Communication method, terminal device, network element, storage medium and chip system
By receiving the first indication information in a dual-connection scenario, instructing the target network element and the terminal device to perform key updates synchronously, using the same security algorithm, the problem of synchronous updates of keys between the terminal device and the network device is solved, and communication security is improved.
Patent Information
- Application Number
- CN202410154931.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-31
- Publication Date
- 2025-08-08
AI Technical Summary
In dual-connection scenarios, how to synchronously update the keys of terminal devices and network devices to ensure communication security.
By receiving the first indication information, the target network element and the terminal device are instructed to perform key updates synchronously, and the same security algorithm is used to ensure consistency of key updates.
The communication security between the terminal device and the target network element during cell handover is realized, ensuring the consistency of key updates, and improving the security during communication.
Smart Images

Figure CN120456010A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a communication method, terminal equipment, network element, storage medium and chip system. Background Art
[0002] Dual Connectivity (DC) allows a user equipment (UE) to simultaneously use two or more cells or radio access networks for data transmission. Mobile communication networks offer a Layer Triggered Mobility (LTM) mechanism, which allows a UE to change its serving cell.
[0003] In the NR field, to ensure secure communication between terminal devices and network equipment, keys are required for secure communication between the terminal and network equipment. If the source and target cells involved in a terminal cell handover are the same base station, no key update is required. In dual-connectivity scenarios, how to synchronize key updates between network equipment and terminal devices during cell handover is a pressing technical challenge. Summary of the Invention
[0004] The embodiments of the present application provide a communication method, terminal equipment, network element, storage medium and chip system, which are applied to the field of communication technology to timely update the keys of the target network element and terminal equipment when performing cell switching between cell groups, thereby improving the security of key use during the communication process.
[0005] In a first aspect, embodiments of the present application provide a communication method. The method may be executed by a terminal device, or may be executed by a component (such as a chip or circuit) configured in the terminal device. This application does not limit this.
[0006] For example, the method includes: receiving first indication information, receiving first indication information, the first indication information is sent by the first network element when triggering cell switching between cell groups, the first indication information is used to instruct the target network element and the terminal device to synchronously perform key update, the cell switching between cell groups refers to switching from the original cell of the first cell group to the target cell of the second cell group, and the original network element corresponding to the first cell group and the target network element corresponding to the second cell group are different.
[0007] As mentioned above, a network element can refer to a device in a network with a certain transmission function. A network element can include a base station or a CU. In addition, a network element can also be a device with other hardware structures or combinations. This application does not limit the specific device type or device composition of the network element. In a dual-connection scenario, the original network element can be the original primary base station MN accessed by the terminal device, and the target network element can be the target MN to be accessed, or the original network element can be the original secondary base station SN accessed by the terminal device, and the target network element can be the target SN to be accessed.
[0008] Specifically, when performing LTM cell handover between cell groups, the first network element sends first indication information to the target network element and the terminal device respectively. The first network element may be the original network element or not.
[0009] It should be understood that the first network element may send the first indication information to the target network element via a beam corresponding to the target network element. The first network element may also send the first indication information to the UE via a beam corresponding to the terminal device.
[0010] In combination with the first aspect, in certain implementations of the first aspect, cell switching between cell groups includes cell switching of the main cell group MCG, the original network element is the original main base station MN, the target network element is the target MN, and the first network element is the original MN; and / or, cell switching between cell groups includes cell switching of the secondary cell group SCG, the original network element is the original secondary base station SN, the target network element is the target SN, and the first network element is the original secondary base station SN or the main base station MN.
[0011] Optionally, in a dual connectivity scenario, based on different execution entities that trigger cell handover and different triggered cell handover objects, the following handover modes may be included:
[0012] 1. MCG cell switching is triggered by MN; 2. SCG cell switching is triggered by MN; 3. When SN is configured with signaling bearer resources, SCG cell switching is triggered by SN; 4. When SN is not configured with signaling bearer resources, SCG cell switching is triggered by SN; 5. When SN is configured with signaling bearer resources, MCG cell switching is triggered by SN; 6. When SN is not configured with signaling bearer resources, MCG cell switching is triggered by SN.
[0013] In combination with the first aspect, in certain implementations of the first aspect, the first indication information is sent by the original SN through signaling bearer resources when the signaling bearer resources are configured; or, the first indication information is sent by the main base station MN when the original SN is not configured with signaling bearer resources, and the MN is sent under the instruction of the second indication information sent by the original SN, and the second indication information is used to instruct the MN to send the first indication information to the target SN and the terminal device.
[0014] To achieve transmission of the first indication information, the first indication information is carried in a media access control-control element MAC CE signaling or a dedicated signaling for handover. That is, the first indication information is sent to the terminal device and the target network element via the MAC CE signaling or the dedicated signaling.
[0015] In conjunction with the first aspect, in some implementations of the first aspect, before receiving the first indication information, the method further includes:
[0016] Receive configuration information, the configuration information is used to configure the candidate network element to determine the security algorithm based on the security information of the terminal device, the candidate network element includes the target network element; when the cell switching between cell groups is the cell switching of the main cell group MCG, the candidate network element includes at least the candidate MN, and / or, when the cell switching between cell groups includes the cell switching of the secondary cell group SCG, the candidate network element includes at least the candidate SN.
[0017] Optionally, the configuration information is used to indicate the correspondence between the set of cells covered by the candidate network element configured by the terminal device and the security algorithm determined by the candidate network element for the terminal device. The security algorithm of the terminal device is determined based on the security information of the terminal device.
[0018] When the first network element sends configuration information to the terminal device, the configuration information can be carried by various messages or signaling specified in the protocol. For example, the configuration information can be carried in an RRC reconfiguration message, or in a Media Access Control-Control Element MAC CE signaling or proprietary signaling.
[0019] Correspondingly, after receiving the RRC reconfiguration message, the terminal device saves the RRC reconfiguration information to configure the security algorithm of the terminal device according to the configuration information carried in the RRC reconfiguration message.
[0020] It should be understood that the configuration information can be carried in a predefined field in the RRC message. In addition to carrying the configuration information, the RRC message may also include the parameters required by the target network element for the terminal device to access the target cell. For example, it may include information about the target cell (such as the physical cell identifier (PCI) of the target cell), frequency information corresponding to the target cell, resource information allocated by the target network element to the terminal device (such as dedicated random access channel (RACH) resources and / or public RACH resources), etc.
[0021] In this application, when both the terminal device and the target network element perform key updates, the same security algorithm is used to ensure that the key update processes of the terminal device and the target network element remain consistent, so that the updated keys of the terminal device and the target network element remain consistent, and the communication security between the terminal device and the target network element is effectively guaranteed.
[0022] Optionally, the candidate network element corresponds to at least one candidate cell, and the configuration information includes at least one of the following:
[0023] A security algorithm configured for each candidate cell and terminal device;
[0024] A security algorithm set configured corresponding to each candidate cell and terminal device, the security algorithm set including multiple security algorithms;
[0025] A security algorithm configured for each candidate cell set / group and terminal device;
[0026] Each candidate cell set / group is configured with a security algorithm set corresponding to the terminal device, and the security algorithm set includes multiple security algorithms.
[0027] When the candidate network elements include at least a candidate MN, the configuration information includes at least one of the following:
[0028] A security algorithm configured for each candidate MN cell and terminal device;
[0029] A security algorithm set configured corresponding to each candidate MN cell and terminal device, the security algorithm set including multiple security algorithms;
[0030] A security algorithm configured for each candidate MN cell set / group and the corresponding terminal device;
[0031] Each candidate MN cell set / group is configured with a security algorithm set corresponding to the terminal device, and the security algorithm set includes multiple security algorithms.
[0032] Wherein, when the candidate network element includes at least a candidate SN, the configuration information includes at least one of the following:
[0033] A security algorithm configured for each candidate SN cell and terminal device;
[0034] A security algorithm set corresponding to each candidate SN cell and terminal device, the security algorithm set includes multiple security algorithms;
[0035] A security algorithm configured for each candidate SN cell set / group and the corresponding terminal device;
[0036] Each candidate SN cell set / group corresponds to a security algorithm set configured for the terminal device, and the security algorithm set includes multiple security algorithms.
[0037] Optionally, the security algorithm set may include algorithm indexes corresponding to multiple security algorithms. A security algorithm may consist of one or more algorithms, and a combination of one or more algorithms may be referred to as a security algorithm. For example, the combination of an integrity protection algorithm and an encryption algorithm may be referred to as a security algorithm, while the integrity protection algorithm alone may also be referred to as a security algorithm, and the encryption algorithm alone may also be referred to as a security algorithm.
[0038] It should be understood that each candidate cell set / group may include one or more candidate cells, and specifically may include information about one or more candidate cells, such as at least one of the following: the candidate cell's physical cell identifier, cell identifier, cell name, etc. Each candidate cell set / group may be mapped to a security algorithm of a terminal device. That is, any candidate cell in each candidate cell set / group uses a security algorithm of the terminal device.
[0039] Candidate cells and terminal devices can each use the same algorithm selection policy to select a target security algorithm from the algorithm security set. Consequently, both candidate cells and terminal devices can perform key updates using the target security algorithm. The algorithm selection policy can be pre-configured, for example, based on parameters such as the security algorithm's computational complexity and computation time.
[0040] Optionally, the security information includes at least one of the following:
[0041] The security capabilities of the terminal device, the security level of the terminal device, and the security attributes of the terminal device.
[0042] It should be understood that the security capabilities of a terminal device may include the hardware security capabilities and software security capabilities of the terminal device. The security level of a terminal device may refer to a security level set according to the security of the terminal device. The security attributes of a terminal device may refer to characteristics set to protect the security of the terminal device.
[0043] By using at least one of the terminal device's security capabilities, security level, and security attributes as the terminal device's security information, the terminal device's security information has a richer meaning. This allows for a more accurate terminal device security algorithm to be derived using the terminal device's security information.
[0044] In conjunction with the first aspect, in some implementations of the first aspect, the first indication information includes at least one of the following:
[0045] Secondary node key update counter SK-counter, next hop link counter NCC, algorithm indication information.
[0046] The SK-counter is a numeric variable used to track and record the number of key updates. Synchronizing the SK-counter to the terminal device and target network element helps each device ensure key security and integrity. The next hop chaining counter (NCC) is a parameter used for key derivation. A security algorithm can refer to an algorithm used for key derivation. For example, it can include a KDF (Key Derivation Function) algorithm.
[0047] Optionally, the algorithm indicates at least one of the following:
[0048] Indication information on whether to use the original security algorithm; Indication information on whether to use the original SN security algorithm; Indication information on whether to use the original MN security algorithm; Algorithm index.
[0049] It should be understood that a predefined field in the algorithm indication information can carry the indication information of whether to use the security algorithm. The algorithm indication information can use another predefined field to represent the indication information of whether to use the original SN security algorithm or the indication information of whether to use the original MN security algorithm. The algorithm indication information can carry the index of the algorithm through the predefined field, for example, the value of the field is the index of the algorithm.
[0050] In a second aspect, an embodiment of the present application provides a communication method, which can be executed by a first network element, or can also be executed by a component (such as a chip or circuit) configured in the first network element. This application does not limit this.
[0051] For example, the method includes: in the case of triggering cell switching between cell groups, sending a first indication message to the target network element and the terminal device, the first indication message is used to instruct the target network element and the terminal device to synchronously perform key update, the cell switching between cell groups refers to the original cell of the first cell group being switched to the target cell of the second cell group, and the original network element corresponding to the first cell group and the target network element corresponding to the second cell group are different.
[0052] The cell handover between the cell groups includes the cell handover of the primary cell group, the original network element is the original primary base station MN, the target network element is the target MN, and the first network element is the original MN;
[0053] And / or, the cell handover between cell groups includes the cell handover of the secondary cell group, the original network element is the original secondary base station SN, the target network element is the target SN, and the first network element is the original SN or the master base station MN.
[0054] In conjunction with the second aspect, in certain implementations of the second aspect, sending the first indication information to the target network element and the terminal device includes: sending the first indication information to the target network element and the terminal device through the signaling bearer resource when a signaling bearer resource is configured;
[0055] Alternatively, sending first indication information to the target network element and the terminal device includes:
[0056] In the case where signaling bearer resources are not configured, second indication information is sent to the MN, where the second indication information is used to instruct the MN to send first indication information to the target SN and the terminal device.
[0057] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes:
[0058] Sending configuration information to the terminal device, where the configuration information is used to configure a security algorithm determined by a candidate network element based on the security information of the terminal device, where the candidate network element includes the target network element;
[0059] When the cell switching between cell groups is the cell switching of the main cell group MCG, the candidate network elements include at least candidate MNs, and / or when the cell switching between cell groups includes the cell switching of the secondary cell group SCG, the candidate network elements include at least candidate SNs.
[0060] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes:
[0061] A cell switching request is sent to the candidate network element, where the cell switching request carries the security information of the terminal device.
[0062] In a third aspect, an embodiment of the present application provides a communication method, which can be executed by a target network element, or can also be executed by a component (such as a chip or circuit) configured in the target network element. This application does not limit this.
[0063] For example, the method includes: receiving a first indication message, the first indication message is sent by the first network element when triggering a cell switch between cell groups, the first indication message is used to instruct the target network element and the terminal device to synchronously perform a key update, the cell switch between cell groups refers to the original cell of the first cell group being switched to the target cell of the second cell group, and the original network element corresponding to the first cell group and the target network element corresponding to the second cell group are different.
[0064] In conjunction with the third aspect, some implementations of the third aspect further include:
[0065] receiving a cell handover request, the cell handover request carrying security information of the terminal device, and the candidate network elements including the target network element;
[0066] Determine the security algorithm of the terminal device based on the security information;
[0067] When the cell switching between cell groups is the cell switching of the main cell group MCG, the candidate network elements include at least candidate MNs, and / or when the cell switching between cell groups includes the cell switching of the secondary cell group SCG, the candidate network elements include at least candidate SNs.
[0068] In a fourth aspect, a communication device is provided, comprising modules or units for executing the method in the first aspect and any possible implementation manner of the first aspect.
[0069] In a fifth aspect, a communication device is provided, comprising modules or units for executing the method in the second aspect and any possible implementation manner of the second aspect.
[0070] In a sixth aspect, a communication device is provided, comprising modules or units for executing the method in the third aspect and any possible implementation manner of the third aspect.
[0071] In a seventh aspect, a communication device is provided, comprising a processor. The processor is coupled to a memory and configured to execute instructions in the memory to implement the method of the first aspect and any possible implementation of the first aspect. Optionally, the device further comprises a memory. Optionally, the device further comprises a communication interface, the processor being coupled to the communication interface.
[0072] In one implementation, the communication device is a terminal device. When the device for processing the candidate cell configuration information is a terminal device, the communication interface may be a transceiver, or an input / output interface.
[0073] In another implementation, the communication device is a chip configured in a terminal device. When the device for processing the candidate cell configuration information is a chip configured in a terminal device, the communication interface may be an input / output interface.
[0074] Optionally, the transceiver may be a transceiver circuit. Optionally, the input / output interface may be an input / output circuit.
[0075] In an eighth aspect, a communication device is provided, comprising a processor. The processor is coupled to a memory and configured to execute instructions in the memory to implement the method of the second aspect and any possible implementation thereof. Optionally, the device further comprises a memory. Optionally, the device further comprises a communication interface, the processor being coupled to the communication interface.
[0076] In one implementation, the communication device is a first network element. When the communication device is the first network element, the communication interface may be a transceiver or an input / output interface.
[0077] In another implementation, the communication device is a chip configured in the first network element. When the communication device is a chip configured in the first network element, the communication interface may be an input / output interface.
[0078] Optionally, the transceiver may be a transceiver circuit. Optionally, the input / output interface may be an input / output circuit.
[0079] In a ninth aspect, a communication device is provided, comprising a processor. The processor is coupled to a memory and configured to execute instructions in the memory to implement the method of the third aspect and any possible implementation thereof. Optionally, the device further comprises a memory. Optionally, the device further comprises a communication interface, the processor being coupled to the communication interface.
