Air interface key processing method and device, communication system and readable storage medium
By obtaining and judging the validity information of the air interface key, the problem of key inconsistency during continuous switching is solved, key consistency is ensured, connection interruption is prevented, and user experience is improved.
Patent Information
- Application Number
- CN202410320692.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-20
- Publication Date
- 2025-09-23
AI Technical Summary
In continuous handover scenarios, the air interface key becomes invalid after the UE is handed over, resulting in inconsistency between the RAN node and the UE key, causing connection interruption and inability to quickly recover, affecting user experience.
By obtaining the air interface key and key validity information corresponding to the UE, the validity status of the key is judged, and the target air interface key is determined according to the status to ensure key consistency.
Prevents connection interruption caused by inconsistent keys between RAN nodes and UE, improving user experience.
Smart Images

Figure CN120692550A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a method, device, communication system and readable storage medium for processing air interface keys. Background Art
[0002] To improve handover signaling efficiency, the industry has proposed a "continuous handover configuration" mechanism. In a continuous handover scenario, after a UE (User Equipment) handover occurs, the handover configuration held by each RAN (Radio Access Network) node remains valid, allowing the UE to directly use these RAN nodes when it subsequently switches to them.
[0003] However, the air interface key in the handover configuration will still become invalid immediately after the UE is handed over. As a result, the air interface key used by the RAN node and the UE will be inconsistent when the UE is handed over next time, resulting in connection interruption and inability to quickly recover, which greatly affects the user experience. Summary of the Invention
[0004] Based on this, it is necessary to provide a method, device, communication system and readable storage medium for processing air interface keys to address the above technical problems.
[0005] In a first aspect, a method for processing an air interface key is provided. The method is applied to a first network element, and the method includes:
[0006] In a handover configuration corresponding to a user equipment UE, obtaining a first air interface key and first key validity information corresponding to the UE;
[0007] Determining, according to the first key validity information, a validity status of the first air interface key;
[0008] Determine a target air interface key corresponding to the UE according to a validity status of the first air interface key.
[0009] As an optional implementation manner, the first key validity information includes one or more of validity indication information, security verification information, cell identity information or next hop chain count value NCC.
[0010] As an optional implementation manner, when the first key validity information includes one or more of security verification information, cell identity information, or NCC, the determining the validity status of the first air interface key according to the first key validity information includes:
[0011] The validity status of the first air interface key is determined according to the first key validity information and the second key validity information carried in the access request sent by the UE.
[0012] As an optional implementation manner, determining the target air interface key corresponding to the UE according to the validity status of the first air interface key includes:
[0013] If the validity state of the first air interface key is valid, determining the first air interface key as a target air interface key corresponding to the UE;
[0014] If the validity status of the first air interface key is invalid, obtaining a second air interface key from the network element that the UE last accessed, and determining the second air interface key as a target air interface key corresponding to the UE.
[0015] As an optional implementation, the method further includes:
[0016] If the validity state of the first air interface key is valid, after the UE is switched this time, sending the third air interface key and third key validity information corresponding to the UE to other network elements;
[0017] If the validity state of the first air interface key is invalid, before the UE is handed over from the first network element to the target network element, sending validity information of a third air interface key and a fourth key corresponding to the UE to the target network element;
[0018] The third key validity information includes one or more of validity indication information, security verification information, cell identity information or NCC, and the fourth key validity information is validity indication information indicating that the validity status of the third air interface key is valid.
[0019] As an optional implementation manner, after determining the validity status of the first air interface key according to the first key validity information, the method further includes:
[0020] If the validity state of the first air interface key is valid, obtaining security verification information corresponding to the UE in the handover configuration corresponding to the UE, and determining whether the UE meets the access condition according to the obtained security verification information and the security verification information carried in the access request sent by the UE;
[0021] If the validity status of the first air interface key is invalid, the security verification information carried in the access request is sent to the network element that the UE last accessed.
[0022] As an optional implementation manner, in the handover configuration corresponding to the UE, before obtaining the first air interface key and the first key validity information corresponding to the UE, the method further includes:
[0023] Receive the first air interface key and first key validity information corresponding to the UE sent by other network elements.
[0024] As an optional implementation manner, when the first network element is a CU unit or a central unit control plane CU-CP unit in a radio access network RAN node with separate central unit / distributed unit CU / DU, the method further includes:
[0025] The first key validity information is sent to the DU unit to which the wireless cell to which the UE is to be switched belongs; wherein the first key validity information is validity indication information indicating whether the first air interface key is valid.
[0026] In a second aspect, a method for processing an air interface key is provided. The method is applied to a second network element, where the second network element is a DU unit in a radio access network RAN node with a separate central unit / distributed unit CU / DU. The method includes:
[0027] Receiving first key validity information corresponding to a user terminal UE, where the first key validity information is validity indication information indicating whether a first air interface key corresponding to an underlying configuration of the UE is valid;
[0028] The underlying configuration is applied according to the first key validity information.
[0029] As an optional implementation manner, applying the underlying configuration according to the first key validity information includes:
[0030] If the first key validity information indicates that the first air interface key is valid, after the UE accesses the DU unit, applying the underlying configuration and sending a downlink data transmission status DDDS frame;
[0031] If the first key validity information indicates that the first air interface key is invalid, after the UE accesses the DU unit, the underlying configuration is applied according to the instruction of the CU unit or the CU-CP unit.
