Security parameter processing method, communication device and storage medium
By negotiating security parameters in advance during the LTM process, the problem of security context transmission delay is solved, and the efficiency and reliability of the communication system are improved.
Patent Information
- Application Number
- CN202480010894.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-09-30
- Filing Date
- 2024-10-31
- Publication Date
- 2025-09-19
AI Technical Summary
In the L1/L2 Triggered Mobility (LTM) process, existing technologies are difficult to effectively reduce the security context transmission delay when the primary node or the primary and secondary nodes change.
The first node sends security context related information of the user equipment UE to the second node in advance, negotiates security parameters, and reduces the transmission delay of the security context during the handover process.
The transmission delay of the security context during the LTM process is reduced, and the efficiency and reliability of the communication system are improved.
Smart Images

Figure CN120677734A_ABST
Abstract
Description
[0001] This application claims priority to PCT application No. PCT / CN2024 / 123059, filed on September 30, 2024. Technical Field
[0002] The present disclosure relates to the field of communication technology, and in particular to a security parameter processing method, communication equipment, and storage medium. Background Art
[0003] Layer 1 / L2 Triggered Mobility (LTM) is a process in which the network triggers a primary cell (PCell) or primary secondary cell (PSCell) switch (cell switch) based on Layer 1 (L1) measurements via the Media Access Control (MAC) Control Element (CE). This PCell or PSCell switch can also be accompanied by a Master Cell Group (MCG) or Secondary Cell Group (SCG) switch. Summary of the Invention
[0004] Embodiments of the present disclosure provide a security parameter processing method, a communication device, and a storage medium.
[0005] According to a first aspect of an embodiment of the present disclosure, a security parameter processing method is provided, which is executed by a first node and includes: sending a first message to a second node, the first message including relevant information about the security context of layer 1 / layer 2 triggering mobility LTM of a user equipment UE; receiving a second message sent by the second node, the second message including security parameters determined based on the first message; sending a third message to the UE based on the second message; the third message including the security parameters; the security parameters are used to protect communication between the UE and the second node.
[0006] According to a second aspect of an embodiment of the present disclosure, a security parameter processing method is provided, which is executed by a second node and includes: receiving a first message sent by a first node, the first message including relevant information about the security context of layer 1 / layer 2 triggering mobility LTM of a user equipment UE; sending a second message to the first node, the second message including security parameters determined based on the first message; the security parameters are used by the first node to send a third message to the UE, the third message including the security parameters; the security parameters are used to protect communication between the UE and the second node.
[0007] According to a third aspect of an embodiment of the present disclosure, a security parameter processing method is provided, which is executed by a user equipment UE, and the method includes: receiving a third message sent by a first node; the third message is used by the UE to determine a security parameter for communicating with a second node.
[0008] According to the fourth aspect of an embodiment of the present disclosure, a first node is provided, wherein the first node includes: a sending module, configured to send a first message to a second node, the first message including relevant information about the security context of layer 1 / layer 2 triggered mobility LTM of a user equipment UE; a receiving module, configured to receive a second message sent by the second node, the second message including security parameters determined based on the first message; the sending module is configured to send a third message to the UE based on the second message; the third message is used by the UE to determine the security parameters for communicating with the second node.
[0009] According to the fifth aspect of an embodiment of the present disclosure, a second node is provided, wherein the second node includes: a receiving module, configured to receive a first message sent by a first node, the first message including relevant information about the security context of layer 1 / layer 2 triggered mobility LTM of a user equipment UE; a sending module, configured to send a second message to the second node, the second message including security parameters determined based on the first message; the security parameters are used by the first node to send a third message to the UE, and the third message is used by the UE to determine the security parameters for communicating with the second node.
[0010] According to the sixth aspect of an embodiment of the present disclosure, a user equipment UE is provided, wherein the UE includes: a receiving module configured to receive a third message sent by a first node; the third message includes first information of M second nodes; the first information of the mth second node is used to indicate a first security algorithm and a first UP security activation status; the first security algorithm is selected by the mth second node according to the first capability information; the first UP security activation status is determined by the mth second node according to the first UP security policy; and m is a positive integer less than or equal to M.
[0011] According to the seventh aspect of an embodiment of the present disclosure, a communication system is provided, wherein the communication system includes: a first node is configured to execute the security parameter processing method provided by any technical solution of the first aspect; a second node is configured to execute the security parameter processing method provided by any technical solution of the second aspect; and a UE is configured to execute the security parameter processing method provided by any technical solution of the third aspect.
[0012] According to an eighth aspect of an embodiment of the present disclosure, a communication device is provided, wherein the communication device includes: one or more processors; wherein the processor is used to call instructions to enable the communication device to execute the security parameter processing method provided by any technical manner of the aforementioned first aspect, second aspect and / or third aspect.
[0013] According to a ninth aspect of an embodiment of the present disclosure, a storage medium is provided, wherein the storage medium stores instructions, which, when the instructions are executed on a communication device, enable the communication device to execute the security parameter processing method provided by any of the first aspect, the second aspect and / or the third aspect.
[0014] According to the tenth aspect of an embodiment of the present disclosure, a program product is provided, wherein the program product includes a computer program, and when the computer program is executed by a communication device, the communication device can implement the security parameter processing method provided by any technical means of the aforementioned first aspect, second aspect and / or third aspect.
[0015] According to the technical approach provided by the embodiments of the present disclosure, the first node sends the relevant information of the UE's security context to the second node in advance, which can reduce the delay when the security context needs to be used compared to temporarily transmitting the relevant information of the security context.
[0016] It should be understood that the foregoing general description and the following detailed description are merely exemplary and explanatory and are not restrictive of the embodiments of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments of the present disclosure and, together with the description, serve to explain the principles of the embodiments of the present disclosure.
[0018] Figure 1A is a schematic diagram showing an architecture of a communication system according to an exemplary embodiment;
[0019] Figure 1B FIG. 1 is a flow chart of LTM according to an exemplary embodiment;
[0020] Figure 1C is a schematic diagram of a key derivation process according to an exemplary embodiment;
[0021] Figure 2A is a flowchart illustrating a method for processing security parameters according to an exemplary embodiment;
[0022] Figure 2B is a flowchart illustrating a method for processing security parameters according to an exemplary embodiment;
[0023] Figure 2Cis a flowchart illustrating a method for processing security parameters according to an exemplary embodiment;
[0024] Figure 2D is a flowchart illustrating a method for processing security parameters according to an exemplary embodiment;
[0025] Figure 3A is a flowchart illustrating a method for processing security parameters according to an exemplary embodiment;
[0026] Figure 3B is a flowchart illustrating a method for processing security parameters according to an exemplary embodiment;
[0027] Figure 4 is a structural diagram of a communication system according to an exemplary embodiment;
[0028] Figure 5A is a schematic structural diagram of a communication device according to an exemplary embodiment;
[0029] Figure 5B The figure is a schematic structural diagram of a chip according to an exemplary embodiment. DETAILED DESCRIPTION
[0030] Embodiments of the present disclosure provide a security parameter processing method, a communication device, a communication system, and a storage medium.
[0031] A first aspect provides a security parameter processing method, wherein the method is performed by a first node and includes:
[0032] Sending a first message to the second node, where the first message includes information related to a security context of layer 1 / layer 2 triggered mobility LTM of a user equipment UE;
[0033] receiving a second message sent by the second node, where the second message includes a security parameter determined based on the first message;
[0034] According to the second message, a third message is sent to the UE; the third message includes a security parameter; and the security parameter is used to protect communication between the UE and the second node.
[0035] Based on the above solution, the first node will send the relevant information of the UE's security context to the second node in advance. Compared with transmitting the relevant information of the security context during the switching process, the delay caused by transmitting the security context during the switching process can be reduced.
[0036] In some embodiments of the first aspect, the first node is the initial base station of the UE's LTM, and the second node is a candidate base station for the UE's LTM; the first message includes the UE's first capability information and at least one of the first user plane UP security policies; the UE's first capability information is used by at least one second node to determine a first security algorithm supported by the UE; the first UP security policy is used to protect the UE's currently activated first session.
[0037] Based on the above solution, when the initial base station configures the candidate node of LTM, it informs the candidate node of the first capability information of the UE and the first UP security policy, thereby achieving early negotiation of the first security algorithm and early communication of the first UP security policy.
[0038] In some embodiments of the first aspect, the second message includes first information of the mth second node; the first information is used to indicate a first security algorithm and a first UP security activation status; the first security algorithm is selected by the mth second node based on the first capability information; the first UP security activation status is determined by the mth second node based on the first UP security policy; m is a positive integer less than or equal to M; M is the total number of second nodes.
[0039] Based on the above solution, the first node receives the second message sent by the mth second node, thereby configuring the candidate node for the UE and assisting the candidate node and the UE in achieving negotiation of a security algorithm therebetween.
[0040] In some embodiments of the first aspect, the third message includes first information; the first information is used by the UE to determine a security parameter for communicating with the second node.
[0041] By sending the third message, the first node configures the candidate node for the UE and assists the candidate node and the UE in achieving negotiation of a security algorithm between the two.
[0042] In some embodiments of the first aspect, the first node is a serving base station of the UE, and the second node is a candidate base station or an initial base station for the UE to perform LTM handover.
[0043] In some embodiments of the first aspect, the first node is a source base station for the UE to perform LTM handover, and the second node is a target base station for the UE to perform LTM handover.
[0044] In some embodiments of the first aspect, sending a first message to a second node includes: obtaining a second user plane UP security policy for a second session of the UE, sending a first message to the second node, the first message including the second UP security policy for the second session; the second UP security policy is used by the second node to determine an activation method for protecting the second session, and the second session is a newly created activation session of the UE.
[0045] In some embodiments of the first aspect, the second message includes second information of the mth second node; the second information of the mth node is used to indicate a second UP security activation state determined by the mth second node, and the second UP security activation state is determined according to a second UP security policy.
[0046] Based on the above solution, by sending the second message, the first node will pre-set the second UP security state of the second session, so that the second session can be quickly carried out when the second session is transferred to the second node, thereby reducing the delay in establishing and starting the second session at the second node.
[0047] In some embodiments of the first aspect, the third message includes second information; the second information is at least used by the UE to determine a security parameter for the second session with the second node.
[0048] Based on the above solution, by sending the third message, the UE will obtain the second information in advance. In this way, when the second session is transferred to the second node, the delay of the second session based on the second node caused by the UE preparation work can be reduced.
[0049] Based on the above method, when the second UP security policy of the second session is obtained, the first message is sent to the second node. In this way, when a new UE session is obtained, the first message is sent to the second node to synchronize the second UP security policy of the second session to the second node within the first time.
[0050] In some embodiments of the first aspect, sending the first message to the second node includes at least one of the following: sending the second UP security policy to the second node after obtaining the second UP security policy of the second session and successfully activating the second session; sending the second UP security policy to the second node before deciding to switch the UE to the second node.
[0051] The above solution defines the second UP security policy for the second session and sends the second UP security policy to the second node if the second session has been successfully activated.
[0052] In some embodiments of the first aspect, sending the UP security policy to the second node includes: sending a handover request to the second node, where the handover request includes the second UP security policy.
[0053] Based on the above solution, the second UP security policy is sent through the handover request instead of using a dedicated message, which has strong compatibility with related technologies.
[0054] A second aspect provides a security parameter processing method, wherein the method is performed by a second node and includes:
[0055] receiving a first message sent by a first node, where the first message includes information related to a security context of layer 1 / layer 2 triggered mobility LTM of a user equipment UE;
[0056] A second message is sent to the second node, the second message including a security parameter determined based on the first message; the security parameter is used by the first node to send a third message to the UE, the third message including the security parameter; the security parameter is used to protect communication between the UE and the second node.