[0080] In one implementation, the communication device is a target network element. When the communication device is a target network element, the communication interface may be a transceiver, or an input / output interface.
[0081] In another implementation, the communication device is a chip configured in the target network element. When the communication device is a chip configured in the target network element, the communication interface may be an input / output interface.
[0082] Optionally, the transceiver may be a transceiver circuit. Optionally, the input / output interface may be an input / output circuit.
[0083] In a tenth aspect, a processor is provided, comprising: an input circuit, an output circuit, and a processing circuit. The processing circuit is configured to receive a signal via the input circuit and transmit a signal via the output circuit, so that the processor executes the method of the first aspect, the second aspect, or the third aspect, and any possible implementation of the first aspect, the second aspect, or the third aspect.
[0084] In a specific implementation, the processor may be one or more chips, the input circuit may be an input pin, the output circuit may be an output pin, and the processing circuit may be a transistor, a gate circuit, a trigger, or various logic circuits. The input signal received by the input circuit may be, for example, but not limited to, received and input by a receiver, and the signal output by the output circuit may be, for example, but not limited to, output to and transmitted by a transmitter. The input circuit and the output circuit may be the same circuit, which functions as an input circuit and an output circuit at different times. The embodiments of the present application do not limit the specific implementation of the processor and various circuits.
[0085] In an eleventh aspect, a processing device is provided, comprising a processor and a memory. The processor is configured to read instructions stored in the memory and receive signals via a receiver and transmit signals via a transmitter to perform the method of the first, second, or third aspect, and any possible implementation of the first, second, or third aspect.
[0086] Optionally, there are one or more processors and one or more memories.
[0087] Optionally, the memory may be integrated with the processor, or the memory may be provided separately from the processor.
[0088] In the specific implementation process, the memory can be a non-transitory memory, such as a read-only memory (ROM), which can be integrated with the processor on the same chip or can be set on different chips. The embodiments of the present application do not limit the type of memory and the setting method of the memory and the processor.
[0089] It should be understood that related data interaction processes, such as sending indication information, can be the process of outputting indication information from the processor, and receiving capability information can be the process of receiving input capability information from the processor. Specifically, data output by the processor can be output to the transmitter, and input data received by the processor can be received from the receiver. The transmitter and receiver can be collectively referred to as a transceiver.
[0090] The processing device in the aforementioned aspect 12 may be one or more chips. The processor in the processing device may be implemented in hardware or software. When implemented in hardware, the processor may be a logic circuit, an integrated circuit, or the like; when implemented in software, the processor may be a general-purpose processor implemented by reading software code stored in a memory, which may be integrated into the processor or located independently of the processor.
[0091] In the thirteenth aspect, an embodiment of the present application provides a terminal device, including a processor, a memory and a transceiver, the transceiver is used to send and receive data, the memory is used to store code instructions, and the processor is used to run the code instructions. When executing the code instructions stored in the memory, the processor is used to instruct the terminal device to execute the method described in the above-mentioned first aspect and any possible implementation method of the first aspect.
[0092] In the fourteenth aspect, an embodiment of the present application provides a network device, including a processor, a memory and a transceiver, the transceiver is used to send and receive data, the memory is used to store code instructions, and the processor is used to run the code instructions. When executing the code instructions stored in the memory, the processor is used to instruct the terminal device to execute the method described in the above-mentioned second aspect and any possible implementation method of the second aspect or the third aspect and any possible implementation method of the third aspect.
[0093] In the fifteenth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program or instruction is stored. When the computer program or instruction is run on a computer, the computer executes the method described in the first aspect, the second aspect, the third aspect, and any possible implementation of the first aspect, the second aspect, and the third aspect.
[0094] In a sixteenth aspect, the present application provides a chip or chip system, comprising at least one processor and a communication interface, wherein the communication interface and the at least one processor are interconnected via a line, and the at least one processor is configured to execute a computer program or instruction to perform the method of the first aspect, the second aspect, or the third aspect, and any possible implementation of the first aspect, the second aspect, or the third aspect. The communication interface in the chip may be an input / output interface, a pin, or a circuit, etc.
[0095] In the seventeenth aspect, an embodiment of the present application provides a computer program product comprising a computer program, which, when the computer program is run on a computer, enables the computer to execute the method in the first aspect, the second aspect or the third aspect and any possible implementation of the first aspect, the second aspect or the third aspect.
[0096] In one possible implementation, the chip or chip system described above in this application further includes at least one memory, in which instructions are stored. The memory may be a storage unit within the chip, such as a register, a cache, etc., or a storage unit of the chip (e.g., a read-only memory, a random access memory, etc.).
[0097] It should be understood that the fourth, seventh and thirteenth aspects of the present application correspond to the technical solution of the first aspect of the present application, the fifth, eighth and fourteenth aspects of the present application correspond to the technical solution of the second aspect of the present application, the sixth, ninth and fourteenth aspects of the present application correspond to the technical solution of the third aspect of the present application, the tenth, eleventh, twelfth and fifteenth to seventeenth aspects of the present application correspond to the technical solutions of the first, second or third aspects of the present application, and the beneficial effects achieved by each aspect and the corresponding feasible implementation methods are similar and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0098] Figure 1 1 is a schematic diagram of the architecture of a communication system 100 used in an embodiment of the present application;
[0099] Figure 2 is a signaling interaction diagram exemplarily illustrating an LTM switching process 200;
[0100] Figure 3 is an example diagram illustrating a CU and DU architecture 300;
[0101] Figure 4 is a signaling interaction diagram exemplarily illustrating a conventional key update method 400;
[0102] Figure 5 is a schematic diagram exemplarily showing a dual connection architecture 500;
[0103] Figure 6 is a signaling interaction diagram of the communication method 600 provided in an embodiment of the present application, shown from the perspective of device interaction;
[0104] Figure 7 is a signaling interaction diagram of the communication method 700 provided in an embodiment of the present application, shown from the perspective of device interaction;
[0105] Figure 8 This is a signaling interaction diagram of the communication method 800 provided in an embodiment of the present application, shown from the perspective of device interaction;
[0106] Figure 9 This is a signaling interaction diagram of the communication method 900 provided in an embodiment of the present application, shown from the perspective of device interaction;
[0107] Figure 10 This is a signaling interaction diagram of the communication method 1000 provided in an embodiment of the present application, shown from the perspective of device interaction;
[0108] Figure 11 This is a signaling interaction diagram of the communication method 1100 provided in an embodiment of the present application, shown from the perspective of device interaction;
[0109] Figure 12 This is a signaling interaction diagram of the communication method 1200 provided in an embodiment of the present application, shown from the perspective of device interaction;
[0110] Figure 13 is a schematic flow chart exemplarily illustrating a key updating method 1300 provided in an embodiment of the present disclosure;
[0111] Figure 14 This is a signaling interaction diagram of the communication method 1400 provided in an embodiment of the present application, shown from the perspective of device interaction;
[0112] Figure 15 is a signaling interaction diagram of the communication method 1500 provided in an embodiment of the present application, shown from the perspective of device interaction;
[0113] Figure 16 is a schematic flow chart exemplarily illustrating a key updating method 1600 provided in an embodiment of the present disclosure;
[0114] Figure 17 is a schematic block diagram of a device for processing candidate cell configuration information provided in an embodiment of the present application;
[0115] Figure 18 This is a possible structural diagram of a terminal device provided in an embodiment of the present application;
[0116] Figure 19 This is a possible structural diagram of a network device provided in an embodiment of the present application, for example, it may be a structural diagram of a base station. DETAILED DESCRIPTION
[0117] The technical solution of this application will be described below with reference to the accompanying drawings.
[0118] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: Long Term Evolution (LTE) system, LTE Frequency Division Duplex (FDD) system, LTE Time Division Duplex (TDD) system, Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication system, future fifth generation (5G) communication system or new radio access technology (NR), vehicle-to-XV2X (V2X), where V2X may include vehicle-to-network (V2N), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), vehicle-to-pedestrian (V2P), etc., Long Term Evolution-Vehicle (LTE-V), Internet of Vehicles, machine type communication (MTC), etc. communication (MTC), Internet of Things (IoT), Long Term Evolution-Machine (LTE-M), Machine to Machine (M2M), etc.
[0119] In order to facilitate understanding of the embodiments of the present application, first Figure 1 A communication system applicable to an embodiment of the present application is described in detail. Figure 1 The schematic diagram of the communication system applicable to the communication method and communication device of the embodiment of the present application is shown. The communication device can be a terminal device, an original network element or a target network element. Figure 1 As shown, the communication system 100 may include at least two network elements, such as Figure 1 As shown in the network element 110 and the network element 120, the communication system 100 may also include at least one terminal device, such as Figure 1The terminal device 130 shown in FIG. The terminal device may be mobile or fixed. Network element 110 and network element 120 are both devices or units that can communicate with terminal device 130 via wireless links, such as base stations, base station controllers, and centralized units (CUs). Each network element can provide communication coverage for a specific geographic area and can communicate with terminal devices within that coverage area (cell).
[0120] Figure 1 Two network elements and one terminal device are shown as an example. Optionally, the communication system 100 may include at least one network element and each network element may include other number of devices within its coverage area. This embodiment of the present application does not limit this.
[0121] The above-mentioned communication devices, such as Figure 1 The network element 110, network element 120, or terminal device 130 in the embodiment may be configured with multiple antennas. The multiple antennas may include at least one transmit antenna for sending signals and at least one receive antenna for receiving signals. In addition, each communication device also includes a transmitter chain and a receiver chain. Those skilled in the art will appreciate that each of these may include multiple components related to signal transmission and reception (e.g., a processor, modulator, multiplexer, demodulator, demultiplexer, or antenna, etc.). Therefore, the network element and the terminal device can communicate using multi-antenna technology.
[0122] Optionally, the wireless communication system 100 may further include other network entities such as a network controller and a mobility management entity, but the embodiments of the present application are not limited thereto.
[0123] In the embodiment of the present application, the network element, which may also be referred to as a network device, may be any device with wireless transceiver functions. The device includes but is not limited to: an evolved Node B (eNB), a Radio Network Controller (RNC), a Node B (NB), a Base Station Controller (BSC), a Base Transceiver Station (BTS), a home base station (e.g., Home evolved Node B, or Home Node B, HNB), a Base Band Unit (BBU), an Access Point (AP) in a Wireless Fidelity (WIFI) system, a wireless relay node, a wireless backhaul node, a transmission point (TP) or a transmission and reception point (TRP), etc. It may also be a gNB (the next Generation Node) in a 5G, such as NR, system. B, next generation base station), or transmission point (TRP or TP), one or a group of (including multiple antenna panels) antenna panels of a base station in a 5G system, or it can also be a network node constituting a gNB or transmission point, such as a baseband unit (BBU), or a centralized unit (CU), a distributed unit (DU), etc.
[0124] In some deployments, a gNB may include a CU and a DU. The gNB may also include an active antenna unit (AAU). The CU implements some gNB functions, while the DU implements some gNB functions. For example, the CU is responsible for processing non-real-time protocols and services, and implementing radio resource control (RRC) and packet data convergence protocol (PDCP) layer functions. The DU is responsible for processing physical layer protocols and real-time services, and implementing radio link control (RLC), media access control (MAC), and physical (PHY) layer functions. The AAU implements some physical layer processing functions, RF processing, and active antenna-related functions. Because RRC layer information ultimately becomes PHY layer information, or is converted from PHY layer information, in this architecture, higher-layer signaling, such as RRC signaling, can also be considered to be sent by the DU, or by both the DU and the AAU. It is understood that a network element can be a device that includes one or more of a CU node, a DU node, or an AAU node. In addition, the CU may be divided into a network element in an access network (radio access network, RAN), or may be divided into a network element in a core network (core network, CN), which is not limited in this application.
[0125] The network element provides services for the cell, and the terminal device communicates with the cell through the transmission resources (for example, frequency domain resources, or spectrum resources) allocated by the network element. The cell can belong to a macro base station (for example, macro eNB or macro gNB, etc.) or a base station corresponding to a small cell. The small cells here can include: metro cells, micro cells, pico cells, femto cells, etc. These small cells have the characteristics of small coverage and low transmission power, and are suitable for providing high-speed data transmission services.
[0126] In the embodiments of the present application, a terminal device may also be referred to as user equipment (UE), access terminal, subscriber unit, subscriber station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user apparatus. The terminal device in the embodiments of the present application may include a handheld device, a vehicle-mounted device, etc. For example, some terminal devices are: mobile phones, tablet computers, PDAs, laptop computers, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication capabilities, computing devices or other processing devices connected to wireless modems, vehicle-mounted devices, wearable devices, terminal devices in 5G networks or future evolved public land mobile communication networks (PLMNs). The terminal equipment in the network (PLMN), etc., is not limited to this in the embodiments of the present application.
[0127] As an example and not a limitation, in the embodiment of the present application, the terminal device may also be a wearable device. Wearable devices may also be called wearable smart devices, which are a general term for wearable devices that are intelligently designed and developed using wearable technology for daily wear, such as glasses, gloves, watches, clothing, and shoes. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothes or accessories. Wearable devices are not only hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are fully functional, large in size, and can achieve complete or partial functions without relying on smartphones, such as smart watches or smart glasses, as well as those that only focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.
[0128] In addition, in the embodiment of the present application, the terminal device can also be a terminal device in the Internet of Things (IoT) system. IoT is an important part of the future development of information technology. Its main technical feature is to connect objects to the network through communication technology, thereby realizing an intelligent network of human-machine interconnection and object-to-object interconnection.
[0129] The terminal device in the embodiments of the present application may also be referred to as: terminal device, user equipment (UE), mobile station (MS), mobile terminal (MT), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication equipment, user agent or user device, etc.
[0130] In the embodiments of the present application, the terminal device or each network element includes a hardware layer, an operating system layer running on the hardware layer, and an application layer running on the operating system layer. The hardware layer includes hardware such as a central processing unit (CPU), a memory management unit (MMU), and memory (also known as main memory). The operating system can be any one or more computer operating systems that implement business processing through processes, such as a Linux operating system, a Unix operating system, an Android operating system, an iOS operating system, or a Windows operating system. The application layer includes applications such as browsers, address books, word processing software, and instant messaging software.
[0131] This application does not limit the specific form of the terminal device.
[0132] To facilitate a clear description of the technical solutions of the embodiments of the present application, some of the terms and technologies involved in the embodiments of the present application are briefly introduced below:
[0133] 1. Cell: A cell is described at a high level from the perspective of resource management, mobility management, or service unit. The coverage area of each network element can be divided into one or more cells, and each cell can correspond to one or more frequency points. In other words, each cell can be considered an area formed by the coverage area of one or more frequency points.
[0134] It should be noted that a cell can be an area within the coverage range of a wireless network of a network element. In an embodiment of the present application, different cells can correspond to the same or different network elements. For example, the network element to which cell #1 belongs and the network element to which cell #2 belongs can be different network elements, such as a base station. That is, cell #1 and cell #2 can be managed by different base stations. Or, for another example, the network element that manages cell #1 and the network element that manages cell #2 can also be different radio frequency processing units of the same base station, such as a radio remote unit (RRU). That is, cell #1 and cell #2 can be managed by the same base station, have the same baseband processing unit and intermediate frequency processing unit, but have different radio frequency processing units. Or, for another example, the network element to which cell #1 belongs and the network element to which cell #2 belongs can be the same network element, such as a base station. That is, cell #1 and cell #2 can be managed by the same base station. In this case, it can be said that cell #1 and cell #2 are co-located. This application does not specifically limit this.
[0135] As mentioned above, in some possible deployments, a gNB may include both a CU and a UD. In this deployment, cell #1 and cell #2 may be managed by the same CU and the same UD, i.e., they share both the CU and the DU; cell #1 and cell #2 may be managed by the same CU and different DUs, i.e., they share the CU but not the DU; or cell #1 and cell #2 may be managed by different CUs and different DUs, i.e., they do not share either the CU or the DU.