[0032] In a third aspect, a method for processing an air interface key is provided, the method being applied to a third network element, the method including:
[0033] Sending a handover request message to the target network element; wherein the handover request message carries a first air interface key and first key validity information corresponding to the user equipment UE.
[0034] As an optional implementation manner, the first key validity information includes one or more of validity indication information, security verification information, cell identity information or next hop chain count value NCC.
[0035] As an optional implementation, the method further includes:
[0036] If the validity status of the first air interface key is invalid, before the UE switches from the third network element to the target network element, the first air interface key and / or second key validity information corresponding to the UE is sent to the target network element; wherein, the second key validity information is validity indication information indicating that the validity status of the first air interface key is valid.
[0037] In a fourth aspect, a first network element is provided, comprising a memory, a transceiver, and a processor;
[0038] The memory is used to store a computer program; the transceiver is used to send and receive data under the control of the processor; and the processor is used to read the computer program in the memory and perform the following operations:
[0039] In a handover configuration corresponding to a user equipment UE, obtaining a first air interface key and first key validity information corresponding to the UE;
[0040] Determining, according to the first key validity information, a validity status of the first air interface key;
[0041] Determine a target air interface key corresponding to the UE according to a validity status of the first air interface key.
[0042] As an optional implementation manner, the first key validity information includes one or more of validity indication information, security verification information, cell identity information or next hop chain count value NCC.
[0043] As an optional implementation manner, when the first key validity information includes one or more of security verification information, cell identity information, or NCC, the determining the validity status of the first air interface key according to the first key validity information includes:
[0044] The validity status of the first air interface key is determined according to the first key validity information and the second key validity information carried in the access request sent by the UE.
[0045] As an optional implementation manner, determining the target air interface key corresponding to the UE according to the validity status of the first air interface key includes:
[0046] If the validity state of the first air interface key is valid, determining the first air interface key as a target air interface key corresponding to the UE;
[0047] If the validity status of the first air interface key is invalid, obtaining a second air interface key from the network element that the UE last accessed, and determining the second air interface key as a target air interface key corresponding to the UE.
[0048] As an optional implementation manner, the processor is further configured to read the computer program in the memory and perform the following operations:
[0049] If the validity state of the first air interface key is valid, after the UE is switched this time, sending the third air interface key and third key validity information corresponding to the UE to other network elements;
[0050] If the validity state of the first air interface key is invalid, before the UE is handed over from the first network element to the target network element, sending validity information of a third air interface key and a fourth key corresponding to the UE to the target network element;
[0051] The third key validity information includes one or more of validity indication information, security verification information, cell identity information or NCC, and the fourth key validity information is validity indication information indicating that the validity status of the third air interface key is valid.
[0052] As an optional implementation manner, the processor is further configured to read the computer program in the memory and perform the following operations:
[0053] If the validity state of the first air interface key is valid, obtaining security verification information corresponding to the UE in the handover configuration corresponding to the UE, and determining whether the UE meets the access condition according to the obtained security verification information and the security verification information carried in the access request sent by the UE;
[0054] If the validity status of the first air interface key is invalid, the security verification information carried in the access request is sent to the network element that the UE last accessed.
[0055] As an optional implementation manner, in the handover configuration corresponding to the UE, before obtaining the first air interface key and the first key validity information corresponding to the UE, the processor is further configured to read the computer program in the memory and perform the following operations:
[0056] Receive the first air interface key and first key validity information corresponding to the UE sent by other network elements.
[0057] As an optional implementation manner, when the first network element is a CU unit or a central unit control plane CU-CP unit in a radio access network RAN node with separate central unit / distributed unit CU / DU, the processor is further configured to read the computer program in the memory and perform the following operations:
[0058] The first key validity information is sent to the DU unit to which the wireless cell to which the UE is to be switched belongs; wherein the first key validity information is validity indication information indicating whether the first air interface key is valid.
[0059] In a fifth aspect, a second network element is provided, characterized in that the second network element is a DU unit in a radio access network RAN node with a separate central unit / distributed unit CU / DU, and the second network element includes a memory, a transceiver, and a processor;
[0060] The memory is used to store a computer program; the transceiver is used to send and receive data under the control of the processor; and the processor is used to read the computer program in the memory and perform the following operations:
[0061] Receiving first key validity information corresponding to a user terminal UE, where the first key validity information is validity indication information indicating whether a first air interface key corresponding to an underlying configuration of the UE is valid;
[0062] The underlying configuration is applied according to the first key validity information.
[0063] As an optional implementation manner, applying the underlying configuration according to the first key validity information includes:
[0064] If the first key validity information indicates that the first air interface key is valid, after the UE accesses the DU unit, applying the underlying configuration and sending a downlink data transmission status DDDS frame;
[0065] If the first key validity information indicates that the first air interface key is invalid, after the UE accesses the DU unit, the underlying configuration is applied according to the instruction of the CU unit or the CU-CP unit.
[0066] In a sixth aspect, a third network element is provided, characterized in that it includes a memory, a transceiver, and a processor;
[0067] The memory is used to store a computer program; the transceiver is used to send and receive data under the control of the processor; and the processor is used to read the computer program in the memory and perform the following operations:
[0068] Sending a handover request message to the target network element; wherein the handover request message carries a first air interface key and first key validity information corresponding to the user equipment UE.
