Communication method, device and system

By using different next-hop link counters and next-hop in LTM cross-site handover, the key is updated, and the problem of secure communication between terminals and network devices in LTM cross-site handover is solved, and secure continuous communication is achieved and signaling overhead is reduced.

CN120434733APending Publication Date: 2025-08-05HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410154755.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-02-02
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

In the LTM cross-site switching scenario, the existing technology has not yet effectively solved how to achieve secure communication between the terminal and the network device.

Method used

By using different next hop link counters (NCC) and next hop (NH) during multiple handovers, there is no need to pass security-related information through RRC reconfiguration messages, and the identification information and root key update keys are used to ensure secure communication between the terminal and network equipment.

Benefits of technology

It realizes secure continuous communication between the terminal and the network device in the LTM cross-site handover scenario, reduces signaling overhead and improves the security of cross-site handover.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120434733A_ABST
    Figure CN120434733A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, and discloses a communication method, device and system. The method comprises the following steps: a terminal side device accesses a first network side device and communicates with the first network side device by using a first next hop link counter NCC, and the first NCC is obtained by adding 1 on the basis of a second NCC by the terminal side device; the second NCC is an NCC used for communication between the terminal side device and the second network side device, or the second NCC is an NCC used for accessing the first network side device last time. Thus, during multiple times of switching, security related information does not need to be transmitted to the terminal side device through an RRC reconfiguration message, thereby facilitating reduction of signaling overhead, and ensuring secure communication between the terminal side device and the network equipment side device at the same time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a communication method, apparatus, and system. Background Art

[0002] Cell handover is a very important feature in a communication system. Mainly before the signal quality of the serving cell becomes poor, the network device switches the terminal device to a neighboring cell with better signal quality, so as to provide a lossless or packet-lossless communication service.

[0003] In order to reduce the handover delay, currently, layer 1 / layer 2 triggered mobility (LTM) handover is introduced. The LTM handover can be triggered by layer 1 / layer 2 signaling.

[0004] However, in the LTM inter-site handover scenario, how to achieve secure communication between the terminal and the network device still needs further research. Summary of the Invention

[0005] This application provides a communication method, apparatus, and system for achieving secure communication between a terminal and a network device.

[0006] In a first aspect, an embodiment of this application provides a communication method. This method can be applied to a terminal-side device, and the terminal-side device can be a terminal or a component in the terminal (such as a chip or a circuit). For example, in this method, the terminal-side device accesses a first network-side device; communicates with the first network-side device using a first next-hop link counter NCC, where the first NCC is obtained by adding 1 to the second NCC of the terminal-side device; the second NCC is the NCC used by the terminal-side device to communicate with a second network-side device, or the second NCC is the NCC used for the last access to the first network-side device.

[0007] By using the above method, for multiple handovers to the same network device, different NHs can be used, so that there is no need to transmit security-related information to the terminal through an RRC reconfiguration message, which is convenient for achieving secure communication between the terminal and the network device in the LTM inter-site handover scenario and ensuring secure communication for continuous inter-site handovers.

[0008] In a possible design, the method further includes: receiving a first message, where the first message includes the second NCC.

[0009] In a possible design, the first message further includes identification information associated with the first network-side device; the method further includes: determining that a key needs to be updated based on the identification information associated with the first network-side device (i.e., the identification information associated with the target cell) and the identification information associated with the second network-side device (i.e., the identification information associated with the source cell), and the key update includes: determining the first NCC and the next hop NH associated with the first NCC.

[0010] It can be understood that "needing to update the key" here can also be understood as "needing to perform vertical deduction of NH" or "needing to replace NH".

[0011] In a possible design, the identification information associated with the first network-side device is associated with the second NCC, or in other words, the cell of the first network-side device (such as the above-mentioned target cell) is associated with the second NCC.

[0012] In a possible design, the first message further includes root key information associated with the second NCC.

[0013] In this way, in the case of replacing the root key, the root key information can be sent to the terminal through the first message, and the security can be effectively improved by replacing the root key.

[0014] The communication method provided in the first aspect above can be replaced with: the terminal-side device receives a first message, the first message is used to indicate N NCCs, N is an integer greater than 1; accesses the first network-side device; and communicates with the first network-side device using the first NCC, the first NCC is one of the N NCCs, and the NH associated with the first NCC is an unused NH.

[0015] In a possible design, the first message includes N NCCs; or, the first message includes the starting NCC among the N NCCs and the value of N, and the N NCCs are consecutive.

[0016] In a possible design, the first message includes identification information associated with the first network-side device; the method further includes: determining that a key needs to be updated based on the identification information associated with the first network-side device and the identification information associated with the second network-side device, and the key update includes: determining the first NCC and the NH associated with the first NCC.

[0017] In a possible design, the identification information associated with the first network-side device is associated with the N NCCs, or in other words, the cell of the first network-side device (such as the above-mentioned target cell) is associated with the N NCCs.

[0018] In a possible design, the first message further includes the root key information associated with the N NCCs.

[0019] In a possible design, accessing the first network-side device includes: initiating a mobility LTM handover triggered by layer 1 / layer 2 to access the first network-side device; or, after the LTM handover fails, accessing the first network-side device through LTM configuration.

[0020] In a second aspect, an embodiment of the present application provides a communication method, which can be applied to a first network-side device. The first network-side device can be a first network device or a component in the first network device (such as a chip or a circuit). For example, in this method, the first network-side device receives a second message, the second message includes N NHs, and N is an integer greater than or equal to 1; determines that the terminal-side device accesses the first network-side device; and uses the first NH among the N NHs to communicate with the terminal-side device, where the first NH is the NH that has not been used among the N NHs.

[0021] By using the above method, for multiple handovers to the first network device, different NHs can be used, so that there is no need to transmit security-related information to the terminal through an RRC reconfiguration message, which facilitates secure communication between the terminal and the network device in the LTM inter-site handover scenario and ensures secure communication for continuous inter-site handovers.

[0022] In a possible design, the N NHs are sorted in a first order, and the first NH is the first unused NH among the N NHs.

[0023] In a possible design, the method further includes: determining the first order based on the second message.

[0024] In a possible design, the N NHs included in the second message are sorted in a first order.

[0025] In a possible design, the second message is used to indicate the NCCs associated with the N NHs; the sorting of the N NHs in the first order includes: the N NHs are sorted from small to large based on the NCCs associated with the N NHs.

[0026] In a possible design, determining that the terminal-side device accesses the first network-side device includes: determining that the terminal-side device initiates an LTM handover to access the first network-side device; or determining that the terminal-side device accesses the first network-side device through LTM configuration after the LTM handover fails.

[0027] In a possible design, the method further includes: sending a third message to a core network element, where the third message is used to request to provide NH to the first network-side device; receiving the second message, including: receiving the second message from the core network element, and the second message is a response message to the third message.

[0028] In a possible design, the third message includes the quantity information of NH.

[0029] In a possible design, sending the third message to the core network element includes: receiving a fourth message from a third network-side device, where the fourth message is used to request the LTM configuration of the first network-side device; in response to the fourth message, sending the third message to the core network element.

[0030] Here, the fourth message is used to request the LTM configuration of the first network-side device, which can be understood as that the fourth message is used to request the LTM configuration of a certain candidate cell of the first network-side device. The fourth message may include the identification information of the candidate cell, such as CGI.

[0031] In a possible design, the method further includes: sending a first message to a terminal-side device, where the first message is used to indicate the NCCs associated with the N NHs.

[0032] In a possible design, the first message includes the NCCs associated with the N NHs; or, the first message includes a second NCC, the N NHs are sorted in ascending order based on the NCCs associated with the N NHs, the NCCs associated with the N NHs are consecutive, and the second NCC is the NCC associated with the starting NH among the N NHs.

[0033] In a possible design, the first message further includes the identification information associated with the first network-side device, and the identification information associated with the first network-side device is associated with the second NCC, or the identification information associated with the first network-side device is associated with the NCCs associated with the N NHs.

[0034] In a possible design, the method further includes: sending a fifth message to a core network element, where the fifth message is used to request path switching, and the fifth message is further used to indicate not to update NH.

[0035] In a third aspect, an embodiment of the present application provides a communication method, which can be applied to a third network side device. The third network side device can be a third network device or a component (such as a chip or a circuit) in the third network device. For example, in this method, the third network side device receives a sixth message from a core network element, the sixth message includes W NHs, where W is an integer greater than 1; sends a second message to the first network side device, the second message includes N NHs, the W NHs include the N NHs, and N is an integer greater than or equal to 1; sends a first message to the terminal side device, the first message is used to indicate the NCCs associated with the N NHs.

[0036] By using the above method, the third network device requests NHs from the core network element and distributes the requested multiple NHs to each candidate network device. Furthermore, for multiple handovers to the same network device, different NHs can be used, and there is no need to transmit security-related information to the terminal through an RRC reconfiguration message, which facilitates secure communication between the terminal and the network device in the LTM inter-site handover scenario, improves the security of continuous inter-site handovers, and ensures secure communication for continuous inter-site handovers.

[0037] In a possible design, the first message includes the NCCs associated with the N NHs; or, the first message includes a second NCC, the N NHs are sorted in ascending order based on the NCCs associated with the N NHs, the NCCs associated with the N NHs are consecutive, and the second NCC is the NCC associated with the starting NH among the N NHs.

[0038] In a possible design, the first message further includes identification information associated with the first network side device, and the identification information associated with the first network side device is associated with the second NCC or the NCCs associated with the N NHs.

[0039] In a possible design, the W NHs further include M NHs, and the M NHs are different from the N NHs; the method further includes: determining that the terminal side device accesses the third network side device; using the second NH among the M NHs to communicate with the terminal side device, and the second NH is the NH among the M NHs that has not been used.

[0040] Fourthly, an embodiment of the present application provides a communication method, which can be applied to a third network-side device. The third network-side device can be a third network device or a component (such as a chip or a circuit) in the third network device. For example, in this method, the third network-side device receives a sixth message from a core network element. The sixth message includes W NHs, where W is an integer greater than 1; receives a seventh message, and the seventh message is used to request security information; in response to the seventh message, sends the security information, and the security information includes the first NH among the W NHs, or an index of the first NH, or a key deduced based on the first NH. The first NH is an unused NH among the W NHs.

[0041] By using the above method, the third network device requests W NHs from the core network element. At each handover, the third network device allocates an unused NH to the target network device of the current handover, so that different NHs can be used for each handover, and there is no need to transmit security-related information to the terminal through an RRC reconfiguration message, which is convenient for implementing secure communication between the terminal and the network device in the LTM inter-site handover scenario, improving the security of continuous inter-site handovers, and ensuring secure communication for continuous inter-site handovers.

[0042] In a possible design, the W NHs are sorted in a first order, and the first NH is the first unused NH among the W NHs.

[0043] In a possible design, the method further includes: determining the sorting of the W NHs based on the second message.

[0044] In a possible design, the W NHs included in the second message are sorted in a first order.

[0045] In a possible design, the second message includes NCCs associated with the W NHs; the sorting of the W NHs in a first order includes: the W NHs are sorted from small to large based on the NCCs associated with the W NHs.

[0046] In a possible design, the method further includes: sending a first message to the terminal-side device, and the first message is used to indicate the NCCs associated with the W NHs.

[0047] In a possible design, the first message includes the NCCs associated with the W NHs; or, the first message includes a second NCC. The W NHs are sorted from small to large based on the NCCs associated with the W NHs, and the NCCs associated with the W NHs are consecutive. The second NCC is the NCC associated with the starting NH among the W NHs.

[0048] In a possible design, the method further includes: sending the W NHs, where the index of the first NH is used to determine the first NH from the W NHs.

[0049] In a fifth aspect, an embodiment of the present application provides a communication method, which can be applied to a first network-side device. The first network-side device can be a first network device or a component in the first network device (such as a chip or a circuit). For example, in this method, the first network-side device determines that a terminal-side device accesses the first network-side device; sends a seventh message, where the seventh message is used to request security information; receives the security information, where the security information includes the first NH or the index of the first NH or a key deduced based on the first NH; and uses the security information to communicate with the terminal-side device.

[0050] In a possible design, determining that the terminal-side device accesses the first network-side device includes: determining that the terminal-side device initiates an LTM handover to access the first network-side device; or determining that the terminal-side device accesses the first network-side device through LTM configuration after an LTM handover fails.

[0051] In a possible design, the method further includes: sending a fifth message to a core network element, where the fifth message is used to request a path switch, and the fifth message is further used to indicate not to update the NH.

[0052] It can be understood that the communication methods provided in the second aspect to the fifth aspect correspond to the first aspect. The beneficial effects of the relevant technical features in the second aspect to the fifth aspect can be referred to the description of the first aspect and will not be elaborated here.

[0053] In a sixth aspect, the present application provides a communication device, which has the functions involved in any one of the first aspect to the fifth aspect above. For example, the communication device includes a module, a unit, or a means corresponding to the operations involved in any one of the first aspect to the fifth aspect above. The function, unit, or means can be implemented by software, or by hardware, or by hardware executing corresponding software.

[0054] In a possible design, the communication device includes a processing unit and a communication unit. Among them, the communication unit can be used to transmit and receive signals to implement communication between the communication device and other devices; the processing unit can be used to perform some internal operations of the communication device. The functions performed by the processing unit and the communication unit can correspond to the operations involved in any one of the first aspect to the fifth aspect above.

[0055] In a possible design, the communication device includes a processor, which can be used to couple with a memory. The memory can store necessary computer programs or instructions for implementing the functions involved in any one of the first to fifth aspects above. The processor can execute the computer programs or instructions stored in the memory. When the computer programs or instructions are executed, the communication device implements the methods in any possible design or implementation manner of the first to fifth aspects above.

[0056] In a possible design, the communication device includes a processor and a memory. The memory can store necessary computer programs or instructions for implementing the functions involved in any one of the first to fifth aspects above. The processor can execute the computer programs or instructions stored in the memory. When the computer programs or instructions are executed, the communication device implements the methods in any possible design or implementation manner of the first to fifth aspects above.

[0057] In a possible design, the communication device includes a processor and an interface circuit. The processor is used to communicate with other devices through the interface circuit and execute the methods in any possible design or implementation manner of the first to fifth aspects above.

[0058] It can be understood that in the sixth aspect above, the processor can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc.; when implemented by software, the processor can be a general-purpose processor that implements by reading the software code stored in the memory. In addition, the above processor can be one or more, and the memory can be one or more. The memory can be integrated with the processor, or the memory and the processor are separately arranged. In the specific implementation process, the memory can be integrated with the processor on the same chip, or can be separately arranged on different chips. The embodiments of the present application do not limit the type of the memory and the setting manner of the memory and the processor.

[0059] In a seventh aspect, the present application provides a communication system, which may include a terminal-side device and a first network-side device. The terminal-side device is used to execute the method described in the first aspect above, and the first network-side device is used to execute the method described in the second aspect above. Optionally, the communication system further includes a third network-side device, and the third network-side device is used to execute the method described in the third aspect above.

[0060] Alternatively, the communication system includes a terminal-side device and a third network-side device. The terminal-side device is configured to execute the method described in the first aspect above, and the first network-side device is configured to execute the method described in the fourth aspect above. Optionally, the communication system further includes a first network-side device, and the first network-side device is configured to execute the method described in the fifth aspect above.

[0061] In an eighth aspect, the present application provides a computer-readable storage medium. The computer-readable instructions are stored in the computer storage medium. When the computer reads and executes the computer-readable instructions, the computer is caused to execute the method in any possible design of the first aspect to the fifth aspect above.

[0062] Exemplarily, the computer-readable storage medium may be any available medium that the computer can access. Taking this as an example but not limited to: the computer-readable medium may include a non-transitory computer-readable medium, random-access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), CD-ROM or other optical disc storage, magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by the computer.

[0063] In a ninth aspect, the present application provides a computer program product. When the computer reads and executes the computer program product, the computer is caused to execute the method in any possible design of the first aspect to the fifth aspect above.