[0136] 2. Switching: In a wireless communication system, when a terminal device moves from one cell to / approaches another cell, switching is required to keep the communication of the terminal device uninterrupted. In an embodiment of the present application, the original cell / source cell represents the cell that provides services to the terminal device before the switch, and the target cell represents the cell that provides services to the terminal device after the switch. Relevant information of the target cell (such as the physical cell identification of the target cell, frequency information, random access resource information required for switching to the target cell, etc.) can be indicated by a switching message, which is sent by the network element to which the source cell belongs (i.e., the source network element) to the terminal device.
[0137] A handover may be an intra-site handover or an inter-site handover. An intra-site handover may refer to a situation where the source cell and the target cell belong to the same network element (such as a base station or CU), where the source cell and the target cell may be the same cell or different cells; an inter-site handover may refer to a situation where the source cell and the target cell belong to different network elements (such as a base station or CU). This application does not limit this.
[0138] It should be understood that a cell is a coverage area of a network element, an original cell corresponds to an original network element (eg, an original base station / original CU), and a target cell corresponds to a target network element (eg, a target base station / target CU).
[0139] In the traditional handover process, the mobility management of the terminal device is controlled by the network element. That is, the network element can instruct the terminal device to which cell to switch to and how to switch through a handover message. For example, the original network element sends a handover message to the terminal device to control the terminal device to switch from the original cell to the target cell. The handover message can be an RRC message. For example, in the LTE system, the RRC message can be an RRC connection reconfiguration message carrying a mobility control information element (mobility control info); in the NR system, the RRC message can be an RRC reconfiguration message carrying a synchronization reconfiguration element (reconfiguration with sync).
[0140] 3. LTM (Layer triggered mobility) handover: In the LTM handover process, the source cell can pre-configure candidate cells.
[0141] Figure 2 This is a signaling interaction diagram of an LTM handover process 200. In step 201, the terminal device may perform layer (L) measurement reporting based on the configured candidate cell. The layer measurement reporting may include any layer measurement reporting, such as layer 1 measurement reporting, layer 2 measurement reporting, or layer 3 measurement reporting. This application uses layer 3 measurement reporting for illustration, but in actual applications, the method for performing layer measurement reporting is not particularly limited.
[0142] The candidate cell may refer to all neighboring cells that the terminal device can access. When the original network element receives the L3 measurement report sent by the terminal device and decides to perform an LTM cell change. In step 202, during the execution of LTM, the original cell may send an LTM handover request to the target cell and potential target cell in the candidate cell. The target cell and potential target cell may respond to the LTM handover request of the original cell. The original cell receives the LTM handover request response. In step 203, the original cell may also send the configuration information of the target cell and potential target cell to the terminal device through an RRC reconfiguration message. In step 204, after receiving the configuration information of the candidate cell, the terminal device may respectively perform downlink synchronization and uplink synchronization for each candidate cell. In step 205, the original cell determines the target cell based on the L3 measurement report of the original cell and the candidate cell and sends an LTM handover command to the UE in step 206. The LTM handover command may be carried in the MAC CE signaling. The MAC CE may include at least the following information: timing advance (TA), transmission configuration indication state (TCI state) identifier (identity document, ID), CFRA resource information, and candidate cell configuration information identifier. In step 207, the terminal device receives the MAC CE and may disconnect from the original cell, perform a random access procedure, connect to the target cell, and perform data transmission through the target cell. Then, step 208 determines that the LTM cell handover is complete.
[0143] It should also be understood that the network element of the original cell and the network element of the target cell can be the same network element, or the original cell and the target cell can be co-located. In this case, for a certain terminal device, the key corresponding to the target cell and the key corresponding to the original cell can be the same.
[0144] It should also be understood that the handover message and the RRC message indicating the handover are described from different perspectives. The handover message is described from a functional perspective, intended to express that the message is used to instruct the terminal device to perform a handover. The RRC message is described from the perspective of message type, intended to express that the message is high-layer signaling. The RRC reconfiguration message is an enumeration of RRC messages. In other words, the handover message is sent to the terminal device via high-layer signaling.
[0145] It should also be understood that different RRC messages are listed above, such as the RRC connection reconfiguration message in LTE and the RRC reconfiguration message in NR. These messages are examples for ease of understanding only and should not constitute any limitation to this application. This application does not limit the specific name of the handover message used to instruct the terminal device to send a handover procedure.
[0146] 3. CU-DU Architecture: In the 5G Radio Access Network (RAN) architecture, the baseband unit (BBU) is divided into two functional units: the CU and the DU. The CU is responsible for functions such as the PDCP layer and the RRC layer, while the DU is responsible for the physical layer, MAC layer, and RLC layer.
[0147] Based on the configuration of protocol stack functions, CU-DU architectures can be categorized into two types: CU-DU separation and CU-DU convergence. In the CU-DU separation architecture, NR protocol stack functions can be dynamically configured and split, with some functions implemented in the CU and the remaining functions in the DU. In the CU-DU convergence architecture, the logical functions of the CU and DU are integrated into the same gNB, implementing the full functionality of the protocol stack.
[0148] For ease of understanding, Figure 3 An example diagram of a CU and DU architecture is shown. Figure 3 ,A CU can be connected to multiple DUs, and each DU can support multiple cells.
[0149] It should be understood that a CU can support multiple cells, and terminal devices within the coverage area of a cell can access the cell.
[0150] 4. Security: When a terminal device communicates with the target cell, the key used by the terminal device and the network must remain consistent. This ensures communication security and secure key sharing between the terminal device and the network device during data transmission.
[0151] Figure 4 This is a signaling interaction diagram of a traditional key update method. Figure 4 The traditional key synchronization is generally performed after the terminal device and the network device complete the authentication. In step 401, both the network device and the terminal device can obtain the anchor key K through security authentication. SEAF , and respectively through the anchor bond K SEAF Further derive the key K AMF The network device can be a base station or a CU. After that, the process of establishing a security context will be started. Further, in step 402, the original base station can obtain the security capabilities of the terminal from the Access and Mobility Management Function (AMF). In step 403, the original base station can determine the security algorithm of the terminal based on the security capabilities of the terminal. In step 404, the UE and the AMF can establish a security context through the anchor key K SEAFDerive the key K of gNB or next generation base station (Next Generation eNodeB, ng-eNB) NG-RAN and the next hop parameter NH, including the key K derived from the gNB NG-RAN The next hop link counter NCC is associated with each key K NG-RAN Associated with the next hop parameter NH. NG-RAN The keys correspond to two types of access networks, one is gNB as the access network, and the other is ng-eNB as the access network; the former indicates that the 5G base station accesses the 5G core network, and the latter indicates that the LTE base station accesses the 5G core network.
[0152] When performing key derivation, the UE and the original base station can further derive K NG-RAN Specifically, the initial parameters, namely K NG-RAN and NCC value is 0, and establish K NG-RAN In step 405, the original base station may send a handover signaling to the terminal device, and the handover signaling may instruct the terminal device to perform a cell handover. Specifically, in step 406, the terminal device may access the target base station through random access.
[0153] After the handover is completed, in step 407, the UE and the target base station can use the current K NG-RAN and NH parameters to derive K NG-RAN * The original base station uses the K derived from the UE and the target base station. NG-RAN * The target key can include the RRC signaling encryption key and the integrity protection key (K RRC-enc ,K RRC-int ) and the encryption key and integrity key (K UP-enc ,and K UP-int ).
[0154] 5. Dual Connectivity (DC) architecture: In NR technology, terminal devices can be connected to two base stations at the same time. One of the base stations can be called the master node (MN), and the other base station can be called the secondary node (SN). The master base station can cover one primary cell (Pcell) and multiple secondary cells (Secondary cells), and the terminal can randomly access the primary cell Pcell. The primary cell and multiple secondary cells form a master cell group (MCG). The secondary base station can cover one primary secondary cell (PScell) and multiple secondary cells Scell. The cells covered by the secondary base station can be called a primary secondary cell group (SCG). The terminal can randomly access the primary secondary cell PScell.
[0155] Figure 5 A schematic diagram of a dual connection architecture is shown. Figure 5 The dual connectivity architecture may include an MCG and an SCG, wherein the MCG may include a Pcell and multiple Scells. The SCG may include a PScell and multiple Scells. A terminal device (UE) may be connected to both a primary cell (Pcell) and a primary / secondary cell (PScell) simultaneously.
[0156] It should be understood that, as mentioned above, the terminal device can access the primary cell and the primary and secondary cells, and use the primary cell for communication. During the communication process, the key configured jointly by the MN and the terminal device needs to be used. Of course, the SN and the terminal device are also configured with a common key. The derivation of the above-mentioned key is completed by the original base station, that is, the MN or SN. If a cell handover occurs, and the target cell of the handover is still the original base station, although the cell handover occurs, since the base station has not changed, the keys of the terminal device and the network device can still remain consistent. The cell handover disclosed in this application may include primary cell handover, primary and secondary cell handover and other types of cell handovers.
[0157] It should also be understood that in a dual-connection scenario, a cell covered by a base station can be called a cell group. If a main cell switch or a main-auxiliary cell switch, or other types of cell switching occurs, if the cell after the switch is still the same cell group as the original cell. That is, a cell switch occurs within a cell group. Since the cell switch occurs within the same cell group, the network device actually accessed by the terminal device has not changed. In this case, the original key can still be used when the terminal device and the network device communicate. However, if a cell switch occurs between cell groups, the network device corresponding to the original cell and the network device corresponding to the target cell are different, a key update needs to be performed to ensure that the changed network device and the terminal device can remain consistent and to ensure communication security after the cell switch.
[0158] In the technical solution of the present application, since the cells covered by a base station can be called a cell group, the cell switching in which the base station changes can be called cell switching across cell groups or cell switching between cell groups. The above-mentioned cell switching names are only for illustrating the specific scenarios of cell switching, and other naming methods can also be used for naming. This application does not impose too many restrictions on this. The essence of cell switching between cell groups is that the base station / CU corresponding to the original cell before the terminal device is switched is different from the base station / CU corresponding to the target cell after the switch.
[0159] In order to solve the key consistency problem after cell switching across cell groups, in the technical solution of the present application, the original MN can send a first indication message to the target network element and the terminal device respectively. The first indication message can instruct the target network element and the terminal device to synchronously perform a key update. By synchronously performing the key update on the target network element and the terminal device, the keys of the target network element and the terminal device can be made the same, thereby improving the communication security between the terminal device and the target network element through the key. In addition, the key update performed by the first indication message does not require the transmission of data or information between the target network element and the terminal device, thereby improving the security of the communication process.
[0160] In order to facilitate understanding of the embodiments of the present application, the following explanations are made before introducing the embodiments of the present application.
[0161] First, in the embodiment of the present application, "used for indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated. For example, including but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information. There is an association relationship between the other information and the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, it is also possible to use a pre-agreement (such as a protocol provision) on whether a certain information element exists to implement the indication of the information to be indicated, thereby reducing the indication overhead to a certain extent.
[0162] Second, in the embodiments of this application, terms such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. For example, the terms "first chip" and "second chip" are used solely to distinguish between different chips and do not define their order. Those skilled in the art will understand that terms such as "first" and "second" do not define the quantity or execution order, and do not necessarily imply differences.
[0163] In the embodiments shown below, the first, second, and various numbers are only used for the convenience of description and are not intended to limit the scope of the embodiments of the present application, for example, to distinguish different indication information, different time intervals, etc.
[0164] Third, "predefinition" or "preconfiguration" can be achieved by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device (for example, including terminal devices and network elements). This application does not limit its specific implementation method.
[0165] Fourth, the "protocol" involved in the embodiments of the present application may refer to a standard protocol in the field of communications, for example, it may include an LTE protocol, an NR protocol, and related protocols used in future communication systems, which is not limited in this application.
[0166] Fifth, "at least one item" refers to one or more items, and "multiple items" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b and c can mean: a, or b, or c, or a and b, or a and c, or b and c, or a, b and c. Where a, b and c can be single or multiple, respectively.
[0167] Sixth, in the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "if" all mean that the device (such as a terminal device or a network element) will make corresponding processing under certain objective circumstances. It does not limit the time, and does not require the device (such as a terminal device or a network element) to have a judgment action when implementing it, nor does it mean that there are other limitations.
[0168] Seventh, to facilitate description of the embodiments of this application, unless otherwise specified, all message names mentioned are those in NR. However, it should be understood that these message names are examples for ease of understanding only and should not constitute any limitation on this application. This application does not exclude the possibility of defining other message names in future protocols to replace the message names listed in this application to achieve the same or similar functions.
[0169] Eighth, the following describes several embodiments in detail with reference to various flowcharts. However, it should be understood that these flowcharts and the descriptions of their corresponding embodiments are provided for ease of understanding only and should not constitute any limitation on this application. Not every step in each flowchart is necessarily required; for example, some steps can be skipped. Furthermore, the order in which the steps are executed is not fixed and is not limited to that shown in the figures. The order in which the steps are executed should be determined by their functions and inherent logic.
[0170] It should be noted that in the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0171] The method provided in the embodiments of the present application is described in detail below with reference to the accompanying drawings.
[0172] It should be understood that the following description is only for ease of understanding and explanation, and the method provided in the embodiment of the present application is described in detail using the interaction between a terminal device and a network element as an example. However, this does not constitute any limitation on the execution subject of the method provided in the present application. For example, the terminal device shown in the embodiment below can be replaced by a component (such as a chip or circuit) configured in the terminal device. The network element shown in the embodiment below can also be replaced by a component (such as a chip or circuit) configured in the network element.
[0173] The embodiments shown below do not particularly limit the specific structure of the execution subject of the method provided in the embodiments of the present application. As long as it is possible to communicate according to the method provided in the embodiments of the present application by running a program that records the code of the method provided in the embodiments of the present application, for example, the execution subject of the method provided in the embodiments of the present application can be a terminal device or a network element, or a functional module in the terminal device or network element that can call and execute the program.
[0174] Figure 6 This is a signaling interaction diagram of the communication method 600 provided by the embodiment of the present application from the perspective of device interaction. Figure 6 As shown, the method 600 may include steps 610 to 690. Each step in the method 600 is described in detail below.
[0175] In step 610, when triggering a cell handover between cell groups, the first network element sends first indication information to the target network element and the terminal device. Accordingly, the target network element may receive the first indication information. The terminal device may also receive the first indication information.
[0176] Among them, the first indication information is used to instruct the target network element and the terminal device to synchronously perform key update. The cell switching between cell groups refers to the switching of the original cell of the first cell group to the target cell of the second cell group. The original network element corresponding to the first cell group and the target network element corresponding to the second cell group are different.
[0177] As mentioned above, a network element can refer to a device in a network with certain transmission functions. A network element can include a base station or a CU. In addition, a network element can also be a device with other hardware structures or combinations. This application does not limit the specific device type or device composition of the network element. In a dual-connectivity scenario, the original network element can be the original mobile node accessed by the terminal device, and the target network element can be the target mobile node to be accessed, or the original network element can be the original network node accessed by the terminal device, and the target network element can be the target network node to be accessed.
[0178] It should be understood that before executing inter-cell handover, the first network element may first trigger inter-cell handover. The first network element may trigger inter-cell handover by receiving a cell handover command or by receiving L3 measurement results reported by the UE that satisfy the cell handover conditions. The cell handover command may be sent by the UE to the original network element. The UE may decide to trigger a cell handover as needed.
[0179] The measurement result reported by the UE determines that the cell switching condition is met, which may specifically include at least one of the following situations:
[0180] 1. The communication quality of the original MN is lower than a preset first quality threshold, or the communication quality of the original SN is lower than a preset first quality threshold.
[0181] 2. The communication quality of the original MN is lower than that of the candidate MN, or the communication quality of the original SN is lower than that of the candidate SN.
[0182] 3. The difference between the communication quality of the candidate MN and the communication quality of the original MN is greater than the second quality threshold, or the difference between the communication quality of the candidate SN and the communication quality of the original SN is greater than the second quality threshold.
[0183] The above-mentioned specific implementation methods for satisfying the cell switching conditions are merely exemplary and should not constitute a specific limitation on triggering cell switching. This application does not impose excessive restrictions on this.