[0069] As an optional implementation manner, the first key validity information includes one or more of validity indication information, security verification information, cell identity information or next hop chain count value NCC.
[0070] As an optional implementation manner, the processor is further configured to read the computer program in the memory and perform the following operations:
[0071] If the validity status of the first air interface key is invalid, before the UE switches from the third network element to the target network element, the first air interface key and / or second key validity information corresponding to the UE is sent to the target network element; wherein, the second key validity information is validity indication information indicating that the validity status of the first air interface key is valid.
[0072] In a seventh aspect, an air interface key processing device is provided, characterized in that the device is applied to a first network element, and the device includes:
[0073] An acquiring unit, configured to acquire, in a handover configuration corresponding to a user equipment UE, a first air interface key and first key validity information corresponding to the UE;
[0074] A first judging unit, configured to judge a validity status of the first air interface key according to the first key validity information;
[0075] The determining unit is configured to determine a target air interface key corresponding to the UE according to a validity status of the first air interface key.
[0076] As an optional implementation manner, the first key validity information includes one or more of validity indication information, security verification information, cell identity information or next hop chain count value NCC.
[0077] As an optional implementation manner, when the first key validity information includes one or more of security verification information, cell identity information, or NCC, the first judgment unit is specifically configured to:
[0078] The validity status of the first air interface key is determined according to the first key validity information and the second key validity information carried in the access request sent by the UE.
[0079] As an optional implementation manner, the determining unit is specifically configured to:
[0080] If the validity state of the first air interface key is valid, determining the first air interface key as a target air interface key corresponding to the UE;
[0081] If the validity status of the first air interface key is invalid, obtaining a second air interface key from the network element that the UE last accessed, and determining the second air interface key as a target air interface key corresponding to the UE.
[0082] As an optional implementation, the device further includes:
[0083] A first sending unit is configured to send, if the validity state of the first air interface key is valid, a third air interface key and third key validity information corresponding to the UE to other network elements after the UE is switched this time;
[0084] A second sending unit is configured to send, if the validity state of the first air interface key is invalid, a third air interface key and fourth key validity information corresponding to the UE to the target network element before the UE is switched from the first network element to the target network element;
[0085] The third key validity information includes one or more of validity indication information, security verification information, cell identity information or NCC, and the fourth key validity information is validity indication information indicating that the validity status of the third air interface key is valid.
[0086] As an optional implementation, the device further includes:
[0087] a second determining unit, configured to, if the validity state of the first air interface key is valid, obtain security verification information corresponding to the UE in the handover configuration corresponding to the UE, and determine whether the UE meets the access condition based on the obtained security verification information and the security verification information carried in the access request sent by the UE;
[0088] The third sending unit is configured to send the security verification information carried in the access request to the network element that the UE last accessed if the validity status of the first air interface key is invalid.
[0089] As an optional implementation, the device further includes:
[0090] The receiving unit is configured to receive the first air interface key and first key validity information corresponding to the UE sent by other network elements.
[0091] As an optional implementation manner, when the first network element is a CU unit or a central unit control plane CU-CP unit in a radio access network RAN node with separate central unit / distributed unit CU / DU, the apparatus further includes:
[0092] The fourth sending unit is used to send the first key validity information to the DU unit to which the wireless cell to which the UE is to be switched belongs; wherein the first key validity information is validity indication information indicating whether the first air interface key is valid.
[0093] In an eighth aspect, an air interface key processing device is provided, characterized in that the device is applied to a second network element, where the second network element is a DU unit in a radio access network RAN node with a separate central unit / distributed unit CU / DU; the device includes:
[0094] A receiving unit, configured to receive first key validity information corresponding to a user terminal UE, where the first key validity information is validity indication information indicating whether a first air interface key corresponding to an underlying configuration of the UE is valid;
[0095] An application unit, configured to apply the underlying configuration according to the first key validity information.
[0096] As an optional implementation manner, the application unit is specifically configured to:
[0097] If the first key validity information indicates that the first air interface key is valid, after the UE accesses the DU unit, applying the underlying configuration and sending a downlink data transmission status DDDS frame;
[0098] If the first key validity information indicates that the first air interface key is invalid, after the UE accesses the DU unit, the underlying configuration is applied according to the instruction of the CU unit or the CU-CP unit.
[0099] In a ninth aspect, a device for processing an air interface key is provided, wherein the device is applied to a third network element and includes:
[0100] The first sending unit is configured to send a handover request message to a target network element; wherein the handover request message carries a first air interface key and first key validity information corresponding to the user equipment UE.
[0101] As an optional implementation manner, the first key validity information includes one or more of validity indication information, security verification information, cell identity information or next hop chain count value NCC.
[0102] As an optional implementation, the device further includes:
[0103] The second sending unit is used to send the first air interface key and / or second key validity information corresponding to the UE to the target network element before the UE switches from the third network element to the target network element if the validity status of the first air interface key is invalid; wherein, the second key validity information is validity indication information indicating that the validity status of the first air interface key is valid.
[0104] In a tenth aspect, a communication system is provided, characterized in that the communication system includes a first network element, a second network element, and a third network element;
[0105] The first network element executes the method steps described in the first aspect, the second network element executes the method steps described in the second aspect, and the third network element executes the method steps described in the third aspect.
