventional RRC message. Instead, the RRC layer of the base station performs security protection on this message through inter-layer interaction with the PDCP layer, and then delivers the security-protected RRC reestablishment message to the MAC layer through inter-layer interaction with the MAC layer and sends it to the UE carried in the MAC CE as a byte stream. The MAC CE also carries the NCC for key update. Correspondingly, the UE first updates the key used by the UE based on the NCC in the MAC CE, and then performs security-related processing on the RRC reestablishment message based on the updated key.
[0192] In some embodiments of the present application, as Figure 7 shown, the communication method provided by the embodiments of the present application may include the following steps A1 to A14.
[0193] A1. The UE is in the connected state and the RRC layer connection needs to be reestablished.
[0194] A2. The UE sends an RRC reestablishment request message to the base station.
[0195] A3. The base station receives the RRC reestablishment request message from the UE.
[0196] A4. The RRC layer of the base station updates the key used by the base station, generates a first encryption key and a first integrity protection key based on the updated key, and instructs the PDCP layer of the base station to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0197] A5. The RRC layer of the base station generates an RRC reestablishment message and requests the PDCP layer of the base station to perform security protection on the RRC reestablishment message.
[0198] A6. The PDCP layer of the base station performs security protection on the RRC reestablishment message, generates a first byte stream, and delivers the first byte stream to the RRC layer of the base station.
[0199] A7. The RRC layer of the base station delivers the first byte stream and the NCC saved in the UE context of the UE to the MAC layer of the base station.
[0200] A8. The MAC layer of the base station generates a first MAC CE based on the NCC and the first byte stream.
[0201] A9. The MAC layer of the base station sends the first MAC CE to the UE.
[0202] A10. The MAC layer of the UE parses the first MAC CE, obtains the NCC and the first byte stream, and delivers the NCC and the first byte stream to the RRC layer of the UE.
[0203] A11. The RRC layer of the UE updates the key used by the UE based on the NCC, generates a first encryption key and a first integrity protection key based on the updated key, and requests the PDCP layer of the UE to process the first byte stream based on the first encryption key and the first integrity protection key.
[0204] A12. The PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key, obtains the decrypted RRC reestablishment message, and delivers the decrypted RRC reestablishment message to the RRC layer of the UE.
[0205] A13. The RRC layer of the UE reestablishes the RRC connection based on the decrypted RRC reestablishment message.
[0206] A14. The UE sends an RRC reestablishment complete message to the base station.
[0207] It should be noted that for the relevant descriptions in the above steps A1 to A14, reference can be made to the descriptions in the above embodiments, and details are not repeated here.
[0208] Each of the above method embodiments, or various possible implementation manners in each method embodiment, can be executed independently, or any two or more of them can be combined with each other. It can be specifically determined according to actual usage requirements, and the embodiments of the present application do not limit this.
[0209] For the communication method provided by the embodiments of the present application, the execution subject may be a communication device. In the embodiments of the present application, taking the communication device executing the communication method as an example, the communication device provided by the embodiments of the present application is described.
[0210] Figure 8 Fig. shows a possible structural schematic diagram of the communication device involved in the embodiments of the present application, which is applied to the UE. As Figure 8 shown, the communication device 40 may include: a sending module 41 and a receiving module 42.
[0211] Among them, the sending module 41 is used to send an RRC reestablishment request message to the base station.
[0212] The receiving module 42 is used to receive a first MAC CE from the base station; wherein, the first MAC CE includes an NCC and a first byte stream, and the first byte stream includes an encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish the RRC connection.
[0213] The embodiments of the present application provide a communication device. Since after the UE sends an RRC reestablishment request message to the base station, the base station can send a first MAC CE including an NCC and a first byte stream to the UE, and the first byte stream includes the encrypted RRC reestablishment message, that is, the base station can carry the NCC outside the encrypted RRC reestablishment message. Therefore, while the UE obtains the NCC update key, the security of the RRC reestablishment message is also improved.
[0214] In a possible implementation manner, the communication device provided by the embodiments of the present application further includes: a parsing module, a transmission module, a processing module, and a request module. The parsing module is configured to parse the first MAC CE to obtain the NCC and the first byte stream after the receiving module 42 receives the first MAC CE from the base station. The transmission module is configured to transmit the NCC and the first byte stream parsed by the parsing module to the RRC layer of the UE. The processing module is configured to update the key used by the UE based on the NCC transmitted by the transmission module, and generate a first encryption key and a first integrity protection key based on the updated key. The request module is configured to request the PDCP layer of the UE to process the first byte stream based on the first encryption key and the first integrity protection key. The processing module is further configured to process the first byte stream based on the first encryption key and the first integrity protection key.
[0215] In a possible implementation manner, the first byte stream corresponds to a first PDCP PDU, and the first PDCP PDU includes an encrypted first MAC-I. The encrypted first MAC-I is generated by the PDCP layer of the base station by performing an integrity protection operation on the RRC reestablishment message. Specifically, the processing module is configured to parse the first PDCP PDU to obtain the encrypted RRC reestablishment message and the encrypted first MAC-I; and perform a decryption operation on the encrypted RRC reestablishment message and the encrypted first MAC-I through the first encryption key to obtain the decrypted RRC reestablishment message and the decrypted first MAC-I; and perform an integrity protection verification operation on the decrypted RRC reestablishment message through the first integrity protection key and the decrypted first MAC-I.
[0216] In a possible implementation manner, the first MAC CE includes a first piece of information, and the first piece of information is a MAC-I generated by performing an integrity protection operation on the RRC reestablishment message. Specifically, the processing module is configured to perform a decryption operation on the first byte stream through the first encryption key to obtain the decrypted RRC reestablishment message; and perform an integrity protection verification operation on the decrypted RRC reestablishment message through the first integrity protection key and the first piece of information.
[0217] In a possible implementation, the first MAC CE includes second information, where the second information is a MAC-I generated by performing an integrity protection operation on the NCC and the first byte stream; the processing module is specifically configured to perform an integrity protection verification operation on the NCC and the first byte stream by using the first integrity protection key and the second information; and when the integrity protection verification operation on the NCC and the first byte stream performed by the PDCP layer of the UE passes, perform a decryption operation on the first byte stream by using the first encryption key to obtain the decrypted RRC reestablishment message.
[0218] In a possible implementation, the parameters used by the PDCP layer of the UE to perform the decryption operation and the integrity protection verification operation are the first parameter or the first parameter set; where the first parameter or the first parameter set includes at least one of the following: the COUNT value is 0, the BEARER is the bearer identifier of the radio signaling bearer SRB1, and the DIRECTION is the downlink direction.
[0219] In a possible implementation, the processing module is further configured to set the first variable maintained by the PDCP entity corresponding to SRB1 to 1 or increment it by 1, where the first variable is the variable corresponding to the COUNT value of the next expected received PDCP service data unit (SDU).
[0220] In a possible implementation, the parameters used by the PDCP layer of the UE to perform the decryption operation and the integrity protection verification operation are the second parameter or the second parameter set; where the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
[0221] In a possible implementation, the processing module is further configured to enter the idle state when the integrity protection verification operation performed by the PDCP layer of the UE fails after processing the first byte stream based on the first encryption key and the first integrity protection key; the transmission module is further configured to, when the integrity protection verification operation performed by the PDCP layer of the UE passes after the processing module processes the first byte stream based on the first encryption key and the first integrity protection key, transmit the decrypted RRC reestablishment message to the RRC layer of the UE.
[0222] In a possible implementation, the processing module is further configured to reestablish the RRC connection based on the decrypted RRC reestablishment message after the transmission module transmits the decrypted RRC reestablishment message to the RRC layer of the UE; the sending module 41 is further configured to send an RRC reestablishment complete message to the base station, where the RRC reestablishment complete message is the message processed by the PDCP layer of the UE through the first encryption key and the first integrity protection key.
[0223] In a possible implementation, the processing module is specifically configured to re - establish an RRC connection according to the decrypted RRC re - establishment message when the NCC in the first MAC CE is the same as the NCC in the RRC re - establishment message.
[0224] The communication device provided in the embodiments of the present application can implement each process implemented by the UE in the above - mentioned method embodiments and achieve the same technical effects. To avoid repetition, details are not described here again.
[0225] Figure 9 Another possible structural schematic diagram of the communication device involved in the embodiments of the present application is shown, which is applied to a base station. As Figure 9 shown, the communication device 50 may include: a receiving module 51 and a transmitting module 52.
[0226] Among them, the receiving module 51 is used to receive an RRC re - establishment request message from the UE.
[0227] The transmitting module 52 is used to send a first MAC CE to the UE; wherein, the first MAC CE includes an NCC and a first byte stream, and the first byte stream includes an encrypted RRC re - establishment message, and the RRC re - establishment message is used to instruct the UE to re - establish an RRC connection.
[0228] In the embodiments of the present application, a communication device is provided. Since after the base station receives an RRC re - establishment request message sent by the UE, it can send a first MAC CE including an NCC and a first byte stream to the UE, and the first byte stream includes an encrypted RRC re - establishment message, that is, the base station can send the NCC to the UE separately without carrying it in the RRC re - establishment message. Therefore, while the UE obtains the NCC update key, the security of the RRC re - establishment message is also improved.
[0229] In a possible implementation, the communication device provided in the embodiments of the present application further includes: a processing module and an indication module. The processing module is used to update the key used by the base station after the receiving module 51 receives an RRC re - establishment request message from the UE, and generate a first encryption key and a first integrity protection key based on the updated key. The indication module is used to instruct the PDCP layer of the base station to restore integrity protection and encryption using the first encryption key and the first integrity protection key generated by the processing module. The processing module is further used to generate an RRC re - establishment message and request the PDCP layer of the base station to perform security protection on the RRC re - establishment message.
[0230] In a possible implementation manner, the communication device provided by the embodiments of the present application further includes: a transmission module and a generation module. The processing module is further configured to, after generating an RRC reestablishment message and requesting the PDCP layer of the base station to perform security protection on the RRC reestablishment message, perform security protection on the RRC reestablishment message, generate a first byte stream, and transmit the first byte stream to the RRC layer of the base station. The first byte stream includes the RRC reestablishment message after being security protected. The security protection includes at least one of the following: an encryption operation, an integrity protection operation. The transmission module is configured to transmit the first byte stream and the NCC saved in the UE context of the UE to the MAC layer of the base station. The generation module is configured to generate a first MAC CE based on the NCC and the first byte stream.