[0064] In a tenth aspect, the present application provides a chip (or chip system). The chip includes a processor, and the processor is coupled to a memory and is configured to read and execute the software program stored in the memory to implement the method in any possible design of the first aspect to the fifth aspect above. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] Figure 1 FIG. is a schematic diagram of a communication system applicable to an embodiment of the present application;

[0066] Figure 2 FIG. is a schematic diagram of key derivation provided by an embodiment of the present application;

[0067] Figure 3 FIG. is a schematic diagram of a possible process of ordinary cross-site switching provided by an embodiment of the present application;

[0068] Figure 4 FIG. is a schematic diagram of a process associated with the communication method provided in Embodiment 1 of the present application;

[0069] Figure 5A Schematic flow diagram associated with the communication method provided in the second embodiment of this application;

[0070] Figure 5B NH schematic diagram provided in the embodiment of this application;

[0071] Figure 6 Schematic flow diagram associated with the communication method provided in the third embodiment of this application;

[0072] Figure 7 Schematic flow diagram associated with the communication method provided in the fourth embodiment of this application;

[0073] Figure 8 Schematic flow diagram associated with the communication method provided in the fifth embodiment of this application;

[0074] Figure 9 Schematic flow diagram associated with the communication method provided in the sixth embodiment of this application;

[0075] Figure 10 Possible exemplary block diagram of the device involved in the embodiment of this application;

[0076] Figure 11 Schematic structural diagram of a network - side device provided in the embodiment of this application;

[0077] Figure 12 Schematic structural diagram of a terminal - side device provided in the embodiment of this application. Detailed implementation manners

[0078] Next, the technical solutions in the embodiments of this application will be described in conjunction with the accompanying drawings in the embodiments of this application. The technical solutions in the embodiments of this application can be applied to various communication systems, such as Universal Mobile Telecommunications System (UMTS), Wireless Local Area Network (WLAN), Wireless Fidelity (Wi - Fi) system, 4th Generation (4G) mobile communication system, such as Long Term Evolution (LTE) system, 5th Generation (5G) mobile communication system, such as New Radio (NR) system, and future evolved communication systems, such as 6th Generation (6G) mobile communication system, etc.

[0079] Aspects, embodiments or features of the present application will be presented in the context of a system that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in connection with the figures. In addition, combinations of these solutions may also be used.

[0080] In addition, in the embodiments of the present application, words such as "exemplarily" and "such as" are used to represent examples, illustrations or explanations. Any embodiment or design described as an "example" in the present application should not be construed as more preferred or more advantageous than other embodiments or designs. Rather, the use of the word "example" is intended to present concepts in a specific manner. In the embodiments of the present application, "of", "corresponding", and "associated" may sometimes be used interchangeably. It should be noted that when the differences are not emphasized, their intended meanings are the same.

[0081] To facilitate understanding of the embodiments of the present application, first, Figure 1 The communication system shown in is used as an example to detail the communication system applicable to the embodiments of the present application. As Figure 1 shown, the communication system 1000 includes a radio access network 100, and optionally, a core network 200. Among them, the radio access network 100 may include at least one network device, such as Figure 1 110a and 110b in, and may also include at least one terminal, such as Figure 1 120a - 120j in. Among them, 110a is a base station, 110b is a micro-station, 120a, 120e, 120f and 120j are mobile phones, 120b is a car, 120c is a fuel dispenser, 120d is a home access point (HAP) arranged indoors or outdoors, 120g is a laptop computer, 120h is a printer, and 120i is a drone.

[0082] Figure 1 In, the terminal can be connected to the network device, and the network device can be connected to the core network device in the core network. The core network device and the network device can be independent different physical devices, or the functions of the core network device and the logical functions of the network device can be integrated on the same physical device, or the functions of part of the core network device and part of the network device can be integrated on a physical device. The terminals can be connected to each other and the network devices can be connected to each other in a wired or wireless manner. Figure 1 This is just a schematic diagram, and other devices may also be included in this communication system, such as wireless relay devices and wireless backhaul devices, which are not drawn in Figure 1 .

[0083] (1) Terminal

[0084] The terminal can be a device that accesses the above communication system and has wireless transceiver functions. The terminal can also be referred to as user equipment (UE), terminal device, user device, access terminal, user unit, user station, mobile station (MS), remote station, remote terminal, mobile device, user terminal, terminal unit, terminal station, terminal device, wireless communication device, user agent, or user device.

[0085] For example, the terminal in the embodiments of the present application can be a mobile phone, personal digital assistant (PDA) computer, laptop computer, tablet (Pad), drone, computer with wireless transceiver functions, machine type communication (MTC) terminal, virtual reality (VR) terminal, augmented reality (AR) terminal, internet of things (IoT) terminal, wireless terminal in industrial control, wireless terminal in self-driving, wireless terminal in remote medical, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, wireless terminal in smart home (such as game console, smart TV, smart speaker, smart refrigerator, and fitness equipment, etc.), vehicle-mounted terminal, RSU with terminal functions.

[0086] (2) Network device

[0087] The network device is located on the network side of the above communication system and has wireless transceiver functions. The network device can also be referred to as an access network node, access network device, or wireless access network device.

[0088] In a possible scenario, the network device can be a base station, an evolved NodeB (eNB), an access point (AP), a transmission reception point (TRP), a next generation-evolved NodeB (ng-eNB), a next generation NodeB (gNB), a next generation base station in a 6G mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system, etc. The network device can be a macro base station (such as Figure 1 110a in Figure 1 ), a micro base station or an indoor station (such as

[0089] 110b in

[0090] ), a relay node or a donor node. Optionally, the network device can also be a server, a wearable device, a vehicle or an in-vehicle device, etc. For example, the network device in vehicle to everything (V2X) technology can be a road side unit (RSU).

[0091] (3) Core network element

[0092] The core network 200 may include one or more core network elements, such as an access and mobility management function (AMF) element, a user plane function (UPF) element, a session management function (SMF) element, a policy control function (PCF) element, etc. Among them, the network device and the core network elements in the core network can be connected through the NG interface. For example, the network device and the AMF element are connected through the NG-C interface, and the network device and the UPF element are connected through the NG-U interface.

[0093] The UPF element is mainly responsible for connecting to the external network and forwarding user data packets according to the routing rules of the SMF element. For example, the uplink data is sent to the data network or other UPF elements, and the downlink data is sent to other UPF elements or the access network device.

[0094] The AMF element is mainly responsible for the access management and mobility management of the terminal device. For example, it is responsible for maintaining the status of the terminal device, managing the reachability of the terminal device, forwarding mobility management non-access-stratum (MM NAS) messages, and forwarding session management (SM) N2 messages.

[0095] The SMF element is mainly responsible for session management in the mobile network, including establishing a session for the terminal device, allocating and releasing resources for the session. The resources include session quality of service (QoS), session path, forwarding rules, etc. For example, allocating an Internet Protocol (IP) address for the terminal device, selecting a UPF element that provides packet forwarding functions, etc.

[0096] The PCF element is mainly responsible for user policy management, including policy authorization, generation of quality of service and charging rules, and sending the corresponding rules to the UPF element through the SMF element to complete the installation of the corresponding policies and rules.

[0097] Although not shown, the above core network may also include other possible network elements, which are not specifically limited.

[0098] The network element in the above communication system can be either a network element in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). Optionally, the above network element can be implemented by one device, jointly implemented by multiple devices, or different functional modules within one device. The embodiments of the present application do not make specific limitations in this regard.

[0099] The network architecture and service scenarios described in the embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those of ordinary skill in the art can know that with the evolution of the communication system architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0100] First, the relevant terms involved in the embodiments of the present application will be explained below. When not specifically stated, these explanations are to support the meanings of the relevant terms and make the embodiments of the present application easier to understand, rather than being regarded as strict limitations on the relevant terms within the scope of protection required by the present application.

[0101] (1) Key derivation

[0102] To ensure secure data transmission between the terminal and the network side, both the terminal and the network side need to perform the same key derivation to ensure that the terminal and the network side use the same key. Herein, the "network side" can include network devices (such as access network devices or gNBs). "Derivation" can also be replaced by "derivation" or other descriptions, without limitation.

[0103] The parameters related to key derivation include the next hop (NH) and the NH link counter (NCC).

[0104] NH: Intermediate key, obtained by chain derivation based on the root key KAMF.

[0105] NCC: In chain derivation, the number of derivation times of NH, NCC is associated with NH. One NCC can uniquely determine one NH.

[0106] Specifically, NH is obtained by the terminal and the AMF network element through chain derivation, that is, the NH generated this time will be used to generate the next NH. The AMF network can send the derived NH and NCC to the network device to facilitate secure communication between the network device and the terminal based on NH. The root key KAMF can be understood as the core network key.

[0107] In one example, the NCC in the embodiments of the present application may include 3 bits and can identify up to 8 NHs at most. In another example, the NCC in the embodiments of the present application may also be replaced by NCC', where NCC' is a combination of NCC and H-NCC, or NCC' is a newly defined NCC. Among them, H-NCC is based on NCC and adds several higher bits to identify more NHs. For example, NCC can identify up to 8 NHs, but H-NCC is also 3 bits, then NCC' is 6 bits and can identify 64 NHs.

[0108] Figure 2 It is a schematic diagram of the process for a network device and a terminal to perform key derivation.

[0109] Horizontal derivation:

[0110] At initial access, the network device can derive the initial key KgNB (i.e., initialKgNB) according to the root key (i.e., KAMF), and derive KgNB1 according to the initial key KgNB. Subsequently, if horizontal derivation is to be performed, the network device derives the key KgNB2 according to KgNB1, the physical cell identifier (PCI) of the cell where the terminal is currently camped, and the frequency point, for example, the downlink frequency point. If horizontal derivation continues, the network device can derive the key KgNB3 according to the key KgNB2, the PCI of the cell where the terminal is currently camped, and the frequency point. And so on, to iteratively update the key KgNB to ensure communication security.

[0111] Vertical derivation:

[0112] This derivation method is for the vertical derivation of NH. The AMF network element can update the NCC (for example, when a path switch occurs during a handover process, the AMF network element can update the NCC). If NCC1 is updated to NCC2, the AMF network element derives NH2 according to KAMF and NCC2. NH2 is associated with NCC2 as a new pair {NH2, NCC2}. The AMF network element can send {NH2, NCC2} to the network device. Then, when the network device needs to derive a key after receiving {NH2, NCC2}, it can perform vertical derivation, that is, derive the key KgNB4 according to NH2, the PCI of the cell where the terminal is currently camped, and the frequency point, and so on.

[0113] According to Figure 2It can be known that the number of vertical deductions can be determined by the difference between the NCC values before and after the update. For example, if the NCC value is updated from NCC0 to NCC1, 1 vertical deduction can be performed based on NH0 related to NCC0 to obtain NH1 related to NCC1. If the NCC value is updated from NCC0 to NCC2, 2 vertical deductions can be performed based on NH0 related to NCC0 to obtain NH2 related to NCC2. If the NCC value is updated from NCC2 to NCC3, 1 vertical deduction can be performed based on NH2 related to NCC2 to obtain NH3 related to NCC3.

[0114] (2) Cell handover

[0115] Cell handover (switch or handover) can be divided into two types. One is the cell handover implemented based on Layer 1 / Layer 2, which can be called Layer 1 / Layer 2 handover or LTM handover. The other is the cell handover implemented based on Layer 3, which can be called Layer 3 handover (L3 handover) or normal handover. Here, Layer 1 can refer to the physical layer, Layer 2 can refer to any one or more of the packet data convergence protocol (PDCP) layer, radio link control (RLC) layer, and media access control (MAC) layer, and Layer 3 can refer to the radio resource control (RRC) layer. Since Layer 1 / Layer 2 is at a lower layer of the protocol stack than the RRC layer (Layer 3), Layer 1 / Layer 2 handover can also be called low-layer handover, or bottom-layer handover, or lower-layer handover. This application does not limit the name of the specific handover technology.

[0116] Compared with Layer 3 handover, LTM handover can effectively reduce the handover delay. The reason is as follows: For Layer 3 handover, in the CU-DU separation architecture, the CU receives the measurement results of the terminal (which are forwarded to the CU by the DU), and determines whether to initiate a handover based on these measurement results. If it is determined to initiate a handover, a handover command message (such as an RRC message) is sent to the DU, and then sent to the terminal by the DU. Since this process involves communication interaction between the CU and the DU (i.e., the interaction of the F1 interface), and the maximum transmission delay of the F1 interface is about 3 ms to 10 ms, it will cause a certain handover delay. However, for LTM handover, the handover decision is issued from the CU to the DU, that is, the DU determines whether to initiate LTM handover based on the measurement results of the terminal. If it is determined to initiate a handover, a handover command message (such as a MAC layer message) is sent to the terminal, thus effectively reducing F1 interaction and lowering the handover delay.

[0117] (3) Scenarios of cell handover

[0118] When the terminal switches between different cells, there may be various specific handover scenarios. For example, the handover scenarios can be divided according to the positional relationship between the source cell and the target cell.

[0119] Scenario 1: The terminal switches from a cell of network device 1 to a cell of network device 2. At this time, network device 1 can be referred to as the source network device, and network device 2 can be referred to as the target network device; that is, the source cell and the target cell of the terminal belong to different network devices. The cell handover associated with Scenario 1 can be referred to as an inter-gNB handover.

[0120] Exemplarily, when adopting a CU-DU split architecture (for example, a network device includes a CU and multiple DUs, and the multiple DUs are centrally controlled by a CU, and each of the multiple DUs can include one or more cells), network device 1 includes CU1 and DU1, and network device 2 includes CU2 and DU2. The above Scenario 1 can also be described as: The terminal switches from a cell of DU1 controlled by CU1 to a cell of DU2 controlled by CU2. That is, the source cell and the target cell of the terminal belong to different CUs. Therefore, the inter-gNB handover can also be understood as an inter-CU handover.

[0121] Scenario 2: The terminal switches from a cell of a network device to another cell of the same network device. That is, the source cell and the target cell of the terminal belong to the same network device. The cell handover associated with Scenario 2 is an intra-gNB handover.

[0122] In the embodiments of this application, the inter-gNB handover implemented based on layer 3 is referred to as a normal inter-gNB handover, and the inter-gNB handover implemented based on layer 1 / layer 2 is referred to as an LTM inter-gNB handover.

[0123] (4) Secure communication for normal inter-gNB handover

[0124] Figure 3 is a schematic diagram of a possible process for normal inter-gNB handover. Figure 3 The illustrated inter-gNB handover includes the terminal switching from network device 0 to network device 1, and then from network device 1 to network device 2. As Figure 3 shown, this process includes:

[0125] S301, the terminal connects to the core network through network device 0.

[0126] The terminal can access the network device 0 through an initial access process or other possible processes, and access the core network through the network device 0. Furthermore, the key KgNB (for ease of description, referred to as K0) and NCC0 (K0 is associated with NCC0) are respectively saved on the terminal and the network device 0, and NCC0 is saved on the AMF network element.

[0127] It should be noted that in any embodiment of this application, the number carried after NCC is only used to distinguish different NCCs and does not represent a specific NCC value; for example, NCC0 is used to represent the NCC value used on the network device 0, and it is not limited that the NCC value is 0. The symbols K0, K1 or K2 used in the embodiments of this application * etc. all refer to the keys for security protection between the terminal and the network device. For example Figure 2 the KgNB, KgNB1 to KgNB12, etc. involved in * and which specific KgNB K0, K1 or K2 specifically refers to can be related to the scenario, and the embodiments of this application do not limit this.

[0128] S302. The network device 0 determines that the terminal needs to be switched.

[0129] As the terminal moves, for example, the terminal gradually moves away from the network device 0, and the network device 0 can sense that the signal strength of the terminal gradually weakens. When the signal strength of the terminal weakens to a certain extent, the network device 0 determines that the terminal needs to be switched to a network device with better signal strength, and thus can select a network device with relatively good signal strength from multiple candidate network devices, such as the network device 1.

[0130] S303. The network device 0 sends a handover request message to the network device 1. Correspondingly, the network device 1 receives the handover request message from the network device 0.

[0131] For example, the network device 0 can horizontally deduce the key K1 based on K0, the PCI of the cell on the network device 1, and the frequency point. The handover request message can include NCC0 and K1, and the handover request message is used to request to switch the terminal to the network device 1; after receiving the handover request information, the network device 1 can save NCC0 and K1.

[0132] S304. The network device 1 sends a handover response message to the network device 0. Correspondingly, the network device 0 receives the handover response message from the network device 1.