[0106] In the eleventh aspect, a computer-readable storage medium is provided, on which a computer program is stored, characterized in that when the computer program is executed by a processor, the steps of the above-mentioned air interface key processing method are implemented.
[0107] The present application provides a method for processing an air interface key. The technical solution provided by the embodiments of the present application brings at least the following beneficial effects: the first network element obtains the first air interface key and the first key validity information corresponding to the UE in the handover configuration corresponding to the UE; judges the validity status of the first air interface key based on the first key validity information; and determines the target air interface key corresponding to the UE based on the validity status of the first air interface key. In this way, the first network element, as the network element to be accessed by the UE, can judge the validity status of the air interface key based on the key validity information in the handover configuration. If the validity status of the air interface key is valid, the first network element can use it directly. If the validity status of the air interface key is invalid, the first network element can obtain the air interface key from the network element to which the UE last accessed. This prevents the connection from being interrupted and unable to be quickly restored due to the inconsistency of the air interface keys used by the RAN node and the UE, thereby greatly improving the user experience.
[0108] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0109] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0110] Figure 1A flowchart of a method for processing an air interface key applied to a first network element provided in an embodiment of the present application;
[0111] Figure 2 A flowchart of a method for processing an air interface key applied to a second network element provided in an embodiment of the present application;
[0112] Figure 3 A flowchart of a method for processing an air interface key applied to a third network element provided in an embodiment of the present application;
[0113] Figure 4 This is a signaling interaction diagram for scenario A in Example 1 of a method for processing an air interface key provided in an embodiment of the present application;
[0114] Figure 5 This is a signaling interaction diagram for scenario B in Example 1 of a method for processing an air interface key provided in an embodiment of the present application;
[0115] Figure 6 This is a signaling interaction diagram for scenario A in embodiment 3 of a method for processing an air interface key provided in an embodiment of the present application;
[0116] Figure 7 This is a signaling interaction diagram for scenario B in embodiment 3 of a method for processing an air interface key provided in an embodiment of the present application;
[0117] Figure 8 A schematic diagram of the structure of a first network element provided in an embodiment of the present application;
[0118] Figure 9 A schematic diagram of the structure of a second network element provided in an embodiment of the present application;
[0119] Figure 10 A schematic diagram of the structure of a third network element provided in an embodiment of the present application;
[0120] Figure 11 A schematic diagram of the structure of an air interface key processing device provided in an embodiment of the present application;
[0121] Figure 12 A schematic diagram of the structure of an air interface key processing device provided in an embodiment of the present application;
[0122] Figure 13 A schematic diagram of the structure of an air interface key processing device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0123] In embodiments of the present invention, the term "and / or" describes the association relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally indicates that the associated objects are in an "or" relationship.
[0124] In the embodiments of the present application, the term "plurality" refers to two or more than two, and other quantifiers are similar.
[0125] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0126] To facilitate understanding of the technical solutions protected by the embodiments of the present application, the embodiments of the present application first introduce some basic communication technologies, as follows:
[0127] 1. Continuous Handover Configuration: Handover refers to the process of reconfiguration of the cell to which the UE is connected. Specifically, the UE is originally connected to the wireless communication system through one wireless cell and later switches to another wireless cell to connect to the communication system. The wireless cell before the handover is called the source cell, and the wireless cell after the handover is called the target cell. If the source cell and the target cell are controlled by different RAN nodes, the RAN node controlling the source cell is called the source node, and the RAN node controlling the target cell is called the target node. The source node can directly perform the handover preparation procedure with the target node, or it can indirectly perform handover preparation with the target node via the core network. In the case where the source node and the target node directly perform the handover preparation procedure, the source node can send a handover request message to the target node to trigger the handover preparation procedure. In the case where the handover preparation is performed indirectly via the core network, the source node can send a source to target transparent container to the target node via the core network to trigger the handover preparation procedure.
[0128] The above two scenarios are collectively referred to as the handover preparation phase. During the handover preparation phase, a large amount of information (such as UE service information) needs to be exchanged between the source node and the target node. The purpose of the handover preparation phase is to generate or modify the target configuration. The target configuration will be used after the corresponding handover is completed.
[0129] After the handover preparation phase, the phase in which the UE actually disconnects from the source cell and accesses the target cell is called the handover execution phase. The handover execution phase and the handover preparation phase can be separated by a long period of time. That is, even if the current wireless channel conditions are not suitable for handover, the network equipment can execute the handover preparation phase in advance to prepare for future handovers, and then execute the handover when the wireless channel conditions are suitable. The start of the handover execution phase can be triggered by either the source node or the UE. The typical scenario triggered by the UE is "Conditional Handover", that is, the network instructs the UE to start the handover execution phase if and only if a certain condition is met.
[0130] A RAN node serving a UE can consider multiple cells as potential target cells. For any potential target cell, if the potential target cell belongs to another RAN node (i.e., a potential target node), the RAN node serving the UE performs a handover preparation phase with each potential target node. If the handover preparation is successful, the potential target cell becomes a candidate target cell. Correspondingly, the potential target node becomes a candidate target node. For each candidate target cell, the corresponding candidate target node maintains a set of handover target configurations.