[0057] In some embodiments of the second aspect, the first node is the initial base station of the UE's LTM, the second node is a candidate node for the UE to perform LTM switching, the first message includes the UE's first capability information and at least one of the first user plane UP security policies; the UE's first capability information is used by at least one second node to determine a first security algorithm supported by the UE; the first UP security policy is used by the second node to determine an activation method for protecting a first session, and the first session is the UE's currently activated session.
[0058] In some embodiments of the second aspect, the method further comprises:
[0059] Selecting a first security algorithm for communicating with the UE based on the first capability information of the UE; determining a first UP security activation state for communicating with the UE based on the first UP security policy;
[0060] The second message includes first information; the first information is used to determine at least one of a first security algorithm selected by the second node and a first UP security activation state.
[0061] In some embodiments of the second aspect, the first node is a serving base station of the UE or a source base station of an LTM handover, and the first message includes a second UP security policy for a second session of the UE.
[0062] In some embodiments of the second aspect, the second message includes second information; the second information is used to indicate a second UP security activation state, and the second UP security activation state is determined according to a second UP security policy.
[0063] In some embodiments of the second aspect, the method also includes: receiving second capability information sent by a third node, where the third node is a core network node; when the second capability information and the first capability information are different, selecting a second security algorithm based on the second capability information; and sending a fourth message to the UE based on the second security algorithm, the fourth message being used by the UE to determine the second security algorithm.
[0064] Based on the above scheme, when the second capability information stored by the core network device for the UE is different from the first capability information, the second security algorithm is preferentially selected based on the second capability information, and in order to be consistent with the UE, a fourth message is sent to the UE to realize re-negotiation of the security algorithm between the UE and the second node.
[0065] In some embodiments of the second aspect, the method further comprises:
[0066] receiving a third UP security policy sent by a fourth node, where the fourth node is a core network node;
[0067] receiving a third UP security policy sent by a fourth node, where the fourth node is a core network node;
[0068] In the case where the third UP security policy is different from the first UP security policy, determining the third UP security activation state according to the third UP security policy;
[0069] According to the third UP security activation state, a fifth message is sent to the UE, where the fifth message is used by the UE to determine the third UP security activation state.
[0070] Based on the above scheme, when the third UP security policy determined by the core network device for the UE is different from the first UP security policy, the third UP security activation state is selected according to the third UP security policy, and in order to be consistent with the UE, the fifth message is sent to the UE to realize the re-negotiation of the UP security activation state between the UE and the second node.
[0071] In some embodiments of the second aspect, the method further comprises:
[0072] receiving a fourth UP security policy associated with the second session and sent by a fourth node, where the fourth node is a core network node;
[0073] In a case where the fourth UP security policy is different from the second UP security policy, determining a fourth UP security activation state according to the fourth UP security policy; the second UP security policy is received by the second node from the first node;
[0074] According to the fourth UP security activation state, a sixth message is sent to the UE, where the sixth message is used by the UE to determine the fourth UP security activation state.
[0075] Based on the above scheme, when the fourth UP security policy determined by the core network device for the UE is different from the second UP security policy, the fourth UP security activation state is selected according to the fourth UP security policy, and in order to be consistent with the UE, a sixth message is sent to the UE to realize re-negotiation of the UP security activation state between the UE and the second node.
[0076] A third aspect provides a security parameter processing method, which is performed by a user equipment (UE). The method includes:
[0077] Receive a third message sent by the first node; the third message is used by the UE to determine security parameters for communicating with the second node.
[0078] In some embodiments of the third aspect, the third message includes first information of M second nodes; the first information of the mth second node is used to indicate at least one of the first security algorithm and the first user plane UP security activation status; the first security algorithm is a first security algorithm selected by the mth second node based on the first capability information of the UE; the first UP security activation status is determined by the mth second node according to the first UP security policy; m is a positive integer less than or equal to M.
[0079] In some embodiments of the third aspect, the third message includes second information of M second nodes; the second information of the mth node is used to indicate the second UP security activation status determined by the mth second node, and the second UP security activation status is determined according to the second UP security policy; m is a positive integer less than or equal to M.
[0080] In some embodiments of the third aspect, the method further includes: receiving a fourth message sent by the mth second node, where the fourth message is used by the UE to determine the second security algorithm.
[0081] In some embodiments of the third aspect, the method further includes: receiving a fifth message sent by the mth second node, the fifth message being used by the UE to determine a third UP security activation state; the third UP security activation state is the UP security activation state of the first session.
[0082] In some embodiments of the third aspect, the method further comprises:
[0083] A sixth message sent by the mth second node is received, where the sixth message is used by the UE to determine a fourth UP security activation state, where the fourth UP security activation state is the UP security activation state of the second session.
[0084] A fourth aspect provides a first node, wherein the first node includes:
[0085] a sending module configured to send a first message to the second node, where the first message includes information related to a security context of layer 1 / layer 2 triggered mobility LTM of a user equipment UE;
[0086] a receiving module configured to receive a second message sent by a second node, where the second message includes a security parameter determined based on the first message;
[0087] The sending module is configured to send a third message to the UE according to the second message; the third message includes a security parameter; the security parameter is used to protect the communication between the UE and the second node.
[0088] A fifth aspect provides a second node, wherein the second node includes:
[0089] a receiving module configured to receive a first message sent by a first node, where the first message includes information related to a security context of layer 1 / layer 2 triggered mobility LTM of a user equipment UE;
[0090] The sending module is configured to send a second message to the second node, the second message including a security parameter determined based on the first message; the security parameter is used by the first node to send a third message to the UE, the third message including the security parameter; the security parameter is used to protect communication between the UE and the second node.
[0091] A sixth aspect provides a user equipment UE, wherein the UE includes: a receiving module configured to receive a third message sent by a first node; the third message includes a security parameter; and the security parameter is used to protect communication between the UE and the second node.
[0092] A seventh aspect provides a communication device, wherein the communication device includes: one or more processors;
[0093] The processor is used to call instructions to enable the communication device to execute the method of any one of the technical solutions provided in the first aspect, the second aspect and / or the third aspect.
[0094] An eighth aspect provides a communication system, wherein the communication system includes: a first node, a second node, and a user equipment UE;
[0095] The first node is configured as the method of any technical solution of the first aspect;
[0096] The second node is configured as the method of any technical solution of the second aspect;
[0097] The UE is configured to execute the method of any technical solution of the third aspect.
[0098] In the ninth aspect, an embodiment of the present disclosure provides a program product, wherein the program product includes a computer program, and when the computer program is executed by a communication device, the communication device is enabled to implement the security parameter processing method described in the optional implementation methods of the first to third aspects.
[0099] In a tenth aspect, an embodiment of the present disclosure provides a computer program, which, when executed on a computer, enables the computer to execute the security parameter processing method described in the optional implementation of the first to third aspects.
[0100] It is understandable that the first node, the second node, the UE, the network device, the communication system, the program product, and the computer program are all used to perform the method provided by the embodiment of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method and will not be repeated here.
[0101] The embodiments of the present disclosure propose a security parameter processing method, communication equipment, communication system and storage medium. The embodiments of the present disclosure are not exhaustive, but are only illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, the method after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0102] In each embodiment of the present disclosure, unless otherwise specified or provided for by logic, the terms and / or descriptions between the embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form a new embodiment based on their inherent logical relationships.
[0103] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.
[0104] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "the", "the", etc., can mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article can be understood as a singular expression or a plural expression.
[0105] In the embodiments of the present disclosure, “plurality” refers to two or more.
[0106] In some embodiments, the terms "at least one", "one or more", "a plurality of", "multiple" and the like can be used interchangeably.
[0107] In some embodiments, descriptions such as "at least one of A and B," "A and / or B," "in one case A, in another case B," or "in one case A, in another case B" may include the following technical descriptions depending on the circumstances: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); and in some embodiments, A and B (both A and B are executed). The same applies when there are more branches, such as A, B, and C.
[0108] In some embodiments, "A or B" and other descriptions may include the following technical approaches, depending on the circumstances: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The above is also applicable when there are more branches such as A, B, and C.
[0109] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different. For another example, if the description object is "information", then the "first category of information" and the "second category of information" can be the same information or different information, and their contents can be the same or different.
[0110] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0111] In some embodiments, terms such as "...", "determine...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.
[0112] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.
[0113] In some embodiments, devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as "device", "equipment", "device (equipment)", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", and "subject" can be used interchangeably.
[0114] In some embodiments, "network" can be interpreted as including network-side devices or network functions such as access network devices and core network devices.
[0115] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station (radio base station)", "fixed station (fixed station)", "node (node)", "access point (access point)", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)" "panel (panel)", "antenna panel (antenna panel)", "antenna array (antenna array)" "node (cell)", "macro node (macro cell)", "small cell (small cell)", "femto cell (femto cell)" "pico cell (pico cell)" "sector (sector)" "node group (cell group)" "serving node" "carrier (node)", "component carrier (component carrier)" and "bandwidth part (BWP)" can be used interchangeably.
[0116] In some embodiments, the terms "UE (terminal)", "UE device (terminal device)", "user equipment (UE)", "user terminal" "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile UE, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc. can be used interchangeably.
[0117] In some embodiments, the access network device, the core network device, or the network device can be replaced by a UE. For example, the various embodiments of the present disclosure can also be applied to a structure in which the communication between the access network device, the core network device, or the network device and the UE is replaced by communication between multiple UEs (for example, device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, it can also be set as a structure in which the UE has all or part of the functions of the access network device. In addition, terms such as "uplink" and "downlink" can also be replaced by terms corresponding to communication between UEs (for example, "side"). For example, uplink channels, downlink channels, etc. can be replaced by side channels, and uplinks, downlinks, etc. can be replaced by side links.
[0118] In some embodiments, the UE may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, the core network device, or the network device may have a structure that has all or part of the functions of the UE.
[0119] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.
[0120] In some embodiments, data, information, etc. may be obtained with the user's consent.
[0121] In addition, each element, each row, or each column in the table of the embodiment of the present disclosure can be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns can also be implemented as an independent embodiment.
[0122] Figure 1A It is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.
[0123] like Figure 1A As shown, the communication system 100 includes a terminal 101 and a network device 102. The network device 102 may include an access network device and / or a core network device. The terminal is also called a UE.
[0124] In some embodiments, the terminal 101 includes, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) UE device, an augmented reality (AR) UE device, a wireless UE device in industrial control, a wireless UE device in self-driving, a wireless UE device in remote medical surgery, a wireless UE device in a smart grid, a wireless UE device in transportation safety, a wireless UE device in a smart city, and at least one of a wireless UE device in a smart home, but is not limited thereto.
[0125] In some embodiments, UE is also referred to as User Equipment (UE).
[0126] In some embodiments, the access network device may be, for example, a node or device that accesses the UE to a wireless network. The access network device may include an evolved NodeB (eNB), a next generation evolved NodeB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a Wi-Fi system, but is not limited thereto.
[0127] In some embodiments, the technical approach of the present disclosure may be applicable to the Open RAN architecture. In this case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure may become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces may be implemented through software or programs.
[0128] In some embodiments, the access network device can be composed of a centralized unit (CU) and a distributed unit (DU), where the CU can also be called a control unit. The CU-DU structure can be used to split the protocol layer of the access network device, with the functions of some protocol layers centrally controlled by the CU, and the functions of the remaining part or all of the protocol layers distributed in the DU, which is centrally controlled by the CU, but is not limited to this.
[0129] In some embodiments, the core network device may be a single device including a first network element, or may be a plurality of devices or a group of devices, each including a first network element. The network element may be virtual or physical. The core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).
[0130] It can be understood that the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical approach of the embodiment of the present disclosure, and does not constitute a limitation on the technical approach provided by the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical approach provided by the embodiment of the present disclosure is also applicable to similar technical problems.