[0231] In a possible implementation manner, the generation module is specifically configured to perform an integrity protection operation on the RRC reestablishment message through a first integrity protection key to generate a first MAC-I; and perform an encryption operation on the RRC reestablishment message and the first MAC-I through a first encryption key to generate a first PDCP PDU. The first PDCP PDU corresponds to the first byte stream, and the first PDCP PDU includes the encrypted RRC reestablishment message and the first MAC-I.
[0232] In a possible implementation manner, the processing module is specifically configured to perform an encryption operation on the RRC reestablishment message through a first encryption key to generate a first byte stream; perform an integrity protection operation on the RRC reestablishment message through a first integrity protection key to generate a first piece of information. The first piece of information is a MAC-I generated by performing an integrity protection operation on the RRC reestablishment message; and transmit the first byte stream and the first piece of information to the RRC layer of the base station. The first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the first piece of information. The first piece of information is transmitted by the RRC layer of the base station to the MAC layer of the base station.
[0233] In a possible implementation manner, the communication device provided by the embodiments of the present application further includes: a request module. The request module is configured to request the PDCP layer of the base station to perform an integrity protection operation on the NCC and the first byte stream before the transmission module transmits the first byte stream and the NCC saved in the UE context of the UE to the MAC layer of the base station. The processing module is further configured to perform an integrity protection operation on the NCC and the first byte stream through a first integrity protection key to generate a second MAC-I, and transmit the second MAC-I to the RRC layer of the base station. The first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the second MAC-I. The second MAC-I is transmitted by the RRC layer of the base station to the MAC layer of the base station.
[0234] In a possible implementation, the communication device provided by the embodiments of the present application further includes: a request module. The request module is configured to request the PDCP layer of the base station to perform an integrity protection operation on the NCC and the first byte stream before the generation module generates the first MAC CE based on the NCC and the first byte stream. A processing module is configured to perform an integrity protection on the NCC and the first byte stream through a first integrity protection key to generate a third MAC-I, and transmit the third MAC-I to the MAC layer of the base station; wherein, the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the third MAC-I.
[0235] In a possible implementation, the parameters used by the PDCP layer of the base station to perform an encryption operation and an integrity protection operation are the first parameter or the first parameter set; wherein, the first parameter or the first parameter set includes at least one of the following: the COUNT value is 0, the BEARER is the bearer identifier of the radio signaling bearer SRB1, and the DIRECTION is the downlink direction.
[0236] In a possible implementation, the processing module is further configured to set the second variable maintained by the PDCP entity corresponding to SRB1 to 1 or increment it by 1, where the second variable is the variable corresponding to the COUNT value of the next PDCP service data unit (SDU) to be sent.
[0237] In a possible implementation, the parameters used by the PDCP layer of the base station to perform an encryption operation and an integrity protection operation are the second parameter or the second parameter set;
[0238] Wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
[0239] The communication device provided by the embodiments of the present application can implement each process implemented by the base station in the above method embodiments and achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0240] The embodiments of the present application provide a communication method, Figure 10 which shows a flowchart of a communication method provided by the embodiments of the present application. As Figure 10 shown, the communication method provided by the embodiments of the present application may include the following steps 501 to step 505.
[0241] Step 501, the UE sends an RRC reestablishment request message to the base station.
[0242] In some embodiments of the present application, when the UE is in the RRC connected state but the RRC connection needs to be re-established, for example, when the connected UE experiences a radio link failure or an integrity check failure, etc., the UE can perform a cell selection process to select a target cell to initiate the RRC re-establishment process, and send an RRC re-establishment request message to the base station where the target cell is located through SRB0.
[0243] Step 502, the UE receives the first signaling from the base station.
[0244] In the embodiments of the present application, the above first signaling is used to request the UE to update the key used by the UE. The first signaling includes NCC, and the first signaling is the second MAC CE or the PDCP control PDU.
[0245] Step 503, the RRC layer of the UE updates the key used by the UE based on the NCC, and generates a first encryption key and a first integrity protection key based on the updated key.
[0246] In some embodiments of the present application, after the RRC of the UE receives the first signaling, it can parse the first signaling to obtain the above NCC.
[0247] In some embodiments of the present application, when the NCC corresponding to the current key is the same as the NCC in the second MAC CE, the RRC layer of the UE can update the key used by the UE based on the current key; otherwise, it can update the key used by the UE based on the NH corresponding to the NCC in the second MAC CE.
[0248] In some embodiments of the present application, when the NCC corresponding to the current key is the same as the NCC in the PDCP control PDU, the RRC layer of the UE can update the key used by the UE based on the current key; otherwise, it can update the key used by the UE based on the NH corresponding to the NCC in the PDCP control PDU.
[0249] Step 504, the RRC layer of the UE instructs the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0250] Step 505, after the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, the PDCP layer of the UE processes the second PDCP PDU from the base station.
[0251] It should be noted that before the integrity protection and encryption are restored using the first encryption key and the first integrity protection key at the PDCP layer of the UE, if the PDCP entity corresponding to the SRB1 of the UE receives a PDCP PDU, for example, if the second PDCP PDU is received first due to the retransmission of the first signaling, the PDCP entity corresponding to the SRB1 of the UE does not process the second PDCP PDU first until the first signaling is received. After the integrity protection and encryption are restored using the first encryption key and the first integrity protection key at the PDCP layer of the UE, the PDCP layer of the UE can process the second PDCP PDU.
[0252] In an embodiment of the present application, the above-mentioned second PDCP PDU includes an RRC re-establishment message that is integrity protected and encrypted, and the RRC re-establishment message is used to instruct the UE to re-establish an RRC connection.
[0253] It can be understood that after the integrity protection and encryption are restored using the first encryption key and the first integrity protection key at the PDCP layer of the UE, the second PDCP PDU from the base station is processed.
[0254] An embodiment of the present application provides a communication method. Since after the UE sends an RRC re-establishment request message to the base station, the UE can receive a first signaling from the base station for requesting the UE to update the keys used by the UE, and the first signaling includes an NCC, the RRC layer of the UE can update the keys used by the UE based on the NCC included in the first signaling, generate a first encryption key and a first integrity protection key based on the updated keys, and instruct the PDCP layer of the UE to restore the integrity protection and encryption using the first encryption key and the first integrity protection key. Then, after the integrity protection and encryption are restored using the first encryption key and the first integrity protection key at the PDCP layer of the UE, the PDCP layer of the UE can process the second PDCP PDU from the base station. The second PDCP PDU includes an RRC re-establishment message that is integrity protected and encrypted, and the RRC re-establishment message is used to instruct the UE to re-establish an RRC connection. That is to say, the integrity protection and encryption are restored first at the PDCP layer of the UE, and then the second PDCP PDU from the base station is processed. Therefore, the RRC re-establishment message can be integrity protected and encrypted, thereby improving the security of the RRC re-establishment message.
[0255] In some embodiments of the present application, when the first signaling is a second MAC CE, the above step 502 can be specifically implemented by the following step 502a and step 502b.
[0256] Step 502a: The MAC layer of the UE receives the second MAC CE from the base station.
[0257] Step 502b: The MAC layer of the UE parses the second MAC CE to obtain the NCC, and delivers the NCC to the RRC layer of the UE.
[0258] It can be understood that after receiving the second MAC CE, the MAC layer of the UE can parse the second MAC CE to obtain the above NCC, and deliver the NCC to the RRC layer of the UE through inter-layer interaction.
[0259] In some embodiments of the present application, if the second MAC CE also carries other MAC-Is, the MAC layer of the UE can also deliver them to the RRC layer of the UE.
[0260] In some embodiments of the present application, when the first signaling is a PDCP control PDU, the above step 502 can be specifically implemented by the following step 502c and step 502d.
[0261] Step 502c: The PDCP layer of the UE receives the PDCP control PDU from the base station.
[0262] Step 502d: The PDCP layer of the UE parses the PDCP control PDU to obtain the NCC, and delivers the NCC to the RRC layer of the UE.
[0263] It can be understood that after receiving the PDCP control PDU, the PDCP layer of the UE can parse the PDCP control PDU to obtain the above NCC, and deliver the NCC to the RRC layer of the UE through inter-layer interaction.
[0264] In some embodiments of the present application, the PDCP layer of the UE can specifically be the PDCP entity corresponding to SRB1.
[0265] In some embodiments of the present application, if the PDCP control PDU also carries other MAC-Is, the PDCP layer of the UE can also deliver them to the RRC layer of the UE.
[0266] In some embodiments of the present application, the above first signaling includes third information, and the third information is a MAC-I generated by performing an integrity protection operation on the NCC; the above step 504 can be specifically implemented by the following step 504a to step 504c.
[0267] Step 504a: The RRC layer of the UE requests the PDCP layer of the UE to perform an integrity protection verification operation on the NCC using the first integrity protection key and the third information.
[0268] Step 504b: The PDCP layer of the UE performs an integrity protection verification operation on the NCC using the first integrity protection key and the third information.
[0269] Step 504c: When the integrity protection verification operation on the NCC by the PDCP layer of the UE passes, the RRC layer of the UE instructs the PDCP layer of the UE to restore integrity protection and encryption using the first encryption key and the first integrity protection key.
[0270] In some embodiments of the present application, when the first signaling is the second MAC CE, the RRC layer of the UE may request the PDCP layer of the UE to perform an integrity protection verification operation on the NCC using the first integrity protection key and the MAC-I included in the second MAC CE.
[0271] In some embodiments of the present application, when the first signaling is the PDCP control PDU, the RRC layer of the UE may request the PDCP layer of the UE to perform an integrity protection verification operation on the NCC using the first integrity protection key and the MAC-I included in the PDCP control PDU.
[0272] In some embodiments of the present application, the parameters used by the PDCP layer of the UE to perform the integrity protection verification operation on the NCC are the second parameter or the second parameter set.
[0273] In some embodiments of the present application, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
[0274] In some embodiments of the present application, the communication method provided by the embodiments of the present application may further include the following step 506.
[0275] Step 506: When the integrity protection verification operation on the NCC by the PDCP layer of the UE fails, the UE enters the idle state.
[0276] In some embodiments of the present application, when the integrity protection verification operation on the NCC by the PDCP layer of the UE passes, the PDCP layer of the UE may be configured to restore integrity protection and encryption using the first encryption key and the first integrity protection key.
[0277] In some embodiments of the present application, the "processing of the second PDCP PDU from the base station by the PDCP layer of the UE" in step 505 may be specifically implemented by the following step 505a.
[0278] Step 505a: The PDCP layer of the UE performs a decryption operation and an integrity protection verification operation on the second PDCP PDU using the first encryption key and the first integrity protection key, and delivers the decrypted RRC reestablishment message to the RRC layer of the UE.