[0131] In the traditional handover mechanism, once a UE undergoes a handover, reestablishment, connection recovery, or other similar state change, the target configuration for the UE held by all candidate target nodes before the change is no longer valid. In other words, the candidate target node cannot use the target configuration for the UE held before the change after the next change (the UE may be applying one of these target configurations, but this set of configurations immediately becomes the "current configuration" after application and loses its identity as the "target configuration"). If the target node needs to prepare for the next handover, the target node needs to re-execute the handover preparation phase. Considering that after each handover, the RAN node serving the UE needs to re-execute the handover preparation phase, which will result in a large signaling load on the internal interface of the network device and a large information processing load on the node, the industry has proposed the concept of "continuous handover configuration". Under this concept, even if the UE undergoes a handover, the target configuration for the UE held by all nodes before the change remains valid and can be used for subsequent handovers.
[0132] 2. Air interface key: In systems such as LTE (Long Term Evolution) and 5G (5th Generation Mobile Communication Technology), high-level signaling interactions and user data interactions between UE and RAN nodes are usually encrypted. In addition, integrity protection is also provided to prevent tampering by middlemen. These security measures are collectively referred to as air interface security mechanisms. The air interface security mechanism is centered on the air interface root key. This air interface root key is called K in the LTE system. eNB , called K in the 5G system NG-RAN (K NG-RAN It can also be divided into K according to the specific type of RAN node ng-eNB and K gNB The air interface root key is a bit string of a specified length. The UE and RAN nodes use the air interface root key or its derivatives for security operations such as encryption and integrity protection.
[0133] The air interface root key is a symmetric key, and the network device and the UE independently calculate the same air interface root key value. The input parameters for calculating the air interface root key are centered on the "superior key" and also include other secondary input parameters. The "superior key" can be a bit string held or provided by the NAS (Non-Access Stratum), or it can be the air interface root key last used by the UE. In the case where the "superior key" is the air interface root key last used by the UE, the "superior key" used each time the air interface root key is updated is naturally statistically irrelevant (they have different values unless they are accidentally the same, the same applies below). In the case where the "superior key" is a bit string held or provided by the NAS, the security mechanism requires that for each bit string held or provided by the NAS, the UE and the network device perform the "use the bit string to generate the air interface root key" operation at most once. This design makes the air interface root key statistically very irregular and difficult for attackers to crack.
[0134] For handover scenarios, if there are source and target nodes, the air interface root key must be changed after the handover compared to before the handover. On the network side, the updated air interface root key is provided to the target node during the handover preparation phase. If the source and target nodes perform the handover preparation process directly, the updated air interface root key is included in the handover request message sent by the source node to the target node. If the handover preparation is performed indirectly through the core network, the updated air interface root key is included in the source-to-target transparent transmission container sent by the core network to the target node.
[0135] 3. CU / DU separation architecture: To support more flexible network deployment, the 5G system introduces a CU (Central Unit) / DU (Distributed Unit) separation architecture. An NG-RAN (Next Generation Radio Access Network) node (RAN node in the 5G system) can be split into a CU and at least one DU. The CU is connected to the core network, while the wireless air interface (such as the wireless cell) is controlled by the DU. The CU and DU are connected via the F1 interface or the W1 interface. A CU can be connected to multiple DUs, but a DU can only be connected to one CU.
[0136] In the CU / DU separation scenario, handover is categorized into three types: intra-DU handover, intra-CU inter-DU handover, and inter-CU handover. Intra-DU handover refers to a handover in which neither the CU nor the DU to which the UE is connected changes. Intra-CU inter-DU handover refers to a handover in which the DU to which the UE is connected changes but the CU to which it is connected does not. All other handovers are referred to as inter-CU handovers, including those between non-separated RAN nodes and RAN nodes with CU / DU separation.
[0137] In addition, the CU can be further divided into the CU-CP (Central Unit-Control Plane) and the CU-UP (Central Unit-User Plane), which are connected by the E1 interface. Similar to the CU / DU separation, a CU-CP can be connected to multiple CU-UPs, but a CU-UP can only be connected to one CU-CP. While the UE is connected to a CU-CP, the CU-CP may change to the CU-UP serving the UE due to reasons such as cross-DU switching.
[0138] The process in which the CU instructs the DU to establish a UE context is called the UE context setup procedure (UE Context Setup procedure), which starts with the CU sending a UE Context Setup Request message (UE Context Setup Request message) to the DU. The application scenario of this process is: there was no context information for the UE in the DU originally, and the context information for the UE needs to be created. For example, in a cross-DU switching scenario, the CU and the target DU perform this process to create context information for the UE. Similarly, the process in which the CU-CP instructs the CU-UP to establish a UE context is called the Bearer Context Setup procedure (Bearer Context Setup procedure), which starts with the CU-CP sending a Bearer Context Setup Request message (Bearer Context Setup Request message) to the CU-UP. The application scenario of this process is: there was no context information for the UE in the CU-UP originally, and the context information for the UE needs to be created. For example, in a reconfiguration scenario in which the CU-UP is changed, the CU-CP and the target CU-UP perform this process to create context information for the UE.