[0131] The following embodiments of the present disclosure can be applied to Figure 1A The communication system 100, or a portion thereof, is shown but is not limited thereto. Figure 1A The various entities shown are examples, and the communication system may include Figure 1A All or part of the subject, and may also include Figure 1A For other entities other than the above, the number and form of each entity are arbitrary, and the connection relationship between each entity is an example. The entities may be connected or not connected, and the connection may be in any way, which may be direct or indirect, and may be wired or wireless.
[0132] The embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), future radio access (FRA), new radio access technology (RAT), new radio (NR), new radio access (NX), future generation radio access (FX), Global System for Mobile Communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other resource configuration methods, and next-generation systems based on and extending these systems. Furthermore, multiple systems can be combined (for example, LTE and NR can be combined).
[0133] LTM supports intra-frequency and inter-frequency mobility, including migration to inter-frequency units other than the current cell. In some technologies, only intra-DU LTM and intra-DU LTM are supported. In other embodiments, NR mobility enhancements are extended to inter-CU LTM, specifically including but not limited to at least one of the following scenarios:
[0134] Example 1: When DU is not configured, CU acts as MN;
[0135] Example 2: When NR-DC is configured, CU acts as SN and MCG remains unchanged;
[0136] Example 3: When NR-DC is configured, the CU acts as the MN, and the SCG remains unchanged or the SCG is released.
[0137] The change of primary cell or primary / secondary cell may be accompanied by a change of the Master Cell Group (MCG) or Secondary Cell Group (SCG). In LTM, the next-generation NodeB (gNB) receives L1 measurement reports from the user equipment (UE). Based on these reports, the gNB changes the UE's serving cell via a cell switch command issued by the MAC CE. The cell switch command indicates the LTM candidate cell configuration that the gNB has previously provided to the UE via Radio Resource Control (RRC) signaling. The UE accesses the target cell indicated in the cell switch command based on the received cell switch command. LTM can be used to reduce mobility delay. LTM candidate cell configurations can only be added, modified, and released by the network through RRC signaling. LTM supports subsequent LTM, where subsequent LTM refers to LTM performed on candidate cells without requiring RRC reconfiguration between the network equipment and the UE. That is, after performing a mobility operation, the UE will not autonomously delete the LTM configuration information. The LTM configuration information can continue to be used to trigger subsequent LTM (Subsequent LTM) even if no RRC reconfiguration or update is performed. For example, the LTM configuration information may include information about candidate cells.
[0138] LTM supports intra-frequency or inter-frequency cell changes. In some scenarios, only distributed unit (DU) intra-LTM and DU intra-LTM are supported. In some scenarios, New Radio (NR) mobility enhancements are extended to inter-CU, inter-node, or inter-gNB LTM. Exemplarily, inter-CU, inter-node, or inter-gNB LTM supports the following scenarios:
[0139] Example 1: When no data center is configured, the CU acts as the MN.
[0140] Example 2: Configuring NR-DC, with the CU acting as the SN and the MCG unchanged;
[0141] Example 3: When NR-DC is configured, the CU acts as a mobile node and the SCG remains unchanged or is released. For inter-CU LTM, multiple candidate gNB-CUs will participate in the migration flow.
[0142] The LTM signaling process can be as follows Figure 1B As shown, it includes the following three stages:
[0143] Phase 1: In Phase 1, also known as the LTM preparation phase, the initiating gNB determines candidate cells based on L3 RRC measurement reports and initiates cross-node interaction for LTM preparation across CUs. Following this interaction, the initiating gNB provides the UE with the LTM configuration based on the RRC configuration of the candidate cells.
[0144] The initiating gNB decides on candidate cells and initiates inter-node interaction for inter-CU LTM preparation. After interaction, the initiating gNB provides the UE with an LTM configuration with RRC configurations for multiple candidate cells.
[0145] Phase 2: Phase 2 is also known as the LTM initialization phase. During this phase, the UE sends an L1 measurement report to the initial gNB. Upon receiving the cell switch command (MAC CE), the UE switches to a candidate cell. To support RACH-less LTM, the UE can synchronize with the candidate cell in advance. Specifically, the UE performs DL and UL synchronization with the candidate cell before receiving the cell switch command.
[0146] Phase 3: Subsequent LTM phase. In the Subsequent LTM phase, steps similar to steps 8 to 14 are performed. Subsequent LTM is triggered by the current serving gNB, which is also one of the candidate gNBs for the candidate LTM.
[0147] The key update synchronization between UE and gNB during handover in non-LTM scenario can be as follows: During handover in inter-CU mobility procedure, the synchronization of AS security keys between UE and target gNB is achieved by using the NCC value used by the source gNB and then forwarded to the target gNB and UE in RRC reconfiguration signaling. When the initial AS security context needs to be established between UE and gNB, AMF and UE will derive K gNB and Next Hop, NH) parameter (NCC (NH chain Counter) and each K gNB Associated with NH parameters. Each K gNB Both are associated with NCC, which corresponds to the NH value.
[0148] In Xn handover, if the source gNB has an unused {NH, NCC} pair, vertical key derivation shall be performed. The source gNB shall first derivate the key from the currently activated K gNB (if horizontal key derivation) or calculate K from NH (if vertical key derivation) NG-RAN* Then, the source gNB will NG-RAN* , NCC} is forwarded to the target gNB. The target gNB shall directly receive the K NG-RAN* As K used with UE gNB The target gNB shall compare the NCC value received from the source gNB with the K gNB The target gNB includes the received NCC in a prepared Handover (HO) command message. The HO command message is sent to the source gNB in a transparent container, which is then forwarded to the UE.
[0149] The UE behavior is the same whether performing intra-gNB-CU handover, Xn handover or N2 handover, except that when performing intra-gNB-CU handover, the UE may retain the same key according to the instruction of the gNB. The UE behavior is also the same in the case of conditional handover, for example, the UE shall use the key in K NG-RAN* Parameters of the selected target cell are derived. Figure 1C This is a schematic diagram of key level derivation.
[0150] If the NCC value in the HO Command message received by the UE from the target gNB via the source gNB is equal to the currently activated K gNB The associated NCC value, the UE will start from the currently activated K gNB K is derived from the target PCI and its frequency (ARFCN-DL or EARFCN-DL) NG-RAN* .
[0151] If the NCC value received by the UE differs from the NCC value associated with the currently activated gNB, the UE shall first synchronize the locally stored NH parameters by calculating iteratively and incrementing the NCC value until it matches the NCC value received from the source gNB via the HO Command message. When the NCC values match, the UE calculates K using the K value from the synchronized NH parameters and the target Physical Cell Identity (PCI) and its Absolute Radio-Frequency Channel Number Downlink (ARFCN-DL) or the (Universal Mobile Telecommunications System, UMTS) Terrestrial Radio Access Network, E-UTRAN Absolute Radio Frequency Channel Number Downlink (EARFCN-DL). NG-RAN* .
[0152] When the UE communicates with the target gNB, it shall use K NG-RAN* As K gNB .
[0153] In the current inter-gNB handover process, security-related configurations (such as NCC, K NG-RAN* ) is first synchronized between the source and target gNBs and then sent by the source gNB to the UE during RRC reconfiguration for each handover. The NCC is used for key synchronization between the UE and the target gNB as described above. However, with the mobility enhancement process designed for inter-gNB LTM, the source gNB no longer sends an RRC reconfiguration during each handover. Therefore, how to update the NCC value and send it to the UE for key synchronization during each handover becomes an open problem. In addition to key synchronization based on the NCC value, other security-related configurations require negotiation between the UE and candidate gNBs regarding the AS security algorithm to be applied, and the UP security policy to be applied to PDU sessions established by the connected UE. The parameters required for AS key refresh, the AS security algorithm, and the UP security policy are all part of the AS security context in the UE and gNB and need to be synchronized during the handover process. Therefore, it is necessary to study how the UE and candidate gNBs negotiate the AS security algorithm and how to correctly apply the UP security policy to PDU sessions during LTM handovers between candidate gNBs.
[0154] The present disclosure provides a method for processing security parameters. Figure 1A The communication system shown is executed. Figure 2AAs shown, the method may include:
[0155] S2101: A first node sends a first message to at least one second node.
[0156] In some embodiments, both the first node and the second node may be access network nodes.
[0157] In some embodiments, the first node may be an initial base station for LTM handover of the UE. The second node may be a candidate base station for LTM handover of the UE.
[0158] In some embodiments, the first node may be a current serving base station of the UE, and the second node may be a base station that subsequently provides service to the UE.
[0159] In some embodiments, the first node sends a first message to the at least one second node during an LTM preparation phase.
[0160] In some embodiments, the first node may send the first message to the at least one second node via an X2 interface, an Xn interface, or a backhaul link.
[0161] In some embodiments, the first message includes information related to a security context of layer 1 / layer 2 triggered mobility LTM of the user equipment UE.
[0162] In some embodiments, the first message may include information related to the security context of the UE's LTM and / or security capabilities of the UE.
[0163] In some embodiments, the first message includes at least one of the following:
[0164] UE identity, used to identify the UE;
[0165] The first capability information of the UE is used to indicate at least the security capability of the UE;
[0166] The first UP security policy is used to protect the first session currently activated by the UE.
[0167] In some embodiments, the UE identifier may be various types of UE identifiers. For example, the UE identifier may be, but is not limited to, at least one of the following:
[0168] Cell Radio Network Temporary Identifier (C-RNTI);
[0169] International Mobile Equipment Identity (IMEI);
[0170] International Mobile Subscriber Identity (IMSI);
[0171] Globally Unique Temporary Identifier (GPSI).
[0172] Temporary Mobile Subscriber Identity (TMSI).
[0173] In some embodiments, the first capability information of the UE may include a first security algorithm supported by the UE or an identifier of the first security algorithm.
[0174] In some embodiments, the first UP security policy may be used to indicate whether the UP of the first session requires integrity protection and / or confidentiality protection.
[0175] In some embodiments, the first capability information of the UE is used by at least one second node to determine a first security algorithm supported by the UE.
[0176] In some other embodiments, the first UP security policy is used to protect the first session currently activated by the UE.
[0177] In some embodiments, the first message may be a handover request sent to one or more second nodes during the LTM candidate preparation phase. The handover request directly carries the UE identifier and the UE's first capability information. In some embodiments, the handover request also carries the first UP security policy of one or more currently active first sessions between the UE and the first node.
[0178] In some embodiments, the first message includes: a session identifier of each first session and a first UP security policy corresponding to the first session.
[0179] In some embodiments, the first message may be a handover request message, which is used as the first message, but does not mean that the UE needs to be handed over to the second node at this time.
[0180] S2102: The second node selects a first security algorithm and / or determines a first UP security activation state.
[0181] In some embodiments, the second node selects a first security algorithm supported by both the UE and the second node according to the first capability information of the UE provided by the first node.
[0182] Exemplarily, the second node may select a first security algorithm for integrity protection supported by both the UE and the second node based on the first capability information of the first node. Also exemplarily, the second node may select a first security algorithm for confidentiality protection supported by both the UE and the second node based on the capability information of the first node.
[0183] In some embodiments, the first UP security activation state is determined by the second node according to the first UP security policy.
[0184] In some embodiments, the first UP security activation state may be used to determine whether and / or how to protect the communication between the UE and the second node.
[0185] For example, the first UP security activation state may include but is not limited to at least one of the following:
[0186] The first state, in the first state, no protection is required;
[0187] A second state, in which integrity protection and confidentiality protection are not required;
[0188] The third state, in the third state, integrity protection is required but confidentiality protection is not required;
[0189] The fourth state, in the fourth state, confidentiality protection is required but integrity protection is not required;
[0190] The fifth state: In the fifth state, confidentiality protection and integrity protection are required.