[0184] In the present application, the switching scenario of the cell handover between cell groups can be any cell handover scenario, for example, it can be an LTM cell handover, that is, performing an LTM cell handover between cell groups. When performing an LTM cell handover between cell groups, the first network element sends first indication information to the target network element and the terminal device respectively. The first indication information can instruct the terminal device and the target network element to synchronously perform a key update. The first network element can be the original network element or not.
[0185] It should be understood that the cell switching methods under the LTM mechanism listed above are only examples and should not constitute any limitation to this application. This application does not limit the specific method for the network device to perform cell switching.
[0186] In this embodiment, the first network element sending the first indication information to the target network element and the terminal device UE may include: the first network element sending the first indication information to the target network element, and the first network element sending the first indication information to the UE. Specifically, the first network element may send the first indication information to the target network element at a first moment, and the first network element may send the indication information to the UE at a second moment. The first moment and the second moment may be the same or different. The first moment may be before the second moment, or the first moment may be after the second moment.
[0187] It should be understood that the first network element can send the first indication information to the target network element through the beam corresponding to the target network element. The first network element can also send the first indication information to the UE through the beam corresponding to the terminal device. The embodiment of the beam in the NR protocol can be a spatial filter (spatial filter), or a spatial filter (spatial filter) or a spatial parameter (spatial parameters). The beam used to send signals can be called a transmission beam (Tx beam), which can be called a spatial transmit filter (spatial domain transmit filter) or a spatial transmit parameter (spatial domain transmit parameter); the beam used to receive signals can be called a reception beam (Rx beam), which can be called a spatial receive filter (spatial domain receive filter) or a spatial receive parameter (spatial domain receive parameter).
[0188] Based on different transmission directions, beams can be divided into transmit beams and receive beams. A transmit beam refers to the distribution of signal strength in different directions in space after a signal is transmitted by an antenna, while a receive beam refers to the distribution of signal strength in different directions in space after a wireless signal is received by an antenna.
[0189] It should be understood that the embodiment of beamforming in the NR protocol listed above is only an example and should not constitute any limitation to this application. This application does not exclude the possibility of defining other terms in future protocols to express the same or similar meanings.
[0190] In this embodiment, after the terminal device and the target network element respectively receive the first indication information, in step 620, the terminal device and the target network element may synchronously perform key update.
[0191] It should be understood that the synchronization in the synchronous execution of key update by the terminal device and the target terminal may include the time when the terminal device and the target network element apply the updated key being the same; or, it may include the time when the terminal device executes the key update being the same as the time when the target network element executes the key update; or, it may include the time when the terminal device and the target network element each execute the key update being different but the time when both apply the updated key being the same.
[0192] For example, the terminal device may perform a key update at a third time, and the target network element may perform a key update at a fourth time. There may be a first time interval between the third time and the fourth time, and the first time interval may include one or more time slots.
[0193] Therefore, in order to synchronize the application time of the terminal device and the target network element, after the terminal device switches to the target cell of the target network element, the terminal device can send a communication status to the target network element. The communication status can indicate that the target network element starts applying the updated key. After the terminal device sends the communication status to the target network element, it can determine to use the updated key.
[0194] In this embodiment, when performing cell switching between cell groups, the first indication information can instruct the terminal device and the target network element to perform key updates respectively. If both perform key updates at the same time, the keys of the terminal device and the target network element can remain consistent, thereby ensuring the security of communication between the terminal device and the target network element.
[0195] It should be understood that in a dual-connection scenario, the terminal device actually accesses the MN and the SN, and the terminal device performs L3 measurement reporting, which can be directed to one of the MN and the SN, or to both. For example, the terminal device can perform L3 measurement reporting to the MN, or the terminal device can perform L3 measurement reporting to the SN, or the terminal device can perform L3 measurement reporting to the SN and the MN at the same time. Accordingly, if the report is made to the MN alone, after the MN receives the measurement result of the measurement report, the MN can also send the measurement result to the SN through signaling or a message. If the report is made to the SN alone, after the SN receives the measurement result of the measurement report, the SN can also send the measurement result to the MN through signaling or a message. In this embodiment, the type of signaling or message for reporting the measurement result is not limited. For example, it can be an RRC message, a MAC CE signaling, or a proprietary signaling.
[0196] As described above, it is possible for either the MN or the SN to obtain measurement report results. Therefore, in a dual connectivity scenario, cell handover between cell groups can be triggered by either the MN or the SN. Cell handover can include MCG cell handover or SCG cell handover.
[0197] It should be understood that in a dual-connection scenario, the terminal device simultaneously accesses the primary and secondary cells (PScells) in the SCG and the primary cell (Pcell) in the MCG. Therefore, for cell switching between cell groups, there are two types of cell switching between cell groups. One type of cell switching between cell groups can be inter-SCG cell switching, that is, switching from an original cell in the first SCG to a target cell in the second SCG; the other type of cell switching between cell groups can be inter-MCG cell switching, that is, switching from an original cell in the first MCG to a target cell in the second MCG.
[0198] In this embodiment, one base station can manage one cell group, and each cell group can correspond to a different base station. Due to IC, for cell handover between cell groups, the network element actually accessed by the terminal device changes, that is, the network element accessed by the terminal device can be switched from the original network element corresponding to the original cell to the target network element corresponding to the target cell. If a cell handover occurs between MCGs, the original network element can be the original MN, and the target network element can be the target MN. If a cell handover occurs between SCGs, the original network element can be the original SN, and the target network element can be the target SN.
[0199] As described above, in the case where cell handover between cell groups includes cell handover of the primary cell group MCG, the original network element is the original primary base station MN, the target network element is the target MN, and the first network element is the original MN or the original SN. Whereas in the case where cell handover between cell groups includes cell handover of the secondary cell group SCG, the original network element is the original secondary base station SN, the target network element is the target SN, and the first network element is the original SN or the primary base station MN.
[0200] Based on the different execution entities and triggered cell handover objects, the technical solutions of the present application may include at least one of the following:
[0201] In embodiment 1, the MN triggers the MCG cell switching.
[0202] In this embodiment, when the MCG cell handover is triggered by the MN, the first indication information may be sent by the original MN to the target MN, and the first network element may be the original MN. Figure 7 A signaling interaction diagram of a communication method 700 is shown.
[0203] In step 701, when the original MN triggers the execution of MCG LTM handover, first indication information is sent to the target MN and the terminal device respectively. The first indication information can instruct the target MN and the terminal device to execute key update synchronously.
[0204] The MCG LTM handover may refer to handover from an original cell of a first MCG to a target cell of a second MCG. The first MCG and the second MCG are different. The original MN corresponding to the first MCG is different from the target MN corresponding to the second MCG.
[0205] It should be understood that the first indication information may also carry the cell information of the original cell and the target cell involved in the cell handover. The cell information may include, for example, the physical identifier of the cell.
[0206] In step 702, the terminal device and the target MN may synchronously perform key update.
[0207] In addition, since the terminal device and the target MN have performed a key update, in order to enable the SN to adjust the key in a timely manner based on the cell switching to avoid the complexity of the key usage process due to the large number of keys, in a possible design, the original MN can also send the first indication information to the SN.
[0208] That is, in step 703, the original MN sends first indication information to the SN. The first indication information may instruct the SN to perform a key update.
[0209] In step 740, the SN performs a key update.
[0210] It should be noted that the execution order of step 702 and step 703 in this embodiment is only exemplary and does not constitute a specific limitation on the execution order of step 702 and step 703. Step 703 can also be executed before step 702, or step 703 can be part of step 701, that is, in step 701, in addition to sending the first indication information to the target MN and the terminal device, the original MN can also send it to the SN. In this embodiment, the specific execution order of step 703 is not excessively limited.
[0211] Example 2: MN triggers SCG cell switching
[0212] In this embodiment, when the SCG cell handover is triggered by the MN, the first indication information may be sent by the MN to the target SN, and the first network element may be the main base station MN. Figure 8 A signaling interaction diagram of a communication method 800 in a MN-triggered SCG cell handover scenario is shown.
[0213] In step 801, when the MN triggers the execution of the SCG cell, it sends first indication information to the target SN and the terminal device respectively. The first indication information can instruct the target SN and the terminal device to synchronously execute the key update.
[0214] The SCG LTM handover may refer to handover from an original cell of a first SCG to a target cell of a second SCG. The first SCG and the second SCG are different. The original SN corresponding to the first MCG and the target SN corresponding to the second MCG are different.
[0215] It should be understood that the first indication information may also carry the cell information of the original cell and the target cell involved in the cell handover. The cell information may include, for example, the physical identifier of the cell.
[0216] In step 802, the terminal device and the target SN may synchronously perform key update.
[0217] Optionally, in step 801, the MN may decide whether to trigger MCG cell handover or SCG cell handover when the SN has not configured signaling bearer resources.
[0218] Example 3: When the SN is configured with signaling bearer resources, the SN triggers the SCG cell handover
[0219] In this embodiment, the first indication information is sent by the original SN through the signaling bearer resources when the signaling bearer resources are configured. The first network element may be the original SN. Figure 9 A signaling interaction diagram of a communication method 900 in a MN-triggered SCG cell handover scenario is shown.
[0220] In step 901, when the original SN determines to trigger SCG cell handover and is configured with signaling bearer resources, it sends first indication information to the target SN and the terminal device respectively. The first indication information can instruct the target SN and the terminal device to perform key update synchronously.
[0221] In step 902, the terminal device and the target SN may perform key update synchronously.
[0222] Optionally, the signaling bearer resource may refer to a logical channel resource configured in the SN for carrying signaling. The signaling bearer resource may be, for example, Signaling Radio Bearer 3 (SRB3). The signaling bearer resource may be used to transmit a specific RRC message, MAC CE signaling, or proprietary signaling. For example, if SBR3 is configured on the original SN and the target SN, respectively, the original SN may send an RRC message, MAC CE signaling, or proprietary signaling to the target SN via SRB3. The RRC message, MAC CE signaling, or proprietary signaling may carry the first indication information.
[0223] In addition, the signaling bearer resources may also be, for example, signaling bearer 1 (Signaling Radio Bearer 1, SRB1), signaling bearer 2 (Signaling Radio Bearer 2, SRB2), NR logical channel (Dedicated Control Channel, DCCH) and other bearer resources. This embodiment does not impose too many restrictions on the resource type of signaling bearer resources.
[0224] Example 4: When the SN is not configured with signaling bearer resources, the SN triggers the SCG cell handover
[0225] In this embodiment, the first indication information is sent by the MN from the original SN without configuring signaling bearer resources. The MN is sent under the instruction of the second indication information sent by the original SN. The second indication information is used to instruct the MN to send the first indication information to the target SN and the terminal device. The first network element can be the original SN. Figure 10A signaling interaction diagram of a communication method 1000 in a MN-triggered SCG handover scenario is shown.
[0226] In step 1001, when the original SN determines that SCG cell handover is triggered and no signaling bearer resources are configured, the original SN sends a second indication message to the MN. Accordingly, the MN can receive the second indication message. The second indication message is used to instruct the MN to send the first indication message to the target SN and the terminal device.
[0227] Exemplarily, the second indication information may be, for example, an SCG cell switching request. In this case, the MN may receive the SCG cell switching request.
[0228] In step 1002, the MN sends first indication information to the target SN and the terminal device respectively under the instruction of the second indication information. The first indication information can instruct the target SN and the terminal device to synchronously perform key update.
[0229] In step 1003, the terminal device and the target SN may synchronously perform key update.
[0230] Figure 10 In the embodiment shown, the SN triggers the SCG cell handover, and then sends the SCG cell handover request to the MN, so that the MN initiates the SCG cell handover. In addition, in actual applications, the MN can also directly trigger the SCG cell handover when the SN does not configure the signaling bearer resources. Figure 8 In step 801 of the illustrated embodiment, the MN may trigger an SCG LTM handover when the SN is not configured with signaling bearer resources. Furthermore, when the SCG LTM handover is triggered, the MN may send first indication information to the target SN and the terminal device, respectively. The first indication information may instruct the target SN and the terminal device to synchronously perform a key update.
[0231] Example 5: When SN is configured with signaling bearer resources, MCG cell switching is triggered by SN
[0232] In this embodiment, the first indication information may be sent by the SN to the original MN through the signaling bearer resources when the signaling bearer resources are configured, and the first network element may be the SN. Figure 11 A signaling interaction diagram of a communication method 1100 in an SN-triggered MCG switching scenario is shown.
[0233] In step 1101, when the SN determines that MCG cell handover is triggered and signaling bearer resources are configured, it sends first indication information to the target MN and the terminal device respectively. The first indication information can instruct the target MN and the terminal device to perform key update synchronously.
[0234] In step 1102, the terminal device and the target MN may synchronously perform key update.
[0235] Example 6: When the SN is not configured with signaling bearer resources, the SN triggers the MCG cell handover
[0236] In this embodiment, the first indication information is sent by the original MN to the target MN by the SN without configuring signaling bearer resources. The original MN is sent under the instruction of the second indication information sent by the original SN. The second indication information is used to instruct the original MN to send the first indication information to the target MN and the terminal device. The first network element can be the SN. Figure 12 A signaling interaction diagram of a communication method 1200 in an SN-triggered MCG switching scenario is shown.
[0237] In step 1201, when the original SN determines that SCG cell handover is triggered and no signaling bearer resources are configured, the original MN sends a second indication message. Accordingly, the original MN can receive the second indication message. The second indication message is used to instruct the original MN to send the first indication message to the target SN and the terminal device.
[0238] Exemplarily, the second indication information may be, for example, an SCG cell switching request. In this case, the original MN may receive the SCG cell switching request.
[0239] In step 1202, the original MN sends first indication information to the target MN and the terminal device respectively under the instruction of the second indication information. The first indication information can instruct the target MN and the terminal device to synchronously perform key update.
[0240] In step 1203, the terminal device and the target MN may synchronously perform key update.
[0241] In step 601, the first network element may send first indication information to the target network element and the terminal device, respectively. Specifically, the first network element may send MAC CE signaling to the terminal device and the target network element, respectively, and the MAC CE signaling may carry the first indication information. Alternatively, the first network element may send dedicated signaling to the terminal device and the target network element, respectively, and the dedicated signaling may carry the first indication information. Accordingly, the terminal device may receive the MAC CE signaling and read the first indication information from the MAC CE signaling. The target network element may receive the MAC CE signaling and read the first indication information from the MAC CE signaling.
[0242] As described above, the first indication information can be carried in MAC CE signaling or proprietary signaling. Transmitting the first indication information through the original MAC CE signaling can save communication resources. Among them, proprietary signaling can refer to signaling set up for transmitting indication information. Setting up proprietary signaling to carry the first indication information can enrich the information interaction between the UE and the network element, allowing the original cell to quickly indicate the first indication information of the target network element and terminal device.
[0243] The first indication information may explicitly instruct the terminal device and the target network element to perform a key update, respectively. For example, the indication may be provided by a predefined field in the MAC CE signaling. In this case, the first indication information may be a predefined field in the MAC CE signaling. The predefined field may be an existing field in the MAC CE signaling or a newly defined field, and this application does not impose any additional restrictions on this.
[0244] The first indication information may also implicitly instruct the terminal device and the target network element to perform key updates, respectively. For example, the MAC CE signaling may include parameters for key updates, such as the next hop link counter NCC, algorithm indication information, and other parameters. When the terminal device receives the MAC CE signaling, it may determine whether to initiate a key update based on the parameters included in the MAC CE signaling.
[0245] Optionally, MAC CE signaling may be transmitted between the terminal device and the network element via a physical uplink shared channel (Physical Uplink Shared Channel, PUSCH) or a physical downlink shared channel (Physical Downlink Shared Channel, PDSCH).
[0246] As described above, the terminal device and the target network element need to perform key updates respectively, and the key update process involves many parameters. In this embodiment, the first indication information may include at least one of the following: a secondary node key update counter SK-counter, a next hop link counter NCC, and algorithm indication information.