[0139] Generally speaking, both CU-CP and CU-UP perform security operations. CU-CP performs security operations for uplink and downlink signaling, while CU-UP performs security operations for uplink and downlink user data. In order for CU-UP to perform security operations for uplink and downlink user data, CU-CP includes necessary security information in the bearer context establishment request message. For example, K calculated from the air interface root key UPint and / or K UPenc , K UPint It is generally used to perform integrity protection or integrity protection verification for uplink and downlink user data, and K UPenc It is generally used to perform encryption or decryption on uplink and downlink data.
[0140] In a CU / DU split architecture, all handover preparation phases are initiated by the CU. In a scenario where the CU is split into CU-CP and CU-UP, all handover preparation phases that need to be initiated by the CU are initiated by the CU-CP.
[0141] During a handover, if the target cell belongs to a DU in a RAN node with a CU / DU split, after the UE accesses the target cell, the DU sends one or more DDDS (Downlink Data Delivery Status) frames to the CU(-UP) to inform the CU(-UP) at which rate the DU wishes to receive downlink user data sent by the CU(-UP). In some scenarios, the CU(-UP) sends downlink user data to the DU only after receiving DDDS frames.
[0142] 4. RRC (Radio Resource Control) reestablishment and UE context retrieval process: In addition to the handover process, the movement of UE between cells can also be performed through connection reestablishment or connection recovery process. That is, the UE accidentally or controlled disconnects from the source cell and then accesses the target cell. "Unexpected disconnection" is also called "RLF (Radio Link Failure)". If the target cell and the source cell belong to different RAN nodes, the UE context retrieval procedure (Retrieve UE Context procedure) is performed between the two RAN nodes. The target node sends a Retrieve UE Context Request message to the source node, and the source node sends a Retrieve UE Context Response message to the target node. The information contained in the Retrieve UE Context Response message is similar to the information contained in the Handover Request message. In particular, the Retrieve UE Context Response message contains the air interface root key to be used at the target node.
[0143] Currently, in continuous handover scenarios, although the handover configuration held by each RAN node remains valid after the UE is handed over, the air interface key in the handover configuration will still become invalid immediately after the UE is handed over. As a result, the air interface key used by the RAN node and the UE will be inconsistent during the next handover, resulting in connection interruption and inability to quickly recover, which greatly affects the user experience.
[0144] Based on this, the embodiment of the present application provides a method for processing an air interface key, which is applied to a first network element, such as Figure 1 The specific processing process is as follows:
[0145] Step 101: In a handover configuration corresponding to the UE, obtain a first air interface key and first key validity information corresponding to the UE.
[0146] In implementation, when the UE is disconnected from the network element it last accessed and connects to the first network element on its own, the UE will send an access request to the first network element. Accordingly, the first network element receives the access request sent by the UE and, based on the access request sent by the UE, obtains the first air interface key and first key validity information corresponding to the UE in the handover configuration corresponding to the UE. The first network element can be a RAN node without CU / DU separation, or a CU unit or CU-CP unit in a RAN node with CU / DU separation, which is not limited in the embodiment of the present application. The first air interface key is the air interface key to be used for secure communication between the first network element and the UE. The first air interface key can be sent by the source node during the handover preparation phase, or updated by other target nodes after the UE is handed over. The disconnection of the UE from the network element it last accessed can be a controlled disconnection or an accidental disconnection due to a radio link failure, which is not limited in the embodiment of the present application. The process of the UE connecting to the first network element on its own can be a connection reestablishment process, a connection recovery process, or other similar connection processes, which is not limited in the embodiment of the present application.
[0147] Step 102: Determine the validity status of the first air interface key according to the first key validity information.
[0148] During implementation, after the first network element obtains the first air interface key and the first key validity information corresponding to the UE in the handover configuration corresponding to the UE, it can further determine the validity status of the first air interface key based on the first key validity information. The validity status includes valid and invalid. "Valid" can also be referred to as "guaranteed to be valid", or "validity is guaranteed", or "handover configuration is conditional"; "invalid" can also be referred to as "not guaranteed to be valid", or "validity is not guaranteed", or "ignoring the air interface key". The determination of the validity status of the first air interface key by the first network element based on the first key validity information will be described in detail later and will not be repeated here.
[0149] Step 103: Determine a target air interface key corresponding to the UE according to the validity status of the first air interface key.
[0150] During implementation, after the first network element determines the validity status of the first air interface key, it can further determine the target air interface key corresponding to the UE based on the validity status of the first air interface key. Afterwards, the first network element can perform access processing on the UE based on the target air interface key. The processing process of the first network element determining the target air interface key corresponding to the UE based on the validity status of the first air interface key will be described in detail later and will not be repeated here. In this way, the first network element, as the network element to be accessed by the UE, can determine the validity status of the air interface key based on the key validity information in the handover configuration. If the validity status of the air interface key is valid, the first network element can use it directly. If the validity status of the air interface key is invalid, the first network element can obtain the air interface key from the network element that the UE last accessed. This prevents the connection from being interrupted and unable to be quickly restored due to the inconsistency of the air interface keys used by the RAN node and the UE, thereby greatly improving the user experience.
[0151] As an optional implementation manner, the first key validity information includes one or more of validity indication information, security verification information, cell identity information or NCC.
[0152] In an implementation, the first key validity information may include one or more of validity indication information, security verification information, cell identity information, or NCC. The validity indication information may indicate the validity or invalidity of the air interface key in an explicit or implicit manner. The explicit manner directly indicates the validity or invalidity of the air interface key by carrying indication information. The implicit manner indicates the validity or invalidity of the air interface key by not carrying indication information.