[0191] S2103: The second node sends a second message to the first node.
[0192] In some embodiments, the second message includes security parameters determined by the second node based on the first message. Exemplarily, the second message includes the first information. The first information of the mth second node indicates a first security algorithm and a first UP security activation status; the first security algorithm is selected by the mth second node based on the first capability information; the first UP security activation status is determined by the mth second node based on the first UP security policy. Exemplarily, the first information may be the first security algorithm selected by the mth second node or the algorithm identifier of the first security algorithm selected by the mth second node.
[0193] It is worth noting that the security parameters included in the second message are not limited to the security parameters determined based on the first message.
[0194] In some embodiments, the second message from the mth second node may include at least one of the following:
[0195] The node identifier of the mth second node;
[0196] Node configuration of the mth second node;
[0197] The first security algorithm selected by the mth second node;
[0198] The algorithm identifier of the first security algorithm selected by the m-th second node;
[0199] The third indication information is used to indicate the first UP security activation state.
[0200] In some embodiments, if the first message is a handover request message, the second message may be a handover request confirmation message. Although the first node and the second node exchange handover request messages and handover request confirmation messages, it does not mean that the UE needs to perform handover.
[0201] S2104: The first node sends a third message to the UE.
[0202] In some embodiments, the third message may include security parameters determined by the second node based on the first message. The security parameters may be used to protect communications between the UE and the second node. For example, the third message includes the first information. In some embodiments, the third message includes node configurations of each second node, and the first information is part of the node configurations of the second nodes.
[0203] In some embodiments, the first node encapsulates the second messages of the respective second nodes in a third message using an RRC container and sends the third message to the UE.
[0204] In some embodiments, the third message may be an RRC configuration message. In one example, the RRC configuration message may be an RRC reconfiguration message.
[0205] In some embodiments, the third message may further include a first parameter. In some embodiments, the first parameter is used by the UE to generate a security key for communicating with the first node.
[0206] In some embodiments, the first information may include, but is not limited to, at least one of the following: the first security algorithm selected by the second node, an algorithm identifier of the first security algorithm, and a third parameter. For example, the third parameter may be a next hop chaining counter (NCC) value. The NCC value may be used by the UE to determine parameters of a security key for communicating with the first node.
[0207] In some embodiments, the first information includes at least some security parameters related to the first session. For example, the first information may include parameters required for the second node to generate a security key when participating in the second session. However, in this case, the first information is not limited to being used for the first session between the UE and the second node, and may also be used for other control plane signaling exchanges and / or user plane data communications outside the first session.
[0208] S2105: The third node sends the second capability information to the second node.
[0209] In some embodiments, the third node may be a core network node. For example, the third node may be a Mobile Management Entity (MME) or an Access Management Function (AMF).
[0210] The second capability information is used to indicate the capabilities of the UE. Exemplarily, the second capability information is used to indicate at least the security capabilities of the UE. Further exemplarily, the second capability information is used to indicate at least the security algorithms supported by the UE.
[0211] Correspondingly, the second node will receive the second capability information.
[0212] In some cases, if the UE performs inter-AMF cell handover or cell reselection, the AMF will send the second capability information to the second node, such as the target node of the cell handover or reselection. In other cases, a third node successfully obtains the UE's second capability information and sends the second capability information to the second node. There are many scenarios in which a third node sends the second capability information to a second node, and the specific implementation is not limited to this example.
[0213] S2106: The second node sends a fourth message to the UE.
[0214] In some embodiments, the second capability information is different from the first capability information, and the second node sends a fourth message to the UE. Exemplarily, the second capability information and the first capability information indicate that the security algorithms supported by the UE are different, and the second node sends the fourth message to the UE. Alternatively, the second capability information and the first capability information indicate that the security algorithms supported by the UE are different and the first security algorithm is not a security algorithm supported by the UE as indicated by the second capability information, and the second node sends the fourth message to the UE. Alternatively, the second capability information indicates that the UE does not support the first security algorithm, and the second node sends the fourth message to the UE. Alternatively, the second capability information indicates that the UE supports the second security algorithm and the first capability information indicates that the UE does not support the second security algorithm, and the second node sends the fourth message to the UE. It is worth noting that the second security algorithm can be a security algorithm supported by any one of the UEs and the second node selected according to the second capability information, and the performance is not required to be better than the first security algorithm.
[0215] In some embodiments, if the second capability information is the same as the first capability information, or the second security algorithm selected according to the second capability information is the same as the first security algorithm selected according to the first capability information, S2106 is an optional step to save unnecessary signaling overhead.
[0216] In some embodiments, the fourth message may be any message for establishing an RRC connection between the second node and the UE. In some embodiments, the fourth message may be any RRC message sent to the UE after the second node and the UE complete establishing the RRC connection.
[0217] S2107: The fourth node sends the third UP security policy to the second node.
[0218] In some embodiments, the fourth node may be a core network node. Exemplarily, the fourth node may include but is not limited to a Session Management Function (SMF) and / or a Policy Control Function (PCF).
[0219] The third UP security policy is used to determine the UP security activation state during communication between the UE and the second node. For example, the UP security activation state indicated by the third UP security policy may be any of the first to fifth states described above. In some cases, the UP security activation state may also include states corresponding to other security algorithms, such as a scrambling algorithm.
[0220] Correspondingly, the second node will receive the third UP security policy.
[0221] In some embodiments, the fourth node may send the third UP security policy to the second node when performing operations such as UE session update, but the fourth node is not limited to sending the third UP security policy to the second node only when performing session update.
[0222] Exemplarily, the third UP security policy and the first UP security policy are both security policies for the first session.
[0223] S2108: The second node sends a fifth message to the UE.
[0224] In some embodiments, when the third UP security policy is different from the first UP security policy, the second node sends a fifth message to the UE. Exemplarily, when the third UP security policy and the first UP security policy indicate different UP security activation states, the second node sends the fifth message to the UE.
[0225] Exemplarily, the fifth message is used by the UE to determine the third UP security activation state.
[0226] In some embodiments, the fifth message may be any message for establishing an RRC connection between the second node and the UE. In some embodiments, the fifth message may be any RRC message sent to the UE after the second node and the UE complete establishing the RRC connection.
[0227] In some embodiments, the fifth message and the fourth message may be the same message. In other embodiments, the fifth message and the fourth message are different messages.
[0228] In the above embodiment, any of steps S2101 to S2108 can be implemented independently. For example, the first node can send a first message to the second node. After receiving the first message, the second node can temporarily store the first message. When the second node needs to switch to becoming the UE's serving node, the second node does not need to temporarily obtain the first message from the first node. In this case, S2101 can be implemented independently. For example, after receiving the first message, the second node can independently determine the first information, but does not necessarily need to send a second message to the first node to prepare for negotiation of the first security algorithm. Instead, the first node can simply complete the selection of the first security algorithm in advance. In some embodiments, S2101 and S2102 can be implemented in combination. S2101 to S2103 can be implemented in combination, where the second node not only completes the selection of the first security algorithm but also returns the first security algorithm to the first node or notifies the first node via a second message that the second node has completed the selection of the first security algorithm. In other words, the first information is also optional content of the second message. In some embodiments, S2101 to S2104 can be implemented in combination. In this way, when the UE is connected to the initial base station, not only is the acquisition of parameters related to the security context between the UE and the first node completed, but also the security parameters for communication between the UE and the second node are acquired.
[0229] It is worth noting that any one or more of S2105 to S2108 can be optional steps and do not need to be executed. For example, if the third node and / or the fourth node does not send the second capability information and / or the third UP security policy to the second node, then it is obviously not necessary to execute S2105 and S2107. Whether S2106 is executed depends on whether the first capability information and the second capability information are the same, or whether the first security algorithm and the second security algorithm are the same. Whether S2108 is executed depends on whether the first UP security policy and the third UP security policy are the same, or whether the UP security activation status determined according to the first UP security policy and the third UP security policy is the same. Exemplarily, S2101 to S2106 can be combined embodiments. S2101 to S2104, S2107 to S2108 can be implemented in combination. It is worth noting that the execution order of S2101 to S2108 can be as follows Figure 2A As shown, but not limited to Figure 2A For example, S2105 and S2107 can be executed simultaneously, or S2107 can be executed first and then S2105. For another example, S2106 and S2108 do not have a certain order.
[0230] In some embodiments, the term "information" can be interchangeable with terms such as "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", and "data".
[0231] In some embodiments, the terms "acquire," "obtain," "get," "receive," "transmit," "bidirectional transmission," and "send and / or receive" are interchangeable and can be interpreted as meaning receiving from another entity, acquiring from a protocol, acquiring from a higher layer, self-processing, or autonomous implementation. Examples of protocols include at least one of a 3GPP protocol, a Wi-Fi protocol, and an audio and / or video protocol. In some embodiments, the term "send" is interchangeable with terms such as "transmit," "report," and "transmit."
[0232] In some embodiments, steps S2101 to S2104 of this embodiment may be performed independently, or in any combination, in any order, provided they are not in conflict. For example, after the second node receives the first message, the second node is removed from the candidate nodes of the UE. In this case, the second node may not perform S2102, and thus, steps S2103 to S2104 do not occur.
[0233] The present disclosure provides a method for processing security parameters. Figure 1A The communication system shown is executed. Figure 2B As shown, the method may include:
[0234] S2201: A first node sends a first message to at least one second node.
[0235] In some embodiments, both the first node and the second node may be access network nodes.
[0236] In some embodiments, the first node may be an initial base station for LTM handover of the UE. The second node may be a candidate base station for LTM handover of the UE.
[0237] In some embodiments, the first node may be a current serving base station of the UE, and the second node may be a neighboring node of the first node.
[0238] In some embodiments, the first node may be a source base station for the UE to perform LTM handover, and the second node may be a target base station for the UE to perform LTM handover.
[0239] In some embodiments, the first node sends a first message to the at least one second node during an LTM preparation phase.
[0240] In some embodiments, the first node may send the first message to the at least one second node via an X2 interface, an Xn interface, or a backhaul link.
[0241] In some embodiments, the first message includes information related to a security context of layer 1 / layer 2 triggered mobility LTM of the user equipment UE.
[0242] In some embodiments, the first message includes at least one of the following:
[0243] UE identifier, used to identify the UE; the identification information of the UE can refer to any of the aforementioned embodiments, and specific examples are not given here;
[0244] The second UP security policy is used to protect the second session currently activated by the UE;
[0245] The session identifier of the second session.
[0246] In some embodiments, the second session may be any session currently activated by the UE. There may be one or more second sessions. The second UP security policies of different second sessions may be the same or different.
[0247] In some embodiments, the first node obtains the second user plane UP security policy of the second session of the UE and sends a first message to the second node, where the first message includes the second UP security policy of the second session; the second UP security policy is used to protect the second session currently activated by the UE.
[0248] Exemplarily, the first node requests the second UP security policy for the second session from the core network node and sends the first message to the second node. Further, after obtaining the second UP security policy for the second session and successfully activating the second session, the second UP security policy is sent to the second node.
[0249] In another exemplary embodiment, the first node determines a second node to hand over the UE to based on the UE's layer 3 measurement report, and before handing over the UE to the second node, sends a first message to the second node. Furthermore, in a preparatory stage for the UE to hand over to the second node, the first node sends a second UP security policy to the second node.
[0250] In some embodiments, the second UP security policy is used to protect a second session currently activated by the UE. Exemplarily, the second session may be a new session created by the UE. Exemplarily, the second session is different from the first session.
[0251] In some embodiments, if the first node is the initial base station of the UE, the first node may further send the second UP security policy to the second node during the process of configuring candidate base stations for the LTM of the UE.
[0252] In some embodiments, the first message is a handover request message.
[0253] S2202: The second node stores the second UP security policy.