[0247] Among them, the auxiliary node key update counter SK-counter refers to a counter used for auxiliary node authentication and key management. Specifically, SK-counter is a digital variable used to track and record the number of key updates. Synchronizing SK-counter to terminal devices and target network elements can assist each device in ensuring the security and integrity of the key. The next hop link counter (NCC) is a parameter used for key derivation. The security algorithm may refer to an algorithm used for key derivation. For example, it may include a KDF (Key derivation function) algorithm. In addition, the first indication information may also include other parameters, such as the key K NG-RAN , so that the terminal device and the target network element use the same key.
[0248] It should be understood that the first indication information may include at least one of SK-counter, NCC and algorithm indication information. When the first indication information explicitly indicates that the terminal device and the target device need to perform a key update, the first indication information may indicate that a key update needs to be performed through a partial field, and may also carry SK-counter, NCC and algorithm indication information through another partial field. When the first indication information implicitly indicates that the terminal device and the target device need to perform a key update, the fields of the first indication information may be SK-counter, NCC and algorithm indication information. The application of SK-counter, NCC and algorithm indication information in the key update process can refer to Figure 13 The embodiment shown.
[0249] For ease of understanding, Figure 13 FIG1 shows a schematic flow chart of a key update method provided by an embodiment of the present disclosure. Figure 13 As shown, the public key update method of the present invention can be configured in a terminal device and a target network element. The method 1300 may include steps 1301 to 1302. Each step in the method 1300 is described in detail below.
[0250] Step 1301: Based on the current K NG-RAN and NCC, derive the updated key K NG-RAN *.
[0251] Step 1302: Update the key K according to the security algorithm NG-RAN *, derive the target key, which can include KRRC-enc (RRC signaling encryption key), KRRC-int (RRC signaling integrity protection key), KUP-enc (encryption key for UP (upload) data packets), and KUP-int (integrity protection key for UP data packets).
[0252] Optionally, the security algorithm may include an integrity protection algorithm and an encryption algorithm.
[0253] Specifically, step 1302 may include: updating the key K according to the integrity protection algorithm NG-RAN *, derive KRRC-int, KUP-int. According to the encryption algorithm and the updated key K NG-RAN *, derive KRRC-enc, KUP-enc.
[0254] The current K involved in step 1301 NG-RAN It can refer to the initial key before the terminal device or target network element performs a key update, or it can refer to the latest key stored in the terminal device or target network element, which needs to be updated. The terminal device and target network element can store their latest K NG-RAN After the key is updated, the terminal device and the target network element can delete the original key.
[0255] In the initial stage of key derivation, the NH parameter can be set to 0. The NH parameter can be NG-RAN Related to NCC. The NH parameter is a key derived from ME and AMF, which can be used to provide forward security and initialize the key K NG-RAN and NCC.
[0256] It should be understood that the algorithm indication information can be used to determine the security algorithm involved in the key update process. Both the terminal device and the target network element can determine the security algorithm used in the key update process through the algorithm indication information.
[0257] The above mentioned counters such as SK-counter and NCC are involved in key updates, which can be audited and tracked when necessary to improve the security of key use.
[0258] In one possible design, the algorithm indication information may be at least one of the following: indication information on whether to use the original security algorithm; indication information on whether to use the original SN security algorithm; indication information on whether to use the original MN security algorithm; and an index of the algorithm.
[0259] The original security algorithm refers to the security algorithm configured on the terminal device. Each security algorithm can be associated with at least one candidate cell. The network element corresponding to the candidate cell associated with a security algorithm can use the security algorithm to perform key update.
[0260] Security algorithms may include integrity protection algorithms and / or encryption algorithms. Integrity protection algorithms may be used to derive KRRC-int and KUP-int. Encryption algorithms may be used to derive KRRC-enc and KUP-enc.
[0261] An algorithm index is an identifier used to query security algorithms. For example, security algorithms can be stored in a table, and each security algorithm can be associated with an index. The corresponding security algorithm can be queried using the index.
[0262] The communication method provided in this embodiment can provide first indication information to the terminal device and the target network element via MAC CE signaling. The first indication information can include the NCC and algorithm indication information used during the key update process. This synchronizes the parameters involved in the key update process and ensures that the updated keys of the terminal device and the target network element remain consistent. During this process, no key transmission is required, which prevents attackers from obtaining the new key during transmission and enhances network security.
[0263] In the following, the algorithm indication information including several different combinations will be used to illustrate how to perform key update through the first indication information.
[0264] 1. Algorithm indication information includes: indication information on whether to use the original security algorithm.
[0265] It should be understood that a predefined field in the algorithm indication information may carry information indicating whether a security algorithm is used. For example, the predefined field may be a first numerical value or a second numerical value. The first numerical value or the second numerical value may be other information such as predefined numbers, letters, or symbols, and this application does not limit this.
[0266] The first value may be information indicating the use of the original security algorithm, and the second value may be information indicating the use of the security algorithm. Alternatively, the second value may be information indicating the use of the security algorithm, and the first value may be information indicating the use of the security algorithm. This application is not limited to this.
[0267] Exemplarily, if the value of the predefined field in the algorithm indication information is 1, it indicates that the security algorithm is used; if the value of the predefined field is 0, it indicates that the security algorithm is not used.
[0268] In addition, the algorithm indication information can also implicitly indicate whether to use a security algorithm. For example, the algorithm indication information can include information such as the algorithm name, algorithm identifier, and algorithm index, which can be used to indicate the use of a security algorithm. However, if the algorithm indication information is not the algorithm name, algorithm identifier, or algorithm index, but is information unrelated to the original security algorithm, such as NULL or algorithm information of a new security algorithm, it can indicate that the original security algorithm is not to be used.
[0269] It should be understood that if the algorithm indication information indicates the use of the original security algorithm, the key can be updated according to the original security algorithm. If the algorithm indication information indicates the use of the original security algorithm, the key can be updated according to the default security algorithm. The default security algorithm may refer to a security algorithm pre-set by both the terminal device and the target network element. The default security algorithm of the terminal device and the default security algorithm of the target network element are the same.
[0270] The original security algorithm may refer to a security algorithm configured in the terminal device. For example, it may be a security algorithm of a configured candidate cell. The original security algorithm may include an original SN security algorithm and / or an original MN security algorithm.
[0271] When the indication information of whether to use the original security algorithm indicates not to use the original security algorithm, the algorithm indication information may further include: whether to execute the integrity protection algorithm and / or the encryption algorithm and / or the algorithm index. The security algorithm is determined by whether the integrity protection algorithm and / or the encryption algorithm and / or the algorithm index are executed.
[0272] It should be understood that the algorithm indication information can use another predefined field to indicate whether an integrity protection algorithm and / or an encryption algorithm are executed. This predefined field can have multiple values, such as 1, 2, 3, or 4. For example, a value of 1 can indicate execution of the integrity protection algorithm. A value of 2 can indicate execution of the encryption algorithm. A value of 3 can indicate execution of both the integrity protection algorithm and the encryption algorithm. A value of 4 can indicate execution of neither the integrity protection algorithm nor the encryption algorithm. The character length of the predefined field can be set based on usage requirements. For example, it can be set to 2 characters, with a value of 1 being 01, a value of 2 being 10, a value of 3 being 11, and a value of 4 being 00. Of course, the above approach is merely exemplary and is not intended to be limiting in this application. It should be understood that if the algorithm indication information indicates execution of the integrity protection algorithm and the encryption algorithm, the integrity protection algorithm and the encryption algorithm are determined to participate in the key update. If the algorithm indication information indicates execution of the integrity protection algorithm, the integrity protection algorithm is determined to participate in the key update. If the algorithm indication information indicates execution of the encryption algorithm, the encryption algorithm is determined to participate in the key update.
[0273] 2. Algorithm indication information includes: indication information on whether to use the original MN security algorithm.
[0274] It should be understood that the original MN security algorithm may refer to the security algorithm determined by the original MN for the terminal device. Specifically, it may refer to indication information that can indicate whether to use the original MN security algorithm when performing MCG cell switching. If the indication information indicates that the original MN security algorithm is to be used, the original MN security algorithm can be used when performing MCG LTM. If the indication information indicates that the original MN security algorithm is not to be used, the original MN security algorithm is not used when performing SCG LTM.
[0275] Furthermore, if the algorithm indication information includes information indicating that the original MN security algorithm is not to be used, the algorithm indication information may also include an algorithm index, where the algorithm index indicates the security algorithm to be used when the original MN security algorithm is not to be used. Furthermore, when executing SCG LTM, the algorithm indication information may also indicate information indicating that the original MN security algorithm is not to be used, to avoid algorithm confusion.
[0276] 3. Algorithm indication information includes: indication information on whether to use the original SN security algorithm.
[0277] It should be understood that the original SN security algorithm may refer to a security algorithm determined by the original SN for the terminal device. Specifically, it may refer to indication information that can indicate whether to use the original SN security algorithm when performing SCG cell switching. If the indication information indicates that the original SN security algorithm is to be used, the original SN security algorithm may be used when performing SCG LTM. If the indication information indicates that the original SN security algorithm is not to be used, the original SN security algorithm is not used when performing SCG LTM.
[0278] Furthermore, if the algorithm indication information includes indication information for not using the original SN security algorithm, the algorithm indication information may also include an algorithm index, where the algorithm index indicates the security algorithm to be used when not using the indication information for the original SN security algorithm. Furthermore, when executing MCG LTM, the algorithm indication information may indicate indication information for not using the original SN security algorithm to avoid initial algorithm confusion.
[0279] 4. Algorithm indication information includes: algorithm index.
[0280] It should be understood that if the algorithm indication information includes an algorithm index, the algorithm corresponding to the index can be directly determined as the security algorithm participating in the key update. The algorithm indication information can carry the algorithm index through a predefined field, for example, the value of the field is the algorithm index.
[0281] 5. The algorithm indication information includes: indication information on whether to use the original security algorithm and indication information on whether to use the original MN / SN security algorithm.
[0282] It should be understood that the indication information indicating whether to use the original security algorithm and the indication information indicating whether to use the original MN / SN security algorithm can be used in combination. That is, if the algorithm indication information includes indication information indicating whether to use the original security algorithm and also indicates the use of the original MN / SN security algorithm, the indication information of the original MN / SN security algorithm can be used. If the algorithm indication information includes indication information indicating whether to use the original security algorithm and also indicates not to use the original MN / SN security algorithm, it is determined that the indication information of the original MN / SN security algorithm in the original security algorithm is not to be used.
[0283] 6. Algorithm indication information includes: whether to use the original security algorithm and the algorithm index.
[0284] It should be understood that if the algorithm indication information includes indication information for using the original security algorithm and the index of the algorithm, it is possible to first determine whether the original security algorithm is the same as the algorithm corresponding to the index. If they are the same, the original security algorithm is used directly; if they are different, the original security algorithm can be selected to perform key update, or the algorithm corresponding to the algorithm index can be used to perform key update.
[0285] It should also be understood that if the algorithm indication information includes not using the original security algorithm and the algorithm index, the key update can be performed directly using the algorithm corresponding to the algorithm index.
[0286] 7. The algorithm indication information includes whether to use the original security algorithm, whether to use the original MN / SN security algorithm and the algorithm index.
[0287] It should be understood that when the algorithm indication information includes indication information on whether to use the original security algorithm, indication information on whether to use the original MN / SN security algorithm, and the index of the algorithm, a priority can be set for the above information. For example, the priority of the indication information on whether to use the original security algorithm is lower than the priority of the indication information on whether to use the original MN / SN security algorithm, and the priority of the indication information on whether to use the original MN / SN security algorithm is lower than the priority of the algorithm index. Of course, the setting of the above priorities is merely exemplary and should not constitute a specific limitation. For example, the priority of the indication information on whether to use the original security algorithm is higher than the priority of the indication information on whether to use the original MN / SN security algorithm, and the priority of the indication information on whether to use the original MN / SN security algorithm is higher than the priority of the algorithm index. The security algorithms participating in the key update are determined based on the priority of each item of indication information in the algorithm indication information.
[0288] When the algorithm indication information includes three types of information: indication information on whether to use the original security algorithm, indication information on whether to use the original MN / SN security algorithm, and the algorithm index, the following implementation methods may be used:
[0289] In embodiment 1, if the algorithm indication information includes indication information for using the original security algorithm, indication information for using the original MN / SN security algorithm, and an algorithm index, the original security algorithm may be determined first, and the algorithm corresponding to the original MN / SN security algorithm indication information and the algorithm index may be used to participate in the key update. If there are duplicate algorithms participating in the key update, one may be randomly selected or the latest algorithm may be selected.
[0290] Implementation method 2: If the algorithm indication information includes indication information of not using the original security algorithm, indication information of not using the original MN / SN security algorithm, and algorithm index, the security algorithm corresponding to the algorithm index may be determined first and participate in the key update.
[0291] Implementation method 3: If the algorithm indication information includes indication information of not using the original security algorithm, when using the indication information of the original MN / SN security algorithm and the index of the algorithm, the security algorithm corresponding to the original MN / SN security algorithm and the index of the algorithm can be determined first, and then the security algorithm participating in the key update can be determined based on the indication information of the original MN / SN security algorithm and the priority of the algorithm index.
[0292] Implementation method 4: If the algorithm indication information includes indication information for using the original security algorithm, and does not use the indication information for the original MN / SN security algorithm and the algorithm index, the security algorithm corresponding to the original security algorithm and the algorithm index can be determined first, and based on the priority of whether to use the indication information of the original security algorithm and the algorithm index, the security algorithm indicated by the algorithm indication information with a higher priority can be determined as the security algorithm participating in the key update.
[0293] In the embodiments of the present application, security algorithms are involved in the process of synchronously executing key updates by the terminal device and the target network element. In actual applications, security algorithms may include multiple types, such as but not limited to AS integrity protection algorithm, AS encryption algorithm, etc., and the specific types or categories of security algorithms are not overly limited in this embodiment. In the face of many security algorithms, in order to improve the adaptability of the terminal device and the security algorithm, so that the security algorithm can operate normally in the terminal device, a security algorithm can be selected for the terminal device based on the security information of the terminal device. In addition, in order to enable the terminal device and the target network element to use the same security algorithm to ensure the consistency of the key, the target network element can execute the selection of the security algorithm of the terminal device, and then configure the security algorithm selected for the terminal device to the terminal device.
[0294] Before performing inter-cell handover, the method 600 further includes: Step 630: In the LTM mechanism, the terminal device may perform L3 measurement reporting to the first network element. Accordingly, the first network element may receive the Layer 3 measurement reporting result reported by the terminal device and trigger a change in the UE's serving cell based on the Layer 3 measurement reporting result. The first network element may initiate inter-cell handover.
[0295] It should be understood that the first network element can use preset handover conditions to determine whether a cell handover between cell groups can be initiated. The handover conditions may, for example, include that the communication quality of a candidate cell meets a preset quality threshold. The candidate cell can be used as a target cell, and the first network element initiates a cell handover request to the target cell and / or a potential target cell initiates a cell handover request. Furthermore, if the target cell is located in a different target network element than the original network element, the first network element may also determine to initiate a cell handover request between cell groups.
[0296] Optionally, the first network element may sort the candidate cells based on their communication quality or select the cells based on a quality threshold to obtain the top N candidate cells with the highest communication quality, where N is a positive integer greater than or equal to 1. The top N candidate cells with the highest communication quality may include target cells and potential target cells. For example, the candidate cell with the highest communication quality may be selected as the target cell, and the remaining N-1 candidate cells may be selected as potential target cells.
[0297] After the first network element initiates a cell handover between cell groups, it may send a cell handover request to a candidate network element in step 640. Accordingly, the candidate network element may receive the cell handover request. The candidate network elements may include a target network element and a potential target network element. In other words, the target network element may receive the cell handover request. The potential target network element may also receive the cell handover request. Of course, the candidate network elements may also include other network elements, and this embodiment does not impose any particular limitations on this.