[0153] As an optional implementation, when the first key validity information includes one or more of security verification information, cell identity information or NCC, the processing process of the first network element judging the validity status of the first air interface key based on the first key validity information is that the first network element judges the validity status of the first air interface key based on the first key validity information and the second key validity information carried in the access request sent by the UE.
[0154] In implementation, if the first key validity information includes security verification information, cell identity information, or NCC, the first network element cannot directly determine the validity status of the first air interface key based on the first key validity information. In this case, the first network element needs to determine the validity status of the first air interface key based on the first key validity information and the second key validity information carried in the access request sent by the UE.
[0155] For the security verification information, the first network element determines whether the security verification information in the handover configuration is the same as the security verification information carried in the access request sent by the UE. If they are the same, the first network element determines that the validity state of the first air interface key is valid. If they are not the same, the first network element determines that the validity state of the first air interface key is invalid. The security verification information in the handover configuration is generated based on the air interface key used for secure communication with the UE when other network elements request the first network element to generate or update the handover configuration. The security verification information carried in the access request sent by the UE is generated by the UE based on the air interface key used for secure communication with the network element accessed last time.
[0156] Regarding the cell identity information, the first network element determines whether the cell identity information in the handover configuration matches the cell identity information carried in the access request sent by the UE. If they match, the first network element determines that the validity status of the first air interface key is valid. If they do not match, the first network element determines that the validity status of the first air interface key is invalid. The cell identity information in the handover configuration is the cell identity information of the cell accessed by the UE, provided by another network element when requesting the first network element to generate or update the handover configuration. The cell identity information carried in the access request sent by the UE is the cell identity information of the cell in the network element that the UE last accessed.
[0157] For NCC, the first network element determines whether the NCC in the handover configuration is the same as the NCC carried in the access request sent by the UE. If they are the same, the first network element determines that the validity state of the first air interface key is valid. If they are not the same, the first network element determines that the validity state of the first air interface key is invalid. Among them, the NCC in the handover configuration is the NCC received from the core network for the UE when other network elements request the first network element to generate or update the handover configuration, and the next hop value indicated by the NCC is a direct or indirect input parameter of other network elements in the process of calculating the air interface key used by the UE for the next handover. The next hop value indicated by the NCC carried in the access request sent by the UE is a direct or indirect input parameter of the network element that the UE accessed last time in the process of calculating the air interface key used by the UE for the next handover.
[0158] As an optional implementation method, the first network element determines the processing process of the target air interface key corresponding to the UE based on the validity status of the first air interface key: if the validity status of the first air interface key is valid, the first air interface key is determined as the target air interface key corresponding to the UE; if the validity status of the first air interface key is invalid, the second air interface key is obtained from the network element to which the UE last accessed, and the second air interface key is determined as the target air interface key corresponding to the UE.
[0159] During implementation, after the first network element determines the validity status of the first air interface key, if the validity status of the first air interface key is valid, it means that the first air interface key can be used directly. Accordingly, the first network element can directly determine the first air interface key as the target air interface key corresponding to the UE. If the validity status of the first air interface key is invalid, it means that the first air interface key cannot be used directly. Accordingly, the first network element needs to obtain the second air interface key from the network element that the UE last accessed, and determine the second air interface key as the target air interface key corresponding to the UE. The network element that the UE last accessed was provided by the UE.
[0160] As an optional implementation, the first network element may also update the air interface key so that when the UE switches next time, other network elements can securely communicate with the UE based on the updated air interface key. Therefore, the first network element further performs the following steps: if the validity status of the first air interface key is valid, then after the UE switches this time, the first network element sends the third air interface key and third key validity information corresponding to the UE to other network elements; if the validity status of the first air interface key is invalid, then before the UE switches from the first network element to the target network element, the first network element sends the third air interface key and fourth key validity information corresponding to the UE to the target network element. The third key validity information includes one or more of validity indication information, security verification information, cell identity information, or NCC, and the fourth key validity information is validity indication information indicating that the validity status of the third air interface key is valid.
[0161] In implementation, if the validity status of the first air interface key is valid, the first network element adopts the key update strategy of "after each handover occurs, the target node of the handover immediately provides the updated security key to other target nodes". Accordingly, the first network element can directly send the third air interface key and third key validity information corresponding to the UE to other network elements after the UE switches this time. Among them, the third key validity information includes one or more of validity indication information, security verification information, cell identity information or NCC. If the validity status of the first air interface key is invalid, the first network element adopts the key update strategy of "after each handover occurs, the target node of the handover waits until the next handover is about to occur before providing the updated security key". Accordingly, before the UE switches from the first network element to the target network element, the first network element sends the third air interface key and fourth key validity information corresponding to the UE to the target network element. Among them, the fourth key validity information is validity indication information indicating that the validity status of the third air interface key is valid.
[0162] As an optional implementation, after the first network element determines the validity status of the first air interface key based on the first key validity information, it may also perform access verification on the UE through security verification information. The specific processing process is as follows: If the validity status of the first air interface key is valid, the security verification information corresponding to the UE is obtained in the handover configuration corresponding to the UE, and whether the UE meets the access conditions is determined based on the obtained security verification information and the security verification information carried in the access request sent by the UE. If the validity status of the first air interface key is invalid, the security verification information carried in the access request is sent to the network element that the UE last accessed.