[0279] It can be understood that since the PDCP layer of the UE has restored integrity protection and encryption using the first encryption key and the first integrity protection key, the PDCP layer of the UE can perform decryption operations and integrity protection verification operations on the received PDCP PDUs, obtain the decrypted RRC re-establishment message, and deliver the decrypted RRC re-establishment message to the RRC layer of the UE.
[0280] In some embodiments of the present application, the communication method provided by the embodiments of the present application may further include the following steps 601 and 602.
[0281] Step 601: The RRC layer of the UE re-establishes the RRC connection based on the decrypted RRC re-establishment message.
[0282] It can be understood that the RRC layer of the UE can process the decrypted RRC re-establishment message and re-establish the RRC connection according to the RRC re-establishment message.
[0283] Step 602: The UE sends an RRC re-establishment complete message to the base station.
[0284] In the embodiments of the present application, the above RRC re-establishment complete message is a message processed by the PDCP layer of the UE using the first encryption key and the first integrity protection key.
[0285] It can be understood that the UE can send an RRC re-establishment complete message to the base station, and the message is encrypted and integrity protected and transmitted on SRB1.
[0286] The embodiments of the present application provide a communication method. Figure 11 The flowchart of a communication method provided by the embodiments of the present application is shown. As Figure 11 shown, the communication method provided by the embodiments of the present application may include the following steps 701 to 703.
[0287] Step 701: The base station receives an RRC re-establishment request message from the UE.
[0288] Step 702: The base station sends a first signaling to the UE.
[0289] In the embodiments of the present application, the above first signaling is used to request the UE to update the keys used by the UE, the first signaling includes NCC, and the first signaling is a second MAC CE or a PDCP control PDU.
[0290] Step 703: The base station sends a second PDCP PDU to the UE.
[0291] In the embodiments of the present application, the above second PDCP PDU includes an RRC re-establishment message that is integrity protected and encrypted, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
[0292] In an embodiment of the present application, a communication method is provided. Since after the base station receives the RRC reestablishment request message sent by the UE, it can send a first signaling to the UE for requesting the UE to update the key used by the UE. The first signaling includes the NCC, and send a second PDCP PDU indicating that the UE reestablishes the RRC connection to the UE. The second PDCP PDU includes the RRC reestablishment message protected by integrity and encrypted, that is, the NCC and the RRC reestablishment message are separated, so the security of the RRC reestablishment message is improved.
[0293] In some embodiments of the present application, before the above step 703, the communication method provided by the embodiments of the present application further includes the following steps 704 and 705.
[0294] Step 704: The RRC layer of the base station updates the key used by the base station, and generates a first encryption key and a first integrity protection key based on the updated key.
[0295] In some embodiments of the present application, after the RRC layer of the base station receives the RRC reestablishment request message sent by the UE, it can obtain the NCC saved in the UE context of the UE, and then update the key used by the base station based on the NCC.
[0296] Step 705: The RRC layer of the base station instructs the PDCP layer of the base station to restore integrity protection and encryption using the first encryption key and the first integrity protection key.
[0297] It should be noted that the RRC layer of the base station can, when generating the first encryption key and the first integrity protection key, instruct the PDCP layer of the base station to restore integrity protection and encryption using the first encryption key and the first integrity protection key, or the RRC layer of the base station can, before the PDCP layer of the base station generates the PDCP control PDU, instruct the PDCP layer of the base station to restore integrity protection and encryption using the first encryption key and the first integrity protection key, or the RRC layer of the base station can, before the base station sends the PDCP control PDU to the UE, instruct the PDCP layer of the base station to restore integrity protection and encryption using the first encryption key and the first integrity protection key. The embodiments of the present application do not limit this.
[0298] In some embodiments of the present application, the above step 702 can be specifically implemented by the following steps 702a to 702c.
[0299] Step 702a: The RRC layer of the base station passes the NCC saved in the UE context of the UE to the MAC layer of the base station.
[0300] In some embodiments of the present application, the RRC layer of the base station can deliver the NCC to the MAC layer of the UE through inter-layer interaction.
[0301] Step 702b: The MAC layer of the base station generates a second MAC CE based on the NCC.
[0302] In an embodiment of the present application, the above second MAC CE is used to request the UE to update the key used by the UE, and the second MAC CE includes the NCC.
[0303] In some embodiments of the present application, the above second MAC CE is used to send the NCC to the UE.
[0304] Step 702c: The base station sends the second MAC CE to the UE.
[0305] In some embodiments of the present application, the above second MAC CE corresponds to a dedicated LCID. That is to say, an LCID is allocated to the second MAC CE. So that after the UE receives the MAC PDU containing the second MAC CE, it can know that it is the second MAC CE through this LCID in the MAC subheader of the MAC PDU. In this way, it is not necessary to occupy at least two bits to indicate what message is being sent, thus saving signaling overhead.
[0306] In some embodiments of the present application, the above step 702a can be specifically implemented through the following steps 702a1 to 702a3.
[0307] Step 702a1: The RRC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC through the first integrity protection key.
[0308] Step 702a2: The PDCP layer of the base station performs an integrity protection operation on the NCC through the first integrity protection key, generates a fourth MAC-I, and passes it to the RRC layer of the base station.
[0309] In some embodiments of the present application, the above fourth MAC-I may be the third information.
[0310] Step 702a3: The RRC layer of the base station passes the NCC and the fourth MAC-I to the MAC layer of the base station.
[0311] In some embodiments of the present application, the above second MAC CE includes the NCC and the fourth MAC-I.
[0312] It can be understood that the MAC layer of the base station can generate a second MAC CE based on the NCC and the fourth MAC-I.
[0313] In some embodiments of the present application, the parameters used by the PDCP layer of the base station to perform the integrity protection operation on the NCC are the second parameter or the second parameter set.
[0314] In some embodiments of the present application, the above second parameter or second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
[0315] In this way, since the NCC is integrity protected, the security is improved.
[0316] In some embodiments of the present application, the above step 702b can be specifically implemented by the following steps 702b1 to 702b3.
[0317] Step 702b1, the MAC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC through the first integrity protection key.
[0318] Step 702b2, the PDCP layer of the base station performs an integrity protection operation on the NCC through the first integrity protection key, generates a fifth MAC-I, and transfers it to the MAC layer of the base station.
[0319] In some embodiments of the present application, the above fifth MAC-I may be the third information.
[0320] Step 702b3, the MAC layer of the base station generates a second MAC CE based on the NCC and the fifth MAC-I.
[0321] In an embodiment of the present application, the above second MAC CE includes the NCC and the fifth MAC-I.
[0322] In some embodiments of the present application, when the RRC layer of the base station only transfers the NCC saved in the UE context of the UE to the MAC layer of the base station, that is, when the NCC does not perform an integrity protection operation, the MAC layer of the base station may request the PDCP layer of the UE to perform an integrity protection operation on the NCC through the first integrity protection key, or perform an integrity protection operation on the byte or byte stream containing the NCC.
[0323] In this way, since the NCC is integrity protected, the security is improved.
[0324] In some embodiments of the present application, the above step 702 can be specifically implemented by the following steps 702d to 702f.
[0325] Step 702d, the RRC layer of the base station transfers the NCC saved in the UE context of the UE to the PDCP layer of the base station.
[0326] In some embodiments of the present application, after receiving the RRC reestablishment message, the RRC layer of the base station may obtain the NCC saved in the UE context of the UE.
[0327] In some embodiments of the present application, the RRC layer of the base station may update the key used by the base station based on the NCC, and generate a first encryption key and a first integrity protection key based on the updated key.
[0328] In some embodiments of the present application, the RRC layer of the base station may deliver the NCC to the PDCP layer of the UE through inter-layer interaction.
[0329] Step 702e: The PDCP layer of the base station generates a PDCP control PDU based on the NCC.
[0330] In an embodiment of the present application, the above PDCP control PDU is used to request the UE to update the key used by the UE, and the PDCP control PDU includes the NCC.
[0331] In some embodiments of the present application, the above PDCP control PDU corresponds to a dedicated PDU Type value, that is, a PDU Type value is assigned to the PDCP control PDU. So that when the UE receives the PDCP control PDU and the value of the PDU Type of the PDCP control PDU is the dedicated PDU Type value, the UE can know that it is a PDCP control PDU.
[0332] Exemplarily, as Figure 12 shown, it is a schematic structural diagram of a PDCP control PDU provided by an embodiment of the present application, where: D / C is used to indicate whether it is a control PDU or a data PDU, PDU Type is used to indicate the type of the control PDU, R is a reserved bit, and NCC is the NCC delivered by the upper layer.
[0333] Step 702f: The base station sends a PDCP control PDU to the UE.
[0334] In some embodiments of the present application, the above PDCP control PDU is used to request the UE to update the key used by the UE.
[0335] In some embodiments of the present application, the above step 702e may be specifically implemented by the following step 702e1 and step 702e2.
[0336] Step 702e1: The PDCP layer of the base station performs an integrity protection operation on the NCC through the first integrity protection key to generate a sixth MAC-I.
[0337] In some embodiments of the present application, the above sixth MAC-I may be the third information.
[0338] Step 702e2: The PDCP layer of the base station generates a PDCP control PDU based on the NCC and the sixth MAC-I.
[0339] In an embodiment of the present application, the above PDCP control PDU includes the sixth MAC-I.
[0340] In some embodiments of the present application, the parameter used by the PDCP layer of the base station to perform the integrity protection operation on the NCC is the second parameter or the second parameter set.
[0341] In this way, since the NCC is integrity protected, the security is improved.
[0342] In some embodiments of the present application, the above step 703 can be specifically implemented by the following steps 703a to 703d.
[0343] Step 703a: The RRC layer of the base station generates an RRC re-establishment message and transmits it to the PDCP layer of the base station.
[0344] In some embodiments of the present application, after the RRC layer of the base station generates the RRC re-establishment message, it can transmit the RRC re-establishment message to the PDCP layer corresponding to SRB1 as a PDCP SDU.
[0345] Step 703b: The PDCP layer of the base station performs an encryption operation and an integrity protection operation on the RRC re-establishment message using the first encryption key and the first integrity protection key to generate a second PDCP PDU.
[0346] Step 703c: The PDCP layer of the base station transmits the second PDCP PDU to the RLC layer of the base station.
[0347] Step 703d: The RLC layer of the base station sends the second PDCP PDU to the UE.
[0348] It can be understood that since the PDCP layer of the base station is configured to use the first encryption key and the first integrity protection key to restore integrity protection and encryption, the PDCP layer of the base station can perform an encryption operation and an integrity protection operation on the RRC re-establishment message using the first encryption key and the first integrity protection key to generate a second PDCP PDU, and transmit the second PDCP PDU to the RLC layer of the base station for sending to the UE.