[0133] For example, the handover response message is a handover request ACK message, which is used to indicate that Network Device 1 allows the terminal to hand over. The handover request ACK message may include Configuration Information 1, and Configuration Information 1 includes parameters for the terminal to hand over to Network Device 1 and NCC0 received by the above Network Device 1.

[0134] S305, Network Device 0 sends a handover command message to the terminal; correspondingly, the terminal receives the handover command message.

[0135] The handover command message may be an RRC reconfiguration message, and this RRC reconfiguration message carries Configuration Information 1.

[0136] S306, the terminal derives a key.

[0137] The terminal can obtain NCC0 from the above Configuration Information 1. If the NCC0 obtained from Configuration Information 1 is the same as the NCC value locally saved by the terminal, the terminal can perform horizontal derivation, that is, derive the key K1 according to K0, the PCI of the cell on Network Device 1, and the frequency point. In this way, the terminal and Network Device 1 maintain the same key, that is, K1.

[0138] S307, the terminal sends a handover completion message to Network Device 1. Correspondingly, Network Device 1 receives the handover completion message from the terminal.

[0139] The handover completion message may be an RRC reconfiguration complete message.

[0140] S308, Network Device 1 sends a path handover request message to the AMF network element; correspondingly, the AMF network element receives the path handover request message.

[0141] S309, the AMF network element sends a path handover response message to Network Device 1; correspondingly, Network Device 1 receives the path handover response message, and then completes the path handover.

[0142] Path handover means that the data transmission path of the terminal is switched from "UPF network element - Network Device 0 - terminal" to "UPF network element - Network Device 1 - terminal". That is, before the path handover, the downlink data is sent from the UPF network element to Network Device 0, and then from Network Device 0 to the terminal; the uplink data is sent from the terminal to Network Device 0, and then from Network Device 0 to the UPF network element; after the path handover, the downlink data is sent from the UPF network element to Network Device 1, and then from Network Device 1 to the terminal; the uplink data is sent from the terminal to Network Device 1, and then from Network Device 1 to the UPF network element.

[0143] After the AMF network element receives the path switching request message, it can increment the locally saved NCC value by 1 to obtain the updated NCC (referred to as NCC1), and perform key derivation based on the updated NCC to obtain the updated NH (referred to as NH1). NCC1 and NH1 are associated as an updated pair {NH1, NCC1}.

[0144] The path switching response message includes {NH1, NCC1}. After the network device 1 receives the path switching response message, it can save {NH1, NCC1}.

[0145] S310, the terminal communicates with the network device 1 using the key K1.

[0146] Here, "the terminal communicates with the network device 1 using the key K1" can mean that the terminal communicates with the network device 1 using the key K1 itself; or it can also mean that the terminal communicates with the network device 1 using Krrc and Kup derived from the key K1. Among them, Krrc is used for encryption, decryption, and integrity protection of control messages, and Kup is used for encryption, decryption, and integrity protection of user data. Other similar descriptions in this application can be processed in the same way.

[0147] S311, the network device 1 determines that the terminal needs to switch.

[0148] The specific implementation for the network device 1 to determine that the terminal needs to switch can refer to the description of the network device 0 determining that the terminal needs to switch. The network device 1 can select a network device with better signal strength from multiple candidate network devices, such as the network device 2.

[0149] S312, the network device 1 sends a switching request message to the network device 2. Correspondingly, the network device 2 receives the switching request message from the network device 1.

[0150] The network device 1 can derive the key K2 based on NH1, the PCI and frequency point of the cell on the network device 2 * , and send a switching request message to the network device 2. The switching request message is used to request to switch the terminal to the network device 2, and the switching request message may include NCC1 and K2 * ; after the network device 1 receives the switching request message, it can save NCC1 and K2 * .

[0151] S313, the network device 2 sends a switching response message to the network device 1. Correspondingly, the network device 1 receives the switching response message from the network device 2.

[0152] For example, the handover response message is a handover request confirmation message, which is used to indicate that the network device 2 allows the terminal to hand over. The handover request confirmation message may include configuration information 2, and the configuration information 2 includes parameters for the terminal to hand over to the network device 2 and the NCC1 received by the above network device 2.

[0153] S314, the network device 1 sends a handover command message to the terminal; correspondingly, the terminal receives the handover command message.

[0154] The handover command message may be an RRC reconfiguration message, and the RRC reconfiguration message carries the above configuration information 2.

[0155] S315, the terminal derives a key.

[0156] The terminal can obtain NCC1 from the above configuration information 2. Since the NCC1 obtained from the configuration information 2 is different from the NCC0 locally saved by the terminal, the terminal performs a corresponding number of vertical derivations according to the difference between NCC1 and NCC0 to obtain the corresponding NH (i.e., NH1), and then derives the key K2 according to NH1, the PCI and frequency point of the cell on the network device 2. * In this way, the terminal and the network device 2 maintain the same key, that is, K2. * .

[0157] S316, the terminal sends a handover completion message to the network device 2. Correspondingly, the network device 2 receives the handover completion message from the terminal.

[0158] S317, the network device 2 sends a path handover request message to the AMF network element; correspondingly, the AMF network element receives the path handover request message.

[0159] S318, the AMF network element sends a path handover response message to the network device 2; correspondingly, the network device 2 receives the path handover response message, and then completes the path handover.

[0160] Path handover means that the data transmission path of the terminal is switched from "UPF network element - network device 1 - terminal" to "UPF network element - network device 2 - terminal".

[0161] After receiving the path handover request message, the AMF network element can update and increment the locally saved NCC value by 1 to obtain the updated NCC (referred to as NCC2), and perform a derivation according to the updated NCC to obtain the updated NH (referred to as NH2). NCC2 and NH2 are associated as an updated pair {NH2, NCC2}.

[0162] The path switching response message includes {NH2, NCC2}. After receiving the path switching response message, network device 2 can save {NH2, NCC2}.

[0163] S319, the terminal and network device 2 communicate using key K2 * for communication.

[0164] It can be understood that subsequently, the terminal can also switch from network device 2 to other network devices (such as network device 3 or network device 1). The specific implementation can refer to the description of the terminal switching from network device 1 to network device 2.

[0165] According to the above introduction, in ordinary cross-site switching, the source access network device can select one target access network device and instruct the terminal to switch to the target access network device through an RRC reconfiguration message. After the terminal switches to the target access network device, this switching ends. In the next switching, the terminal will receive a new RRC reconfiguration message; that is, each switching will trigger an RRC reconfiguration process, and each switching will transmit security-related information to the terminal through the RRC reconfiguration message. In LTM cross-site switching, the source access network device instructs the terminal to switch to the target access network device through layer 1 / layer 2 signaling (such as a MAC control element (CE)), that is, each switching does not trigger an RRC reconfiguration process, resulting in the inability to transmit security-related information to the terminal through the RRC reconfiguration message, presenting a security problem.

[0166] Based on this, embodiments of the present application will study the related implementation of secure communication between the terminal and the network device in the LTM cross-site switching scenario. The communication method provided by the embodiments of the present application involves a terminal-side device and at least one network-side device (such as a first network-side device, a second network-side device, and a third network-side device). Among them, the "terminal-side device" can be a terminal or a component in the terminal, such as a chip or a chip system set in the terminal; the "network-side device" can be a network device or a component in the network device, such as a chip or a chip system set in the network device. The network device can be an access network node, or the network device includes a CU of the access network node and a DU of the access network node. In the embodiments of the present application, the example of "the terminal-side device is a terminal and the network-side device is a network device (that is, the first network-side device is the first network device, the second network-side device is the second network device, and the third network-side device is the third network device)" will be used for description.

[0167] For example, the communication method provided in the embodiment of the present application includes three possible schemes (Scheme 1, Scheme 2 and Scheme 3). These three schemes are briefly introduced here. The introduction here is only to make the embodiment of the present application easier to understand, and should not be regarded as a strict limitation of the technical features in the scope of protection required by this application, that is, not all of the technical features introduced here are necessary technical features.

[0168] Solution 1, Configuration Phase (or Handover Preparation Phase): The core network element provides at least one NH and at least one NCC to different network devices. Each network device maintains its own at least one NH and sends at least one NCC obtained from the core network element to the terminal. Handover Phase: If a terminal accesses the same network device multiple times, both the terminal and the network device can identify unused NHs from the at least one NH of the network device.

[0169] Solution 2, Configuration Phase: The core network element provides W NHs and W NCCs to a third network device, where W is an integer greater than 1. The third network device distributes these W NHs and W NCCs to other network devices (optionally, also to the third network device itself). Different network devices maintain at least one NH and transmit at least one NCC obtained from the third network device to the terminal. Handover Phase: If a terminal accesses the same network device multiple times, both the terminal and the network device can determine an unused NH from the at least one NH of the network device.

[0170] Solution 3: During the configuration phase, the core network element provides W NHs and W NCCs to the third network device, which then sends the W NCCs to the terminal. During the handover phase, during each handover, the target network device requests an unused NH from the third network device and securely communicates with the terminal based on the NH.

[0171] By adopting any of the above-mentioned solutions 1 to 3, there is no need to transmit security-related information to the terminal through RRC reconfiguration messages during multiple switching, thereby reducing signaling overhead while ensuring secure communication between the terminal and the network device.

[0172] The embodiments of the present application are described in detail below in conjunction with Examples 1 to 6.

[0173] Example 1

[0174] In the first embodiment, the first solution will be described.

[0175] Figure 4 This is a flow chart associated with the communication method provided in Example 1 of this application. Figure 4 As shown, the process may include:

[0176] S401, the core network element sends a second message for the terminal to the first network device. The second message includes N NHs, where N is an integer greater than or equal to 1; correspondingly, the first network device receives the second message.

[0177] Exemplarily, the core network element determines N NHs, and then sends the second message to the first network device. Here, the core network element is an AMF network element, and the first network device is the initial source network device or candidate network device of the terminal (see the following for details), and the candidate network device is different from the initial source network device. After the terminal accesses the core network element through the initial source network device, the same root key KAMF (such as KAMF0) is saved on the terminal and the core network element. The terminal uses NCC0 (different from the first NCC and the second NCC in the following) to communicate with the initial source network device, and the initial source network device uses the NH associated with NCC0 to communicate with the terminal.

[0178] (1) Describe "the core network element sends a second message for the terminal to the first network device".

[0179] Exemplarily, the first network device sends a third message to the core network element. The third message is used to request to provide the NH for the terminal to the first network device; in response to the third message, the core network element determines N NHs, and sends the second message for the terminal to the first network device, that is, the second message is the response message of the third message.

[0180] Optionally, the third message includes the quantity information of the NH. The quantity information of the NH is used to indicate that the quantity of the requested NH is Q, where Q is an integer greater than or equal to 1. N can be equal to Q, or can be greater than Q, or can be less than Q. The embodiments of the present application do not limit the size relationship between Q and N; that is, the core network element can provide the same quantity of NHs (i.e., N = Q) to the first network device according to the quantity information carried in the third message, or can also provide different quantities of NHs (i.e., N is not equal to Q) to the first network device. In addition, if the third message does not include the quantity information of the NH, then the core network element determines the quantity of the NH by itself.

[0181] It can be understood that here the first network device is taken as an example for description. Other network devices can also request the NH for the terminal from the core network element respectively. Then the core network element provides at least one NH to different network devices respectively. The NHs provided by the core network element to different network devices are different, and the quantities of the NHs provided by the core network element to different network devices can be the same or different.

[0182] (2) Describe "the core network element determines N NHs".

[0183] For example, in response to the third message, the core network element determines whether to replace the root key (i.e., KAMF). If it is determined not to replace KAMF, the core network element derives K NHs based on the initial KgNB (the specific derivation can be before or after the third message, without limitation), and these K NHs are all unused NHs. If it is determined to replace KAMF, the core network element derives a new KAMF (e.g., KAMF1) based on the current KAMF (such as KAMF0), and then derives K NHs based on KAMF1. Among them, the K NHs can be expressed as NH(i), where 0 <= i <= K - 1, and NH(i) is associated with NCC(i) one by one, and K is an integer greater than or equal to N.

[0184] Further, Method 1: The core network element selects N consecutive NHs from the K NHs, that is, the NCCs associated with the N NHs are consecutive, and NH(i) is derived with NH(i - 1) as the input. Method 2: The core network element selects N non - consecutive NHs from the K NHs, that is, the NCCs associated with the N NHs are non - consecutive. Then, the core network element sends the selected N NHs to the first network device through the second message. From the perspective of the core network element, the status of these N NHs changes from unused NHs to used NHs. Optionally, after allocating N NHs to the first network device, the core network element updates the current NH in the core network element to the last NH of the N NHs, so as to allocate different N NHs to different network devices.

[0185] (3) Introduce the content included in the second message.

[0186] As described above, the second message includes N NHs.

[0187] As a possible implementation, the second message further includes the NCCs associated with the N NHs (i.e., N NCCs), and the NCCs associated with the N NHs can be consecutive or non - consecutive. For example, when N = 3 and the NCCs associated with the N NHs are consecutive, the second message includes {NH1, NCC1}, {NH2, NCC2}, {NH3, NCC3}. Another example, when N = 3 and the NCCs associated with the N NHs are non - consecutive, the second message includes {NH1, NCC1}, {NH3, NCC3}, {NH5, NCC5}.

[0188] As another implementation, the second message further includes the second NCC and the value of N. The NCCs associated with the N NHs are consecutive (e.g., sorted from small to large). The second NCC is the NCC associated with the initial NH among the N NHs (or the second NCC is the smallest NCC among the NCCs associated with the N NHs). For example, when N = 3, the second message includes 3 NHs (i.e., NH1, NH2, NH3), the second NCC, and the value of N. The second NCC is associated with NH1, the NCC associated with NH2 is the second NCC plus 1, and the NCC associated with NH3 is the second NCC plus 2.

[0189] In addition, if the core network element replaces the root key with KAMF1, the second message may further include root key information, and the root key information may be information used to identify KAMF1, such as the identification information of KAMF1.

[0190] S402. The third network device sends a first message to the terminal; correspondingly, the terminal receives the first message.

[0191] Exemplarily, the third network device is the initial source network device of the terminal. The initial source network device determines to initiate LTM configuration according to the measurement results reported by the terminal. The first message may be an RRC message, such as an RRC reconfiguration message.

[0192] (1) The "third network device sends a first message to the terminal" is introduced in combination with Example 1 and Example 2.

[0193] Example 1: The above-mentioned first network device is the initial source network device of the terminal, that is, the first network device and the third network device are the same network device.

[0194] In this case, for example, when determining to initiate LTM configuration, the first network device determines cell 1 as a candidate cell for the terminal. Cell 1 is a cell of the first network device. Then, the first network device sends a third message for the terminal to the core network element. In addition, if it is determined that the cell of the first network device is not a candidate cell for the terminal, the first network device does not need to send a third message for the terminal to the core network element.

[0195] Further, after the first network device receives the second message from the core network element, it sends a first message (i.e., an RRC reconfiguration message) to the terminal. The first message includes the LTM configuration of cell 1 (e.g., including at least one of early synchronization configuration, CSI report configuration, and TCI state configuration), and the NCC information 1 associated with cell 1.

[0196] Optionally, the RRC reconfiguration message may further include the LTM configurations of other candidate cells, other NCC information, and the identification information associated with other network devices.

[0197] Example 2: The first network device is a candidate network device of the terminal, and this candidate network device is different from the initial source network device (i.e., the third network device), that is, the first network device and the third network device are different network devices.

[0198] In this case, for example, when it is determined to initiate the LTM configuration, the third network device sends a fourth message (such as the fourth message is a handover request message, and for ease of description, it is called handover request message 1 here) to the first network device. The handover request message 1 is used to request cell 1 as a candidate cell of the terminal (that is, to request the LTM configuration of cell 1 of the first network device). In response to the handover request message 1, the first network device accepts cell 1 as a candidate cell of the terminal, cell 1 is a cell of the first network device, and sends a third message to the core network element. In addition, if it is determined that the cell of the first network device is not a candidate cell of the terminal, the first network device does not need to send a third message to the core network element.