[0298] After the candidate network element receives the cell switching request, if it determines that the terminal device can access the covered cell, it can send a response message of the cell switching request to the first network element. In the dual-connection scenario, when the cell switching between cell groups is the cell switching of the main cell group MCG, the candidate network element includes at least a candidate MN, and / or, when the cell switching between cell groups includes the cell switching of the secondary cell group SCG, the candidate network element includes at least a candidate SN. The candidate MN includes the target MN and the potential target MN. The candidate SN includes the target SN and the potential target SN.
[0299] It should be understood that the cell handover request may include various parameters required for performing cell handover, for example, information of the target cell (such as the physical cell identifier (PCI) of the target cell), frequency information corresponding to the target cell, etc.
[0300] Optionally, after receiving the cell switching request sent by the first network element, the candidate network element may obtain security information of the terminal device in step 650 .
[0301] As described above, the candidate network element may trigger the acquisition of the security information of the terminal device based on the cell handover request. Further, the candidate network element may respond to the cell handover request and acquire the security information in the cell handover request.
[0302] In a possible design, the cell handover request may also carry the security information of the terminal device or may not carry the security information of the terminal device. The security information of the terminal device is transmitted to the target network element and the potential target network element through the cell handover request.
[0303] Optionally, the target network element or potential target network element may obtain security information of the terminal device and determine a security algorithm for the terminal device based on the security information of the terminal device. A mapping relationship between the security information of the terminal device and the security algorithm of the terminal device is established so that the security algorithm used by the terminal device and the security algorithm used by the target network element or potential target network element are the same, thereby ensuring that the key update process of the terminal device and the target network element or potential target network element is consistent and obtain the same key.
[0304] In another possible design, the security information of the terminal device may also be provided to the candidate network element by a core network element, such as an Access and Mobility Management Function (AMF) network element, a Session Management Function (SMF), or a User Plane Function (UPF). After receiving the cell handover request, the candidate network element may send an acquisition request to the core network element. The acquisition request may instruct the core network element to send the security information of the terminal to the candidate network element.
[0305] Optionally, the security information of the terminal device may include at least one of the following:
[0306] The security capabilities of the terminal device, the security level of the terminal device, and the security attributes of the terminal device.
[0307] It should be understood that the security capabilities of a terminal device may include the terminal device's hardware security capabilities and software security capabilities. Specifically, the terminal device's hardware security capabilities may refer to the ability of the terminal device's hardware to resist network risks. The terminal device's software security capabilities may refer to the ability of the terminal device's software to resist risks.
[0308] It should be understood that the security level of a terminal device may refer to a security level set according to the security of the terminal device. For example, the security level of a terminal device may include two categories: basic level and enhanced level. For another example, the security level of a terminal device may include multiple levels such as first security level, second security level, and third security level. Each level represents different security performance or security capabilities.
[0309] For example, the security levels of the first security level, the second security level, and the third security level may be arranged in descending order or in descending order. Of course, in this embodiment, the division of the security levels of the terminal device is merely exemplary and does not constitute a detailed limitation. In the embodiments of this application, there are no excessive restrictions on the number and order of the security levels.
[0310] It should be understood that the security attributes of a terminal device may refer to characteristics designed to protect the security of the terminal device. For example, these may include attributes such as confidentiality, integrity, availability, and trustworthiness. The higher the strength of the terminal device's security attributes and the richer the security attributes, the stronger the terminal device's security capabilities. Conversely, the lower the strength of the terminal device's security attributes and the fewer the security attributes, the weaker the terminal device's security capabilities. Of course, the security attributes of a terminal device may also include other characteristics, and the specific content of the terminal device's security attributes is not excessively limited in this embodiment.
[0311] In the embodiments of the present application, at least one of the terminal device's security capability, the terminal device's security level, and the terminal device's security attributes is used as the terminal device's security information, thereby enriching the specific meaning of the terminal device's security information. Thus, a more accurate terminal device security algorithm can be obtained by utilizing the terminal device's security information.
[0312] In order to determine the security algorithm of the terminal device, in step 660, the candidate network element may determine the security algorithm of the terminal device based on the security information.
[0313] It should be understood that a mapping relationship or mapping table may be pre-set between security information and security algorithms. The candidate network element may determine the security algorithm of the terminal device based on the security information of the terminal device. Specifically, the candidate network element may determine, through the mapping relationship or mapping table, a security algorithm that has a mapping relationship with the security information of the terminal device, and then use the security algorithm as the security algorithm of the terminal device.
[0314] It should be understood that the pre-set mapping relationship between security information and security algorithms may refer to an algorithmic solution model or formula corresponding to the security information and the security algorithm. This algorithmic solution model or formula can be used to solve the security algorithm corresponding to the security information. For example, the input of this mapping formula may be the characteristics of the security information, and the output may be the determined security algorithm. The security algorithm solution model may be, for example, an artificial intelligence model. The formula may be a mapping formula for a local mapping calculation function. This formula can be used to solve the security algorithm corresponding to the security information. Of course, the above mapping relationship is merely exemplary and does not constitute a specific limitation.
[0315] It should be understood that the pre-set mapping table of security information and security algorithms may refer to a table formed by the corresponding relationship between security information and security algorithms. A row in the table may be a security information and the security algorithm corresponding to the security information, or a set of security information and the set of corresponding security algorithms.
[0316] In the embodiment of the present application, the pre-set mapping relationship or mapping table between security information and security algorithms may include at least one of the following:
[0317] Each piece of security information and the corresponding security algorithm; each piece of security information and the corresponding algorithm set, the algorithm set may include multiple security algorithms, specifically may include algorithm indexes corresponding to multiple security algorithms; a security information set and the corresponding security algorithm; a security information set and the corresponding algorithm set, the security information set includes multiple security information, specifically may include information identifiers or information names corresponding to multiple security information, the algorithm set may include multiple security algorithms, specifically may include algorithm indexes corresponding to multiple security algorithms.
[0318] As described above, each network element can correspond to one or more cells. A network element can associate each of its cells or cell groups with the security algorithm of a terminal device, so that the terminal device's security algorithm can be associated with the cell for use. This allows the terminal device to obtain the security algorithm corresponding to the target cell during a cell handover. Therefore, in step 570, the candidate network element can send the security algorithm determined for the terminal device to the first network element. Correspondingly, the first network element can receive the security algorithm of the terminal device sent by the candidate network element.
[0319] It should be understood that the candidate network element sending the security algorithm of the terminal device to the first network element may include: sending the security algorithm of the terminal device to the first network element via a response message to the handover request. That is, when the candidate network element sends the security algorithm of the terminal device to the first network element, the handover request response message may carry the security algorithm of the terminal device.
[0320] The handover request response message may include parameters required to determine the cell handover of the terminal device. For example, it may include information about the target cell, the response result, and the time. Furthermore, the handover request response message may also include other parameters, such as the security algorithm determined by the candidate network element for the terminal device.
[0321] It should be understood that the first network element may receive a terminal device security algorithm sent by one or more candidate network elements. The candidate network elements may include a target network element and a potential target network element. The first network element may also be configured to: determine configuration information based on the terminal device security algorithm sent by at least one candidate network element. Specifically, the terminal device security algorithm sent by at least one candidate network element may be combined to obtain the configuration information.
[0322] In order to synchronize the correspondence between each cell and the corresponding security algorithm with the terminal device, the first network element may send configuration information to the terminal device in step 680. The configuration information may be used to configure the correspondence between the candidate cells and the security algorithms of the terminal device.
[0323] Specifically, the correspondence between the covered candidate cells and the security algorithms determined by the candidate network elements for the terminal device, or, each candidate cell is configured with a security algorithm set, and each algorithm in the set is identified by an algorithm index, and / or, the configuration information is used to indicate the correspondence between the terminal device configuration cell set covered by the candidate network element and the security algorithm determined by the candidate network element for the terminal device, and the security algorithm of the terminal device is determined based on the security information of the terminal device.
[0324] In one possible design, when the first network element sends configuration information to the terminal device, the configuration information can be carried by various messages or signaling specified in the protocol. For example, the configuration information can be carried in an RRC reconfiguration message, or in a media access control-control element MAC CE signaling or proprietary signaling.
[0325] In one implementation, the first network element may send an RRC reconfiguration message to the terminal device, where the RRC reconfiguration message may carry the configuration information. Specifically, the first network element may send the RRC reconfiguration message to the terminal device while being in an RRC connection with the terminal device.
[0326] Correspondingly, after receiving the RRC reconfiguration message, the terminal device saves the RRC reconfiguration message to configure the security algorithm of the terminal device according to the configuration information carried in the RRC reconfiguration message.
[0327] It should be understood that the configuration information can be carried in a predefined field in the RRC message. The configuration information can be set in a predefined field in the RRC signaling. In addition to carrying the configuration information, the RRC message may also include the parameters required by the target network element for the terminal device to access the target cell. For example, it may include information about the target cell (such as the physical cell identifier (PCI) of the target cell), frequency information corresponding to the target cell, resource information allocated by the target network element to the terminal device (such as dedicated random access channel (RACH) resources and / or public RACH resources), etc.
[0328] Optionally, after the terminal device configures the security algorithm of the terminal device according to the configuration information carried by the RRC reconfiguration message, it can also send an RRC reconfiguration completion message to the first network element based on the above parameters. The RRC reconfiguration completion message can prompt the first network element that it has completed the resource configuration of the target cell. It should be noted that in some embodiments of the present application, it is described that the terminal device can feedback the RRC reconfiguration completion message to the network element, but this feedback step may be unnecessary. For example, the first network element can start sending the first indication information without receiving the RRC reconfiguration completion message. For another example, the first network element can start a predefined timer after sending the RRC message, and when the timer expires, it can start sending the first indication information. The type and duration of the timer are not limited.
[0329] In this embodiment, the configuration information is sent to the terminal device via an RRC message. Using existing signaling transmission can avoid unnecessary channel overhead, save communication resources, and achieve flexible and efficient information transmission while improving service performance.
[0330] In another implementation, the first network element may send a Media Access Control (MACCE) signaling to the terminal device, where the MAC CE signaling carries the configuration information. Accordingly, the terminal device may receive the MAC CE and configure the security algorithm according to the configuration information carried in the MAC CE signaling.
[0331] In this embodiment, the configuration information is sent to the terminal device via MAC CE signaling, which can reduce the number of signaling transmissions. The cell switching command and the configuration information related to the cell switching are transmitted to the terminal device at the same time, which can improve transmission efficiency and achieve more flexible cell adjustment.
[0332] It should be understood that MAC CE signaling can carry configuration information through predefined fields.
[0333] In another implementation, the first network element may send proprietary signaling to the terminal device. The proprietary signaling may carry configuration information. Accordingly, the terminal device may receive the proprietary signaling and configure the security algorithm according to the configuration information carried in the proprietary signaling.
[0334] It should be understood that the proprietary signaling may be pre-configured signaling for transmitting information between the terminal device and the first network element. In this embodiment, the specific signaling structure of the proprietary signaling is not excessively limited.
[0335] In this embodiment, since proprietary signaling has higher transmission efficiency and greater flexibility, transmitting configuration information to the terminal device through proprietary signaling can improve the transmission efficiency and transmission security of the configuration information.
[0336] The communication method provided in this embodiment can configure the security algorithm determined by each candidate network element for the terminal device to the terminal device through configuration information, so that the security algorithm in the terminal device and each candidate network element is the same. Therefore, when both the terminal device and the target network element perform a key update, the same security algorithm is used, ensuring that the key update process of the terminal device and the target network element is consistent, so that the updated keys of the terminal device and the target network element are consistent, and the communication security between the terminal device and the target network element is effectively guaranteed.
[0337] As mentioned above, the configuration information can configure the corresponding relationship between the candidate cell and the security algorithm of the terminal device. The following lists several possible structures of the configuration information.
[0338] 1. A security algorithm configured corresponding to each candidate cell and terminal device.
[0339] It should be understood that the candidate cells and the security algorithms of the terminal device may be in a corresponding relationship. That is, each candidate cell may have a mapping relationship with a security algorithm of the terminal device, and the mapping relationship may reflect the association relationship among the candidate cell, the terminal device, and the security algorithm.
[0340] In the case where the candidate network elements include at least candidate MNs, each candidate MN cell is configured with a security algorithm corresponding to the terminal device.
[0341] When the candidate network elements include at least candidate SNs, each candidate SN cell is configured with a security algorithm corresponding to the terminal device.
[0342] The candidate MN cell may refer to a cell corresponding to the candidate MN, and the candidate SN cell may refer to a cell corresponding to the candidate SN.
[0343] 2. Each candidate cell and terminal device is configured with a corresponding security algorithm set, which includes multiple security algorithms.
[0344] It should be understood that each candidate cell may have a corresponding relationship with a security algorithm set of the terminal device. That is, each candidate cell may have a mapping relationship with a security algorithm set of the terminal device, and the mapping relationship may reflect the association relationship between the candidate cell, the terminal device, and the security algorithm set.
[0345] Optionally, the security algorithm set may include algorithm indexes corresponding to multiple security algorithms. A security algorithm may consist of one or more algorithms, and a combination of one or more algorithms may be referred to as a security algorithm. For example, the combination of an integrity protection algorithm and an encryption algorithm may be referred to as a security algorithm, while the integrity protection algorithm alone may also be referred to as a security algorithm, and the encryption algorithm alone may also be referred to as a security algorithm.
[0346] In the case that the candidate network elements include at least candidate MNs, each candidate MN cell and terminal device is configured with a security algorithm set correspondingly.
[0347] In the case where the candidate network elements include at least candidate SNs, each candidate SN cell and terminal device is configured with a security algorithm set correspondingly.
[0348] 3. Each candidate cell set / group and terminal device is configured with a corresponding security algorithm.
[0349] It should be understood that each candidate cell set / group may include one or more candidate cells, and specifically may include information about one or more candidate cells, such as at least one of the following: the candidate cell's physical cell identifier, cell identifier, cell name, etc. Each candidate cell set / group may be mapped to a security algorithm of a terminal device. That is, any candidate cell in each candidate cell set / group uses a security algorithm of the terminal device.
[0350] In the case that the candidate network elements include at least candidate MNs, each candidate MN cell set / group and the terminal device are configured with a corresponding security algorithm.
[0351] In the case where the candidate network elements include at least candidate SNs, each candidate SN cell set / group and the terminal device are configured with a corresponding security algorithm.
[0352] 4. Each candidate cell set / group and terminal device is configured with a security algorithm set, which includes multiple security algorithms.
[0353] It should be understood that any candidate cell in each candidate cell set / group may use a security algorithm set correspondingly configured by the terminal device. That is, the candidate cell may use any security algorithm in the security algorithm set to perform key update.
[0354] Furthermore, the candidate cell and the terminal device can each use the same algorithm selection strategy to select a target security algorithm from the algorithm security set, so that both the candidate cell and the terminal device can perform key updates using the target security algorithm. The algorithm selection strategy can be pre-set, for example, based on parameters such as the computational complexity and computation time of the security algorithm.
[0355] In the case that the candidate network elements include at least candidate MNs, each candidate MN cell set / group and each terminal device are configured with a corresponding security algorithm set.
[0356] In the case where the candidate network elements include at least candidate SNs, each candidate SN cell set / group and the terminal device are configured with a security algorithm set.
[0357] In the above embodiment, in step 620, after the target base station and the terminal device can respectively perform key updates under the instruction of the first indication information, the method can also include: step 690, the terminal device initiates a random access process to the target network element.
[0358] In this embodiment, the random access process between the terminal device and the target cell can refer to the existing technology and will not be described here for the sake of brevity.
[0359] Hereinafter, the technical solution of the present disclosure will be described in detail by taking the LTM mechanism as the switching mechanism during cell switching and combining the cell switching triggering method and switching mechanism involved in the cell switching process.
[0360] In order to better understand the embodiments of the present application, Figure 14-17 The application scenarios of the communication method disclosed in the present invention are further explained.
[0361] Scenario 1: SCG LTM cell handover is triggered by MN or by the original SN configured with signaling bearer resources
[0362] Figure 14 This is a signaling interaction diagram of a communication method provided in an embodiment of the present application. Figure 14 The process shown includes steps 1401 to 1410 .