[0349] In some embodiments of the present application, the above step 703 can be specifically implemented by the following step 703e.
[0350] Step 703e: After the first signaling is sent, or after the first signaling is successfully sent, or after the base station receives the reception confirmation message of the first signaling, the base station sends the second PDCP PDU to the UE.
[0351] In some embodiments of the present application, as Figure 13 shown, the communication method provided by the embodiments of the present application may include the following steps B1 to B12.
[0352] B1. The UE is in the connected state, and the RRC layer connection needs to be re-established.
[0353] B2. The UE sends an RRC re-establishment request message to the base station.
[0354] B3. The base station receives the RRC re-establishment request message from the UE.
[0355] B4. The RRC layer of the base station passes the NCC saved in the UE context of the UE to the MAC layer of the base station.
[0356] B5. The MAC layer of the base station generates a second MAC CE including the NCC based on the NCC.
[0357] B6. The base station sends the second MAC CE to the UE.
[0358] B7. The UE receives the second MAC CE from the base station.
[0359] B8. The RRC layer of the UE updates the key used by the UE based on the NCC included in the second MAC CE, and generates a first encryption key and a first integrity protection key based on the updated key, and instructs the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0360] B9. The base station sends a second PDCP PDU to the UE.
[0361] B10. The PDCP layer of the UE performs a decryption operation and an integrity protection verification operation on the second PDCP PDU using the first encryption key and the first integrity protection key, and delivers the decrypted RRC re-establishment message to the RRC layer of the UE.
[0362] B11. The RRC layer of the UE re-establishes the RRC connection based on the decrypted RRC re-establishment message.
[0363] B12. The UE sends an RRC re-establishment completion message to the base station.
[0364] It should be noted that for the relevant descriptions in the above steps B1 to B12, reference may be made to the descriptions in the above embodiments, and details are not described herein again.
[0365] It should be noted that in the above steps, "the RRC layer of the base station generates an RRC reestablishment message and passes it to the PDCP layer of the base station. The PDCP layer of the base station performs an encryption operation and an integrity protection operation on the RRC reestablishment message using the first encryption key and the first integrity protection key, generates a second PDCP PDU, and passes the second PDCP PDU to the RLC layer of the base station" and "the base station generates a second MAC CE" can be executed simultaneously. However, the base station needs to first send the second MAC CE to the UE and then send the second PDCP PDU to the UE. Alternatively, the base station can send the sub-PDU corresponding to the second MAC CE and the sub-PDU corresponding to the second PDCP PDU in a single MAC PDU to the UE, but the sub-PDU corresponding to the second MAC CE is placed in the front. In short, it is necessary to ensure that the UE processes the second MAC CE first, and only after the PDCP layer of the UE restores integrity protection and encryption using the first encryption key and the first integrity protection key can the PDCP layer of the UE process the second PDCP PDU.
[0366] It should be noted that before the PDCP layer of the UE restores integrity protection and encryption using the first encryption key and the first integrity protection key, if the PDCP entity corresponding to the SRB1 of the UE receives a PDCP PDU, for example, if the second PDCP PDU is received first due to the retransmission of the second MAC CE, the PDCP entity corresponding to the SRB1 of the UE does not process the second PDCP PDU first until the second MAC CE is received. Only after the PDCP layer of the UE restores integrity protection and encryption using the first encryption key and the first integrity protection key can the PDCP layer of the UE process the second PDCP PDU.
[0367] In some embodiments of the present application, as Figure 14 shown, the communication method provided by the embodiments of the present application may include the following steps C1 to C12.
[0368] C1. The UE is in the connected state and the RRC layer connection needs to be reestablished.
[0369] C2. The UE sends an RRC reestablishment request message to the base station.
[0370] C3. The base station receives the RRC reestablishment request message from the UE.
[0371] C4. The RRC layer of the base station passes the NCC saved in the UE context of the UE to the PDCP layer of the base station.
[0372] C5. The PDCP layer of the base station generates a PDCP control PDU including the NCC based on the NCC.
[0373] C6. The base station sends a PDCP control PDU to the UE.
[0374] C7. The UE receives the PDCP control PDU from the base station.
[0375] C8. The RRC layer of the UE updates the key used by the UE based on the NCC included in the PDCP control PDU, generates a first encryption key and a first integrity protection key based on the updated key, and instructs the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0376] C9. The base station sends a second PDCP PDU to the UE.
[0377] C10. The PDCP layer of the UE performs a decryption operation and an integrity protection verification operation on the second PDCP PDU using the first encryption key and the first integrity protection key, and delivers the decrypted RRC reestablishment message to the RRC layer of the UE.
[0378] C11. The RRC layer of the UE reestablishes the RRC connection based on the decrypted RRC reestablishment message.
[0379] C12. The UE sends an RRC reestablishment complete message to the base station.
[0380] It should be noted that for the relevant descriptions in steps C1 to C12 above, reference can be made to the descriptions in the above embodiments, and details will not be repeated here.
[0381] Each of the above method embodiments, or various possible implementation manners in each method embodiment, can be executed alone, or any two or more of them can be combined and executed. Specifically, it can be determined according to actual usage requirements, and the embodiments of the present application do not limit this.
[0382] In the communication method provided by the embodiments of the present application, the execution subject can be a communication device. In the embodiments of the present application, taking the communication device executing the communication method as an example, the communication device provided by the embodiments of the present application is described.
[0383] Figure 15 A possible structural schematic diagram of the communication device involved in the embodiments of the present application is shown, which is applied to the UE. As Figure 15 shown, the communication device 60 may include: a sending module 61, a receiving module 62, a processing module 63, and an indicating module 64.
[0384] Among them, the sending module 61 is used to send an RRC reestablishment request message to the base station.
[0385] A receiving module 62, configured to receive a first signaling from a base station, where the first signaling is used to request the UE to update a key used by the UE, the first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU.
[0386] A processing module 63, configured to update the key used by the UE based on the NCC, and generate a first encryption key and a first integrity protection key based on the updated key.
[0387] An indicating module 64, configured to instruct the PDCP layer of the UE to use the first encryption key and the first integrity protection key generated by the processing module 63 to restore integrity protection and encryption.
[0388] The processing module 63 is further configured to, after the PDCP layer of the UE restores integrity protection and encryption by using the first encryption key and the first integrity protection key, process a second PDCP PDU from the base station, where the second PDCP PDU includes an RRC reestablishment message that is integrity-protected and encrypted, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0389] An embodiment of this application provides a communication device. Since, after the UE sends an RRC reestablishment request message to the base station, the UE can receive the first signaling from the base station for requesting the UE to update the key used by the UE, the RRC layer of the UE can update the key used by the UE based on the NCC included in the first signaling, generate a first encryption key and a first integrity protection key based on the updated key, and instruct the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption. Then, after the PDCP layer of the UE restores integrity protection and encryption by using the first encryption key and the first integrity protection key, the PDCP layer of the UE can process the second PDCP PDU from the base station. The second PDCP PDU includes an RRC reestablishment message that is integrity-protected and encrypted, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection. That is to say, the PDCP layer of the UE restores integrity protection and encryption first, and then processes the second PDCP PDU from the base station. Therefore, the RRC reestablishment message can be integrity-protected and encrypted, thereby improving the security of the RRC reestablishment message.
[0390] In a possible implementation, the first signaling includes third information, and the third information is a MAC-I generated by performing integrity protection operation on the NCC; the indication module 64 is specifically configured to request the PDCP layer of the UE to perform an integrity protection verification operation on the NCC by using the first integrity protection key and the third information; and perform an integrity protection verification operation on the NCC by using the first integrity protection key and the third information; and in the case that the integrity protection verification operation on the NCC by the PDCP layer of the UE passes, the RRC layer of the UE instructs the PDCP layer of the UE to restore integrity protection and encryption by using the first encryption key and the first integrity protection key.
[0391] In a possible implementation, the processing module 63 is further configured to enter the idle state in the case that the integrity protection verification operation on the NCC by the PDCP layer of the UE fails.
[0392] In a possible implementation, the parameters used by the PDCP layer of the UE to perform an integrity protection verification operation on the NCC are the second parameter or the second parameter set; wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
[0393] In a possible implementation, in the case that the first signaling is the second MAC CE, the receiving module 62 is specifically configured to receive the second MAC CE from the base station; and parse the second MAC CE to obtain the NCC, and deliver the NCC to the RRC layer of the UE.
[0394] In a possible implementation, in the case that the first signaling is the PDCP control PDU, the receiving module 62 is specifically configured to receive the PDCP control PDU from the base station; and parse the PDCP control PDU to obtain the NCC, and deliver the NCC to the RRC layer of the UE.
[0395] In a possible implementation, the processing module 63 is specifically configured to perform a decryption operation and an integrity protection verification operation on the second PDCP PDU by using the first encryption key and the first integrity protection key, and deliver the decrypted RRC reestablishment message to the RRC layer of the UE.
[0396] In a possible implementation, the processing module 63 is further configured to reestablish the RRC connection based on the decrypted RRC reestablishment message; the sending module 61 is further configured to send an RRC reestablishment completion message to the base station, and the RRC reestablishment completion message is a message processed by the PDCP layer of the UE by using the first encryption key and the first integrity protection key.
[0397] The communication device provided by the embodiment of the present application can implement each process implemented by the UE in the above method embodiment and achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0398] Figure 16 FIG. shows another possible structural schematic diagram of the communication device involved in the embodiment of the present application, which is applied to a base station. As Figure 16 shown, the communication device 70 may include: a receiving module 71 and a transmitting module 72.
[0399] The receiving module 71 is configured to receive an RRC reestablishment request message from the UE.
[0400] The transmitting module 72 is configured to send a first signaling to the UE. The first signaling is used to request the UE to update the key used by the UE. The first signaling includes an NCC. The first signaling is a second MAC CE or a PDCP control PDU; and send a second PDCP PDU to the UE. The second PDCP PDU includes an RRC reestablishment message that is integrity protected and encrypted. The RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
[0401] The embodiment of the present application provides a communication device. Since after the base station receives the RRC reestablishment request message sent by the UE, it can send a first signaling to the UE for requesting the UE to update the key used by the UE. The first signaling includes an NCC, and send a second PDCP PDU instructing the UE to reestablish an RRC connection to the UE. The second PDCP PDU includes an RRC reestablishment message that is integrity protected and encrypted, that is, the NCC and the RRC reestablishment message are separated, so the security of the RRC reestablishment message is improved.