[0199] Further, after receiving the second message for the terminal from the core network element, the first network device sends a handover response message 1 to the third network device. The handover response message 1 includes the LTM configuration of cell 1 and the NCC information 1 associated with cell 1. Then, after receiving the handover response message 1, the third network device sends a first message (such as an RRC reconfiguration message) to the terminal. The first message includes the LTM configuration of cell 1 and the NCC information 1 associated with cell 1.

[0200] In Example 2, if cell 2 is also a cell of the first network device, the third network device can also send a handover request message 2 for the terminal to the first network device. The handover request message 2 is used to request the LTM configuration of cell 2 (for example, including at least one of early synchronization configuration, CSI report configuration, and TCI state configuration); in response to the handover request message 2, the first network device determines that the NCCs associated with cell 1 and cell 2 are the same, and sends a handover response message 2 to the third network device. The handover response message 2 includes the LTM configuration of cell 2 and also includes information indicating that the NCCs associated with cell 1 and cell 2 are the same (for example, the same group identification information). In this case, the third network device can send a first message to the terminal after receiving the handover response message 1 and the handover response message 2. The first message includes the LTM configuration of cell 1 and the NCC information 1 associated with cell 1, and also includes the LTM configuration of cell 2 and information indicating that the NCCs associated with cell 1 and cell 2 are the same (for example, the group identification information corresponding to cell 2 and cell 1 is the same).

[0201] In the above two examples, the association between cell 1 and NCC information 1 can indicate the terminal to the terminal in any of the following ways: Way 1, include NCC information 1 in the configuration of cell 1 to indicate the association between cell 1 and NCC information 1; Way 2, include the information of cell 1 in the configuration of NCC information 1 to indicate the association between cell 1 and NCC information 1. The information of cell 1 can be the identification information of the first network device, or the identification information of cell 1, or the group identification information corresponding to cell 1.

[0202] (2) Introduce the security-related content of the first message (such as NCC information 1).

[0203] NCC information 1 is used to indicate the NCCs associated with N NHs (for example, N NCCs) or the second NCC.

[0204] Specifically, if the second message includes the NCCs associated with N NHs (for example, N NCCs associated with N NHs one by one), then NCC information 1 includes the NCCs associated with N NHs (for example, N NCCs associated with N NHs one by one). If the second message includes the second NCC, then NCC information 1 includes the second NCC. Optionally, it also includes the value of N. In the case of including the value of N, the NCCs associated with N NHs can be jointly indicated by the second NCC and the value of N.

[0205] It can be understood that the first message may also include the NCC information associated with other cells. The content included in the NCC information associated with other cells can refer to the description of NCC information 1.

[0206] Optionally, the first message further includes the identification information associated with cell 1. The identification information associated with cell 1 is used to determine whether to perform vertical key derivation for NH when the terminal switches to the first network device (for example, cell 1). The identification information associated with cell 1 can be the above-mentioned NCC information 1, or the identification information of the first network device, or the group identification information corresponding to cell 1, or other possible information, without limitation. For example, when the identification information associated with the source cell and the identification information associated with the target cell are different, the terminal performs vertical key derivation for NH. In an inter-site handover scenario, the "identification information associated with cell 1" can be replaced with the "identification information associated with the first network device", and the "identification information associated with the source cell" can be replaced with the "identification information associated with the source network device", and the "identification information associated with the target cell" can be replaced with the "identification associated with the target network device".

[0207] In addition, when the second message includes the root key information, the first message further includes the root key information associated with cell 1, or the root key information associated with NCC1 information 1. This root key information is used to instruct the terminal to determine the root key KAMF when switching to cell 1, and then perform vertical key derivation for NH based on the root key determined by this root key information.

[0208] S403, the terminal accesses the first network device; correspondingly, the first network device determines that the terminal accesses the first network device.

[0209] For example, the terminal accesses the cell of the first network device, that is, cell 1.

[0210] There are various scenarios for the terminal to access the first network device. One possible scenario (Scenario 1) is that the terminal initiates a mobility LTM handover to access the first network device; specifically, the terminal receives a handover command message for instructing a handover to the first network device (for example, cell 1), and in response to the handover command message, the terminal accesses the first network device. Another possible scenario (Scenario 2) is that after the LTM handover fails, the terminal accesses the first network device through LTM configuration; specifically, the terminal determines that the handover fails (such as a failure to handover to another network device), and in response to this handover failure, the terminal selects to access the first network device and accesses the first network device based on the LTM configuration of the first network device.

[0211] Exemplarily, the ways for a terminal to access a first network device may include: Way 1, the terminal accesses the first network device through random access. For example, the terminal accesses the first network device through physical random access channel (RACH) resources. After completing random access, the first network device determines that the terminal has accessed the first network device (i.e., the terminal accesses the first network device through LTM configuration). For example, in the random access Message 3, the identity information of the terminal is included, and this identity information is carried in the LTM configuration. Therefore, the first network device can determine that the terminal accesses the first network device through LTM configuration. Way 2, the terminal accesses the first network device through non-random access. For example, the terminal accesses the first network device through physical uplink shared channel (PUSCH) resources, and the PUSCH resources can be configured grant (CG) resources or dynamic grant (DG) resources. Correspondingly, the first network device determines that the terminal has accessed the first network device (i.e., the terminal accesses the first network device through LTM configuration) based on the transmission on the PUSCH resources. For example, the PUSCH resources are indicated to the terminal in the LTM configuration. Therefore, the first network device can determine that the terminal accesses the first network device through LTM configuration through the PUSCH resources.

[0212] In addition, the first network device can determine based on whether it receives a cell handover notification message which scenario the terminal accesses the first network device based on. For example, if the first network device receives a cell handover notification message from the source network device (this cell handover notification message corresponds to LTM handover), it determines that the terminal accesses the first network device based on Scenario 1. If the first network device does not receive a cell handover notification message from the source network device, it determines that the terminal accesses the first network device based on Scenario 2.

[0213] S404, the first network device and the terminal perform secure communication.

[0214] The following describes "the first network device and the terminal perform secure communication" from the perspectives of the first network device and the terminal respectively.

[0215] (1) Introduction from the perspective of the first network device.

[0216] From the perspective of the first network device, the secure communication between the first network device and the terminal may include: for cross-site handover, based on the above N NHs, determining the currently unused NH, and performing secure processing (including at least one of integrity protection, integrity protection confirmation, encryption, or decryption) on the terminal's data using the determined NH. Specifically, the first network device determines the NH used for the current cross-site handover from the N NHs, that is, the first NH. The first NH is the NH that was not used in the previous cross-site handover, that is, the previously used NHs are no longer used, thereby ensuring that different NHs are used for multiple cross-site handovers to the first network device.

[0217] For example, the N NHs may be sorted in the first order, and the first NH is the first unused NH among the N NHs. For example, the N NHs are NH1, NH2, and NH3, NH1 is the used NH (for example, when the terminal last accessed the first network device, the NH used by the first network device was NH1), and the remaining NHs are unused NHs, then the first NH is NH2. Among them, the first order is the order of NCC from small to large or the order of the N NHs indicated by the core network element.

[0218] Exemplarily, the first network device may determine the first order based on the second message. Two possible ways are described below in combination with Method 1 and Method 2.

[0219] Method 1: The N NHs included in the second message are sorted in the first order, that is, the core network element indicates the first order through the second message, and the first network device directly obtains the N NHs sorted in the first order from the second message. In this case, the N NHs being sorted in the first order may mean that the N NHs are sorted based on the NCCs associated with the N NHs from small to large; or it may also refer to other possible sorting methods, which are not specifically limited.

[0220] Method 2: The second message includes N NHs and the NCCs associated with the N NHs. The first network device sorts the N NHs based on the NCCs associated with the N NHs from small to large. In this case, the N NHs being sorted in the first order may mean that the N NHs are sorted based on the NCCs associated with the N NHs from small to large.

[0221] It can be understood that based on the sorting of the above N NHs, the above first message includes the sorting information of the N NCCs, and the N NHs are associated with the N NCCs one by one. Specifically, when the NCC information 1 includes the NCCs associated with the N NHs, the NCCs associated with the N NHs are also sorted in the first order, so that the NH used by the terminal during a certain handover is the same as the NH used by the first network device.

[0222] (2) Introduction from the perspective of the terminal.

[0223] From the perspective of the terminal, for secure communication between the first network device and the terminal, it may include: after receiving the NCC information 1, for cross-site handover, based on the NCC information 1 associated with cell 1, the terminal determines the NCC used for the current cross-site handover (i.e., handover to cell 1), that is, the first NCC, and uses the first NCC to communicate with the first network device. It should be noted that the NCC used in the previous cross-site handover is not used in this cross-site handover. Communicating with the first network device using the first NCC specifically means: based on the first NCC, the terminal determines the first NH (i.e., for the same handover, the NH determined by the terminal is the same as the NH determined by the first network device) and uses the first NH to perform security processing on the data of the terminal (including at least one of integrity protection, integrity protection confirmation, encryption, or decryption), and the first NCC is associated with the first NH.

[0224] In one example, if the above NCC information 1 includes N NCCs associated with NHs (i.e., N NCCs), then the first NCC is one of the N NCCs, and the NH associated with the first NCC is the unused NH. For example, the N NCCs are sorted in the first order, and the first NCC is the first unused NCC among the N NCCs. For example, the N NCCs are NCC1 (associated with NH1), NCC2 (associated with NH2), NCC3 (associated with NH3), NCC1 is the used NCC (for example, when the terminal last accessed the first network device, the NCC used by the terminal was NCC1), and the remaining NCCs are unused NCCs, then the first NCC is NCC2.

[0225] For this example, when the N NCCs are consecutive, it can also be understood that: the first NCC is obtained by adding 1 to the second NCC, and the second NCC is the NCC used for the previous access to the first network device.

[0226] In another example, if the above NCC information 1 includes the second NCC, when the terminal first accesses the first network device, it can use the second NCC to communicate with the first network device; after that, when the terminal accesses the first network device again, it can obtain the first NCC by adding 1 to the second NCC, and then use the first NCC to communicate with the first network device; and so on.

[0227] Optionally, from the perspective of the terminal, for secure communication between the first network device and the terminal, it may include: The terminal determines whether to update the key, or rather determines whether to perform a vertical derivation for NH, based on the identification information associated with the source cell and the identification information associated with the target cell (i.e., cell 1). For example, if the identification information associated with the source cell is different from the identification information associated with the target cell (i.e., cell 1) (inter-site handover), the terminal determines that a vertical derivation for NH needs to be performed; if the identification information associated with the source cell is the same as the identification information associated with the target cell (intra-site handover), the terminal determines that a vertical derivation for NH does not need to be performed, that is, NH remains unchanged. A specific example is: If the NCC associated with the source cell is different from the NCC associated with the target cell, the terminal determines that a vertical derivation for NH needs to be performed; if the NCC associated with the source cell is the same as the NCC associated with the target cell, the terminal determines that a vertical derivation for NH does not need to be performed. Therefore, an inter-site handover can also be understood as a handover that requires replacing NH, and an intra-site handover can also be understood as a handover that does not require replacing NH.

[0228] For example, when the network device to which the source cell belongs is the second network device and the second network device is different from the first network device, the terminal determines that a vertical derivation for NH needs to be performed; when the network device to which the source cell belongs is the first network device, the terminal determines that a vertical derivation for NH does not need to be performed. In the embodiments of the present application, the scenario where "the key derivation method is vertical derivation" is used as an example for description. Therefore, updating the key may include determining the first NCC and the first NH associated with the first NCC as described above. In addition, the embodiments of the present application do not limit the specific timing for the terminal to update the key.

[0229] When the first message includes the root key information, the terminal determines the updated root key KAMF based on the root key information, and then derives the NH for this handover (such as the first NH) based on the updated root key KAMF and the corresponding NCC (such as the first NCC).

[0230] Based on the above method, after the first network device and the terminal determine the first NH, the first network device and the terminal respectively perform the following operations: Using the first NH and the target cell information for this handover (such as the PCI and downlink frequency of the cell) as input parameters, derive the KgNB of the target cell, and then derive Kup and Krrc based on KgNB, and use Kup and Krrc for secure communication between the first network device and the terminal.

[0231] It can be understood that in the above S403, during the process of the terminal accessing the first network device, the terminal and the first network device can also perform secure communication in the manner described in S404. That is to say, S404 can be applicable to the communication after the terminal accesses the first network device and can also be applicable to the communication during the process of the terminal accessing the first network device. Other embodiments can be understood by reference.

[0232] Optionally, the above method further includes S405.

[0233] S405, the first network device sends a fifth message to the core network element. The fifth message is used to request path switching and also used to indicate not to update the NH; correspondingly, the core network element receives the fifth message.

[0234] For example, the fifth message is a path switching request message, and the fifth message includes the address information of the downlink data. In response to S403, the first network device sends the fifth message to the core network element. After receiving the fifth message, the core network element can not update the NH, and then send a path switching response message to the first network device. The path switching response message does not include the NH and NCC. It should be noted that in the existing path switching response message, the NH and NCC must be carried. In this application, the NH and NCC have been provided to the first network device in the previous steps, and there is no need to provide the NH and NCC additionally in this message.

[0235] After receiving the fifth message, the core network element (for example, the AMF network element) notifies other core network elements (for example, the UPF network element) to use the above address information of the downlink data to send the downlink data to the first network device.

[0236] It can be understood that taking the first network device as an example, the first network device associates N NHs. Each time the terminal switches to the first network device, it uses the NH that has not been used in the previous switch among the N NHs. If the first network device determines that the N NHs are about to be used up or have been used up, the first network device can request new NHs from the core network element again and send the NCC information associated with the new NHs to the terminal for subsequent switching. Other network devices can be processed by referring to the first network device.

[0237] Adopting this method, for multiple switches to the same network device, different NHs can be used, so that there is no need to transmit security-related information to the terminal through the RRC reconfiguration message, which is convenient for realizing secure communication between the terminal and the network device in the LTM cross-site switching scenario and ensuring the secure communication of cross-site continuous switching.

[0238] Embodiment 2

[0239] In Embodiment 2 ( Figure 5A)In the following, based on the above-mentioned Embodiment 1, a possible implementation process will be described. That is, Embodiment 2 can be combined with Embodiment 1, and the specific implementation of the relevant steps in Embodiment 2 can refer to Embodiment 1.

[0240] Figure 5A It is a schematic flowchart associated with the communication method provided in Embodiment 2 of this application. Figure 5A The LTM inter-site handover shown means that the terminal switches from Network Device 0 to Network Device 1 (the first handover), and then from Network Device 1 to Network Device 2 (the second handover). Among them, Network Device 0 is the initial source network device (such as the third network device in Embodiment 1). As Figure 5A shown, this process may include:

[0241] S501, the terminal connects to the core network through Network Device 0.

[0242] The terminal can access Network Device 0 through the initial access process or other possible processes, and access the core network through Network Device 0. Furthermore, the same root key KAMF (such as KAMF0) is saved on the terminal and the core network element. The terminal uses NCC0 (different from NCC1 to NCC7 below) to communicate with Network Device 0, and Network Device 0 uses the NH associated with NCC0 to communicate with the terminal.

[0243] S502, Network Device 0 determines multiple candidate cells (or multiple candidate network devices) for the LTM handover.

[0244] Exemplarily, according to the measurement results reported by the terminal, if Network Device 0 determines to initiate the LTM configuration, it can determine multiple candidate cells for the LTM handover. For example, the determined multiple candidate cells include Cell a, Cell b1, Cell b2, and Cell c. Among them, Cell a is a cell of Network Device 0, Cell b1 and Cell b2 are cells of Network Device 1, and Cell c is a cell of Network Device 2. That is, the multiple candidate network devices include Network Device 0, Network Device 1, and Network Device 2.

[0245] S503, Network Device 0 sends Message 1 to the core network element, and Message 1 is used to request the core network element to provide NH to Network Device 0.

[0246] Here, Message 1 is used to request the core network element to provide NH to Network Device 0, and can also be replaced with "Message 1 is used to request the core network element to provide NH and NCC to Network Device 0".

[0247] Optionally, message 1 includes the quantity information of NHs. Since the NCCs are associated with the NHs one by one, the "quantity information of NHs" can also be replaced with the "quantity information of NCCs". For example, network device 0 can estimate the number of times that the terminal performs an inter-station handover and switches to network device 1, and then determine the above-mentioned quantity information of NHs or NCCs according to this number of times.