[0254] In some embodiments, the second UP security policy is used by the second node to determine an activation method for protecting a second session, where the second session is a newly created activation session of the UE.
[0255] In some embodiments, after the second node stores the second UP security policy, the UE switches to the second node. The second node can directly protect the UE's second session based on the locally stored second UP security policy. In this way, the second node does not need to request the second UP security policy from the core network or temporarily request the second UP security policy from the first node.
[0256] In some embodiments, the second node may determine a second UP security activation state according to the second UP security policy. The optional states of the second UP security activation state may be the same as those of the first UP security activation state, for example, both may be any one of the first state value and the fifth state.
[0257] S2203: The second node sends a second message.
[0258] In some embodiments, the second message includes security parameters determined by the second node based on the first message. Exemplarily, the second message includes second information. However, it is worth noting that the content of the second message is not limited to the security parameters determined by the second node based on the first message.
[0259] In some embodiments, if the first message is a handover request message, the second message may be a handover request confirmation message.
[0260] In some embodiments, sending the second message may be an optional step. For example, if the first message is a notification message, the second node does not need to respond to the first node.
[0261] In some embodiments, the second message includes second information of the mth second node; the second information of the mth node is used to indicate a second UP security activation state determined by the mth second node, and the second UP security activation state is determined according to a second UP security policy.
[0262] In some embodiments, the second message may be used to indicate a second UP security activation state selected by the second node.
[0263] Correspondingly, the first node will receive the second message sent by the second node.
[0264] S2204: The first node sends a third message to the UE.
[0265] In some embodiments, the third message includes security parameters determined by the second node based on the first message. The security parameters may be used to protect communications between the UE and the second node. Exemplarily, the third message includes second information; the second information is used at least by the UE to determine security parameters for a second session with the second node. Exemplarily, the security parameters may include parameters for generating a key, etc.
[0266] It is worth noting that this step is an optional step, and the second UP security activation state can also be sent to the UE during the process of establishing an RRC connection between the second node and the UE.
[0267] S2205: The third node sends the second capability information to the second node.
[0268] In some embodiments, the third node may be a core network node. For example, the third node may be a Mobile Management Entity (MME) or an Access Management Function (AMF).
[0269] The second capability information is used to indicate the capabilities of the UE. Exemplarily, the second capability information is used to indicate at least the security capabilities of the UE. Further exemplarily, the second capability information is used to indicate at least the security algorithms supported by the UE.
[0270] Correspondingly, the second node will receive the second capability information.
[0271] In some cases, if the UE performs inter-AMF cell handover or cell reselection, the AMF will send the second capability information to the second node, such as the target node of the cell handover or reselection. In other cases, a third node successfully obtains the UE's second capability information and sends the second capability information to the second node. There are many scenarios in which a third node sends the second capability information to a second node, and the specific implementation is not limited to this example.
[0272] S2206: The second node sends a fourth message to the UE.
[0273] In some embodiments, the second capability information is different from the first capability information, and the second node sends a fourth message to the UE. Exemplarily, the second capability information and the first capability information indicate that the security algorithms supported by the UE are different, and the second node sends the fourth message to the UE. Alternatively, the second capability information and the first capability information indicate that the security algorithms supported by the UE are different and the first security algorithm is not a security algorithm supported by the UE as indicated by the second capability information, and the second node sends the fourth message to the UE. Alternatively, the second capability information indicates that the UE does not support the first security algorithm, and the second node sends the fourth message to the UE. Alternatively, the second capability information indicates that the UE supports the second security algorithm and the first capability information indicates that the UE does not support the second security algorithm, and the second node sends the fourth message to the UE. It is worth noting that the second security algorithm can be a security algorithm supported by any one of the UEs and the second node selected according to the second capability information, and the performance is not required to be better than the first security algorithm.
[0274] In some embodiments, if the second capability information is the same as the first capability information, or the second security algorithm selected according to the second capability information is the same as the first security algorithm selected according to the first capability information, S2106 is an optional step to save unnecessary signaling overhead.
[0275] In some embodiments, the fourth message may be any message for establishing an RRC connection between the second node and the UE. In some embodiments, the fourth message may be any RRC message sent to the UE after the second node and the UE complete establishing the RRC connection.
[0276] S2207: The fourth node sends the fourth UP security policy to the second node.
[0277] In some embodiments, the fourth node may be a core network node. Exemplarily, the fourth node may include but is not limited to a Session Management Function (SMF) and / or a Policy Control Function (PCF).
[0278] The fourth UP security policy is used to determine the UP security activation state when the UE communicates with the second node. For example, the UP security activation state indicated by the fourth UP security policy may be any one of the first to fifth states described above. In some cases, the UP security activation state may also include states corresponding to other security algorithms, such as a scrambling algorithm.
[0279] Correspondingly, the second node will receive the fourth UP security policy.
[0280] In some embodiments, the fourth node may send the fourth UP security policy to the second node when performing operations such as UE session update, but the fourth node is not limited to sending the fourth UP security policy to the second node only when performing session update.
[0281] Exemplarily, the fourth UP security policy and the second UP security policy are both security policies for the first session.
[0282] The second UP security policy and the fourth UP security policy are associated with the same session, exemplarily, the second session.
[0283] S2208: The second node sends a sixth message to the UE.
[0284] In some embodiments, when the fourth UP security policy is different from the second UP security policy, the second node sends a fifth message to the UE. Exemplarily, when the third UP security policy and the second UP security policy indicate different UP security activation states, the second node sends a sixth message to the UE.
[0285] Exemplarily, the sixth message is used by the UE to determine the third UP security activation state.
[0286] In some embodiments, the sixth message may be any message for establishing an RRC connection between the second node and the UE. In some embodiments, the sixth message may be any RRC message sent to the UE after the second node and the UE complete establishing the RRC connection.
[0287] In some embodiments, the sixth message and the fourth message may be the same message. In other embodiments, the sixth message and the fourth message are different messages.
[0288] In the above embodiment, any of steps S2201 to S2208 can be implemented independently. For example, the first node can send a first message to the second node. After receiving the first message, the second node can temporarily store the first message. When the second node needs to switch to becoming the UE's serving node, the second node does not need to temporarily obtain the first message from the first node. In this case, S2201 can be implemented independently. For example, after receiving the first message, the second node can independently determine the second information, but does not necessarily need to send the second message to the first node to prepare for negotiation of the first security algorithm. Instead, the first node can simply complete the selection of the first security algorithm in advance. In some embodiments, S2201 and S2202 can be implemented in combination. S2201 to S2203 can be implemented in combination, where the second node not only completes the selection of the first security algorithm but also returns the first security algorithm to the first node or notifies the first node via a second message that the second node has completed the selection of the first security algorithm. In other words, the second information is also optional content of the second message. In some embodiments, S2201 to S2204 can be implemented in combination. In this way, when the UE is connected to the initial base station, not only is the acquisition of parameters related to the security context between the UE and the first node completed, but also the security parameters for communication between the UE and the second node are acquired.
[0289] It is worth noting that any one or more of S2205 to S2208 can be optional steps and do not need to be executed. For example, if the third node and / or the fourth node does not send the second capability information and / or the third UP security policy to the second node, it is obviously not necessary to execute S2205 and S2207. Whether S2206 is executed depends on whether the first capability information and the second capability information are the same, or whether the first security algorithm and the second security algorithm are the same. Whether S2208 is executed depends on whether the first UP security policy and the third UP security policy are the same, or whether the UP security activation status determined according to the first UP security policy and the third UP security policy is the same. Exemplarily, S2201 to S2206 can be combined with embodiments. S2201 to S2204, S2207 to S2208 can be implemented in combination.
[0290] It is worth noting that the execution order of S2201 to S2208 can be as follows: Figure 2B As shown, but not limited to Figure 2B For example, S2205 and S2207 can be executed simultaneously, or S2207 can be executed first and then S2205. For another example, S2206 and S2208 do not have a certain order.
[0291] In some embodiments, the term "information" can be interchangeable with terms such as "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", and "data".
[0292] In some embodiments, "obtain", "get", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be interchangeable with each other, which can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining by self-processing, autonomous implementation and other meanings. The protocol includes, for example, at least one of the 3GPP protocol, the Wi-Fi protocol, the audio and / or video protocol. In some embodiments, the term "send" can be interchangeable with terms such as "transmit", "report", and "transmit". In some embodiments, each step S2201 to S2203 of this embodiment can be implemented independently, or can be arbitrarily reversed and implemented in combination under non-contradictory conditions. In some embodiments, S2203 is an optional step. For example, the first node may assume that the second node has received the first message, without the need for the second node to specifically reply to the second message for confirmation.
[0293] It is worth noting that: in the embodiment of the present disclosure, both the first session and the second session belong to the currently activated session of the UE. Figure 2A The corresponding embodiment can be used as Figure 2B A special case of the corresponding embodiment. In some embodiments, Figure 2B The corresponding embodiment can also be used as Figure 2A The subsequent execution process of the corresponding embodiment.
[0294] The present disclosure provides a method for processing security parameters. Figure 1A The communication system shown is executed. Figure 2C As shown, the method may include:
[0295] S2301: A first node sends a first message to at least one second node.
[0296] In some embodiments, both the first node and the second node may be access network nodes.
[0297] In some embodiments, the first node may be an initial base station for LTM handover of the UE. The second node may be a candidate base station for LTM handover of the UE.
[0298] In some embodiments, the first node may be a current serving base station of the UE, and the second node may be a base station that subsequently provides service to the UE.
[0299] In some embodiments, the first node sends a first message to the at least one second node during an LTM preparation phase.
[0300] In some embodiments, the first node may send the first message to the at least one second node via an X2 interface, an Xn interface, or a backhaul link.
[0301] In some embodiments, the first message includes information related to a security context of layer 1 / layer 2 triggered mobility LTM of the user equipment UE.
[0302] In some embodiments, the first message may include information related to the security context of the UE's LTM and / or security capabilities of the UE.
[0303] In some embodiments, the first message includes at least one of the following:
[0304] UE identity, used to identify the UE;
[0305] The first capability information of the UE is used to indicate at least the security capability of the UE;
[0306] The first UP security policy is used to protect the first session currently activated by the UE.
[0307] The first message contains specific content and related descriptions of each content. For the specific message corresponding to the first message, please refer to Figure 2A The corresponding embodiments will not be repeated here.
[0308] S2302: The second node selects a first security algorithm and / or determines a first UP security activation state.
[0309] In some embodiments, the second node selects a first security algorithm supported by both the UE and the second node according to the first capability information of the UE provided by the first node.
[0310] Exemplarily, the second node may select a first security algorithm for integrity protection supported by both the UE and the second node based on the first capability information of the first node. Also exemplarily, the second node may select a first security algorithm for confidentiality protection supported by both the UE and the second node based on the capability information of the first node.
[0311] In some embodiments, the first UP security activation state is determined by the second node according to the first UP security policy.
[0312] In some embodiments, the first UP security activation state may be used to determine whether and / or how to protect the communication between the UE and the second node.
[0313] In some embodiments, the first UP security activation state, the first UP security policy, the second node, and the first capability information can be found in Figure 2A The corresponding embodiments will not be repeated here.
[0314] S2303: The second node sends a second message to the first node.
[0315] In some embodiments, the second message includes security parameters determined by the second node based on the first message. Exemplarily, the second message includes the first information. The first information of the mth second node indicates a first security algorithm and a first UP security activation status; the first security algorithm is selected by the mth second node based on the first capability information; the first UP security activation status is determined by the mth second node based on the first UP security policy. Exemplarily, the first information may be the first security algorithm selected by the mth second node or the algorithm identifier of the first security algorithm selected by the mth second node.
[0316] It is worth noting that the security parameters included in the second message are not limited to the security parameters determined based on the first message.