[0402] In a possible implementation manner, the communication device provided by the embodiment of the present application further includes: a processing module and an indication module; the processing module is configured to update the key used by the base station and generate a first encryption key and a first integrity protection key based on the updated key before the transmitting module 72 sends the second PDCP PDU to the UE. The indication module is configured to instruct the PDCP layer of the base station to restore integrity protection and encryption using the first encryption key and the first integrity protection key generated by the processing module.
[0403] In a possible implementation manner, the communication device provided by the embodiment of the present application further includes: a transfer module and a generation module. The transfer module is configured to transfer the NCC saved in the UE context of the UE to the MAC layer of the base station. The generation module is configured to generate a second MAC CE based on the NCC transferred by the transfer module. The second MAC CE is used to request the UE to update the key used by the UE. The second MAC CE includes an NCC. The transmitting module 72 is specifically configured to send the second MAC CE generated by the generation module to the UE.
[0404] In a possible implementation, the transmission module is specifically configured to request the PDCP layer of the base station to perform an integrity protection operation on the NCC using the first integrity protection key; and perform an integrity protection operation on the NCC using the first integrity protection key to generate a fourth MAC-I, and transmit it to the RRC layer of the base station; and transmit the NCC and the fourth MAC-I to the MAC layer of the base station; wherein, the second MAC CE includes the NCC and the fourth MAC-I.
[0405] In a possible implementation, the generation module is specifically configured to request the PDCP layer of the base station to perform an integrity protection operation on the NCC using the first integrity protection key; and perform an integrity protection operation on the NCC using the first integrity protection key to generate a fifth MAC-I, and transmit it to the MAC layer of the base station; and generate a second MAC CE based on the NCC and the fifth MAC-I, and the second MAC CE includes the NCC and the fifth MAC-I.
[0406] In a possible implementation, the communication device provided in the embodiment of the present application further includes: a transmission module and a generation module; the transmission module is configured to transmit the NCC saved in the UE context of the UE to the PDCP layer of the base station. The generation module is configured to generate a PDCP control PDU based on the NCC transmitted by the transmission module, and the PDCP control PDU is used to request the UE to update the key used by the UE, and the PDCP control PDU includes the NCC. The sending module 72 is specifically configured to send the PDCP control PDU generated by the generation module to the UE.
[0407] In a possible implementation, the generation module is specifically configured to perform an integrity protection operation on the NCC using the first integrity protection key to generate a sixth MAC-I; and generate a PDCP control PDU based on the NCC and the sixth MAC-I, and the PDCP control PDU includes the sixth MAC-I.
[0408] In a possible implementation, the parameters used by the PDCP layer of the base station to perform an integrity protection operation on the NCC are the second parameter or the second parameter set; wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
[0409] In a possible implementation, the sending module 72 is specifically configured to generate an RRC re-establishment message and transmit it to the PDCP layer of the base station; and perform an encryption operation and an integrity protection operation on the RRC re-establishment message using the first encryption key and the first integrity protection key to generate a second PDCP PDU; and transmit the second PDCP PDU to the radio link control RLC layer of the base station; and send the second PDCP PDU to the UE.
[0410] In a possible implementation, the sending module 72 is specifically used to send a second PDCP PDU to the UE after the first signaling is sent, or after the first signaling is successfully sent, or after the base station receives the reception confirmation message of the first signaling.
[0411] The communication device provided by the embodiments of the present application can implement each process implemented by the base station in the above method embodiments and achieve the same technical effects. To avoid repetition, details are not described here again.
[0412] Optionally, as Figure 17 shown, the embodiments of the present application further provide a communication device 5000, including a processor 5001 and a memory 5002. A program or instruction that can run on the processor 5001 is stored on the memory 5002. For example, when the communication device 5000 is a UE, when the program or instruction is executed by the processor 5001, each step of the above UE-side method embodiment is implemented, and the same technical effects can be achieved. When the communication device 5000 is a base station, when the program or instruction is executed by the processor 5001, each step of the above base station method embodiment is implemented, and the same technical effects can be achieved. To avoid repetition, details are not described here again.
[0413] The embodiments of the present application further provide a UE, including a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the steps in the above method embodiments. This UE embodiment corresponds to the above UE-side method embodiment. Each implementation process and implementation method of the above method embodiment can be applied to this UE embodiment, and the same technical effects can be achieved.
[0414] Specifically, Figure 18 FIG. is a schematic diagram of the hardware structure of a UE for implementing the embodiments of the present application.
[0415] The UE 100 includes, but is not limited to, at least some components such as a radio frequency unit 101, a network module 102, an audio output unit 103, an input unit 104, a sensor 105, a display unit 106, a user input unit 107, an interface unit 108, a memory 109, and a processor 110.
[0416] Those skilled in the art can understand that the UE 100 may further include a power supply (such as a battery) for supplying power to each component. The power supply can be logically connected to the processor 110 through a power management system, so as to implement functions such as management of charging, discharging, and power consumption management through the power management system. Figure 18 The UE structure shown in does not limit the UE. The UE may include more or fewer components than shown, or combine certain components, or have different component arrangements, which are not described here again.
[0417] It should be understood that in the embodiments of the present application, the input unit 104 may include a Graphics Processing Unit (GPU) 1041 and a microphone 1042. The graphics processor 1041 processes the image data of static pictures or videos obtained by an image capture device (such as a camera) in the video capture mode or the image capture mode. The display unit 106 may include a display panel 1061, and the display panel 1061 may be configured in the form of, for example, a liquid crystal display, an organic light-emitting diode, etc. The user input unit 107 includes at least one of a touch panel 1071 and other input devices 1072. The touch panel 1071 is also referred to as a touch screen. The touch panel 1071 may include two parts: a touch detection device and a touch controller. The other input devices 1072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, a joystick, which will not be elaborated here.
[0418] In the embodiments of the present application, after receiving downlink data from a network-side device, the radio frequency unit 101 may transmit it to the processor 110 for processing; in addition, the radio frequency unit 101 may send uplink data to the network-side device. Generally, the radio frequency unit 101 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, etc.
[0419] The memory 109 can be used to store software programs or instructions and various data. The memory 109 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data. Among them, the first storage area may store an operating system, application programs or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 109 may include a volatile memory or a non-volatile memory, or the memory 109 may include both a volatile memory and a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (Synchronous DRAM, SDRAM), a double data rate synchronous dynamic random access memory (Double Data Rate SDRAM, DDR SDRAM), an enhanced synchronous dynamic random access memory (Enhanced SDRAM, ESDRAM), a synchronous link dynamic random access memory (Synch link DRAM, SLDRAM), and a direct rambus random access memory (Direct Rambus RAM, DRRAM). The memory 109 in the embodiments of the present application includes, but is not limited to, these and any other suitable types of memories.
[0420] The processor 110 may include one or more processing units; optionally, the processor 110 integrates an application processor and a modem processor. Among them, the application processor mainly processes operations related to the operating system, user interface, and application programs, etc., and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above modem processor may not be integrated into the processor 110 either.
[0421] The UE provided in the embodiments of the present application can implement each process implemented by the terminal in the above method embodiments and achieve the same technical effects. To avoid repetition, it will not be described in detail here.
[0422] An embodiment of the present application further provides a base station, including a processor and a communication interface, where the communication interface is coupled to the processor, and the processor is configured to run a program or instructions to implement the steps of the above method embodiment. This base station embodiment corresponds to the above base station method embodiment, and each implementation process and implementation manner of the above method embodiment can be applied to this base station embodiment and can achieve the same technical effect.
[0423] Specifically, an embodiment of the present application further provides a base station. As Figure 19 shown, the base station 600 includes: an antenna 61, a radio frequency device 62, a baseband device 63, a processor 64, and a memory 65. The antenna 61 is connected to the radio frequency device 62. In the uplink direction, the radio frequency device 62 receives information through the antenna 61 and sends the received information to the baseband device 63 for processing. In the downlink direction, the baseband device 63 processes the information to be sent and sends it to the radio frequency device 62. After processing the received information, the radio frequency device 62 sends it out through the antenna 61.
[0424] The method executed by the base station in the above embodiments can be implemented in the baseband device 63, and the baseband device 63 includes a baseband processor.
[0425] The base station provided by the embodiment of the present application can implement each process implemented by the base station in the above method embodiment and achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0426] The baseband device 63 may include, for example, at least one baseband board, and a plurality of chips are provided on the baseband board. As Figure 19 shown, one of the chips is, for example, a baseband processor, which is connected to the memory 65 through a bus interface to call the program in the memory 65 and execute the network device operations shown in the above method embodiment.
[0427] The base station may further include a network interface 66, and this interface is, for example, a common public radio interface (CPRI).
[0428] Specifically, the base station 600 of the embodiment of the present application further includes: instructions or programs stored on the memory 65 and executable on the processor 64. The processor 64 calls the instructions or programs in the memory 65 to execute Figure 19 the methods executed by the respective modules shown, and achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0429] An embodiment of the present application further provides a readable storage medium, on which a program or instructions are stored. When the program or instructions are executed by a processor, they implement each process of the above method embodiment and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0430] Among them, the processor is the processor in the communication device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory ROM, random access memory RAM, magnetic disks, or optical discs, etc.
[0431] Another embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement each process of the above method embodiment and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0432] It should be understood that the chip mentioned in the embodiments of the present application can also be referred to as a system-on-chip, system chip, chip system, or system-on-chip.
[0433] Another embodiment of the present application provides a computer program / program product. The computer program / program product is stored in a storage medium. The computer program / program product is executed by at least one processor to implement each process of the above method embodiment and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0434] The embodiments of the present application further provide a communication system, including: a UE and a terminal. The UE can be used to execute the steps of the communication method as described above, and the terminal can be used to execute the steps of the communication method as described above.
[0435] It should be noted that in this article, the term "including", "comprising", or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article, or device. Without more limitations, the element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article, or device including the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed. It may also include performing functions in a substantially simultaneous manner or in a reverse order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may be added, omitted, or combined. Additionally, the features described with reference to certain examples may be combined in other examples.
[0436] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described method of the embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art can be embodied in the form of a computer software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present application.
[0437] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them belong to the protection scope of the present application.