[0248] S504, the core network element sends message 2 to network device 0, and message 2 includes M NHs.

[0249] For example, see Figure 5B As shown, the core network element deduces K NHs, and the K NHs include NH1 to NH7 (i.e., K = 7). The core network element allocates M of the K NHs to network device 0. The M NHs can be consecutive or non-consecutive, and the specific implementation can refer to the relevant description of S401 in Embodiment 1. For example, the M NHs include NH1 and NH2.

[0250] Optionally, message 2 further includes the NCC information associated with the M NHs (referred to as NCC information a). The NCC information a includes the NCCs associated with the M NHs, such as NCC1 and NCC2; or the M NHs included in message 2 are sorted in ascending order based on the NCCs associated with the M NHs, and the NCCs associated with the M NHs are consecutive, then the NCC information a includes the NCC associated with the initial NH among the M NHs (i.e., the smallest NCC among the NCCs associated with the M NHs), such as NCC1. Optionally, the value of M is also included. The NCC information a (and the following NCC information b and NCC information c) can refer to the relevant description of "NCC information 1" in Embodiment 1.

[0251] S505, network device 0 sends a handover request message to network device 1; correspondingly, network device 1 receives the handover request message from network device 0.

[0252] Here, the handover request message is used to request the LTM configuration of cell b1. For example, the handover request message includes LTM indication information and the cell global identifier (CGI) of cell b1.

[0253] S506, network device 1 sends message 3 to the core network element, and message 3 is used to request the core network element to provide NHs to network device 1.

[0254] Optionally, message 3 includes the quantity information of NHs.

[0255] S507, the core network element sends message 4 to network device 1, and message 4 includes P NHs.

[0256] For example, see Figure 5BAs shown, the core network element allocates P out of (K - N) NHs to network device 1. The P NHs can be consecutive or non - consecutive. For the specific implementation, refer to the relevant description of S401 in Embodiment 1. For example, the P NHs include NH3 and NH4. It can be understood that if K - N = 0 or the number of K - N is small, the core network element can further deduce more NHs and then allocate P NHs to network device 1.

[0257] Optionally, message 4 further includes NCC information (referred to as NCC information b) associated with the P NHs. NCC information b includes the NCCs associated with the P NHs, such as NCC3 and NCC4; or, if the P NHs included in message 4 are sorted in ascending order based on the NCCs associated with the P NHs and the NCCs associated with the P NHs are consecutive, then NCC information b includes the NCC associated with the initial NH among the P NHs (i.e., the smallest NCC among the NCCs associated with the P NHs), such as NCC3. Optionally, it also includes the value of P.

[0258] S508, Network device 1 sends a handover response message to network device 0; correspondingly, network device 0 receives the handover response message from network device 1.

[0259] Exemplarily, the handover response message includes the LTM configuration of cell b1 and NCC information b. The LTM configuration of cell b1 includes transmission configuration indication (TCI) state configuration, cell group configuration (such as the group identification information corresponding to cell b1), and may also include other possible configurations.

[0260] It can be understood that network device 0 can also send a handover request message to network device 1 for cell b2. The handover request message is used to request the LTM configuration of cell b2; in response to this handover request message, network device 1 sends a handover response message to network device 0. The handover response message includes the LTM configuration of cell b2 and also includes information indicating that the NCCs associated with cell b2 and cell b1 are the same. Both cell b2 and cell b1 are associated with NCC information b, and both cell b2 and cell b1 are associated with P NHs.

[0261] S509, Network device 0 sends a handover request message to network device 2. Correspondingly, network device 2 receives the handover request message from network device 0.

[0262] Here, the handover request message is used to request the LTM configuration of cell c.

[0263] S510, Network device 2 sends message 5 to the core network element. Message 5 is used to request the core network element to provide NHs to network device 2.

[0264] Optionally, message 5 includes the quantity information of NHs.

[0265] S511. The core network element sends message 6 to network device 2. Message 6 includes N NHs. Correspondingly, network device 2 receives message 6.

[0266] For example, refer to Figure 5B As shown, the core network element allocates N (N = K - M - P) NHs to network device 2. The N NHs can be consecutive or non - consecutive. The specific implementation can refer to the relevant description of S401 in Embodiment 1. For example, the N NHs include NH5, NH6, and NH7. It can be understood that if K - M - P = 0 or the quantity of K - M - P is small, the core network element can further deduce more NHs and then allocate N NHs to network device 2.

[0267] Optionally, message 6 further includes the NCC information (referred to as NCC information c) associated with the N NHs. NCC information c includes the NCCs associated with the N NHs, such as NCC5, NCC6, and NCC7. Or the N NHs included in message 6 are sorted in ascending order based on the NCCs associated with the N NHs. If the NCCs associated with the N NHs are consecutive, then NCC information c includes the NCC associated with the initial NH among the N NHs (i.e., the smallest NCC among the NCCs associated with the N NHs), such as NCC5. Optionally, it further includes the value of N.

[0268] S512. Network device 2 sends a handover response message to network device 0. Correspondingly, network device 0 receives the handover response message from network device 2.

[0269] Exemplarily, the handover response message includes the LTM configuration of cell c and NCC information c.

[0270] S513. Network device 0 sends an RRC re - configuration message to the terminal. Correspondingly, the terminal receives the RRC re - configuration message.

[0271] Exemplarily, the RRC re - configuration message includes the LTM configuration of cell a, the NCC information a associated with cell a, also includes the LTM configuration of cell b1, the LTM configuration of cell b2, the NCC information b associated with cell b1 and cell b2, also includes the LTM configuration of cell c, the NCC information c associated with cell c.

[0272] Optionally, the first message further includes the identification information associated with cell 1 (i.e., the identification information associated with network device 0), the identification information associated with cell b1 / b2 (i.e., the identification information associated with network device 1), the identification information associated with cell c (i.e., the identification information associated with network device 2).

[0273] S514, Network device 0 determines that the terminal needs to handover, and the target network device for the handover is network device 1.

[0274] Among them, there are multiple specific implementations for network device 0 to determine the target network device, and the embodiments of this application do not limit this. For example, network device 0 can determine that the target network device is network device 1 according to the measurement report reported by the terminal.

[0275] S515, Network device 0 sends a handover command message to the terminal. Correspondingly, the terminal receives the handover command message from network device 0.

[0276] For example, the handover command message is a MAC CE, and the handover command message includes the identification information of the target cell (such as cell b1).

[0277] S516, In response to the handover command message, the terminal handovers to network device 1.

[0278] S517, Network device 1 sends a path handover request message to the AMF network element. The path handover request message is used to indicate not to update the NH; correspondingly, the AMF network element receives the path handover request message.

[0279] S518, The AMF network element sends a path handover response message to network device 1; correspondingly, network device 1 receives the path handover response message, and then completes the path handover.

[0280] Here, the path handover means that the data transmission path of the terminal is switched from "UPF network element - network device 0 - terminal" to "UPF network element - network device 1 - terminal". The path handover response message does not include the NH and NCC.

[0281] S519, The terminal communicates securely with network device 1.

[0282] From the perspective of network device 1, network device 1 uses the first unused NH (i.e., NH3) among the P NHs to perform security processing on the data of the terminal (including at least one of integrity protection, integrity protection confirmation, encryption, or decryption).

[0283] From the perspective of the terminal, since cell b1 is associated with the NCC information b, and then the terminal uses the first unused NCC (i.e., NCC3) according to the NCC information b (for example, the NCC information b includes NCC3 and NCC4) to communicate with network device 1; specifically, the terminal determines the NH3 associated with NCC3 based on NCC3, and then uses NH3 to perform security processing on the data of the terminal.

[0284] In this way, it can be ensured that the keys used by the network device 1 and the terminal are the same, so as to enable secure communication between the network device 1 and the terminal. The specific implementation of S519 can refer to S404 in Embodiment 1.

[0285] It can be understood that if the terminal switches to the network device 1 again next time, the network device 1 uses the first unused NH among the P NHs (i.e., NH4) to communicate with the terminal; the terminal uses the first unused NCC (i.e., NCC4) to communicate with the network device 1, or the terminal adds 1 to NCC4 (i.e., the NCC used when accessing the network device 1 last time) to obtain NCC4, and then uses NCC4 to communicate with the network device 1.

[0286] S520, the network device 1 determines that the terminal needs to switch, and the target network device for the switch is the network device 2.

[0287] S521, the network device 1 sends a handover command message to the terminal. Correspondingly, the terminal receives the handover command message from the network device 1.

[0288] For example, the handover command message is a MAC CE, and the handover command message includes the identification information of the target cell (such as cell c).

[0289] S522, in response to the handover command message, the terminal switches to the network device 2.

[0290] S523, the network device 2 sends a path switch request message to the AMF network element. The path switch request message is used to indicate not to update the NH; correspondingly, the AMF network element receives the path switch request message.

[0291] S524, the AMF network element sends a path switch response message to the network device 2; correspondingly, the network device 2 receives the path switch response message, and then completes the path switch.

[0292] Here, the path switch means that the data transmission path of the terminal is switched from "UPF network element - network device 1 - terminal" to "UPF network element - network device 2 - terminal". The path switch response message does not include the NH and the NCC.

[0293] S525, the terminal communicates securely with the network device 2.

[0294] From the perspective of the network device 2, the network device 2 uses the first unused NH among the N NHs (i.e., NH5) to perform secure processing on the data of the terminal.

[0295] From the perspective of the terminal, since cell c is associated with NCC information c, the terminal then uses the first unused NCC (i.e., NCC5) according to NCC information c (for example, NCC information c includes NCC5, NCC6, and NCC7) to communicate with network device 2; specifically, the terminal determines NH5 associated with NCC5 based on NCC5, and then uses NH5 to perform security processing on the data of the terminal.

[0296] In this way, it can be ensured that the keys used by network device 2 and the terminal are the same, thus enabling secure communication between network device 2 and the terminal. The specific implementation of S525 can refer to S404 in Embodiment 1.

[0297] It can be understood that if the terminal switches to network device 2 again next time, since NH5 has been used, network device 2 uses the first unused NH among N NHs (i.e., NH6) to communicate with the terminal; since NCC6 has been used, the terminal uses the first unused NCC (i.e., NCC6) to communicate with network device 2, or the terminal adds 1 to NCC5 (i.e., the NCC used to access network device 2 last time) to obtain NCC6, and then uses NCC6 to communicate with network device 2.

[0298] It can be understood that subsequently, the terminal can also switch from network device 2 to network device 0 or network device 1, and the specific implementation can refer to the description of the terminal switching from network device 1 to network device 2; or, if the candidate network devices for LTM switching also include network device 3, then subsequently the terminal can also switch from network device 2 to network device 3, and the specific implementation can refer to the description of the terminal switching from network device 1 to network device 2.

[0299] Embodiment 3

[0300] In Embodiment 3, Scheme 2 will be described.

[0301] Figure 6 It is a schematic flowchart associated with the communication method provided in Embodiment 3 of this application. As Figure 6 shown, this process may include:

[0302] S601, the core network element sends a sixth message to the third network device, and the sixth message includes W NHs, where W is an integer greater than 1; correspondingly, the third network device receives the sixth message.

[0303] Among them, the core network element is an AMF network element, and the third network device is the initial source network device of the terminal. After the terminal accesses the core network element through the initial source network device, the same root key KAMF (such as KAMF0) is saved on the terminal and the core network element.

[0304] Based on the measurement results reported by the terminal, if the third network device determines to initiate LTM configuration, it can determine multiple candidate cells, and then send a third message to the core network element. The third message is used to request the provision of NH to the third network device. Different from Embodiment 1, regardless of whether the multiple candidate cells include the cells of the third network device, the third network device sends the third message to the core network element. In response to the third message, the core network element sends a sixth message to the third network device, that is, the sixth message is the response message of the third message. Among them, the third message can refer to the description in Embodiment 1.

[0305] In response to the third message, the core network element determines W NHs and sends a sixth message to the third network device. The NCCs associated with the W NHs can be consecutive. For example, in response to the third message, the core network element determines whether to replace the root key (i.e., KAMF). When it is determined not to replace KAMF, the core network element derives W NHs based on the initial KgNB, and these W NHs are all unused NHs. When it is determined to replace KAMF, the core network element derives a new KAMF (such as KAMF1) based on the current KAMF (such as KAMF0), and then derives W NHs based on KAMF1. The W NHs can be expressed as NH(i), 0 <= i <= W - 1, and NH(i) is associated with NCC(i) one by one. Furthermore, the core network element sends the W NHs to the third network device through the sixth message. From the perspective of the core network element, the status of these W NHs changes from unused NHs to used NHs.

[0306] Exemplarily, the sixth message further includes NCC information 2. For example, NCC information 2 includes the NCCs associated with the W NHs (i.e., N NCCs); or, NCC information 2 includes a second NCC, and the W NHs included in the sixth message are sorted in ascending order based on the NCCs associated with the W NHs, and the second NCC is the NCC associated with the initial NH among the W NHs. In addition, if the core network element replaces the root key with KAMF1, the sixth message may further include root key information, and the root key information may be information used to identify KAMF1. Specifically, it can refer to the description of the "second message" in Embodiment 1.

[0307] S602, the third network device sends a second message to the first network device. The second message includes N NHs; correspondingly, the first network device receives the second message.

[0308] Here, the first network device is a candidate network device of the terminal, and this candidate network device is different from the initial source network device (i.e., the third network device), that is, the first network device and the third network device are different network devices.

[0309] For example, the third network device determines a cell as a candidate cell for a terminal. If Cell 1 is a cell of the first network device, after the third network device obtains W NHs, it can allocate N NHs out of the W NHs to the first network device and send a second message to the first network device. The second message is a handover request message, and the second message is also used to request the LTM configuration of Cell 1 of the first network device. Optionally, the second message further includes NCC information 1 associated with Cell 1. For specific reference, see the description in Embodiment 1. After receiving the second message, the first network device can obtain N NHs and send a handover response message to the third network device. The handover response message includes the LTM configuration of the first cell. Optionally, it also includes NCC information 1 associated with Cell 1.

[0310] Optionally, the third network device can also allocate NHs to network devices to which other candidate cells belong. For example, if the network devices to which other candidate cells belong include the second network device and the third network device, the third network device can also allocate P NHs to the second network device and M NHs to itself from the remaining (W - N) NHs and send the allocated P NHs to the second network device.

[0311] S603. The third network device sends a first message to the terminal; correspondingly, the terminal receives the first message from the third network device.

[0312] The first message can be an RRC message, such as an RRC reconfiguration message. For example, the first message includes the LTM configuration of Cell 1 and NCC information 1 associated with Cell 1.

[0313] Exemplarily, the NCC information 1 includes NCCs associated with N NHs; or the NCC information 1 includes a second NCC. The N NHs are sorted in ascending order based on the NCCs associated with the N NHs, and the NCCs associated with the N NHs are consecutive. The second NCC is the NCC associated with the initial NH among the N NHs.

[0314] It can be understood that the first message can also include other possible information. For specific reference, see the description of the first message in Embodiment 1.

[0315] S604. The terminal accesses the first network device; correspondingly, the first network device can determine that the terminal accesses the first network device.

[0316] S605. The first network device and the terminal perform secure communication.

[0317] Optionally, the above method further includes S606.

[0318] S606. The first network device sends a fifth message to the core network element. The fifth message is used to request path switching and also indicates not to update the NH. Correspondingly, the core network element receives the fifth message.

[0319] The above S604 to S606 can refer to the descriptions of S403 to S405 in Embodiment 1. The above S601 to S603 focus on describing the differences between Embodiment 3 and Embodiment 1. For other content except for these differences, the two can be referred to each other.

[0320] It can be understood that taking the first network device as an example, the first network device is associated with N NHs. Each time the terminal switches to the first network device, it uses the NHs in the N NHs that have not been used in previous switches. If the first network device determines that the N NHs are about to be used up or have been used up, the first network device can request new NHs from the core network element again and send the NCC information associated with the new NHs to the terminal for subsequent switches. Or, if the first network device determines that the N NHs are about to be used up or have been used up, the first network device can request new NHs from the third network device. Then, the third network device can request new NHs from the core network element and send the new NHs to the first network device. Other network devices can follow the first network device for processing.