[0363] In step 1401, the terminal device performs L3 measurement reporting, for example, reporting the measurement results of each candidate cell to the MN or the original SN. Accordingly, the MN or the original SN receives the measurement results and determines to perform cell handover between cell groups based on the measurement results of the terminal device.
[0364] Optionally, the measurement result may include an L3 measurement result.
[0365] In step 1402, the MN or the original SN sends an LTM cell handover request to the target SN when determining to execute SCG LTM. The LTM cell handover request may carry security information of the terminal device. The target network element may include the target SN and potential target SN.
[0366] Accordingly, the target SN and the potential target SN may receive the LTM cell handover request.
[0367] In step 1403, the target SN / potential target SN may determine the security algorithm of the terminal device according to the security information of the terminal device carried in the LTM cell handover request.
[0368] In step 1404, the target SN / potential target SN sends an LTM handover request response message to the original network element. The LTM handover request response message may carry the security algorithm of the terminal device.
[0369] In step 1405, the MN or the original SN sends an RRC message to the terminal device. The RRC message may carry configuration information. The configuration information may include at least one of the following:
[0370] Each candidate SN cell is configured with a corresponding security algorithm for the terminal device; each candidate SN cell is configured with a corresponding security algorithm set for the terminal device, and the security algorithm set includes multiple security algorithms; each candidate SN cell set / group is configured with a corresponding security algorithm for the terminal device; each candidate SN cell set / group is configured with a corresponding security algorithm set for the terminal device, and the security algorithm set includes multiple security algorithms.
[0371] In step 1406, the terminal device saves the configuration information.
[0372] In step 1407, the terminal device sends an RRC reconfiguration completion message to the MN or the original SN. The RRC reconfiguration completion message can prompt the MN that the resource configuration of the target cell has been completed.
[0373] In step 1408, the MN or the original SN terminal device sends a MAC CE signaling, which may carry first indication information. The MN or the original SN sends the first indication information to the target SN. The first indication information may be used to instruct the terminal device and the target SN to synchronously perform a key update.
[0374] The first indication information may include at least one of the following: SK-counter, next hop link counter NCC, and algorithm indication information.
[0375] In step 1409, the target SN and the terminal device may synchronously perform key update under the instruction of the first indication information.
[0376] In step 1410, a random access process may be initiated between the target SN and the terminal device.
[0377] For details of this embodiment, please refer to the detailed description of other embodiments in the specification, and will not be repeated here.
[0378] Scenario 2: MCG LTM cell handover triggered by MN
[0379] Figure 15 This is a signaling interaction diagram of a communication method provided in an embodiment of the present application. Figure 15 The process shown includes steps 1501 to 1510 .
[0380] In step 1501, the terminal device performs L3 measurement reporting, for example, reporting the measurement results of each candidate cell to the MN. Accordingly, the MN receives the measurement results and determines to perform cell handover between cell groups based on the measurement results of the terminal device.
[0381] Optionally, the measurement result may include an L3 measurement result.
[0382] In step 1502, the original MN sends an LTM cell handover request to the target MN when it determines to execute SCG LTM. The LTM cell handover request may carry the security information of the terminal device. The target network element may include the target MN and the potential target SN.
[0383] Accordingly, the target MN and the potential target MN may receive the LTM cell handover request.
[0384] In step 1503, the target MN / potential target MN may determine the security algorithm of the terminal device according to the security information of the terminal device carried in the LTM cell handover request.
[0385] In step 1504, the target MN / potential target MN sends an LTM handover request response message to the original network element. The LTM handover request response message may carry the security algorithm of the terminal device.
[0386] In step 1505, the original MN sends an RRC message to the terminal device. The RRC message may carry configuration information. The configuration information may include at least one of the following:
[0387] Each candidate MN cell is configured with a corresponding security algorithm for the terminal device; each candidate MN cell is configured with a corresponding security algorithm set for the terminal device, and the security algorithm set includes multiple security algorithms; each candidate MN cell set / group is configured with a corresponding security algorithm for the terminal device; each candidate MN cell set / group is configured with a corresponding security algorithm set for the terminal device, and the security algorithm set includes multiple security algorithms.
[0388] In step 1506, the terminal device saves the configuration information.
[0389] In step 1507, the terminal device sends an RRC reconfiguration complete message to the MN. The RRC reconfiguration complete message can prompt the MN that the resource configuration of the target cell has been completed.
[0390] In step 1508, the MN terminal device sends a MAC CE signaling, which may carry first indication information. The original MN sends the first indication information to the target MN. The first indication information may be used to instruct the terminal device and the target SN to synchronously perform a key update.
[0391] The first indication information may include at least one of the following: SK-counter, next hop link counter NCC, and algorithm indication information.
[0392] In step 1509, the target MN and the terminal device may synchronously perform key update under the instruction of the first instruction information.
[0393] In step 1510, a random access process may be initiated between the target MN and the terminal device.
[0394] For details of this embodiment, please refer to the detailed description of other embodiments in the specification, and will not be repeated here.
[0395] Scenario 3: SCG LTM cell handover is triggered by a SN that is not configured with signaling bearer resources
[0396] Figure 16 This is a signaling interaction diagram of a communication method provided in an embodiment of the present application. Figure 16 The process shown includes steps 1601 to 1610 .
[0397] In step 1601, the terminal device performs L3 measurement reporting, for example, reporting the measurement results of each candidate cell to the original SN. Accordingly, the SN receives the measurement results and determines to perform cell handover between cell groups based on the measurement results of the terminal device.
[0398] Optionally, the measurement result may include an L3 measurement result.
[0399] In step 1602, the original SN sends second indication information to the MN when determining to execute SCG LTM. The second indication information is used to instruct the MN to send the first indication information to the target SN and the terminal device.
[0400] In step 1603, the MN sends an LTM cell handover request to the target SN under the instruction of the second instruction information. The LTM cell handover request may carry the security information of the terminal device. The target network element may include the target SN and the potential target SN.
[0401] Accordingly, the target SN and the potential target SN may receive the LTM cell handover request.
[0402] In step 1604, the target SN / potential target SN may determine the security algorithm of the terminal device according to the security information of the terminal device carried in the LTM cell handover request.
[0403] In step 1605, the target SN / potential target SN sends an LTM handover request response message to the MN. The LTM handover request response message may carry the security algorithm of the terminal device.
[0404] In step 1606, the MN sends an RRC message to the terminal device. The RRC message may carry configuration information. The configuration information may include at least one of the following:
[0405] Each candidate SN cell is configured with a corresponding security algorithm for the terminal device; each candidate SN cell is configured with a corresponding security algorithm set for the terminal device, and the security algorithm set includes multiple security algorithms; each candidate SN cell set / group is configured with a corresponding security algorithm for the terminal device; each candidate SN cell set / group is configured with a corresponding security algorithm set for the terminal device, and the security algorithm set includes multiple security algorithms.
[0406] In step 1607, the terminal device saves the configuration information.
[0407] In step 1608, the terminal device sends an RRC reconfiguration complete message to the MN. The RRC reconfiguration complete message can prompt the MN that the resource configuration of the target cell has been completed.
[0408] In step 1609, the MN terminal device sends a MAC CE signaling, which may carry first indication information. The MN sends the first indication information to the target SN. The first indication information may be used to instruct the terminal device and the target SN to synchronously perform a key update.
[0409] The first indication information may include at least one of the following: SK-counter, next hop link counter NCC, and algorithm indication information.
[0410] In step 1610, the target SN and the terminal device may synchronously perform key update under the instruction of the first indication information.
[0411] In step 1611, a random access process may be initiated between the target SN and the terminal device.
[0412] For details of this embodiment, please refer to the detailed description of other embodiments in the specification, and will not be repeated here.
[0413] Above, combined Figures 6 to 16 The communication method provided by the embodiment of the present application is described in detail. Figure 17 The device provided in the embodiments of the present application is described in detail.
[0414] Figure 17 1700 is a schematic block diagram of a communication device 1700 provided in an embodiment of the present application. Figure 17 As shown, the communication device 1700 may include a processing unit 1710 and a transceiver unit 1720 .
[0415] In one possible design, the communication device 1700 can implement the operations of the corresponding terminal device in the above method embodiment. For example, the communication device can be a terminal device, or a component configured in the terminal device, such as a chip or circuit.
[0416] The communication device can realize Figures 6 to 16 For example, the transceiver unit 1710 may execute steps 610, 630, 640, 650, 670, or 680 in the method 600, and the processing unit 1720 may execute steps 1620, 1660, etc. in the method 160. The units in the communication device 160 and the above-mentioned other operations and / or functions are respectively for the purpose of realizing Figure 17 The corresponding process in the method embodiment shown.
[0417] Specifically, the communication device 1700 is used to perform Figure 6 When using the communication method shown, the transceiver unit 1720 can be used to: receive a first indication message, the first indication message is sent by the first network element when triggering a cell switch between cell groups, the first indication message is used to instruct the target network element and the terminal device to synchronously perform a key update, the cell switch between cell groups refers to the original cell of the first cell group being switched to the target cell of the second cell group, and the original network element corresponding to the first cell group and the target network element corresponding to the second cell group are different.
[0418] Specifically, before receiving the first indication information, it also includes: receiving configuration information, where the configuration information is used to configure the security algorithm determined by the candidate network element according to the security information of the terminal device, and the candidate network element includes the target network element.
[0419] When the cell switching between cell groups is the cell switching of the main cell group MCG, the candidate network elements include at least candidate MNs, and / or when the cell switching between cell groups includes the cell switching of the secondary cell group SCG, the candidate network elements include at least candidate SNs.
[0420] Among them, when the candidate network elements include at least candidate MNs, the configuration information includes at least one of the following: a security algorithm configured corresponding to each candidate MN cell and the terminal device; a security algorithm set configured corresponding to each candidate MN cell and the terminal device, and the security algorithm set includes multiple security algorithms; a security algorithm configured corresponding to each candidate MN cell set / group and the terminal device; a security algorithm set configured corresponding to each candidate MN cell set / group and the terminal device, and the security algorithm set includes multiple security algorithms.
[0421] In the case where the candidate network elements include at least candidate SNs, the configuration information includes at least one of the following: a security algorithm configured corresponding to each candidate SN cell and the terminal device;
[0422] Each candidate SN cell and terminal device is configured with a security algorithm set, which includes multiple security algorithms;
[0423] Each candidate SN cell set / group and terminal device is configured with a corresponding security algorithm;
[0424] Each candidate SN cell set / group and terminal device is configured with a corresponding security algorithm set, which includes multiple security algorithms.
[0425] It should be understood that in a dual-connection scenario, a terminal device can be connected to both the MN and the SN at the same time. Cell switching between cell groups includes cell switching of a primary cell group MCG, where the original network element is the original primary base station MN, the target network element is the target MN, and the first network element is the original MN; and / or, cell switching between cell groups includes cell switching of a secondary cell group SCG, where the original network element is the original secondary base station SN, the target network element is the target SN, and the first network element is the original SN or the primary base station MN.
[0426] In another possible design, the communication device 1600 can implement the operations corresponding to the first network element in the above method embodiment. For example, the communication device can be the first network element, or a component configured in the first network element, such as a chip or circuit.
[0427] Specifically, the communication device 1700 performs Figure 6 When using the communication method shown, the transceiver unit 1720 can be used to: when triggering cell switching between cell groups, send a first indication message to the target network element and the terminal device, the first indication message is used to instruct the target network element and the terminal device to synchronously perform key updates, and the cell switching between cell groups refers to the switching of the original cell of the first cell group to the target cell of the second cell group, and the original network element corresponding to the first cell group and the target network element corresponding to the second cell group are different.
[0428] Specifically, the transceiver unit 1720 is also used to: send configuration information to the terminal device, the configuration information is used to configure the candidate network element to determine the security algorithm based on the security information of the terminal device, and the candidate network element includes the target network element; when the cell switching between cell groups is the cell switching of the main cell group MCG, the candidate network element includes at least the candidate MN, and / or, when the cell switching between cell groups includes the cell switching of the secondary cell group SCG, the candidate network element includes at least the candidate SN.
[0429] Specifically, the transceiver unit 1720 is further configured to send a cell switching request to the candidate network element, where the cell switching request carries the security information of the terminal device or does not carry the security information of the terminal device.
[0430] In another possible design, the communication device 1700 may implement the operations corresponding to the candidate network element in the above method embodiment, and the candidate network element may include the target network element. For example, the communication device may be a candidate network element, or a component configured in the candidate network element, such as a chip or circuit.
[0431] Specifically, the communication device 1700 performs Figure 6 When using the communication method shown, the transceiver unit 1720 can be used to: receive a first indication message, the first indication message is sent by the first network element when triggering a cell switch between cell groups, the first indication message is used to instruct the target network element and the terminal device to synchronously perform a key update, the cell switch between cell groups refers to the original cell of the first cell group being switched to the target cell of the second cell group, and the original network element corresponding to the first cell group and the target network element corresponding to the second cell group are different.
[0432] Specifically, the transceiver unit 1720 is also used to: receive a cell switching request, the cell switching request carries the security information of the terminal device or does not carry the security information of the terminal device, and the candidate network element includes the target network element; determine the security algorithm of the terminal device based on the security information; when the cell switching between cell groups is the cell switching of the main cell group MCG, the candidate network elements include at least the candidate MN, and / or, when the cell switching between cell groups includes the cell switching of the secondary cell group SCG, the candidate network elements include at least the candidate SN.
[0433] It should be understood that the specific process of each unit executing the above corresponding steps has been described in detail in the above method embodiment, and for the sake of brevity, it will not be repeated here.
[0434] It should also be understood that the division of modules in the embodiments of the present application is illustrative and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the various embodiments of the present application may be integrated into a single processor, or may exist physically separately, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or software functional modules.
[0435] It should be understood that the communication device 1700 may correspond to Figure 1 The terminal device 130 or the network elements 110-120 in the communication system 100 shown in FIG. The processing unit 1710 in the communication apparatus 1700 may correspond to a processor in the terminal device 130 or the network elements 110-120, and the processor in the terminal device 130 or the network elements 110-120 may call instructions stored in the memory to implement the above functions, such as network coding and obtaining original packets; the transceiver unit 1720 may correspond to an interface in the terminal device 130 or the network elements 110-120, and may respond to instructions from the processor to implement the above functions of receiving and / or sending data.
[0436] It should also be understood that the transceiver unit 1720 in the communication device 1700 can be implemented by a transceiver or a communication interface, for example, corresponding to Figure 18 The transceiver 2020 in the terminal device 2000 shown in FIG. Figure 19 The processing unit 1710 in the communication device 1700 can be implemented by at least one processor, for example, corresponding to Figure 18 The processor 2010 in the terminal device 2000 shown in FIG. Figure 19 The processor 3200 in the network device 3000 is shown in FIG.
[0437] Figure 18 This is a schematic diagram of the structure of the terminal device 2000 provided in the embodiment of the present application. The terminal device 2000 can be applied to Figure 1In the system shown, the functions of the terminal device in the above-described method embodiment are performed. As shown in the figure, the terminal device 2000 includes a processor 2010 and a transceiver 2020. Optionally, the terminal device 2000 also includes a memory 2030. The processor 2010, the transceiver 2020, and the memory 2030 can communicate with each other via internal connection paths to transmit control and / or data signals. The memory 2030 is used to store computer programs, and the processor 2010 is used to call and execute the computer programs from the memory 2030 to control the transceiver 2020 to transmit and receive signals. Optionally, the terminal device 2000 may also include an antenna 2040 for transmitting uplink data or uplink control signaling output by the transceiver 2020 via wireless signals.
[0438] The processor 2010 and the memory 2030 can be combined into a processing device, and the processor 2010 is used to execute the program code stored in the memory 2030 to implement the above functions. In specific implementation, the memory 2030 can also be integrated into the processor 2010, or independent of the processor 2010. The processor 2010 can be combined with the memory 2030 to form a processing device. Figure 17 Corresponding to the processing unit 11 in .