Claims
1. A communication method, characterized in that, The method includes: A user equipment (UE) sends a radio resource control (RRC) reestablishment request message to a base station; The media access control (MAC) layer of the UE receives a first media access control control element (MAC CE) from the base station; Wherein, the first MAC CE includes a next-hop chain count (NCC) and a first byte stream, the first byte stream includes an encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
2. The method according to claim 1, wherein After the MAC layer of the UE receives the first MAC CE from the base station, the method further includes: The MAC layer of the UE parses the first MAC CE to obtain the NCC and the first byte stream; The MAC layer of the UE passes the NCC and the first byte stream to the RRC layer of the UE; The RRC layer of the UE updates a key used by the UE based on the NCC, and generates a first encryption key and a first integrity protection key based on the updated key; The RRC layer of the UE requests the packet data convergence protocol (PDCP) layer of the UE to process the first byte stream based on the first encryption key and the first integrity protection key; The PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key.
3. The method according to claim 2, wherein The first byte stream corresponds to a first PDCP protocol data unit (PDU), the first PDCP PDU includes an encrypted first message authentication code (MAC-I), and the encrypted first MAC-I is generated by the PDCP layer of the base station by performing an integrity protection operation on the RRC reestablishment message; The PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key, including: The PDCP layer of the UE parses the first PDCP PDU to obtain the encrypted RRC reestablishment message and the encrypted first MAC-I; The PDCP layer of the UE performs a decryption operation on the encrypted RRC reestablishment message and the encrypted first MAC-I through the first encryption key to obtain the decrypted RRC reestablishment message and the decrypted first MAC-I; The PDCP layer of the UE performs an integrity protection verification operation on the decrypted RRC reestablishment message through the first integrity protection key and the decrypted first MAC-I.
4. The method according to claim 2, wherein The first MAC CE includes first information, and the first information is a MAC-I generated by performing an integrity protection operation on the RRC reestablishment message; The PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key, including: The PDCP layer of the UE performs a decryption operation on the first byte stream through the first encryption key to obtain the decrypted RRC reestablishment message; The PDCP layer of the UE performs an integrity protection verification operation on the decrypted RRC reestablishment message by using the first integrity protection key and the first information.
5. The method according to claim 2, wherein The first MAC CE includes second information, where the second information is a MAC-I generated by performing an integrity protection operation on the NCC and the first byte stream. The PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key, including: The PDCP layer of the UE performs an integrity protection verification operation on the NCC and the first byte stream by using the first integrity protection key and the second information. When the integrity protection verification operation performed by the PDCP layer of the UE on the NCC and the first byte stream passes, the PDCP layer of the UE performs a decryption operation on the first byte stream by using the first encryption key to obtain the decrypted RRC reestablishment message.
6. The method according to any one of claims 3 to 5, characterized in that The parameters used by the PDCP layer of the UE to perform the decryption operation and the integrity protection verification operation are the first parameter or the first parameter set. Wherein, the first parameter or the first parameter set includes at least one of the following: the COUNT value is 0, the BEARER is the bearer identifier of the radio signaling bearer SRB1, and the DIRECTION is the downlink direction.
7. The method according to claim 6, wherein The method further includes: The PDCP layer of the UE sets the first variable maintained by the PDCP entity corresponding to the SRB1 to 1 or increments it by 1, where the first variable is the variable corresponding to the COUNT value of the next expected received PDCP service data unit (SDU).
8. The method according to claim 4 or 5, characterized in that, The parameters used by the PDCP layer of the UE to perform the decryption operation and the integrity protection verification operation are the second parameter or the second parameter set. Wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
9. The method according to any one of claims 3 to 5, characterized in that After the PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key, the method further includes: When the integrity protection verification operation performed by the PDCP layer of the UE fails, the UE enters the idle state. When the integrity protection verification operation performed by the PDCP layer of the UE passes, the PDCP layer of the UE passes the decrypted RRC reestablishment message to the RRC layer of the UE.
10. The method according to claim 9, wherein After the PDCP layer of the UE passes the decrypted RRC reestablishment message to the RRC layer of the UE, the method further includes: The RRC layer of the UE reestablishes the RRC connection based on the decrypted RRC reestablishment message. The UE sends an RRC reestablishment complete message to the base station, where the RRC reestablishment complete message is the message processed by the PDCP layer of the UE by using the first encryption key and the first integrity protection key.
11. The method according to claim 10, wherein The RRC layer of the UE reestablishes the RRC connection based on the decrypted RRC reestablishment message, including: When the NCC in the first MAC CE is the same as the NCC in the RRC reestablishment message, the RRC layer of the UE reestablishes the RRC connection according to the decrypted RRC reestablishment message.
12. A communication method, characterized in that, The method includes: The base station receives an RRC reestablishment request message from the UE; The MAC layer of the base station sends a first MAC CE to the UE; Wherein, the first MAC CE includes an NCC and a first byte stream, and the first byte stream includes an encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish the RRC connection.
13. The method according to claim 12, wherein After the base station receives the RRC reestablishment request message from the UE, the method further includes: The RRC layer of the base station updates the key used by the base station, and generates a first encryption key and a first integrity protection key based on the updated key; The RRC layer of the base station instructs the PDCP layer of the base station to use the first encryption key and the first integrity protection key to restore integrity protection and encryption; The RRC layer of the base station generates the RRC reestablishment message, and requests the PDCP layer of the base station to perform security protection on the RRC reestablishment message.
14. The method according to claim 13, wherein After the RRC layer of the base station generates the RRC reestablishment message, and requests the PDCP layer of the base station to perform security protection on the RRC reestablishment message, the method further includes: The PDCP layer of the base station performs security protection on the RRC reestablishment message, generates the first byte stream, and transfers the first byte stream to the RRC layer of the base station. The first byte stream includes the RRC reestablishment message protected by security, and the security protection includes at least one of the following: encryption operation, integrity protection operation; The RRC layer of the base station transfers the first byte stream and the NCC saved in the UE context of the UE to the MAC layer of the base station; The MAC layer of the base station generates the first MAC CE based on the NCC and the first byte stream.
15. The method according to claim 14, wherein The PDCP layer of the base station performs security protection on the RRC reestablishment message, and generates the first byte stream, including: The PDCP layer of the base station performs an integrity protection operation on the RRC reestablishment message through the first integrity protection key, and generates a first MAC-I; The PDCP layer of the base station performs an encryption operation on the RRC reestablishment message and the first MAC-I through the first encryption key, generates a first PDCP PDU, the first PDCP PDU corresponds to the first byte stream, and the first PDCP PDU includes the encrypted RRC reestablishment message and the first MAC-I.
16. The method according to claim 14, characterized in that, The PDCP layer of the base station performs security protection on the RRC reestablishment message, generates the first byte stream, and transfers the first byte stream to the RRC layer of the base station, including: The PDCP layer of the base station performs an encryption operation on the RRC reestablishment message through the first encryption key, and generates the first byte stream; The PDCP layer of the base station performs an integrity protection operation on the RRC re-establishment message using the first integrity protection key, generating a first piece of information, where the first piece of information is the MAC-I generated by performing the integrity protection operation on the RRC re-establishment message; The PDCP layer of the base station transfers the first byte stream and the first piece of information to the RRC layer of the base station; Among them, the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the first piece of information, where the first piece of information is transferred from the RRC layer of the base station to the MAC layer of the base station.
17. The method according to claim 14, characterized in that, Before the RRC layer of the base station transfers the first byte stream and the NCC saved in the UE context of the UE to the MAC layer of the base station, the method further includes: The RRC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC and the first byte stream; The PDCP layer of the base station performs an integrity protection operation on the NCC and the first byte stream using the first integrity protection key, generating a second MAC-I, and transferring the second MAC-I to the RRC layer of the base station; Among them, the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the second MAC-I, where the second MAC-I is transferred from the RRC layer of the base station to the MAC layer of the base station.
18. The method according to claim 14, characterized in that, Before the MAC layer of the base station generates the first MAC CE based on the NCC and the first byte stream, the method further includes: The MAC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC and the first byte stream; The PDCP layer of the base station performs integrity protection on the NCC and the first byte stream using the first integrity protection key, generating a third MAC-I, and transferring the third MAC-I to the MAC layer of the base station; Among them, the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the third MAC-I.
19. The method according to any one of claims 15 to 18, characterized in that, The parameters used by the PDCP layer of the base station to perform the encryption operation and the integrity protection operation are the first parameter or the first parameter set; Among them, the first parameter or the first parameter set includes at least one of the following: the COUNT value is 0, the BEARER is the bearer identifier of the radio signaling bearer SRB1, and the DIRECTION is the downlink direction.
20. The method according to claim 19, wherein The method further includes: The PDCP layer of the base station sets the second variable maintained by the PDCP entity corresponding to the SRB1 to 1 or increments it by 1, where the second variable is the variable corresponding to the COUNT value of the next PDCP service data unit SDU to be sent.
21. The method according to any one of claims 16 to 18, characterized in that, The parameters used by the PDCP layer of the base station to perform the encryption operation and the integrity protection operation are the second parameter or the second parameter set; Wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
22. A communication method, characterized in that, The method includes: The UE sends an RRC reestablishment request message to the base station; The UE receives a first signaling from the base station, where the first signaling is used to request the UE to update the key used by the UE, the first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU; The RRC layer of the UE updates the key used by the UE based on the NCC, and generates a first encryption key and a first integrity protection key based on the updated key; The RRC layer of the UE instructs the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption; After the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, the PDCP layer of the UE processes a second PDCP PDU from the base station, where the second PDCP PDU includes an RRC reestablishment message that is integrity protected and encrypted, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
23. The method according to claim 22, wherein The first signaling includes third information, where the third information is a MAC-I generated by performing an integrity protection operation on the NCC; the RRC layer of the UE instructing the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption includes: The RRC layer of the UE requests the PDCP layer of the UE to perform an integrity protection verification operation on the NCC using the first integrity protection key and the third information; The PDCP layer of the UE performs an integrity protection verification operation on the NCC using the first integrity protection key and the third information; When the integrity protection verification operation on the NCC by the PDCP layer of the UE passes, the RRC layer of the UE instructs the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
24. The method according to claim 23, wherein The method further includes: When the integrity protection verification operation on the NCC by the PDCP layer of the UE fails, the UE enters the idle state.
25. The method according to claim 23, wherein The parameters used by the PDCP layer of the UE to perform the integrity protection verification operation on the NCC are a second parameter or a second parameter set; Wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
26. The method according to claim 22, characterized in that When the first signaling is a second MAC CE, the UE receiving the first signaling from the base station includes: The MAC layer of the UE receives the second MAC CE from the base station; The MAC layer of the UE parses the second MAC CE to obtain the NCC, and delivers the NCC to the RRC layer of the UE.
27. The method according to claim 22, characterized in that, When the first signaling is a PDCP control PDU, the UE receives the first signaling from the base station, including: The PDCP layer of the UE receives a PDCP control PDU from the base station; The PDCP layer of the UE parses the PDCP control PDU to obtain the NCC, and delivers the NCC to the RRC layer of the UE.