[0321] By adopting this method, the initial source network device of the terminal requests NHs from the core network element, distributes the requested multiple NHs to each candidate network device, and the initial source network device sends the NCC information associated with each candidate cell to the terminal through an RRC message. Furthermore, for multiple switches to the same network device, different NHs can be used, and there is no need to transmit security-related information to the terminal through an RRC reconfiguration message, which facilitates secure communication between the terminal and the network device in the LTM inter-site switch scenario, improves the security of continuous inter-site switches, and ensures secure communication for continuous inter-site switches.

[0322] Embodiment 4

[0323] In Embodiment 4 ( Figure 7 ), based on the above Embodiment 2, a possible implementation process will be described. That is, Embodiment 4 can be combined with Embodiment 3, and the specific implementation of the relevant steps in Embodiment 4 can refer to Embodiment 3 and can also refer to Embodiment 2.

[0324] Figure 7 This is a schematic flowchart associated with the communication method provided in Embodiment 4 of this application. Figure 7 The LTM inter-site switch shown means that the terminal switches from network device 0 to network device 1 (the first switch), and then from network device 1 to network device 2 (the second switch). Among them, network device 0 is the initial source network device (such as the third network device in Embodiment 3). AsFigure 7 As shown, the process may include:

[0325] S701, the terminal connects to the core network through network device 0.

[0326] The terminal can access network device 0 through the initial access process or other possible processes, and access the core network through network device 0. Furthermore, the same root key KAMF (such as KAMF0) is saved on the terminal and the core network element. The terminal uses NCC0 (different from NCC1 to NCC7 below) to communicate with network device 0, and network device 0 uses NH associated with NCC0 to communicate with the terminal.

[0327] S702, network device 0 determines multiple candidate cells (or multiple candidate network devices) for LTM switching.

[0328] Exemplarily, network device 0 determines multiple candidate cells for LTM switching according to the measurement results reported by the terminal. If it is determined to initiate LTM configuration, for example, the multiple candidate cells determined include cell a, cell b1, cell b2, and cell c. Among them, cell 0 is the cell of network device 0, cell b1 and cell b2 are the cells of network device 1, and cell c is the cell of network device 2. That is, the multiple candidate network devices include network device 0, network device 1, and network device 2.

[0329] S703, network device 0 sends message 1 to the core network element, and message 1 is used to request the core network element to provide NH to network device 0.

[0330] Optionally, message 1 includes the quantity information of NH.

[0331] S704, the core network element sends message 2 to network device 0, and message 2 includes W NHs; correspondingly, network device 0 receives message 2.

[0332] For example, the core network element derives W NHs. The NCCs associated with the W NHs can be consecutive. The W NHs include NH1 to NH7 (i.e., W = 7), and the core network element sends the W NHs to network device 0 through message 2.

[0333] Optionally, message 2 further includes the NCC information (i.e., NCC information 2) associated with the W NHs. NCC information 2 includes the NCCs associated with the W NHs, such as NCC1 to NCC7; or if the W NHs included in message 2 are sorted in ascending order based on the NCCs associated with the W NHs, then NCC information 2 includes the NCC associated with the initial NH among the W NHs (i.e., the smallest NCC among the NCCs associated with the W NHs), such as NCC1. Optionally, it further includes the value of W.

[0334] Since network device 0 is a candidate network device for the terminal, network device 0 can allocate M out of W NHs to itself. For example, the M NHs include NH1 and NH2.

[0335] S705, network device 0 sends a handover request message to network device 1; correspondingly, network device 1 receives the handover request message from network device 0.

[0336] Here, the handover request message is used to request the LTM configuration of cell b1.

[0337] Exemplarily, network device 0 allocates P out of (W - M) NHs to network device 1. The handover request message includes the P NHs and NCC information b. For example, the P NHs include NH3 and NH4. NCC information b includes the NCCs associated with the P NHs, such as NCC3 and NCC4; or, if the P NHs included in message 4 are sorted in ascending order based on the NCCs associated with the P NHs and the NCCs associated with the P NHs are consecutive, then NCC information b includes the NCC associated with the initial NH among the P NHs (i.e., the smallest NCC among the NCCs associated with the P NHs), such as NCC3, and optionally, also includes the value of P.

[0338] S706, network device 1 sends a handover response message to network device 0; correspondingly, network device 0 receives the handover response message from network device 1.

[0339] Exemplarily, the handover response message includes the LTM configuration of cell b1 and the NCC information b associated with cell b1.

[0340] It can be understood that network device 0 can also send a handover request message to network device 1 for cell b2. The handover request message is used to request the LTM configuration of cell b2; in response to this handover request message, network device 1 sends a handover response message to network device 0. The handover response message includes the LTM configuration of cell b2 and also includes information indicating that the NCCs associated with cell b2 and cell b1 are the same.

[0341] S707, network device 0 sends a handover request message to network device 2. Correspondingly, network device 2 receives the handover request message from network device 0.

[0342] Here, the handover request message is used to request the LTM configuration of cell c.

[0343] Exemplarily, network device 0 allocates N (N = W - M - P) NHs to network device 2. The handover request message includes N NHs and NCC information c. For example, the N NHs include NH5, NH6, and NH7. The NCC information c includes the NCCs associated with the N NHs, such as NCC5, NCC6, and NCC7; or the N NHs included in message 6 are sorted in ascending order based on the NCCs associated with the N NHs, and if the NCCs associated with the N NHs are consecutive, the NCC information c includes the NCC associated with the initial NH among the N NHs (i.e., the smallest NCC among the NCCs associated with the N NHs), such as NCC5. Optionally, it also includes the value of N.

[0344] S708. Network device 2 sends a handover response message to network device 0; correspondingly, network device 0 receives the handover response message from network device 2.

[0345] Exemplarily, the handover response message includes the LTM configuration of cell c and the NCC information c associated with cell c.

[0346] S709. Network device 0 sends an RRC reconfiguration message to the terminal; correspondingly, the terminal receives the RRC reconfiguration message.

[0347] Exemplarily, the RRC reconfiguration message includes the LTM configuration of cell a, the NCC information a associated with cell a (refer to the description of Embodiment 2), also includes the LTM configuration of cell b1, the LTM configuration of cell b2, the NCC information b associated with cell b1 and cell b2, and also includes the LTM configuration of cell c, the NCC information c associated with cell c. Optionally, the first message also includes the identification information associated with cell 1 (i.e., the identification information associated with network device 0), the identification information associated with cell b1 / b2 (i.e., the identification information associated with network device 1), and the identification information associated with cell c (i.e., the identification information associated with network device 2).

[0348] Optionally, the first message also includes the identification information associated with cell 1 (i.e., the identification information associated with network device 0), the identification information associated with cell b1 / b2 (i.e., the identification information associated with network device 1), and the identification information associated with cell c (i.e., the identification information associated with network device 2).

[0349] S710 to S721 refer to the description of S514 to S525 in Embodiment 3 and will not be elaborated here.

[0350] Embodiment 5

[0351] In Embodiment 5, Scheme 3 will be described.

[0352] Figure 8 It is a schematic flowchart associated with the communication method provided in Embodiment 5 of this application. As Figure 8As shown, the process may include:

[0353] S801, the core network element sends a sixth message to the third network device. The sixth message includes W NHs, where W is an integer greater than 1. Correspondingly, the third network device receives the sixth message.

[0354] Exemplarily, the core network element determines W NHs and then sends the sixth message to the third network device. The NCCs associated with the W NHs may be consecutive. Here, the core network element is the AMF network element, and the third network device is the initial source network device of the terminal. After the terminal accesses the core network element through the initial source network device, the same root key KAMF (such as KAMF0) is saved on the terminal and the core network element.

[0355] The content included in the sixth message can be referred to the description in Embodiment 3, and the specific implementation of S801 can be referred to the description of S601.

[0356] S802, the third network device sends a first message to the terminal. Correspondingly, the terminal receives the first message.

[0357] Among them, the first message may be an RRC message, such as an RRC reconfiguration message. For example, the first message includes the LTM configuration and NCC information 2 of multiple candidate cells. Optionally, the first message further includes the identification information associated with the multiple candidate cells (such as the identification information of the network device to which the candidate cell belongs, or the group identification information associated with the candidate cell, or other possible information).

[0358] Among them, the NCC information 2 includes the NCCs associated with the W NHs; or the NCC information 2 includes a second NCC. The W NHs are sorted from small to large based on the NCCs associated with the W NHs, and the second NCC is the NCC associated with the initial NH among the W NHs.

[0359] S803, the terminal accesses the first network device. Correspondingly, the first network device can determine that the terminal accesses the first network device.

[0360] The specific implementation of the above S803 can be referred to the description of S403.

[0361] S804, the first network device sends a seventh message to the third network device. The seventh message is used to request security information. Correspondingly, the third network device receives the seventh message.

[0362] S805, in response to the seventh message, the third network device sends an eighth message to the first network device. The eighth message includes security information.

[0363] (1) Introduce the security information.

[0364] Exemplarily, the security information includes the first NH among the W NHs, and the first NH is the unused NH among the W NHs. Alternatively, the security information includes the index of the first NH. In this case, the third network device may also send the W NHs to the first network device, and the index of the first NH is used by the first network device to determine the first NH from the W NHs. For example, the third network device sends the W NHs to the first network device through a handover request message. Alternatively, the third network device derives a key based on the first NH, and the security information includes the key derived based on the first NH.

[0365] Among them, the W NHs are sorted in the first order, and the first NH is the first unused NH among the W NHs. The first NH is the NH that has not been used in the previous inter-site handover, that is, the previously used NHs are no longer used, so as to ensure that different NHs are used for multiple inter-site handovers to the first network device. For example, the W NHs are NH1, NH2, NH3, NH4, NH5, NH6, NH7, NH1 is the used NH (for example, when the terminal communicates with the second network device, the NH used by the second network device is NH1), and the remaining NHs are unused NHs, then the first NH is NH2. Among them, the first order is the order from smallest to largest of NCC or the order of the W NHs indicated by the core network element.

[0366] Exemplarily, the third network device may determine the first order based on the sixth message. Two possible methods are described below in combination with Method 1 and Method 2.

[0367] Method 1: The W NHs included in the sixth message are sorted in the first order. That is, the core network element indicates the first order through the sixth message, and the first network device directly obtains the W NHs sorted in the first order from the sixth message. In this case, the W NHs being sorted in the first order may mean that the W NHs are sorted from smallest to largest based on the NCC associated with the W NHs; or it may also refer to other possible sorting methods, which are not specifically limited.

[0368] Method 2: The sixth message includes the W NHs and the NCCs associated with the W NHs. The first network device sorts the W NHs from smallest to largest based on the NCCs associated with the W NHs. In this case, the W NHs being sorted in the first order may mean that the W NHs are sorted from smallest to largest based on the NCCs associated with the W NHs.

[0369] It can be understood that, based on the sorting of the above W NHs, the sorting information of the W NCCs is included in the above first message, and the W NHs are associated with the W NCCs one by one. Specifically, when the NCC information 2 includes the NCCs associated with the W NHs, the NCCs associated with the W NHs are also sorted in the first order, so that the NH used by the terminal during a certain handover is the same as the NH used by the first network device.

[0370] (2) Introduce "the first network device sends a seventh message to the third network device".

[0371] Exemplarily, the first network device may send a seventh message to the third network device after determining that the terminal has accessed the first network device; or, the first network device may also send a seventh message to the third network device when it is determined that the terminal is about to access the first network device. For example, after the first network device receives a cell handover notification message, it sends a seventh message to the third network device. The embodiments of the present application do not limit the specific timing for the first network device to send the seventh message.

[0372] Or, the second network device sends a seventh message to the third network device; in response to the seventh message, the third network device sends security information to the second network device; further, the second network device sends the security information to the first network device, for example, sends the security information to the first network device through a cell handover notification message, and the specific method is not limited.

[0373] Or, the second network device sends a seventh message to the third network device, and the seventh message includes the identification information associated with the first network device (see the above for details); in response to the seventh message, the third network device sends security information to the first network device.

[0374] S806, the first network device and the terminal perform secure communication.

[0375] Next, "the first network device and the terminal perform secure communication" will be described from the perspective of the first network device and the terminal respectively.

[0376] (1) Introduce from the perspective of the first network device.

[0377] From the perspective of the first network device, after receiving the security information, the first network device uses the security information to perform security processing on the data of the terminal (including at least one of integrity protection, integrity protection confirmation, encryption, or decryption).

[0378] (2) Introduce from the perspective of the terminal.

[0379] From the perspective of the terminal, secure communication between the first network device and the terminal may mean that: after receiving the NCC information 2, for cross-site handover, the terminal determines the NCC used for the current cross-site handover, that is, the first NCC, based on the NCC information 2, and uses the first NCC to communicate with the first network device. It should be noted that the NCC used in the previous cross-site handover is not used in this cross-site handover. Communicating with the first network device using the first NCC specifically means that the terminal determines the first NH (that is, for the same handover, the NH determined by the terminal is the same as the NH determined by the first network device) based on the first NCC, and performs security processing on the data of the terminal using the first NH (including at least one of integrity protection, integrity protection confirmation, encryption, or decryption). The first NCC is associated with the first NH.

[0380] In one example, if the above NCC information 2 includes NCCs associated with W NHs (that is, W NCCs), then the first NCC is one of the W NCCs, and the NH associated with the first NCC is the unused NH. For example, if the W NCCs are sorted in the first order, the first NCC is the first unused NCC among the W NCCs. For example, if the W NCCs are NCC1 (associated with NH1), NCC2 (associated with NH2), NCC3 (associated with NH3), NCC4 (associated with NH4), NCC5 (associated with NH5), NCC6 (associated with NH6), NCC7 (associated with NH7), and NCC1 is the used NCC (for example, the NCC used by the terminal to communicate with the second network device (that is, the source access network device of the current handover) is NCC1), and the remaining NCCs are unused NCCs, then the first NCC is NCC2.

[0381] For this example, when the W NCCs are consecutive, it can also be understood that: the first NCC is obtained by adding 1 to the second NCC, and the second NCC is the NCC used by the terminal to communicate with the second network device (that is, the source access network device of the current handover).

[0382] In another example, if the above NCC information 2 includes the second NCC, then when the terminal makes the first handover, it can use the second NCC to communicate with the target network device of the handover; after that, when the terminal makes another handover, it can obtain the first NCC by adding 1 to the second NCC, and then use the first NCC to communicate with the target network device of the handover; and so on.

[0383] Based on the above method, after the first network device and the terminal determine the first NH, the first network device and the terminal respectively perform the following operations: taking the first NH and the target cell information of this handover (such as the PCI and downlink frequency of the cell) as input parameters, deducing the KgNB of the target cell, and then deducing Kup and Krrc based on KgNB, and using Kup and Krrc for secure communication between the first network device and the terminal.

[0384] It can be understood that in the above S803, during the process of the terminal accessing the first network device, the terminal and the first network device can also perform secure communication in the manner described in S806. That is to say, S806 can be applicable to the communication after the terminal accesses the first network device, and can also be applicable to the communication during the process of the terminal accessing the first network device.

[0385] Optionally, the above method further includes S807.

[0386] S807, the first network device sends a fifth message to the core network element. The fifth message is used to request path switching and is also used to indicate not to update the NH; correspondingly, the core network element receives the fifth message.

[0387] The above S806 can refer to the description of S405 in Embodiment 1.

[0388] It can be understood that after the third network device obtains W NHs from the core network element, each time the terminal switches, the third network device can allocate one unused NH among the N NHs to the target network device for the switch. If the third network device determines that the W NHs are about to be used up or have been used up, the third network device can request new NHs and NCCs from the core network element and send the new NCCs to the terminal for subsequent switching.

[0389] Adopting this method, the initial source network device of the terminal requests W NHs from the core network element and sends the NCC information 2 to the terminal; furthermore, each time there is a switch, the initial source network device allocates an unused NH to the target network device for the current switch, and the terminal uses an unused NCC to communicate with the target network device for the current switch, so that different NHs can be used for each switch, and there is no need to transmit security-related information to the terminal through RRC reconfiguration messages, facilitating secure communication between the terminal and the network device in the LTM cross-site switching scenario, improving the security of continuous cross-site switching, and ensuring secure communication for cross-site continuous switching.