[0317] In some embodiments, the second message from the mth second node may include at least one of the following:
[0318] The node identifier of the mth second node;
[0319] Node configuration of the mth second node;
[0320] The first security algorithm selected by the mth second node;
[0321] The algorithm identifier of the first security algorithm selected by the m-th second node;
[0322] The third indication information is used to indicate the first UP security activation state.
[0323] In some embodiments, if the first message is a handover request message, the second message may be a handover request confirmation message. Although the first node and the second node exchange handover request messages and handover request confirmation messages, it does not mean that the UE needs to perform handover.
[0324] S2304: The first node sends a third message to the UE.
[0325] In some embodiments, the third message may include security parameters determined by the second node based on the first message. The security parameters may be used to protect communications between the UE and the second node. For example, the third message includes the first information. In some embodiments, the third message includes node configurations of each second node, and the first information is part of the node configurations of the second nodes.
[0326] In some embodiments, the first node encapsulates the second messages of the respective second nodes in a third message using an RRC container and sends the third message to the UE.
[0327] In some embodiments, the third message may be an RRC configuration message. In one example, the RRC configuration message may be an RRC reconfiguration message.
[0328] In some embodiments, the third message may further include a first parameter. In some embodiments, the first parameter is used by the UE to generate a security key for communicating with the first node.
[0329] In some embodiments, the first information may include, but is not limited to, at least one of the following: the first security algorithm selected by the second node, an algorithm identifier of the first security algorithm, and a third parameter. For example, the third parameter may be a next hop chaining counter (NCC) value. The NCC value may be used by the UE to determine parameters of a security key for communicating with the first node.
[0330] In some embodiments, the first information includes at least some security parameters related to the first session. For example, the first information may include parameters required for the second node to generate a security key when participating in the second session. However, in this case, the first information is not limited to being used for the first session between the UE and the second node, and may also be used for other control plane signaling exchanges and / or user plane data communications outside the first session.
[0331] The present disclosure provides a method for processing security parameters. Figure 1A The communication system shown is executed. Figure 2D As shown, the method may include:
[0332] S2401: A first node sends a first message to at least one second node.
[0333] In some embodiments, both the first node and the second node may be access network nodes.
[0334] In some embodiments, the first node may be an initial base station for LTM handover of the UE. The second node may be a candidate base station for LTM handover of the UE.
[0335] In some embodiments, the first node may be a current serving base station of the UE, and the second node may be a neighboring node of the first node.
[0336] In some embodiments, the first node may be a source base station for the UE to perform LTM handover, and the second node may be a target base station for the UE to perform LTM handover.
[0337] In some embodiments, the first node sends a first message to the at least one second node during an LTM preparation phase.
[0338] In some embodiments, the first node may send the first message to the at least one second node via an X2 interface, an Xn interface, or a backhaul link.
[0339] In some embodiments, the first message includes information related to a security context of layer 1 / layer 2 triggered mobility LTM of the user equipment UE.
[0340] In some embodiments, the first message includes at least one of the following:
[0341] UE identifier, used to identify the UE; the identification information of the UE can refer to any of the aforementioned embodiments, and specific examples are not given here;
[0342] The second UP security policy is used to protect the second session currently activated by the UE;
[0343] The session identifier of the second session.
[0344] In some embodiments, the second session may be any session currently activated by the UE. There may be one or more second sessions. The second UP security policies of different second sessions may be the same or different.
[0345] In some embodiments, the first node obtains the second user plane UP security policy of the second session of the UE and sends a first message to the second node, where the first message includes the second UP security policy of the second session; the second UP security policy is used to protect the second session currently activated by the UE.
[0346] Exemplarily, the first node requests the second UP security policy for the second session from the core network node and sends the first message to the second node. Further, after obtaining the second UP security policy for the second session and successfully activating the second session, the second UP security policy is sent to the second node.
[0347] In another exemplary embodiment, the first node determines a second node to hand over the UE to based on the UE's layer 3 measurement report, and before handing over the UE to the second node, sends a first message to the second node. Furthermore, in a preparatory stage for the UE to hand over to the second node, the first node sends a second UP security policy to the second node.
[0348] In some embodiments, the second UP security policy is used to protect a second session currently activated by the UE. Exemplarily, the second session may be a new session created by the UE. Exemplarily, the second session is different from the first session.
[0349] In some embodiments, if the first node is the initial base station of the UE, the first node may further send the second UP security policy to the second node during the process of configuring candidate base stations for the LTM of the UE.
[0350] In some embodiments, the first message is a handover request message.
[0351] S2402: The second node stores the second UP security policy.
[0352] In some embodiments, the second UP security policy is used by the second node to determine an activation method for protecting a second session, where the second session is a newly created activation session of the UE.
[0353] In some embodiments, after the second node stores the second UP security policy, the UE switches to the second node. The second node can directly protect the UE's second session based on the locally stored second UP security policy. In this way, the second node does not need to request the second UP security policy from the core network or temporarily request the second UP security policy from the first node.
[0354] In some embodiments, the second node may determine a second UP security activation state according to the second UP security policy. The optional states of the second UP security activation state may be the same as those of the first UP security activation state, for example, both may be any one of the first state value and the fifth state.
[0355] S2403: The second node sends a second message.
[0356] In some embodiments, the second message includes security parameters determined by the second node based on the first message. Exemplarily, the second message includes second information. However, it is worth noting that the content of the second message is not limited to the security parameters determined by the second node based on the first message.
[0357] In some embodiments, if the first message is a handover request message, the second message may be a handover request confirmation message.
[0358] In some embodiments, sending the second message may be an optional step. For example, if the first message is a notification message, the second node does not need to respond to the first node.
[0359] In some embodiments, the second message includes second information of the mth second node; the second information of the mth node is used to indicate a second UP security activation state determined by the mth second node, and the second UP security activation state is determined according to a second UP security policy.
[0360] In some embodiments, the second message may be used to indicate a second UP security activation state selected by the second node.
[0361] Correspondingly, the first node will receive the second message sent by the second node.
[0362] S2404: The first node sends a third message to the UE.
[0363] In some embodiments, the third message includes security parameters determined by the second node based on the first message. The security parameters may be used to protect communications between the UE and the second node. Exemplarily, the third message includes second information; the second information is used at least by the UE to determine security parameters for a second session with the second node. Exemplarily, the security parameters may include parameters for generating a key, etc.
[0364] It is worth noting that this step is an optional step, and the second UP security activation state can also be sent to the UE during the process of establishing an RRC connection between the second node and the UE.
[0365] An embodiment of the present disclosure provides a security parameter processing method, which can be used to achieve complete security context synchronization when a UE performs LTM switching. Exemplarily, the security context synchronization may include a negotiated AS security algorithm and a UP security policy applied to the current PDU session.
[0366] In some embodiments, as Figure 3A As shown in Figure 1, to achieve enhanced inter-gNB LTM, the RRC configuration of the candidate gNB can be pre-configured by the initial gNB and passed to the UE during the LTM preparation phase.
[0367] During the LTM preparation phase, the UE security capabilities are sent by the initiating gNB to the candidate gNBs. Each candidate gNB selects an AS security algorithm for the UE's AS security based on the UE security capabilities and the security capabilities of the candidate gNBs. Each candidate gNB then includes the selected AS security algorithm in the LTM configuration sent to the UE via the initiating gNB.
[0368] Furthermore, during LTM preparation, an active PDU Session may be running between the UE and the initial gNB. For this purpose, UP security is activated based on the UP security policy of the initial gNB received from the core network. The present invention proposes that the UP security policy associated with a specific active PDU Session is also sent by the initial gNB to the candidate gNB during the LTM preparation phase. If the PDU Session remains unchanged during LTM handover, the target gNB (one of the candidate gNBs) applies the UP security policy received during the LTM preparation phase to the PDU Session. If the PDU Session changes, i.e., the old PDU Session is released and a new one is established, the UP security policy for the new PDU Session needs to be reconfigured on the candidate gNB via LTM preparation.
[0369] like Figure 3BAs shown, the security algorithm negotiation and UP security policy in inter-gNB LTM may include:
[0370] 1. The connected UE sends an RRC measurement report to the serving / source gNB.
[0371] 2. The serving / source gNB decides to prepare the candidate gNB for LTM.
[0372] 3. The serving / source gNB sends a handover request to each candidate gNB. The handover request includes the UE security capabilities and the UP security policy associated with the UE's currently active PDU session (e.g., Session 1). The UP security policy is received from the core network (SMF) during PDU session establishment and stored in the serving / source gNB. For example, step 3 may include steps 3a and 3b. Step 3a: gNB0 sends a handover request to gNB1. Step 3b: gNB0 sends a handover request to gNB2. In this case, each handover request sent by gNB0 includes the UE's capability information, which is the first capability information described above.
[0373] 4. Each candidate gNB selects an AS security algorithm for the UE's AS security based on the received UE security capabilities, the candidate gNB's own security capabilities, and the algorithm priority list configured in the candidate gNB. The candidate gNB then stores the selected AS security algorithm in the LTM configuration for transmission to the UE. For example, step 4 may include steps 4a and 4b. Step 4a: gNB1 performs access control, selects an AS algorithm, and stores the UP security policy for session 1. Step 4b: gNB2 performs access control, selects an AS algorithm, and stores the UP security policy for session 1.
[0374] Each candidate gNB also stores the received UP security policy associated with the currently active PDU Session (e.g. Session 1).
[0375] 5. Each candidate gNB returns the LTM configuration to the serving / source UE via a Handover Request Acknowledgement. Exemplarily, step 5 may include steps 5a and 5b. Step 5a: gNB1 sends a Handover Request Acknowledgement to gNB0, which may include: gNB1 configuration. This configuration may include the AS algorithm selected by gNB1. Exemplarily, the AS algorithm in the embodiments of the present disclosure is one of the aforementioned security algorithms, which can be used to protect AS layer communications. Step 5b: gNB2 sends a Handover Request Acknowledgement to gNB0, which may include: gNB2 configuration. This configuration may include the AS algorithm selected by gNB2. Exemplarily, the AS algorithm in the embodiments of the present disclosure is one of the aforementioned security algorithms, which can be used to protect AS layer communications.
[0376] 6. The serving / source gNB sends the LTM configuration for itself and the candidate gNBs to the UE. The serving / source gNB includes NCC1 in the RRC reconfiguration message. If the serving / source gNB has an unused NH, the configured NCC value NCC1 = 1. If the serving / source gNB does not have any unused NH, the configured NCC value NCC1 = 0.
[0377] 7-11. Perform LTM handover via AS secure synchronization key update and handover the UE to gNB1.
[0378] 7. The UE sends a Layer 1 measurement report to the serving or source BS (e.g., gNB0).
[0379] 8. After selecting the target gNB (Candidate gNB1), the serving / source gNB determines whether the LTM process needs to be triggered. If the serving / source gNB does not have any unused NH, the serving / source gNB performs horizontal key derivation, i.e., based on K gNB0 Derived K NB-RAN *(i.e., K NG-RAN *←KDF(K gNB0 , cell identity)). If the serving / source gNB has an unused NH (associated with NCC1), the serving / source gNB performs vertical key derivation, i.e., derives K from the unused NH. NB-RAN *(i.e., K NG-RAN *←KDF(NH1, cell ID)).
[0380] 9. The serving / source gNB sends the derived K to candidate gNB1 NB-RAN * and for K NB-RAN * derived NCC value (i.e. NCC1). gNB1 sets K NB-RAN *Used as K gNB1 , and returns the NCC value (NCC1) to the serving / source gNB. For example, step 9 may include steps 9a, 9b, and 9c. Step 9a: gNB1 sends a key request to gNB0, requesting a key or security parameters for key generation, e.g., KgNB1, KNG-RAN*, NCC1. Step 9b: Generates KNG-RAN* based on KNG-RAN*. Step 9c: A key confirmation request is sent, including NCC1.