[0439] The transceiver 2020 can be used with Figure 17 The transceiver 2020 may include a receiver (or receiver, receiving circuit) and a transmitter (or transmitter, transmitting circuit). The receiver is used to receive signals, and the transmitter is used to transmit signals.
[0440] It should be understood that Figure 18 The terminal device 2000 shown can realize Figures 6 to 16 The illustrated method embodiments involve various processes of the terminal device. The operations and / or functions of the various modules in the terminal device 2000 are respectively for implementing the corresponding processes in the aforementioned method embodiments. For details, please refer to the description of the aforementioned method embodiments. To avoid repetition, detailed descriptions are appropriately omitted here.
[0441] The processor 2010 can be used to execute the actions implemented within the terminal device described in the previous method embodiments, while the transceiver 2020 can be used to execute the actions of the terminal device sending to or receiving from the network device described in the previous method embodiments. For details, please refer to the description of the previous method embodiments and will not be repeated here.
[0442] Optionally, the terminal device 2000 may further include a power supply 2050 for providing power to various devices or circuits in the terminal device.
[0443] In addition, in order to make the functions of the terminal device more complete, the terminal device 2000 can also include one or more of an input unit 2060, a display unit 2070, an audio circuit 2080, a camera 2090 and a sensor 2100, and the audio circuit can also include a speaker 2082, a microphone 2084, etc.
[0444] Figure 19 This is a schematic diagram of the structure of a network element provided in an embodiment of the present application, for example, a schematic diagram of the structure of a base station. The base station 3000 can be applied to Figure 1 In the system shown in FIG. 1 , the functions of the network device in the above method embodiment are performed. As shown in the figure, the base station 3000 may include one or more radio frequency units, such as a remote radio unit (RRU) 3100 and one or more baseband units (BBU) (also known as distributed units (DU)) 3300. The RRU 3100 may be called a transceiver unit, and the Figure 17 . Optionally, the transceiver unit 3100 may also be referred to as a transceiver, a transceiver circuit, or a transceiver, etc., and may include at least one antenna 3101 and a radio frequency unit 3102. Optionally, the transceiver unit 3100 may include a receiving unit and a transmitting unit, the receiving unit may correspond to a receiver (or receiver, receiving circuit), and the transmitting unit may correspond to a transmitter (or transmitter, transmitting circuit). The RRU 3100 part is mainly used for receiving and transmitting radio frequency signals and converting radio frequency signals into baseband signals, for example, for sending indication information to terminal devices. The BBU 3300 part is mainly used for baseband processing, controlling the base station, etc. The RRU 3100 and the BBU 3300 may be physically arranged together or physically separated, that is, a distributed base station.
[0445] BBU 3300 is the control center of the base station, also known as the processing unit, which can be used with Figure 17 The processing unit 1720 in the embodiment corresponds to the baseband processing unit 1720, which is mainly used to perform baseband processing functions such as channel coding, multiplexing, modulation, spread spectrum, etc. For example, the BBU (processing unit) can be used to control the base station to execute the operation process of the network device in the above method embodiment, such as generating the above indication information.
[0446] In one example, the BBU 3300 can be composed of one or more single boards, and multiple single boards can jointly support a wireless access network with a single access standard (such as an LTE network), or can separately support wireless access networks with different access standards (such as an LTE network, a 5G network, or other networks). The BBU 3300 also includes a memory 3201 and a processor 3202. The memory 3201 is used to store necessary instructions and data. The processor 3202 is used to control the base station to perform necessary actions, such as controlling the base station to execute the operation process of the network device in the above method embodiment. The memory 3201 and the processor 3202 can serve one or more single boards. That is, a memory and a processor can be set separately on each single board. Alternatively, multiple single boards can share the same memory and processor. In addition, necessary circuits can also be set on each single board.
[0447] It should be understood that Figure 19 The base station 3000 shown is capable of Figures 2 to 16 The illustrated method embodiment involves various processes of the target network device. The operations and / or functions of the various modules in base station 3000 are respectively for implementing the corresponding processes in the above method embodiment. For details, please refer to the description of the above method embodiment. To avoid repetition, detailed description is appropriately omitted here.
[0448] The BBU 3300 can be used to perform the actions implemented within the network device described in the previous method embodiments, while the RRU 3100 can be used to perform the actions described in the previous method embodiments, where the network device sends data to or receives data from a terminal device. For details, please refer to the description in the previous method embodiments and will not be repeated here.
[0449] It should be understood that Figure 19 The base station 3000 shown is only one possible architecture of a network device and should not constitute any limitation to this application. The method provided in this application is applicable to network devices with other architectures. For example, network devices including CUs, DUs, and active antenna units (AAUs) are not limited to the specific architecture of the network device.
[0450] An embodiment of the present application further provides a processing device, including a processor and an interface; the processor is used to execute the method in any of the above method embodiments.
[0451] It should be understood that the above-mentioned processing device may be one or more chips. For example, the processing device may be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chips.
[0452] During implementation, each step of the above method can be completed by an integrated logic circuit of the hardware in the processor or by instructions in the form of software. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor. The software module can be located in a storage medium mature in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in conjunction with its hardware. To avoid repetition, it will not be described in detail here.
[0453] It should be noted that the processor in the embodiments of the present application can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method embodiment can be completed by an integrated logic circuit of the hardware in the processor or by instructions in the form of software. The above processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The various methods, steps, and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
[0454] It is understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct RAM bus RAM (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0455] According to the method provided in the embodiment of the present application, the present application also provides a computer program product, which includes: a computer program code, which, when executed on a computer, causes the computer to execute Figures 2 to 10 The method of any of the embodiments shown.
[0456] According to the method provided in the embodiment of the present application, the present application also provides a computer-readable medium, which stores a program code, and when the program code is run on a computer, the computer executes Figures 2 to 10 The method of any of the embodiments shown.
[0457] According to the method provided in the embodiment of the present application, the present application also provides a system, which includes one or more terminal devices and one or more network devices as mentioned above.
[0458] The network devices in the above-mentioned various apparatus embodiments completely correspond to the network devices or terminal devices in the terminal devices and method embodiments, and the corresponding steps are performed by the corresponding modules or units. For example, the communication unit (transceiver) performs the receiving or sending steps in the method embodiments, and other steps except sending and receiving can be performed by the processing unit (processor). The functions of the specific units can be referred to the corresponding method embodiments. Among them, there can be one or more processors.
[0459] As used in this specification, the terms "component," "module," "system," and the like are used to represent computer-related entities, hardware, firmware, a combination of hardware and software, software, or software in execution. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an executable file, an execution thread, a program, and / or a computer. By way of illustration, both an application running on a computing device and a computing device can be a component. One or more components can reside in a process and / or an execution thread, and a component can be located on a computer and / or distributed between two or more computers. In addition, these components can be executed from various computer-readable media having various data structures stored thereon. Components can communicate, for example, via local and / or remote processes based on signals having one or more data packets (e.g., data from two components interacting with another component on a local system, a distributed system, and / or a network, such as the Internet interacting with other systems via signals).
[0460] Those skilled in the art will appreciate that the various illustrative logical blocks and steps described in conjunction with the embodiments disclosed herein can be implemented using electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0461] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0462] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0463] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0464] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0465] In the above embodiments, the functions of each functional unit can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions (programs). When the computer program instructions (program) are loaded and executed on a computer, the process or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrated therein. Available media may be magnetic media (eg, floppy disks, hard disks, tapes), optical media (eg, high-density digital video discs (DVDs)), or semiconductor media (eg, solid state disks (SSDs)).
[0466] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, and other media that can store program codes.
[0467] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A communication method, characterized in that: include: Receive first indication information, where the first indication information is sent by the first network element when triggering a cell handover between cell groups. The first indication information is used to instruct the target network element and the terminal device to synchronously perform a key update. The cell handover between the cell groups refers to switching from the original cell of the first cell group to the target cell of the second cell group. The original network element corresponding to the first cell group and the target network element corresponding to the second cell group are different.
2. The method according to claim 1, characterized in that The cell handover between the cell groups includes the cell handover of the master cell group MCG, the original network element is the original master base station MN, the target network element is the target MN, and the first network element is the original secondary base station SN; And / or, the cell handover between the cell groups includes cell handover of a secondary cell group SCG, the original network element is an original secondary base station SN, the target network element is a target SN, and the first network element is the original secondary base station SN or a master base station MN.
3. The method according to claim 2, characterized in that The first indication information is sent by the original secondary base station SN through the signaling bearer resource when the signaling bearer resource is configured by the original secondary base station SN; Alternatively, the first indication information is sent by the main base station MN by the original secondary base station SN without configuring signaling bearer resources, and the MN is sent under the instruction of the second indication information sent by the original secondary base station SN, and the second indication information is used to instruct the MN to send the first indication information to the target SN and the terminal device.
4. The method according to any one of claims 1 to 3, characterized in that Before receiving the first indication information, the method further includes: receiving configuration information, where the configuration information is used to configure a security algorithm determined by a candidate network element according to the security information of the terminal device, the candidate network element including the target network element; When the cell switching between the cell groups is the cell switching of the main cell group MCG, the candidate network elements include at least candidate MNs, and / or when the cell switching between the cell groups includes the cell switching of the secondary cell group SCG, the candidate network elements include at least candidate SNs.
5. The method according to claim 4, characterized in that The candidate network element corresponds to at least one candidate cell, and the configuration information includes at least one of the following: A security algorithm configured corresponding to each candidate cell and the terminal device; A security algorithm set configured corresponding to each candidate cell and the terminal device, the security algorithm set including multiple security algorithms; A security algorithm configured corresponding to each candidate cell set / group and the terminal device; Each candidate cell set / group is configured with a security algorithm set corresponding to the terminal device, and the security algorithm set includes multiple security algorithms.
6. The method according to claim 4, characterized in that The security information includes at least one of the following: The security capabilities of the terminal device, the security level of the terminal device, and the security attributes of the terminal device.
7. The method according to claim 4, characterized in that The configuration information is carried in an RRC reconfiguration message, or carried in a MAC CE signaling or dedicated signaling.
8. The method according to any one of claims 1 to 7, characterized in that The first indication information includes at least one of the following: Secondary node key update counter SK-counter, next hop link counter NCC, algorithm indication information.
9. The method according to claim 8, characterized in that The algorithm indicates at least one of the following information: Indication of whether to use the original security algorithm; Indication information on whether to use the original secondary base station SN security algorithm; Indication information on whether to use the original secondary base station SN security algorithm; The index of the algorithm.
10. The method according to any one of claims 1 to 9, characterized in that The first indication information is carried in a media access control-control element MAC CE used for handover or in dedicated signaling.
11. A communication method, characterized in that: include: In the case of triggering cell switching between cell groups, a first indication message is sent to the target network element and the terminal device, wherein the first indication message is used to instruct the target network element and the terminal device to synchronously perform key update. The cell switching between the cell groups refers to switching the original cell of the first cell group to the target cell of the second cell group, and the original network element corresponding to the first cell group and the target network element corresponding to the second cell group are different.
12. The method according to claim 11, characterized in that The method is applied to a first network element, the cell handover between the cell groups includes the cell handover of a primary cell group, the original network element is an original primary base station MN, the target network element is a target MN, and the first network element is an original secondary base station SN; And / or, the cell handover between the cell groups includes cell handover of a secondary cell group, the original network element is an original secondary base station SN, the target network element is a target SN, and the first network element is the original secondary base station SN or the master base station MN.
13. The method according to claim 12, characterized in that The sending the first indication information to the target network element and the terminal device includes: In the case of configuring signaling bearer resources, sending first indication information to the target network element and the terminal device through the signaling bearer resources; Alternatively, the sending the first indication information to the target network element and the terminal device includes: In the case where signaling bearer resources are not configured, second indication information is sent to the MN, where the second indication information is used to instruct the MN to send the first indication information to the target SN and the terminal device.
14. The method according to any one of claims 11 to 13, characterized in that: Also includes: Sending configuration information to the terminal device, where the configuration information is used to configure a security algorithm determined by a candidate network element according to the security information of the terminal device, the candidate network element including the target network element; When the cell switching between the cell groups is the cell switching of the main cell group MCG, the candidate network elements include at least candidate MNs, and / or when the cell switching between the cell groups includes the cell switching of the secondary cell group SCG, the candidate network elements include at least candidate SNs.
15. The method according to claim 14, characterized in that The candidate network element corresponds to at least one candidate cell, and the configuration information includes at least one of the following: A security algorithm configured corresponding to each candidate cell and the terminal device; A security algorithm set configured corresponding to each candidate cell and the terminal device, the security algorithm set including multiple security algorithms; A security algorithm configured corresponding to each candidate cell set / group and the terminal device; Each candidate cell set / group is configured with a security algorithm set corresponding to the terminal device, and the security algorithm set includes multiple security algorithms.
16. The method according to claim 14, characterized in that The security information includes at least one of the following: The security capabilities of the terminal device, the security level of the terminal device, and the security attributes of the terminal device.
17. The method according to claim 14, characterized in that The configuration information is carried in an RRC reconfiguration message, or carried in a MAC CE signaling or dedicated signaling.
18. The method according to any one of claims 14 to 17, characterized in that: Also includes: Send a cell switching request to the candidate network element, where the cell switching request carries the security information of the terminal device.
19. The method according to any one of claims 11 to 18, characterized in that The first indication information includes at least one of the following: Secondary node key update counter SK-counter, next hop link counter NCC, algorithm indication information.
20. The method according to any one of claims 11 to 19, characterized in that: The first indication information is carried in a medium access control-control element MAC CE used for handover or in dedicated signaling.
21. A communication method, characterized in that: include: Receive first indication information, where the first indication information is sent by the first network element when triggering cell switching between cell groups. The first indication information is used to instruct the target network element and the terminal device to synchronously perform key updates. The cell switching between cell groups refers to switching the original cell of the first cell group to the target cell of the second cell group. The original network element corresponding to the first cell group and the target network element corresponding to the second cell group are different.
22. The method according to claim 21, characterized in that The cell handover between the cell groups includes the cell handover of the master cell group MCG, the original network element is the original master base station MN, the target network element is the target MN, and the first network element is the original secondary base station SN; And / or, the cell handover between the cell groups includes cell handover of a secondary cell group SCG, the original network element is an original secondary base station SN, the target network element is a target SN, and the first network element is the original secondary base station SN or a master base station MN.
23. The method according to claim 22, characterized in that The first indication information is sent by the original secondary base station SN through the signaling bearer resource when the signaling bearer resource is configured by the original secondary base station SN; Alternatively, the first indication information is sent by the main base station MN by the original secondary base station SN without configuring signaling bearer resources, and the MN is sent under the instruction of the second indication information sent by the original secondary base station SN, and the second indication information is used to instruct the MN to send the first indication information to the target SN and the terminal device.
24. The method according to claim 22 or 23, characterized in that The method is applied to a target network element, where the target network element is a candidate network element, and the method further includes: receiving a cell handover request, where the cell handover request carries security information of the terminal device, and the target network element is a candidate network element; Determining a security algorithm for the terminal device based on the security information; When the cell switching between the cell groups is the cell switching of the main cell group MCG, the candidate network elements include at least candidate MNs, and / or when the cell switching between the cell groups includes the cell switching of the secondary cell group SCG, the candidate network elements include at least candidate SNs.
25. The method according to any one of claims 21 to 24, characterized in that The first indication information includes at least one of the following: Next hop chain counter NCC, secondary node key update counter SK-counter, algorithm indication information.
26. A terminal device, characterized in that: including: processor and memory; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the terminal device executes the information processing method according to any one of claims 1 to 10.
27. A first network element, characterized in that: include: processor and memory; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the first network element executes the information processing method according to any one of claims 11 to 20.
28. A target network element, characterized in that: include: processor and memory; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the target network element executes the information processing method according to any one of claims 21 to 25.
29. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 25 is implemented.
30. A chip system, characterized in that: The system comprises at least one processor and a communication interface, wherein the communication interface and the at least one processor are interconnected via a line, and the at least one processor is used to run a computer program or instruction to execute the method according to any one of claims 1 to 25.