[0390] Embodiment 6

[0391] In Embodiment 6 ( Figure 9 ), a possible implementation process will be described based on the above Embodiment 5. That is, Embodiment 6 can be combined with Embodiment 5, and the specific implementation of the relevant steps in Embodiment 6 can refer to Embodiment 5.

[0392] Figure 9 It is a schematic flowchart associated with the communication method provided in Embodiment 6 of this application. Figure 9The LTM inter-site handover shown includes the terminal switching from network device 0 to network device 1 (the first handover), and then from network device 1 to network device 2 (the second handover). Among them, network device 0 is the initial source network device (such as the third network device in Embodiment 5). As Figure 9 shown, this process may include:

[0393] S901, the terminal connects to the core network through network device 0.

[0394] The terminal can access network device 0 through the initial access process or other possible processes, and access the core network through network device 0. Furthermore, the same root key KAMF (such as KAMF0) is saved on the terminal and the core network element. The terminal uses NCC0 (different from NCC1 to NCC7 below) to communicate with network device 0, and network device 0 uses the NH associated with NCC0 to communicate with the terminal.

[0395] S902, network device 0 determines multiple candidate cells (or multiple candidate network devices) for the LTM handover.

[0396] Exemplarily, network device 0 determines multiple candidate cells for the LTM handover according to the measurement results reported by the terminal. If it is determined to initiate the LTM configuration, for example, the multiple candidate cells determined include cell a, cell b1, cell b2, and cell c. Among them, cell 0 is the cell of network device 0, cell b1 and cell b2 are the cells of network device 1, and cell c is the cell of network device 2. That is, the multiple candidate network devices include network device 0, network device 1, and network device 2.

[0397] S903, network device 0 sends message 1 to the core network element. Message 1 is used to request the core network element to provide NH to network device 0.

[0398] Optionally, message 1 includes the quantity information of NH.

[0399] S904, the core network element sends message 2 to network device 0. Message 2 includes W NHs; correspondingly, network device 0 receives message 2.

[0400] For example, the core network element derives W NHs. The NCCs associated with the W NHs are consecutive. The W NHs include NH1 to NH7 (i.e., W = 7), and sends the W NHs to network device 0 through message 2.

[0401] Optionally, Message 2 further includes NCC information associated with W NHs (i.e., NCC information 2). NCC information 2 includes NCCs associated with W NHs, such as NCC1 to NCC7; or if the W NHs included in Message 2 are sorted in ascending order based on the NCCs associated with the W NHs, then NCC information 2 includes the NCC associated with the initial NH among the W NHs, such as NCC1, and optionally, also includes the value of W.

[0402] S905, Network device 0 sends a handover request message to Network device 1; correspondingly, Network device 1 receives the handover request message from Network device 0.

[0403] Here, the handover request message is used to request the LTM configuration of cell b1.

[0404] S906, Network device 1 sends a handover response message to Network device 0; correspondingly, Network device 0 receives the handover response message from Network device 1.

[0405] Exemplarily, the handover response message includes the LTM configuration of cell b1.

[0406] It can be understood that Network device 0 can also send a handover request message to Network device 1 for cell b2, and the handover request message is used to request the LTM configuration of cell b2; in response to this handover request message, Network device 1 sends a handover response message to Network device 0, and the handover response message includes the LTM configuration of cell b2.

[0407] S907, Network device 0 sends a handover request message to Network device 2. Correspondingly, Network device 2 receives the handover request message from Network device 0.

[0408] Here, the handover request message is used to request the LTM configuration of cell c.

[0409] S908, Network device 2 sends a handover response message to Network device 0; correspondingly, Network device 0 receives the handover response message from Network device 2.

[0410] Exemplarily, the handover response message includes the LTM configuration of cell c.

[0411] S909, Network device 0 sends an RRC reconfiguration message to the terminal; correspondingly, the terminal receives the RRC reconfiguration message.

[0412] Exemplarily, the RRC reconfiguration message includes the LTM configuration of cell a, the LTM configuration of cell b1, the LTM configuration of cell b2, the LTM configuration of cell c, and also includes NCC information 2.

[0413] S910, Network device 0 determines that the terminal needs to handover, and the target network device for the handover is Network device 1.

[0414] Among them, there are multiple specific implementations for the network device 0 to determine the target network device, and the embodiments of this application do not limit this. For example, the network device 0 can determine the target network device as the network device 1 according to the measurement report reported by the terminal.

[0415] S911. The network device 0 sends a handover command message to the terminal. Correspondingly, the terminal receives the handover command message from the network device 0.

[0416] For example, the handover command message is a MAC CE, and the handover command message includes the identification information of the target cell (such as cell b1).

[0417] S912. The network device 0 sends a cell handover notification message to the network device 1. The cell handover notification message is used to indicate that a handover command has been initiated for the terminal; correspondingly, the network device 1 receives the cell handover notification message.

[0418] S913. In response to the cell handover notification message, the network device 1 sends a request message 1 to the network device 0. The request message 1 is used to request security information; correspondingly, the network device 0 receives the request message 1.

[0419] S914. The network device 0 sends security information 1 to the network device 1; correspondingly, the network device 1 receives the security information 1.

[0420] Exemplarily, the network device 0 allocates the first unused NH (i.e., NH1) among the W NHs to the network device 1, and then sends the security information 1 to the network device 1. The security information 1 includes NH1, or the index of NH1, or the key KgNB deduced based on NH1.

[0421] S915. In response to the handover command message, the terminal switches to the network device 1.

[0422] S916. The network device 1 sends a path switch request message to the AMF network element. The path switch request message is used to indicate not to update the NH; correspondingly, the AMF network element receives the path switch request message.

[0423] S917. The AMF network element sends a path switch response message to the network device 1; correspondingly, the network device 1 receives the path switch response message, and then completes the path switch.

[0424] Here, the path switch means that the data transmission path of the terminal is switched from "UPF network element - network device 0 - terminal" to "UPF network element - network device 1 - terminal". The path switch response message does not include the NH and NCC.

[0425] S918. The terminal conducts secure communication with the network device 1.

[0426] From the perspective of network device 1, network device 1 communicates with the terminal using the received security information 1 described above.

[0427] From the perspective of the terminal, the terminal communicates with network device 1 according to NCC information 2 (for example, NCC information 2 includes NCC1 to NCC7), using the first unused NCC (i.e., NCC1). Specifically, based on NCC1, the terminal determines NH1 associated with NCC1, and then uses NH1 to perform security processing on the terminal's data.

[0428] In this way, it can be ensured that the keys used by network device 1 and the terminal are the same, thus enabling secure communication between network device 1 and the terminal.

[0429] S919, network device 1 determines that the terminal needs to switch, and the target network device for the switch is network device 2.

[0430] S920, network device 1 sends a handover command message to the terminal. Correspondingly, the terminal receives the handover command message from network device 1.

[0431] For example, the handover command message is MAC CE, and the handover command message includes the identification information of the target cell (such as cell c).

[0432] S921, network device 1 sends a cell handover notification message to network device 2. The cell handover notification message is used to indicate that a handover command has been initiated for the terminal; correspondingly, network device 2 receives the cell handover notification message.

[0433] S922, in response to the cell handover notification message, network device 2 sends a request message 2 to network device 0. The request message 2 is used to request security information; correspondingly, network device 0 receives the request message 2.

[0434] S923, network device 0 sends security information 2 to network device 2; correspondingly, network device 2 receives security information 2.

[0435] Exemplarily, network device 0 allocates the first unused NH (i.e., NH2, NH1 has been used) among the W NHs to network device 2, and then sends security information 2 to network device 2. The security information 2 includes NH2, or the index of NH2, or the key KgNB deduced based on NH2.

[0436] S924, in response to the handover command message, the terminal switches to network device 2.

[0437] S925, network device 2 sends a path switch request message to the AMF network element. The path switch request message is used to indicate not to update the NH; correspondingly, the AMF network element receives the path switch request message.

[0438] S926. The AMF network element sends a path switching response message to network device 2. Correspondingly, network device 2 receives the path switching response message and thus completes the path switching.

[0439] Here, path switching means that the data transmission path of the terminal is switched from "UPF network element - network device 1 - terminal" to "UPF network element - network device 2 - terminal". The path switching response message does not include NH and NCC.

[0440] S927. The terminal conducts secure communication with network device 2.

[0441] From the perspective of network device 2, network device 2 uses the received security information 2 above to communicate with the terminal.

[0442] From the perspective of the terminal, the terminal uses the first unused NCC (i.e., NCC2, NCC1 has been used) according to NCC information 2 (for example, NCC information 2 includes NCC1 to NCC7) to communicate with network device 2. Specifically, based on NCC2, the terminal determines NH2 associated with NCC2, and then uses NH2 to perform security processing on the data of the terminal.

[0443] In this way, it can be ensured that the keys used by network device 2 and the terminal are the same, thus enabling secure communication between network device 2 and the terminal.

[0444] It can be understood that subsequently, the terminal can also switch from network device 2 to network device 0 or network device 1. The specific implementation can refer to the description of the terminal switching from network device 1 to network device 2; or, if the candidate network devices for LTM switching also include network device 3, then subsequently the terminal can also switch from network device 2 to network device 3. The specific implementation can refer to the description of the terminal switching from network device 1 to network device 2.

[0445] Regarding the above-mentioned multiple embodiments, it can be understood that:

[0446] (1) In any embodiment of the present invention, "in response to A (message), perform B (action)" can be understood as "perform B according to A", or can be understood as "because of A, so perform B". In any embodiment of the present invention, if A is associated with B and B is associated with C, then it can be considered that A is associated with C. "Associated" and "corresponding" can be mutually replaced.

[0447] (2) In each embodiment of the present application, if there is no special indication and logical conflict, the terms and / or descriptions between different embodiments are consistent and can be cross-referenced. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships. In addition, within the same embodiment, different implementation manners or different examples can also be cross-referenced or referred to each other.

[0448] (3) The various digital numbers involved in the present application are only for the convenience of description and do not limit the scope of the present application. The step numbers in the above flowcharts are only an example of the execution process and do not constitute a limitation on the execution order of the steps. That is, the size of each step number does not mean the sequence of execution. The execution order of each step should be determined by its function and internal logic. In addition, not all the steps shown in each flowchart are necessary steps, and some steps can be added or deleted based on the actual needs on the basis of each flowchart.

[0449] The above mainly introduces the solutions provided by the embodiments of the present application from the perspective of the interaction between the network-side device and the terminal-side device. It can be understood that, in order to implement the above functions, the network-side device and the terminal-side device may include the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, combining the units and algorithm steps of each example described in the embodiments disclosed herein, the embodiments of the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described function for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0450] The embodiments of the present application can perform the division of functional units on the network-side device and the terminal-side device according to the above method examples. For example, each functional unit can be divided corresponding to each function, or two or more functions can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0451] In the case of adopting an integrated unit, Figure 10 shows a possible exemplary block diagram of the device involved in the embodiments of the present application. As Figure 10As shown, the device 1000 may include: a processing unit 1002 and a communication unit 1003. The processing unit 1002 is used to control and manage the operations of the device 1000. The communication unit 1003 is used to support the communication between the device 1000 and other devices. Optionally, the communication unit 1003 may also be referred to as a transceiver unit, and may include a receiving unit and / or a transmitting unit, which are respectively used to perform receiving and transmitting operations. The device 1000 may further include a storage unit 1001, which is used to store the program code and / or data of the device 1000.

[0452] (1) The device 1000 may be the terminal-side device (such as a terminal) in the above embodiments. The processing unit 1002 may support the device 1000 to perform the operations of the terminal in the above method examples. Alternatively, the processing unit 1002 mainly performs the internal operations of the terminal in the method examples, and the communication unit 1003 may support the communication between the device 1000 and other devices.

[0453] In one embodiment, the processing unit 1002 is used to: access a first network-side device; communicate with the first network-side device using a first next-hop link counter NCC, where the first NCC is obtained by adding 1 to the second NCC of the terminal-side device; the second NCC is the NCC used by the terminal-side device to communicate with a second network-side device, or the second NCC is the NCC used for the last access to the first network-side device.

[0454] In a possible design, the communication unit 1003 is used to: receive a first message, where the first message includes the second NCC.

[0455] In a possible design, the first message further includes the identification information associated with the first network-side device; the method further includes: determining that a key needs to be updated based on the identification information associated with the first network-side device and the identification information associated with the second network-side device, and the updated key includes: determining the first NCC and the next hop NH associated with the first NCC.

[0456] In a possible design, the identification information associated with the first network-side device is associated with the second NCC.

[0457] In a possible design, the first message further includes the root key information associated with the second NCC.

[0458] In another embodiment, the communication unit 1003 is configured to: receive a first message for indicating N NCCs, where N is an integer greater than 1; the processing unit 1002 is configured to: access a first network-side device; communicate with the first network-side device using a first NCC, where the first NCC is one of the N NCCs, and the NH associated with the first NCC is an unused NH.

[0459] In a possible design, the first message includes N NCCs; alternatively, the first message includes the starting NCC among the N NCCs and the value of N, and the N NCCs are consecutive.

[0460] In a possible design, the first message includes identification information associated with the first network-side device; the method further includes: determining that a key needs to be updated based on the identification information associated with the first network-side device and the identification information associated with the second network-side device, where the updated key includes: determining the first NCC and the NH associated with the first NCC.

[0461] In a possible design, the identification information associated with the first network-side device is associated with the N NCCs.

[0462] In a possible design, the first message further includes root key information associated with the N NCCs.

[0463] In a possible design, the processing unit 1002 is specifically configured to: initiate a layer 1 / layer 2-triggered mobility LTM handover to access the first network-side device; or, after an LTM handover fails, access the first network-side device through LTM configuration.

[0464] (2) The device 1000 may be the network-side device (such as the first network device) in the above embodiment. The processing unit 1002 may support the device 1000 in performing the actions of the first network device in the method examples above. Alternatively, the processing unit 1002 mainly performs the internal actions of the first network device in the method examples, and the communication unit 1003 may support communication between the device 1000 and other devices.

[0465] In an embodiment, the communication unit 1003 is configured to: receive a second message including N NHs, where N is an integer greater than or equal to 1; determine that a terminal-side device accesses the first network-side device; communicate with the terminal-side device using a first NH among the N NHs, where the first NH is an unused NH among the N NHs.

[0466] In a possible design, the N NHs are sorted in a first order, and the first NH is the first unused NH among the N NHs.

[0467] In a possible design, the processing unit 1002 is configured to: determine the first order based on the second message.

[0468] In a possible design, the N NHs included in the second message are sorted in the first order.

[0469] In a possible design, the second message is used to indicate the NCCs associated with the N NHs; the sorting of the N NHs in the first order includes: the N NHs are sorted in ascending order based on the NCCs associated with the N NHs.

[0470] In a possible design, the processing unit 1002 is specifically configured to: determine that the terminal-side device initiates an LTM handover to access the first network-side device; or determine that the terminal-side device accesses the first network-side device through LTM configuration after an LTM handover fails.

[0471] In a possible design, the communication unit 1003 is further configured to: send a third message to a core network element, where the third message is used to request to provide NHs to the first network-side device; receive the second message from the core network element, and the second message is a response message to the third message.

[0472] In a possible design, the third message includes the quantity information of NHs.

[0473] In a possible design, the communication unit 1003 is further configured to: receive a fourth message from a third network-side device, where the fourth message is used to request the LTM configuration of the first network-side device; and in response to the fourth message, send the third message to the core network element.

[0474] In a possible design, the communication unit 1003 is further configured to: send a first message to the terminal-side device, where the first message is used to indicate the NCCs associated with the N NHs.

[0475] In a possible design, the first message includes the NCCs associated with the N NHs; or the first message includes a second NCC, the N NHs are sorted in ascending order based on the NCCs associated with the N NHs, the NCCs associated with the N NHs are consecutive, and the second NCC is the NCC associated with the starting NH among the N NHs.

[0476] In a possible design, the first message further includes the identification information associated with the first network-side device, and the identification information associated with the first network-side device is associated with the second NCC, or the identification information associated with the first network-side device is associated with the NCCs associated with the N NHs.