[0381] 10. The serving / source gNB sends a MAC CE message to the UE, indicating the target gNB (candidate gNB1). In some embodiments, the MAC CE may include an indication of the key update type (i.e., the first indication information).
[0382] 11. Upon receiving a MAC CE from the serving / source gNB, the following steps may be performed. In one example, the UE first determines the key update type based on the pre-configured cell identity of the target gNB or based on the key update type indication received via a MAC CE message. If the indication is from the K AMF Update, UE performs derivation, i.e. K gNB =KDF(uplink NAS count, K AMF In another embodiment, if the indication is given by K gNB To update, the UE performs horizontal key derivation (i.e., K NG-RAN *←KDF(K gNB0 , cell identity); if the NH is indicated to be updated, the UE selects the NCC1 pre-configured by the serving / source gNB in the LTM preparation phase for vertical key derivation, that is, deriving NH and K NG-RAN *(i.e., NH1=KDF(NH,K AMF ), K NG-RAN *←KDF(NH1, cell identity)). In some embodiments, the UE leaves the serving / source gNB and applies the configuration of the target gNB (candidate gNB1), which includes setting K NG-RAN *K to be used for gNB1 gNB1 .
[0383] 12-14. After completing the path switching procedure with the AMF, LTM handover is complete. The AMF generates a new NH and NCC pair (NH2, NCC2) and passes it to gNB1, where the new NCC value (NCC2) is sent to the UE via RRC reconfiguration.
[0384] 12. The UE sends an RRC Reconfiguration Complete message to gNB1.
[0385] 13a. The target gNB (gNB1) sends an N2 path switch request to the AMF, which includes an LTM switch indication (i.e., the second indication information).
[0386] 13b. Upon receiving the N2 path switching request, the AMF updates the NH (e.g., from NH1 to NH2) and increases the corresponding NCC value (e.g., from NCC1 to NCC2).
[0387] 13c.AMF returns the new NH and NCC (i.e., NH2 and NCC2) to gNB1 in the N2 Path Switch Response message.
[0388] 14. Upon receiving the LTM handover indication, gNB1 forwards or transparently transmits the new NCC value (NCC2) signaled by the AMF via NAS, so that the UE receives the updated NCC value. This NCC value is the value of the first parameter described above.
[0389] 15. User data for PDU session 1 is handed over from gNB0 to gNB1. gNB1 applies the UP security policy received from gNBO during the LTM preparation phase to protect the user data.
[0390] 16. While connected to gNB1, the UE releases PDU Session 1 and establishes a new PDU Session (e.g., Session 2) with gNB1. gNB1 receives the new UP security policy associated with PDU Session 2 from the core network (e.g., SMF).
[0391] 17. After the new UP is securely activated, gNB1 decides to perform LTM candidate preparation.
[0392] 18. gNB1 sends a handover request to the candidate gNB (gNB2), which includes the UP security policy associated with the UE’s currently active PDU Session 2.
[0393] 19. gNB2 stores the received UP security policy associated with the currently active PDU Session 2.
[0394] 20. gNB2 returns the LTM configuration to gNB1 via the Handover Request Confirmation.
[0395] 21-25. LTM handover is performed together with AS security synchronization key update, and the UE is handed over to gNB2.
[0396] 21. While the UE remains mobile, the UE sends an L1 measurement report to the serving / source gNB (gNB1).
[0397] 22. After selecting the target gNB (candidate gNB2), the serving / source gNB (gNB1) determines whether to trigger the LTM procedure. Since the serving / source gNB has an unused NH (NH2 associated with NCC2), the serving / source gNB performs vertical key derivation, i.e., deriving K from the unused NH. NB-RAN *(i.e., K NG-RAN *←KDF(NH2, cell ID)).
[0398] In some embodiments, in case of a subsequent intra-CU handover trigger, if the serving / source gNB does not have any unused NH, the serving / source gNB performs horizontal key derivation, i.e., based on K gNB1 Derived K NB-RAN *(i.e., K NG-RAN *←KDF(K gNB1 , cell identification)).
[0399] 23a. The serving / source gNB (gNB1) sends the derived K to the candidate gNB2. NB-RAN* and for K NB-RAN *Derived NCC value (i.e., NCC2).
[0400] 23b.gNB2 will K NB-RAN *Used as K gNB2 ;
[0401] 23c. Return the NCC value (NCC2) to the serving / source gNB.
[0402] 24. gNB1 sends a MAC CE message to the UE, indicating the target gNB (candidate gNB2). In some embodiments, the MAC CE may include an indication of the key update type (i.e., the first indication information).
[0403] 25. The UE first determines the handover key update type based on the pre-configured cell identity of the target gNB or based on the key update type indication received via the MAC CE message. AMF Update, UE derives K gNB =KDF(uplink NAS count, K AMF ). If the instruction is from K gNB To update, the UE performs horizontal key derivation (i.e., K NG-RAN *←KDF(K gNB1 , cell identifier); if the instruction is to be updated by NH, the UE selects NCC2 for vertical key derivation, that is, derives NH and K NG-RAN *(i.e., NH2=KDF(NH1,K AMF ), K NG-RAN *←KDF(NH2, cell identity)). The UE leaves the serving / source gNB and applies the configuration of the target gNB (candidate gNB2), which includes setting K NG-RAN *K to be used for gNB2 gNB2 .
[0404] 26-28. After completing the path switching procedure with the AMF, the LTM handover is complete. The AMF generates a new NH and NCC pair (NH3, NCC3) and passes it to gNB2, where the new NCC value (NCC3) is sent to the UE via RRC reconfiguration.
[0405] 26. The UE sends an RRC Reconfiguration Complete message to the target gNB.
[0406] 27a. The target gNB (gNB2) sends an N2 path switch request to the AMF, which includes an LTM switch indication (i.e., the second indication information).
[0407] 27b. Upon receiving the N2 path switching request, the AMF updates the NH (e.g., from NH2 to NH3) and increases the corresponding NCC value (e.g., from NCC2 to NCC3).
[0408] 27c. The MF returns the new NH and NCC (i.e., NH3 and NCC3) to gNB2 in the N2 Path Switch Response message.
[0409] 28. Upon receiving the LTM handover indication, the target base station forwards or transparently transmits the new NCC value (NCC3) sent by the AMF via NAS signaling to the UE.
[0410] 29. User data for PDU session 2 is handed over from gNB1 to gNB2. gNB2 applies the UP security policy received from gNB2 during the LTM preparation phase to protect the user data.
[0411] In some embodiments, the gNB shall be able to send the UE security capabilities and UP security policies associated with the active PDU Sessions to multiple candidate gNBs during the LTM preparation phase.
[0412] The gNB shall be able to include the selection of the AS security algorithm in the LTM configuration sent to the UE.
[0413] The gNB shall be able to store the received UP security policy for PDU sessions of UEs that are not handed over to itself.
[0414] The gNB shall be able to initiate LTM candidate configuration when the UP security policy applied by itself changes.
[0415] In some embodiments, the UE's 5G security capabilities and the UE's UP security policy are configured by the serving gNB to the candidate gNB during the LTM candidate preparation phase.
[0416] The selected AS security algorithm and the UE’s UP security activation status are stored in the LTM candidate configuration of each candidate gNB and sent by the serving gNB to the UE via an RRC reconfiguration message.
[0417] If the gNB receives information about the UE's 5G security capabilities from the AMF in the Path-Switch Acknowledge message, and the security algorithm reselected by the gNB is different from the security algorithm selected in the gNB's LTM candidate configuration, the gNB shall initiate an intra-cell handover procedure, which may include an RRC connection reconfiguration procedure indicating the change of the selected security algorithm.
[0418] Once the gNB receives the UE’s 5G security capabilities from the AMF in the Path-Switch Acknowledge message, it may decide to perform the LTM Candidate Preparation procedure to update the UE’s 5G security capabilities to all candidate gNBs.
[0419] If the gNB receives the UP security policy of the UE for the activated PDU Session from the SMF in the Path-Switch Acknowledge message, once the UP security activation status of the UE for the activated PDU Session stored by the gNB in the LTM candidate configuration does not match the UP security policy received from the SMF, the gNB shall initiate the intra-cell handover procedure including the RRC Connection Reconfiguration procedure to activate or deactivate UP security according to the UP security policy received from the SMF.
[0420] Once the gNB receives the UP security policy of the UE activating the PDU Session from the SMF in the Path-Switch Acknowledge message, it can decide to perform the LTM candidate preparation procedure to update the UP security policy of the UE activating the PDU Session to all candidate gNBs.
[0421] In the absence of any contradiction or conflict, any of the above embodiments can be combined with each other.
[0422] The embodiments of the present disclosure also provide an apparatus for implementing any of the above methods. For example, an apparatus is provided, comprising units or modules for implementing each step performed by a UE in any of the above methods. For another example, another apparatus is provided, comprising units or modules for implementing each step performed by a network device (e.g., an access network device or a core network device) in any of the above methods.
[0423] It should be understood that the division of the various units or modules in the above device is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), and the functions of some or all of the above units or modules are realized by designing the logical relationship of the components in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be realized by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, thereby realizing the functions of some or all of the above units or modules. All units or modules of the above devices can be realized in the form of software called by the processor, or in the form of hardware circuits, or in part by software called by the processor, and the rest by hardware circuits.
[0424] In the embodiments of the present disclosure, a processor is a circuit with signal processing capabilities. In one implementation, the processor may be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of a hardware circuit. The logical relationship of the above-mentioned hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DLP), or a computer programmable logic device (CLP). Processing Unit, DPU) etc.
[0425] like Figure 4 As shown, an embodiment of the present disclosure provides a communication system, including: a first node 4101, M second nodes 4102 and a UE 4103.
[0426] In some embodiments, the first node 4101 is configured to send a first message to the first node.
[0427] Exemplarily, the first message includes information related to the security context of the layer 1 / layer 2 triggered mobility LTM of the user equipment UE.
[0428] In one scenario, the first node is the initial base station of the UE's LTM, and the second node is the candidate base station of the UE's LTM; the first message includes the UE's first capability information and at least one of the first user plane UP security policies; the UE's first capability information is used by at least one second node to select a first security algorithm supported by the UE; the first UP security policy is used by the second node to determine the activation method for protecting the first session, and the first session is the UE's currently activated session.
[0429] In some embodiments, the second node 4102 is configured to send a second message to the first node.
[0430] In one scenario, the second message includes the first information of the mth second node; the first information of the mth second node is used to indicate the first security algorithm and the first UP security activation status; the first security algorithm is selected by the mth second node based on the first capability information; the first UP security activation status is determined by the mth second node based on the first UP security policy; m is a positive integer less than or equal to M; M is the total number of second nodes.
[0431] In some embodiments, the first node 4101 is configured to send a third message to the terminal.
[0432] In some embodiments, the third message includes first information; the first information is used by the UE to determine a security parameter for communicating with the second node.
[0433] In other scenarios, the first node is the serving base station of the UE, and the second node is the candidate base station or initial base station for the UE to perform LTM switching; or, the first node is the source base station for the UE to perform LTM switching, and the second node is the target base station for the UE to perform LTM switching.
[0434] In some embodiments, the first node 4101 is used to obtain the second user plane UP security policy of the second session of the UE, and send a first message to the second node, where the first message includes the second UP security policy of the second session; the second UP security policy is used by the second node to determine the activation method for protecting the second session, and the second session is a newly created activation session of the UE.
[0435] In some embodiments, the second message includes second information of the mth second node; the second information of the mth node is used to indicate a second UP security activation state determined by the mth second node, and the second UP security activation state is determined according to a second UP security policy.
[0436] In some embodiments, the third message includes second information; the second information is at least used by the UE to determine security parameters for the second session with the second node.