28. The method according to claim 22, characterized in that, The PDCP layer of the UE processes a second PDCP PDU from the base station, including: The PDCP layer of the UE performs a decryption operation and an integrity protection verification operation on the second PDCP PDU using the first encryption key and the first integrity protection key, and delivers the decrypted RRC reestablishment message to the RRC layer of the UE.
29. The method according to claim 28, wherein The method further includes: The RRC layer of the UE reestablishes an RRC connection based on the decrypted RRC reestablishment message; The UE sends an RRC reestablishment complete message to the base station, and the RRC reestablishment complete message is a message processed by the PDCP layer of the UE using the first encryption key and the first integrity protection key.
30. A communication method, characterized in that, The method includes: The base station receives an RRC reestablishment request message from the UE; The base station sends first signaling to the UE, where the first signaling is used to request the UE to update the key used by the UE. The first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU; The base station sends a second PDCP PDU to the UE, and the second PDCP PDU includes an integrity-protected and encrypted RRC reestablishment message, where the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
31. The method according to claim 30, wherein Before the base station sends a second PDCP PDU to the UE, the method further includes: The RRC layer of the base station updates the key used by the base station, and generates a first encryption key and a first integrity protection key based on the updated key; The RRC layer of the base station instructs the PDCP layer of the base station to restore integrity protection and encryption using the first encryption key and the first integrity protection key.
32. The method according to claim 30, characterized in that, The base station sends first signaling to the UE, including: The RRC layer of the base station delivers the NCC saved in the UE context of the UE to the MAC layer of the base station; The MAC layer of the base station generates the second MAC CE based on the NCC, where the second MAC CE is used to request the UE to update the key used by the UE, and the second MAC CE includes the NCC; The base station sends the second MAC CE to the UE.
33. The method according to claim 32, wherein The RRC layer of the base station delivers the NCC saved in the UE context of the UE to the MAC layer of the base station, including: The RRC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC using the first integrity protection key; The PDCP layer of the base station performs an integrity protection operation on the NCC using the first integrity protection key, generates a fourth MAC-I, and passes it to the RRC layer of the base station; The RRC layer of the base station passes the NCC and the fourth MAC-I to the MAC layer of the base station; Among them, the second MAC CE includes the NCC and the fourth MAC-I.
34. The method according to claim 32, wherein The MAC layer of the base station generates the second MAC CE based on the NCC, including: The MAC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC using the first integrity protection key; The PDCP layer of the base station performs an integrity protection operation on the NCC using the first integrity protection key, generates a fifth MAC-I, and passes it to the MAC layer of the base station; The MAC layer of the base station generates the second MAC CE based on the NCC and the fifth MAC-I, and the second MAC CE includes the NCC and the fifth MAC-I.
35. The method according to claim 30, wherein The base station sends a first signaling to the UE, including: The RRC layer of the base station passes the NCC saved in the UE context of the UE to the PDCP layer of the base station; The PDCP layer of the base station generates the PDCP control PDU based on the NCC, and the PDCP control PDU is used to request the UE to update the key used by the UE, and the PDCP control PDU includes the NCC; The base station sends the PDCP control PDU to the UE.
36. The method according to claim 35, wherein The PDCP layer of the base station generates the PDCP control PDU based on the NCC, including: The PDCP layer of the base station performs an integrity protection operation on the NCC using the first integrity protection key, generates a sixth MAC-I; The PDCP layer of the base station generates the PDCP control PDU based on the NCC and the sixth MAC-I, and the PDCP control PDU includes the sixth MAC-I.
37. The method according to claim 33 or 34 or 36, characterized in that, The parameters used by the PDCP layer of the base station to perform the integrity protection operation on the NCC are the second parameter or the second parameter set; Among them, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
38. The method according to claim 31, wherein The base station sends a second PDCP PDU to the UE, including: The RRC layer of the base station generates the RRC reestablishment message and passes it to the PDCP layer of the base station; The PDCP layer of the base station performs an encryption operation and an integrity protection operation on the RRC reestablishment message using the first encryption key and the first integrity protection key, and generates the second PDCP PDU; The PDCP layer of the base station passes the second PDCP PDU to the radio link control RLC layer of the base station; The RLC layer of the base station sends the second PDCP PDU to the UE.
39. The method according to any one of claims 31 to 38, characterized in that, The base station sends a second PDCP PDU to the UE, including: After the first signaling is sent, or after the first signaling is successfully sent, or after the base station receives the reception confirmation message of the first signaling, the base station sends the second PDCP PDU to the UE.
40. A communication device, characterized in that, The device includes: a sending module and a receiving module; The sending module is configured to send an RRC reestablishment request message to the base station; The receiving module is configured to receive a first MAC CE from the base station; Wherein, the first MAC CE includes an NCC and a first byte stream, and the first byte stream includes an encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
41. The device according to claim 40, wherein, The device further includes: a parsing module, a transmitting module, a processing module, and a requesting module; The parsing module is configured to parse the first MAC CE to obtain the NCC and the first byte stream after the receiving module receives the first MAC CE from the base station; The transmitting module is configured to transmit the NCC and the first byte stream parsed by the parsing module to the RRC layer of the UE; The processing module is configured to update the key used by the UE based on the NCC transmitted by the transmitting module, and generate a first encryption key and a first integrity protection key based on the updated key; The requesting module is configured to request the PDCP layer of the UE to process the first byte stream based on the first encryption key and the first integrity protection key; The processing module is further configured to process the first byte stream based on the first encryption key and the first integrity protection key.
42. The device according to claim 41, characterized in that, The first byte stream corresponds to a first PDCP PDU, and the first PDCP PDU includes an encrypted first MAC-I, and the encrypted first MAC-I is generated by the PDCP layer of the base station by performing an integrity protection operation on the RRC reestablishment message; The processing module is specifically configured to parse the first PDCP PDU to obtain the encrypted RRC reestablishment message and the encrypted first MAC-I; and perform a decryption operation on the encrypted RRC reestablishment message and the encrypted first MAC-I through the first encryption key to obtain the decrypted RRC reestablishment message and the decrypted first MAC-I; And perform an integrity protection verification operation on the decrypted RRC reestablishment message through the first integrity protection key and the decrypted first MAC-I.
43. The device according to claim 41, wherein, The first MAC CE includes first information, and the first information is MAC-I generated by performing an integrity protection operation on the RRC reestablishment message; The processing module is specifically configured to perform a decryption operation on the first byte stream through the first encryption key to obtain the decrypted RRC reestablishment message; and perform an integrity protection verification operation on the decrypted RRC reestablishment message through the first integrity protection key and the first information.
44. The device according to claim 41, characterized in that The first MAC CE includes second information, and the second information is a MAC-I generated by performing an integrity protection operation on the NCC and the first byte stream; The processing module is specifically configured to perform an integrity protection verification operation on the NCC and the first byte stream by using the first integrity protection key and the second information; And when the integrity protection verification operation on the NCC and the first byte stream performed by the PDCP layer of the UE passes, perform a decryption operation on the first byte stream by using the first encryption key to obtain the decrypted RRC reestablishment message.
45. The device according to any one of claims 42 to 44, characterized in that, Parameters used by the PDCP layer of the UE to perform the decryption operation and the integrity protection verification operation are a first parameter or a first parameter set; Wherein, the first parameter or the first parameter set includes at least one of the following: the COUNT value is 0, the BEARER is the bearer identifier of the radio signaling bearer SRB1, and the DIRECTION is the downlink direction.
46. The device according to claim 45, characterized in that, The processing module is further configured to set the first variable maintained by the PDCP entity corresponding to the SRB1 to 1 or increment it by 1, and the first variable is a variable corresponding to the COUNT value of the next expected received PDCP service data unit SDU.
47. The device according to claim 43 or 44, characterized in that, Parameters used by the PDCP layer of the UE to perform the decryption operation and the integrity protection verification operation are a second parameter or a second parameter set; Wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
48. The device according to any one of claims 42 to 44, characterized in that, The processing module is further configured to enter the idle state when the integrity protection verification operation performed by the PDCP layer of the UE fails after processing the first byte stream based on the first encryption key and the first integrity protection key; The transmission module is further configured to, when the integrity protection verification operation performed by the PDCP layer of the UE passes after the processing module processes the first byte stream based on the first encryption key and the first integrity protection key, transmit the decrypted RRC reestablishment message to the RRC layer of the UE.
49. The device according to claim 48, characterized in that, The processing module is further configured to reestablish an RRC connection based on the decrypted RRC reestablishment message after the transmission module transmits the decrypted RRC reestablishment message to the RRC layer of the UE; The sending module is further configured to send an RRC reestablishment complete message to the base station, and the RRC reestablishment complete message is a message processed by the PDCP layer of the UE through the first encryption key and the first integrity protection key.
50. The device according to claim 49, characterized in that, The processing module is specifically configured to reestablish an RRC connection according to the decrypted RRC reestablishment message when the NCC in the first MAC CE is the same as the NCC in the RRC reestablishment message.
51. A communication device, characterized in that, The device includes: a receiving module and a sending module; The receiving module is configured to receive an RRC reestablishment request message from the UE; The sending module is configured to send a first MAC CE to the UE; Wherein, the first MAC CE includes an NCC and a first byte stream, and the first byte stream includes an encrypted RRC reestablishment message for instructing the UE to reestablish an RRC connection.
52. The device according to claim 51, characterized in that, The apparatus further includes: a processing module and an indication module; The processing module is configured to update a key used by the base station and generate a first encryption key and a first integrity protection key based on the updated key after the receiving module receives an RRC reestablishment request message from the UE; The indication module is configured to instruct the PDCP layer of the base station to restore integrity protection and encryption using the first encryption key and the first integrity protection key generated by the processing module; The processing module is further configured to generate the RRC reestablishment message and request the PDCP layer of the base station to perform security protection on the RRC reestablishment message.
53. The device according to claim 52, wherein, The apparatus further includes: a delivery module and a generation module; The processing module is further configured to, after generating the RRC reestablishment message and requesting the PDCP layer of the base station to perform security protection on the RRC reestablishment message, perform security protection on the RRC reestablishment message, generate the first byte stream, and deliver the first byte stream to the RRC layer of the base station. The first byte stream includes the RRC reestablishment message after security protection, and the security protection includes at least one of the following: an encryption operation and an integrity protection operation; The delivery module is configured to deliver the first byte stream and the NCC saved in the UE context of the UE to the MAC layer of the base station; The generation module is configured to generate the first MAC CE based on the NCC and the first byte stream.