[0477] In a possible design, the communication unit 1003 is further configured to: send a fifth message to a core network element, where the fifth message is used to request path switching, and the fifth message is further used to indicate not to update the NH.

[0478] It should be understood that the division of units in the above device is only a division of logical functions. In actual implementation, they can be fully or partially integrated into a physical entity, or physically separated. And the units in the device can all be implemented in the form of software called by a processing element; they can also all be implemented in hardware form; they can also be partially implemented in the form of software called by a processing element and partially implemented in hardware form. For example, each unit can be a separately established processing element, or can be integrated in a certain chip of the device. In addition, it can also be stored in the memory in the form of a program and called and executed by a certain processing element of the device to perform the functions of the unit. In addition, all or part of these units can be integrated together or can be independently implemented. The processing element mentioned here can also be a processor, which can be an integrated circuit with signal processing capabilities. In the implementation process, the operations of the above method or each of the above units can be implemented through the integrated logic circuit of the hardware in the processor element or in the form of software called by the processing element.

[0479] In one example, the units in any of the above devices can be one or more integrated circuits configured to implement the above method, for example: one or more application specific integrated circuits (ASICs), or one or more microprocessors (digital signal processors, DSPs), or one or more field programmable gate arrays (field programmable gate arrays, FPGAs), or a combination of at least two of these integrated circuit forms. Again, when the units in the device can be implemented in the form of a processing element scheduler, the processing element can be a processor, such as a general central processing unit (central processing unit, CPU), or other processors that can call programs. Again, these units can be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0480] The above receiving unit is an interface circuit of the device, which is used to receive signals from other devices. For example, when the device is implemented in the form of a chip, the receiving unit is an interface circuit of the chip for receiving signals from other chips or devices. The above transmitting unit is an interface circuit of the device, which is used to transmit signals to other devices. For example, when the device is implemented in the form of a chip, the transmitting unit is an interface circuit of the chip for transmitting signals to other chips or devices.

[0481] See Figure 11 , which is a schematic structural diagram of a network-side device (such as a network device) provided by an embodiment of the present application. The network device can be applied to, for example, Figure 1 shown in the communication system, and perform the functions of the network device in the above method embodiment. As Figure 11 shown, the network device 110 can be an access network node. The network device 110 may include one or more DUs 1101 and one or more CUs 1102. The DU 1101 may include at least one antenna 11011, at least one radio frequency unit 11012, at least one processor 11013 and at least one memory 11014. The DU 1101 part is mainly used for the transceiver of radio frequency signals, the conversion between radio frequency signals and baseband signals, and partial baseband processing. The CU 1102 may include at least one processor 11022 and at least one memory 11021.

[0482] The CU 1102 part is mainly used for baseband processing and controlling the network device, etc. The DU 1101 and CU 1102 may be physically set together or physically separated, that is, a distributed base station. The CU 1102 is the control center of the network device, and can also be called a processing unit, which is mainly used to complete the baseband processing function. For example, the CU 1102 can be used to control the network device to execute the operation process of the network device in the above method embodiment.

[0483] In addition, optionally, the network device 110 may include one or more radio frequency units, one or more DUs and one or more CUs. Among them, the DU may include at least one processor 11013 and at least one memory 11014, the radio frequency unit may include at least one antenna 11011 and at least one radio frequency unit 11012, and the CU may include at least one processor 11022 and at least one memory 11021.

[0484] In one example, the CU 1102 may be composed of one or more single boards. Multiple single boards may jointly support a radio access network with a single access indication (such as a 5G network), or may separately support radio access networks with different access systems (such as an LTE network, a 5G network or other networks). The memory 11021 and the processor 11022 may serve one or more single boards. That is to say, a memory and a processor may be separately provided on each single board. Or multiple single boards may share the same memory and processor. In addition, necessary circuits may be provided on each single board. The DU 1101 may be composed of one or more single boards. Multiple single boards may jointly support a radio access network with a single access indication (such as a 5G network), or may separately support radio access networks with different access systems (such as an LTE network, a 5G network or other networks). The memory 11014 and the processor 11013 may serve one or more single boards. That is to say, a memory and a processor may be separately provided on each single board. Or multiple single boards may share the same memory and processor. In addition, necessary circuits may be provided on each single board.

[0485] Figure 11 The network device shown can implement each process related to the network device in the above method embodiments. Figure 11 The operations and / or functions of each module in the network device shown are respectively for implementing the corresponding processes in the above method embodiments. For details, please refer to the descriptions in the above method embodiments. To avoid repetition, the detailed descriptions are appropriately omitted here.

[0486] See Figure 12 , which is a schematic structural diagram of a terminal-side device (such as a terminal) provided in an embodiment of the present application. The terminal can be applied to, for example, Figure 1 the communication system shown, and is used to implement the operations of the terminal in the above embodiments. As Figure 12 shown, the terminal includes: an antenna 1210, a radio frequency part 1220, and a signal processing part 1230. The antenna 1210 is connected to the radio frequency part 1220. In the downlink direction, the radio frequency part 1220 receives the information sent by the network device through the antenna 1210 and sends the information sent by the network device to the signal processing part 1230 for processing. In the uplink direction, the signal processing part 1230 processes the information of the terminal and sends it to the radio frequency part 1220. After the radio frequency part 1220 processes the information of the terminal, it is sent to the network device through the antenna 1210.

[0487] The signal processing part 1230 may include a modulation and demodulation subsystem for implementing the processing of each communication protocol layer of data; it may also include a central processing subsystem for implementing the processing of the terminal operating system and the application layer; in addition, it may also include other subsystems, such as a multimedia subsystem, a peripheral subsystem, etc. The multimedia subsystem is used to control the terminal camera, screen display, etc., and the peripheral subsystem is used to implement the connection with other devices. The modulation and demodulation subsystem may be a separately provided chip.

[0488] The modulation and demodulation subsystem may include one or more processing elements 1231. For example, it includes a main control CPU and other integrated circuits. In addition, the modulation and demodulation subsystem may also include a storage element 1232 and an interface circuit 1233. The storage element 1232 is used to store data and programs, but the programs for executing the methods executed by the terminal in the above methods may not be stored in the storage element 1232, but in a memory outside the modulation and demodulation subsystem, and are loaded and used by the modulation and demodulation subsystem when in use. The interface circuit 1233 is used to communicate with other subsystems.

[0489] The modulation and demodulation subsystem may be implemented by a chip, which includes at least one processing element and an interface circuit. The processing element is used to execute each step of any of the above methods executed by the terminal, and the interface circuit is used to communicate with other devices. In one implementation, the units for implementing each step in the above methods by the terminal may be implemented in the form of a processing element scheduler. For example, the device for the terminal includes a processing element and a storage element, and the processing element calls the program stored in the storage element to execute the methods executed by the terminal in the above method embodiments. The storage element may be a storage element on the same chip as the processing element, that is, an on-chip storage element.

[0490] In another implementation, the program for executing the methods executed by the terminal in the above methods may be in a storage element on a different chip from the processing element, that is, an off-chip storage element. At this time, the processing element calls or loads the program from the off-chip storage element onto the on-chip storage element to call and execute the methods executed by the terminal in the above method embodiments.

[0491] In yet another implementation, the units for implementing each step in the above methods by the terminal may be configured as one or more processing elements, and these processing elements are provided on the modulation and demodulation subsystem. Here, the processing elements may be integrated circuits. For example: one or more ASICs, or one or more DSPs, or one or more FPGAs, or a combination of these types of integrated circuits. These integrated circuits may be integrated together to form a chip.

[0492] The units in the terminal that implement the various steps in the above method can be integrated together and implemented in the form of a SOC. This SOC chip is used to implement the above method. At least one processing element and a storage element can be integrated in this chip, and the method executed by the above terminal is implemented in the form of a program stored in the storage element being called by the processing element; alternatively, at least one integrated circuit can be integrated in this chip for implementing the method executed by the above terminal; alternatively, the above implementation methods can be combined, and the functions of some units are implemented in the form of a program called by the processing element, and the functions of some units are implemented in the form of an integrated circuit.

[0493] It can be seen that the above device for a terminal can include at least one processing element and an interface circuit, where at least one processing element is used to execute any of the methods executed by the terminal provided in the above method embodiments. The processing element can execute some or all of the steps executed by the terminal in the first way: that is, by calling the program stored in the storage element; or in the second way: that is, by combining the integrated logic circuit in the processor element with instructions to execute some or all of the steps executed by the terminal; of course, some or all of the steps executed by the terminal can also be executed by combining the first way and the second way.

[0494] The processing element here is the same as the above description and can be implemented by a processor. The function of the processing element can be the same as that of the Figure 10 processing unit described therein. Exemplarily, the processing element can be a general-purpose processor, such as a CPU, or can also be one or more integrated circuits configured to implement the above method, such as: one or more ASICs, or one or more microprocessors DSPs, or one or more FPGAs, etc., or a combination of at least two of these integrated circuit forms. The storage element can be implemented by a memory, and the function of the storage element can be the same as that of the Figure 10 storage unit described therein. The storage element can be a single memory or a collective term for multiple memories.

[0495] Figure 12 The terminal shown can implement each process related to the terminal in the above method embodiments. Figure 12 The operations and / or functions of each module in the terminal shown are respectively for implementing the corresponding processes in the above method embodiments. For details, reference can be made to the description in the above method embodiments. To avoid repetition, the detailed description is appropriately omitted here.

[0496] This application embodiment also provides a communication system, which includes the terminal in the above method embodiment, and also includes the first network device in the above method embodiment. Optionally, it also includes the third network device in the above method embodiment.

[0497] In the embodiments of the present application, the terms "system" and "network" can be used interchangeably. "At least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, or B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one of the following" or a similar expression refers to any combination of these items, including any combination of single item or plural items. For example, "at least one of A, B or C" includes A, B, C, AB, AC, BC or ABC, and "at least one of A, B and C" can also be understood to include A, B, C, AB, AC, BC or ABC. Also, unless otherwise specified, the ordinal numbers such as "first" and "second" mentioned in the embodiments of the present application are used to distinguish multiple objects and are not used to limit the order, time sequence, priority or importance degree of multiple objects.

[0498] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, optical storage, etc.) that contain computer-usable program code.

[0499] The present application is described with reference to the flowcharts and / or block diagrams of the method, device (system), and computer program product according to the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0500] These computer program instructions can also be stored in a computer-readable memory that can guide the computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device realizes the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0501] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing instructions for implementing the steps specified in one process or multiple processes and / or boxes Figure 1 one process or multiple processes and / or boxes Figure 1 or functions specified in one box or multiple boxes.

Claims

1. A communication method, characterized in that: The method is applied to a terminal-side device, and includes: Accessing a first network-side device; communicating with the first network-side device using a first next-hop link counter NCC, where the first NCC is obtained by adding 1 to the second NCC by the terminal-side device; The second NCC is the NCC used by the terminal-side device to communicate with the second network-side device, or the second NCC is the NCC used for the last access to the first network-side device.

2. The method according to claim 1, characterized in that The method further comprises: A first message is received, where the first message includes the second NCC.

3. The method according to claim 2, characterized in that The first message further includes identification information associated with the first network-side device; The method further comprises: Based on the identification information associated with the first network side device and the identification information associated with the second network side device, it is determined that a key needs to be updated, and the key updating includes: determining the first NCC and a next hop NH associated with the first NCC.

4. The method according to claim 3, characterized in that The identification information associated with the first network-side device is associated with the second NCC.

5. The method according to any one of claims 2 to 4, characterized in that The first message also includes root key information associated with the second NCC.

6. A communication method, characterized in that: The method is applied to a terminal-side device, and includes: receiving a first message, where the first message is used to indicate N NCCs, where N is an integer greater than 1; Accessing a first network-side device; A first NCC is used to communicate with the first network-side device, where the first NCC is one of the N NCCs, and a NH associated with the first NCC is an unused NH.

7. The method according to claim 6, characterized in that The first message includes N NCCs; or, The first message includes a starting NCC and a value of N among the N NCCs, and the N NCCs are continuous.

8. The method according to claim 6 or 7, characterized in that The first message includes identification information associated with the first network-side device; The method further comprises: Based on the identification information associated with the first network side device and the identification information associated with the second network side device, it is determined that a key needs to be updated, and the key updating includes: determining the first NCC and the NH associated with the first NCC.

9. The method according to claim 8, characterized in that The identification information associated with the first network-side device is associated with the N NCCs.

10. The method according to any one of claims 6 to 9, characterized in that The first message also includes root key information associated with the N NCCs.

11. The method according to any one of claims 1 to 10, characterized in that Accessing the first network-side device includes: Initiate a layer 1 / layer 2 triggered mobility LTM handover to access the first network side device; or, After the LTM switching fails, the first network-side device is accessed through the LTM configuration.

12. A communication method, characterized in that: The method is applied to a first network-side device, and includes: receiving a second message including N NHs, where N is an integer greater than or equal to 1; Determining that the terminal-side device is connected to the first network-side device; A first NH among the N NHs is used to communicate with the terminal-side device, where the first NH is an unused NH among the N NHs.

13. The method according to claim 12, characterized in that The N NHs are sorted in a first order, and the first NH is the first unused NH among the N NHs.

14. The method according to claim 13, characterized in that The method further comprises: Based on the second message, the first order is determined.

15. The method according to claim 14, characterized in that The N NHs included in the second message are sorted in a first order.

16. The method according to claim 14, characterized in that The second message is used to indicate the NCC associated with the N NHs; Sorting the N NHs according to the first order includes: sorting the N NHs from small to large based on NCCs associated with the N NHs.

17. The method according to any one of claims 12 to 16, characterized in that Determining that the terminal-side device is connected to the first network-side device includes: Determine that the terminal-side device initiates LTM switching to access the first network-side device; or, After determining that the terminal side device fails in LTM switching, access to the first network side device is performed through LTM configuration.

18. The method according to any one of claims 12 to 17, characterized in that The method further includes: sending a third message to a core network element, wherein the third message is used to request that the first network side device provide NH; Receiving the second message includes: receiving the second message from the core network element, where the second message is a response message to the third message.

19. The method according to claim 18, characterized in that The third message includes the quantity information of NHs.

20. The method according to claim 18 or 19, characterized in that Sending a third message to the core network element includes: receiving a fourth message from a third network-side device, wherein the fourth message is used to request LTM configuration of the first network-side device; In response to the fourth message, the third message is sent to the core network element.

21. The method according to any one of claims 12 to 19, characterized in that The method further comprises: A first message is sent to a terminal side device, where the first message is used to indicate the NCC associated with the N NHs.

22. The method according to claim 21, characterized in that The first message includes the NCC associated with the N NHs; or, The first message includes a second NCC, the N NHs are sorted from small to large based on NCCs associated with the N NHs, the NCCs associated with the N NHs are continuous, and the second NCC is the NCC associated with the starting NH among the N NHs.

23. The method according to claim 22, characterized in that The first message also includes identification information associated with the first network side device, where the identification information associated with the first network side device is associated with the second NCC, or the identification information associated with the first network side device is associated with the NCC associated with the N NHs.

24. The method according to any one of claims 13 to 23, characterized in that The method further comprises: A fifth message is sent to the core network element, where the fifth message is used to request path switching and is further used to indicate not to update the NH.

25. A communication device, characterized in that: The method comprises a module for executing the method according to any one of claims 1 to 11, or a module for executing the method according to any one of claims 12 to 24.

26. A communication device, characterized in that: The communication device comprises a processor coupled to a memory, wherein a computer program is stored in the memory; the processor is used to call the computer program in the memory so that the communication device executes the method according to any one of claims 1 to 11, or the method according to any one of claims 12 to 24.

27. A communication system, characterized in that: The communication system includes a network side device and a terminal side device; wherein the terminal side device is used to execute the method described in any one of claims 1 to 11, and the network side device is used to execute the method described in any one of claims 12 to 24.

28. A computer-readable storage medium, characterized in that The storage medium stores a computer program or instruction. When the computer program or instruction is executed by a computer, the method according to any one of claims 1 to 11 or the method according to any one of claims 12 to 24 is implemented.

29. A computer program product, characterized in that When a computer reads and executes the computer program product, the method according to any one of claims 1 to 11 is executed, or the method according to any one of claims 12 to 24 is executed.