[0437] In some scenarios, the second node 4102 is also used to receive second capability information sent by a third node, where the third node is a core network node; when the second capability information is different from the first capability information, a second security algorithm is selected according to the second capability information; and according to the second security algorithm, a fourth message is sent to the UE, and the fourth message is used by the UE to determine the second security algorithm.
[0438] In some embodiments, the second node 4102 is also used to receive a third UP security policy associated with the first session sent by a fourth node, where the fourth node is a core network node; when the third UP security policy is different from the first UP security policy, the third UP security activation status is determined according to the third UP security policy; the first UP security policy is received by the second node from the first node; based on the third UP security activation status, a fifth message is sent to the UE, and the fifth message is used by the UE to determine the third UP security activation status.
[0439] In some embodiments, the second node 4102 is also used to receive a fourth UP security policy associated with the second session sent by a fourth node, where the fourth node is a core network node; when the fourth UP security policy is different from the second UP security policy, the fourth UP security activation status is determined according to the fourth UP security policy; the second UP security policy is received by the second node from the first node; and based on the fourth UP security activation status, a sixth message is sent to the UE, and the sixth message is used by the UE to determine the fourth UP security activation status.
[0440] In some embodiments, UE 4103 is also used to receive a fifth message sent by the mth second node, and the fifth message is used by the UE to determine a third UP security activation state; the third UP security activation state is the UP security activation state of the first session; or, to receive a sixth message sent by the mth second node, and the sixth message is used by the UE to determine a fourth UP security activation state, and the fourth UP security activation state is the UP security activation state of the second session.
[0441] An embodiment of the present disclosure further provides a communication device, which may include: one or more processors; wherein the processor is used to call instructions to enable the communication device to execute a security parameter processing method that can be implemented in any of the aforementioned embodiments.
[0442] In some embodiments, as Figure 5A and / or Figure 5B As shown, the communication device 8100 further includes one or more memories 8102 for storing instructions. Optionally, all or part of the memories 8102 may be located outside the communication device 8100.
[0443] The communication device may be the aforementioned UE and network device. In some embodiments, the network device may be a master node and / or an auxiliary node.
[0444] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the communication steps such as sending and receiving in the above method are performed by the transceiver 8103, and the other steps are performed by the processor 8101.
[0445] In some embodiments, a transceiver may include a receiver and a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, and transceiver circuit may be used interchangeably; the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be used interchangeably; and the terms receiver, receiving unit, receiver, and receiving circuit may be used interchangeably.
[0446] Optionally, the communication device 8100 further includes one or more interface circuits 8104, which are connected to the memory 8102. The interface circuits 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuits 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0447] The communication device 8100 described in the above embodiment may be a network device or a UE, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited thereto. Figure 5A The communication device may be an independent device or a part of a larger device. For example, the communication device may be: (1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a UE device, an intelligent UE device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.
[0448] Figure 5B 8200 provided by the embodiment of the present disclosure. For the case where the communication device 8100 can be a chip or a chip system, please refer to Figure 5B The structure diagram of the chip 8200 is shown, but is not limited to this.
[0449] The chip 8200 includes one or more processors 8201 , and the processor 8201 is used to call instructions so that the chip 8200 executes any of the above security parameter processing methods.
[0450] In some embodiments, chip 8200 further includes one or more interface circuits 8202, which are connected to memory 8203. Interface circuit 8202 can be used to receive signals from memory 8203 or other devices, and can be used to send signals to memory 8203 or other devices. For example, interface circuit 8202 can read instructions stored in memory 8203 and send the instructions to processor 8201. Optionally, the terms interface circuit, interface, transceiver pin, and transceiver are interchangeable.
[0451] In some embodiments, the chip 8200 further includes one or more memories 8203 for storing instructions. Alternatively, all or part of the memories 8203 may be located outside the chip 8200.
[0452] The present disclosure also provides a storage medium having instructions stored thereon, which, when executed on the communication device 8100, causes the communication device 8100 to execute any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but may also be a transient storage medium.
[0453] The present disclosure further provides a program product, which, when executed by the communication device 8100, enables the communication device 8100 to perform any of the above security parameter processing methods. Optionally, the program product is a computer program product.
[0454] The present disclosure also provides a computer program, which, when executed on a computer, enables the computer to execute any one of the above security parameter processing methods.
[0455] Other embodiments of the present invention will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered as exemplary only, with the true scope and spirit of the present invention being indicated by the following claims.
[0456] It should be understood that the embodiments of the present disclosure are not limited to the precise structures described above and shown in the drawings, and various modifications and changes can be made without departing from the scope thereof. The scope of the embodiments of the present disclosure is limited only by the appended claims.
Claims
1. A security parameter processing method, wherein: Executed by the first node, the method includes: Sending a first message to the second node, where the first message includes information related to a security context of layer 1 / layer 2 triggered mobility LTM of a user equipment UE; receiving a second message sent by the second node, where the second message includes a security parameter determined based on the first message; According to the second message, a third message is sent to the UE; the third message includes the security parameter; and the security parameter is used to protect communication between the UE and the second node.
2. The method according to claim 1, wherein The first node is an initial base station of the LTM of the UE, and the second node is a candidate base station of the UE LTM; the first message includes the first capability information of the UE and at least one of the first user plane UP security policy; the first capability information of the UE is used by the at least one second node to select a first security algorithm supported by the UE; The first UP security policy is used by the second node to determine an activation method for protecting a first session, where the first session is a currently activated session of the UE.
3. The method according to claim 2, wherein: The second message includes the first information of the mth second node; the first information of the mth second node is used to indicate the first security algorithm and the first UP security activation state; The first security algorithm is selected by the mth second node according to the first capability information; The first UP security activation state is determined by the mth second node according to the first UP security policy; m is a positive integer less than or equal to M; and M is the total number of the second nodes.
4. The method according to claim 2 or 3, wherein: The third message includes the first information; the first information is used by the UE to determine security parameters for communicating with the second node.
5. The method according to claim 1, wherein The first node is a serving base station of the UE, and the second node is a candidate base station or an initial base station for the UE to perform LTM handover; or, The first node is a source base station for the UE to perform LTM handover, and the second node is a target base station for the UE to perform LTM handover.
6. The method according to claim 5, wherein: The sending the first message to the second node includes: Obtain the second user plane UP security policy of the second session of the UE, send the first message to the second node, and the first message includes the second UP security policy of the second session; the second UP security policy is used by the second node to determine the activation method for protecting the second session, and the second session is a newly created activation session of the UE.
7. The method according to claim 6, wherein: The second message includes second information of the mth second node; the second information of the mth node is used to indicate a second UP security activation state determined by the mth second node, and the second UP security activation state is determined according to the second UP security policy.
8. The method according to claim 7, wherein: The third message includes second information; the second information is at least used by the UE to determine security parameters for the second session with the second node.
9. The method according to claim 6, wherein: The sending of the first message to the second node includes at least one of the following: After obtaining the second UP security policy for the second session and successfully activating the second session, sending the second UP security policy to the second node; Before the UE switches to the second node, the second UP security policy is sent to the second node.
10. The method according to any one of claims 6 to 9, wherein: The sending the second UP security policy to the second node includes: A switching request is sent to the second node, where the switching request includes the second UP security policy.
11. A security parameter processing method, wherein: Executed by the second node, the method includes: receiving a first message sent by a first node, where the first message includes information related to a security context of layer 1 / layer 2 triggered mobility LTM of a user equipment UE; A second message is sent to the first node, where the second message includes a security parameter determined based on the first message; the security parameter is used by the first node to send a third message to the UE, where the third message includes the security parameter; and the security parameter is used to protect communication between the UE and the second node.
12. The method according to claim 11, wherein The first node is an initial base station for LTM of the UE, the second node is a candidate node for the UE to perform LTM handover, the first message includes first capability information of the UE and at least one of a first user plane UP security policy; the first capability information of the UE is used by the at least one second node to select a first security algorithm supported by the UE; The first UP security policy is used by the second node to determine an activation method for protecting a first session, where the first session is a currently activated session of the UE.
13. The method according to claim 11 or 12, wherein: The method further comprises: selecting, based on the first capability information of the UE, a first security algorithm for communicating with the UE; and determining, based on the first UP security policy, a first UP security activation state for communicating with the UE; The second message includes first information; the first information is used to determine at least one of the first security algorithm selected by the second node and the first UP security activation state.
14. The method according to claim 13, wherein The first node is a serving base station of the UE or a source base station of LTM handover, and the first message includes a second UP security policy of a second session of the UE.
15. The method according to claim 14, wherein The second message includes second information; the second information is used to indicate a second UP security activation state, and the second UP security activation state is determined according to the second UP security policy.
16. The method according to any one of claims 11 to 15, wherein: The method further comprises: receiving second capability information sent by a third node, where the third node is a core network node; When the second capability information is different from the first capability information, selecting a second security algorithm according to the second capability information; A fourth message is sent to the UE according to the second security algorithm, where the fourth message is used by the UE to determine the second security algorithm.
17. The method according to any one of claims 11 to 16, wherein: The method further comprises: receiving a third UP security policy associated with the first session and sent by a fourth node, where the fourth node is a core network node; In a case where the third UP security policy is different from the first UP security policy, determining a third UP security activation state according to the third UP security policy; the first UP security policy is received by the second node from the first node; A fifth message is sent to the UE according to the third UP security activation state, where the fifth message is used by the UE to determine the third UP security activation state.
18. The method according to any one of claims 11 to 17, wherein: The method further comprises: receiving a fourth UP security policy associated with the second session and sent by a fourth node, where the fourth node is a core network node; In a case where the fourth UP security policy is different from the second UP security policy, determining a fourth UP security activation state according to the fourth UP security policy; the second UP security policy is received by the second node from the first node; Sending a sixth message to the UE according to the fourth UP security activation state, where the sixth message is used by the UE to determine the fourth UP security activation state.
19. A method for processing security parameters, wherein: The method is performed by a user equipment UE, and includes: A third message sent by the first node is received; the third message includes a security parameter; and the security parameter is used to protect communication between the UE and the second node.
20. The method according to claim 19, wherein The third message includes first information of M second nodes; the first information of the mth second node is used to indicate at least one of a first security algorithm and a first user plane UP security activation state; the first security algorithm is a first security algorithm selected by the mth second node based on the first capability information of the UE; The first UP security activation state is determined by the mth second node according to the first UP security policy; m is a positive integer less than or equal to M.
21. The method according to claim 19, wherein The third message includes second information of M second nodes; the second information of the mth node is used to indicate a second UP security activation state determined by the mth second node, where the second UP security activation state is determined according to the second UP security policy; The m is a positive integer less than or equal to M.
22. The method according to any one of claims 19 to 21, wherein: The method further comprises: Receive the fourth message sent by the mth second node, the fourth message is used by the UE to determine the second security algorithm; or, receive the fifth message sent by the mth second node, the fifth message is used by the UE to determine the third UP security activation state; the third UP security activation state is the UP security activation state of the first session; or, receive the sixth message sent by the mth second node, the sixth message is used by the UE to determine the fourth UP security activation state, the fourth UP security activation state is the UP security activation state of the second session.
23. A communication device, characterized in that: The communication device is used to execute the communication method according to any one of claims 1-10, 11-18, or 19-22.
24. A communication system, wherein: The communication system includes a first node, a second node and a user equipment UE; The first node is configured to perform the method according to any one of claims 1 to 10; The second node is configured to perform the method according to any one of claims 11 to 18; The UE is configured to perform the method according to any one of claims 19 to 22.
25. A program product, wherein The program product includes a computer program, and when the computer program is executed by a communication device, the communication device is enabled to implement the security parameter processing method according to any one of claims 1-10, 11-18, or 19-22.