54. The device according to claim 53, characterized in that, Specifically, the generation module is configured to perform an integrity protection operation on the RRC reestablishment message using the first integrity protection key to generate a first MAC-I; and perform an encryption operation on the RRC reestablishment message and the first MAC-I using the first encryption key to generate a first PDCP PDU. The first PDCP PDU corresponds to the first byte stream and includes the encrypted RRC reestablishment message and the first MAC-I.
55. The device according to claim 53, characterized in that, Specifically, the processing module is configured to perform an encryption operation on the RRC reestablishment message using the first encryption key to generate the first byte stream; and perform an integrity protection operation on the RRC reestablishment message using the first integrity protection key to generate a first piece of information, where the first piece of information is a MAC-I generated by performing an integrity protection operation on the RRC reestablishment message; And deliver the first byte stream and the first piece of information to the RRC layer of the base station; Wherein, the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the first piece of information, and the first piece of information is delivered from the RRC layer of the base station to the MAC layer of the base station.
56. The device according to claim 53, characterized in that, The apparatus further includes: a request module; The request module is used to request the PDCP layer of the base station to perform an integrity protection operation on the NCC and the first byte stream before the transfer module transfers the first byte stream and the NCC saved in the UE context of the UE to the MAC layer of the base station; The processing module is further used to perform an integrity protection operation on the NCC and the first byte stream through the first integrity protection key, generate a second MAC-I, and transfer the second MAC-I to the RRC layer of the base station; Wherein, the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the second MAC-I, and the second MAC-I is transferred from the RRC layer of the base station to the MAC layer of the base station.
57. The device according to claim 53, characterized in that, The device further includes: a request module; The request module is used to request the PDCP layer of the base station to perform an integrity protection operation on the NCC and the first byte stream before the generation module generates the first MAC CE based on the NCC and the first byte stream; The processing module is used to perform integrity protection on the NCC and the first byte stream through the first integrity protection key, generate a third MAC-I, and transfer the third MAC-I to the MAC layer of the base station; Wherein, the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the third MAC-I.
58. The device according to any one of claims 54 to 57, characterized in that, The parameters used by the PDCP layer of the base station to perform the encryption operation and the integrity protection operation are the first parameter or the first parameter set; Wherein, the first parameter or the first parameter set includes at least one of the following: the COUNT value is 0, the BEARER is the bearer identifier of the radio signaling bearer SRB1, and the DIRECTION is the downlink direction.
59. The device according to claim 58, characterized in that, The processing module is further used to set the second variable maintained by the PDCP entity corresponding to the SRB1 to 1 or increment it by 1, and the second variable is the variable corresponding to the COUNT value of the next PDCP service data unit SDU to be sent.
60. The device according to any one of claims 55 to 57, characterized in that, The parameters used by the PDCP layer of the base station to perform the encryption operation and the integrity protection operation are the second parameter or the second parameter set; Wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
61. A communication device, characterized in that, The device includes: a sending module, a receiving module, a processing module, and an indication module; The sending module is used to send an RRC reestablishment request message to the base station; The receiving module is used to receive a first signaling from the base station, the first signaling is used to request the UE to update the key used by the UE, the first signaling includes the NCC, and the first signaling is the second MAC CE or the PDCP control PDU; The processing module is used to update the key used by the UE based on the NCC, and generate a first encryption key and a first integrity protection key based on the updated key; The indication module is configured to instruct the PDCP layer of the UE to use the first encryption key and the first integrity protection key generated by the processing module to restore integrity protection and encryption; The processing module is further configured to, after the PDCP layer of the UE restores integrity protection and encryption by using the first encryption key and the first integrity protection key, process a second PDCP PDU from the base station, where the second PDCP PDU includes an RRC reestablishment message that is integrity-protected and encrypted, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
62. The device according to claim 61, wherein The first signaling includes third information, where the third information is a MAC-I generated by performing an integrity protection operation on the NCC; the indication module is specifically configured to request the PDCP layer of the UE to perform an integrity protection verification operation on the NCC by using the first integrity protection key and the third information; and perform an integrity protection verification operation on the NCC by using the first integrity protection key and the third information; And when the integrity protection verification operation on the NCC by the PDCP layer of the UE is passed, the RRC layer of the UE instructs the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
63. The apparatus according to claim 62, characterized in that, The processing module is further configured to enter the idle state when the integrity protection verification operation on the NCC by the PDCP layer of the UE fails.
64. The device according to claim 62, characterized in that, Parameters used by the PDCP layer of the UE to perform the integrity protection verification operation on the NCC are a second parameter or a second parameter set; Wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
65. The device according to claim 61, characterized in that, When the first signaling is a second MAC CE, the receiving module is specifically configured to receive the second MAC CE from the base station; and parse the second MAC CE to obtain the NCC, and deliver the NCC to the RRC layer of the UE.
66. The device according to claim 61, characterized in that, When the first signaling is a PDCP control PDU, the receiving module is specifically configured to receive the PDCP control PDU from the base station; and parse the PDCP control PDU to obtain the NCC, and deliver the NCC to the RRC layer of the UE.
67. The device according to claim 61, characterized in that, The processing module is specifically configured to perform a decryption operation and an integrity protection verification operation on the second PDCP PDU by using the first encryption key and the first integrity protection key, and deliver the decrypted RRC reestablishment message to the RRC layer of the UE.
68. The device according to claim 67, characterized in that, The processing module is further configured to reestablish an RRC connection based on the decrypted RRC reestablishment message; The sending module is further configured to send an RRC reestablishment completion message to the base station, where the RRC reestablishment completion message is a message processed by the PDCP layer of the UE by using the first encryption key and the first integrity protection key.
69. A communication device, characterized in that, The device includes: a receiving module and a transmitting module; The receiving module is configured to receive an RRC reestablishment request message from a UE; The transmitting module is configured to send a first signaling to the UE, the first signaling being used to request the UE to update the key used by the UE, the first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU; and send a second PDCP PDU to the UE, where the second PDCP PDU includes an RRC reestablishment message that is integrity protected and encrypted, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
70. The device according to claim 69, wherein, The device further includes: a processing module and an indication module; the processing module is configured to update the key used by the base station before the transmitting module sends the second PDCP PDU to the UE, and generate a first encryption key and a first integrity protection key based on the updated key; The indication module is configured to instruct the PDCP layer of the base station to restore integrity protection and encryption using the first encryption key and the first integrity protection key generated by the processing module.
71. The device according to claim 69, characterized in that, The device further includes: a transfer module and a generation module; The transfer module is configured to transfer the NCC saved in the UE context of the UE to the MAC layer of the base station; The generation module is configured to generate the second MAC CE based on the NCC transferred by the transfer module, the second MAC CE being used to request the UE to update the key used by the UE, and the second MAC CE includes the NCC; The transmitting module is specifically configured to send the second MAC CE generated by the generation module to the UE.
72. The device according to claim 71, characterized in that, The transfer module is specifically configured to request the PDCP layer of the base station to perform an integrity protection operation on the NCC through the first integrity protection key; and perform an integrity protection operation on the NCC through the first integrity protection key to generate a fourth MAC-I, and transfer it to the RRC layer of the base station; and transfer the NCC and the fourth MAC-I to the MAC layer of the base station; Wherein, the second MAC CE includes the NCC and the fourth MAC-I. The device according to claim 71, wherein The generation module is specifically configured to request the PDCP layer of the base station to perform an integrity protection operation on the NCC through the first integrity protection key; and perform an integrity protection operation on the NCC through the first integrity protection key to generate a fifth MAC-I, and transfer it to the MAC layer of the base station; And generate the second MAC CE based on the NCC and the fifth MAC-I, and the second MAC CE includes the NCC and the fifth MAC-I.
74. The apparatus according to claim 69, wherein The device further includes: a transfer module and a generation module; The transfer module is configured to transfer the NCC saved in the UE context of the UE to the PDCP layer of the base station; The generating module is configured to generate the PDCP control PDU based on the NCC transmitted by the transmitting module, where the PDCP control PDU is used to request the UE to update the key used by the UE, and the PDCP control PDU includes the NCC; The transmitting module is specifically configured to transmit the PDCP control PDU generated by the generating module to the UE.
75. The apparatus according to claim 74, wherein, The generating module is specifically configured to perform an integrity protection operation on the NCC by using the first integrity protection key to generate a sixth MAC-I; and generate the PDCP control PDU based on the NCC and the sixth MAC-I, where the PDCP control PDU includes the sixth MAC-I.
76. The device according to claim 72 or 73 or 75, characterized in that, The parameters used by the PDCP layer of the base station to perform the integrity protection operation on the NCC are the second parameter or the second parameter set; Wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction. The device according to claim 70, wherein The transmitting module is specifically configured to generate the RRC reestablishment message and transmit it to the PDCP layer of the base station; and perform an encryption operation and an integrity protection operation on the RRC reestablishment message by using the first encryption key and the first integrity protection key to generate the second PDCP PDU; And transmit the second PDCP PDU to the radio link control RLC layer of the base station; And transmit the second PDCP PDU to the UE. The device according to any one of claims 70 to 77, characterized in that The transmitting module is specifically configured to transmit the second PDCP PDU to the UE after the first signaling is transmitted, or after the first signaling is successfully transmitted, or after the base station receives the reception confirmation message of the first signaling.
79. A user equipment, characterized in that, It includes a processor and a memory, where the memory stores a program or instruction that can run on the processor, and when the program or instruction is executed by the processor, the steps of the communication method according to any one of claims 1 to 11 are implemented.
80. A user equipment, characterized in that, It includes a processor and a memory, where the memory stores a program or instruction that can run on the processor, and when the program or instruction is executed by the processor, the steps of the communication method according to any one of claims 22 to 29 are implemented.
81. A base station, characterized in that, It includes a processor and a memory, where the memory stores a program or instruction that can run on the processor, and when the program or instruction is executed by the processor, the steps of the communication method according to any one of claims 12 to 21 are implemented.
82. A base station, characterized in that, It includes a processor and a memory, where the memory stores a program or instruction that can run on the processor, and when the program or instruction is executed by the processor, the steps of the communication method according to any one of claims 30 to 39 are implemented.
83. A readable storage medium, characterized in that, The program or instruction is stored on the readable storage medium, and when the program or instruction is executed by the processor, it implements the steps of the communication method according to any one of claims 1 to 11, or implements the steps of the communication method according to any one of claims 12 to 21, or implements the steps of the communication method according to any one of claims 22 to 29, or implements the steps of the communication method according to any one of claims 30 to 39.