[0163] In an implementation, if the validity status of the first air interface key is valid, the first network element obtains security verification information corresponding to the UE from the handover configuration corresponding to the UE. The first network element then determines whether the security verification information in the handover configuration is identical to the security verification information carried in the access request sent by the UE. If they are identical, the first network element determines that the UE meets the access conditions. If they are different, the first network element determines that the UE does not meet the access conditions.
[0164] If the validity status of the first air interface key is invalid, the first network element sends the security verification information carried in the access request to the network element to which the UE last accessed. The network element to which the UE last accessed calculates the security verification information based on the air interface key used for secure communication with the UE, and determines whether the security verification information is the same as the security verification information sent by the first network element. If they are the same, the network element to which the UE last accessed determines that the UE meets the access conditions. Correspondingly, the network element to which the UE last accessed sends the air interface key used by the first network element for secure communication with the UE to the first network element. If they are not the same, the network element to which the UE last accessed determines that the UE does not meet the access conditions.
[0165] As an optional implementation, before the first network element obtains the first air interface key and first key validity information corresponding to the UE in the switching configuration corresponding to the UE, the first network element receives the first air interface key and first key validity information corresponding to the UE sent by other network elements.
[0166] In implementation, when other network elements require the first network element to generate or update a handover configuration, the other network elements may send the first air interface key and first key validity information corresponding to the UE to the first network element. Correspondingly, the first network element may receive the first air interface key and first key validity information corresponding to the UE sent by the other network elements and generate or update the handover configuration.
[0167] As an optional implementation, when the first network element is a CU unit or CU-CP unit in a RAN node with CU / DU separation, after the first network element receives the first air interface key and first key validity information corresponding to the UE sent by other network elements, it can also send the first key validity information to the DU unit to which the wireless cell to which the UE is to be switched belongs.
[0168] During implementation, the first network element, as a CU(-CP) unit, sends a UE context establishment request message or a UE context modification request message to the DU unit. The UE context establishment request message and the UE context modification request message request the DU unit to prepare underlying configurations for the UE so that the UE can use them after accessing the DU unit. The UE context establishment request message and the UE context modification request message carry first key indication information, which indicates whether the first air interface key corresponding to the underlying configuration is valid or invalid; equivalently, the first key indication information indicates that after the UE accesses the cell controlled by the DU unit, the underlying configuration takes effect immediately, or cannot take effect immediately.
[0169] The embodiment of the present application also provides a method for processing an air interface key, which is applied to a second network element. The second network element is a DU unit in a RAN node with CU / DU separation. Figure 2 The specific processing process is as follows:
[0170] Step 201: Receive first key validity information corresponding to a UE, wherein the first key validity information is validity indication information indicating whether a first air interface key corresponding to an underlying configuration of the UE is valid.
[0171] In implementation, the DU unit receives a UE context establishment request message or a UE context modification request message sent by the CU(-CP) unit and carrying the first key validity information corresponding to the UE. The first key validity information is validity indication information indicating whether the first air interface key corresponding to the underlying configuration of the UE is valid. The DU unit feeds back a UE context establishment response message or a UE context modification response message to the CU(-CP) unit. The UE context establishment response message and the UE context modification response message carry the underlying configuration prepared by the DU unit for the UE.
[0172] Step 202: Apply the underlying configuration according to the first key validity information.
[0173] In implementation, after the DU unit receives the first key validity information corresponding to the UE sent by the receiving CU(-CP) unit, it can apply the underlying configuration according to the first key validity information.
[0174] As an optional implementation, the second unit applies the underlying configuration according to the first key validity information as follows: if the first key validity information indicates that the first air interface key is valid, then after the UE accesses the DU unit, the underlying configuration is applied and a DDDS frame is sent. If the first key validity information indicates that the first air interface key is invalid, then after the UE accesses the DU unit, the underlying configuration is applied according to the instructions of the CU unit or the CU-CP unit.
[0175] In implementation, if the first key validity information indicates that the first air interface key is valid, the DU unit can immediately apply the underlying configuration after the UE accesses the DU unit, and send a DDDS frame to the CU(-CP) unit. The DDDS frame is used to request the CU(-CP) unit to send downlink user data to the DU unit. The downlink user data is user data that is securely processed according to the first air interface key. If the first key validity information indicates that the first air interface key is invalid, after the UE accesses the DU unit, the second network element needs to apply the underlying configuration according to the CU(-CP) unit instruction after the CU(-CP) unit obtains the air interface key from the network element that the UE last accessed. In this way, if the key validity information indicates that the air interface key is valid, the second network element can directly apply the underlying configuration after the UE accesses the DU unit, thereby increasing the speed of sending downlink user data to the UE, thereby improving the user experience.
[0176] The embodiment of the present application also provides a method for processing an air interface key, which is applied to a third network element, such as Figure 3 The specific processing process is as follows:
[0177] Step 301: Send a handover request message to a target network element, wherein the handover request message carries a first air interface key corresponding to the UE and first key validity information.
[0178] In implementation, the third network element, acting as a source node, may send a handover request message to the target network element during the handover preparation phase. The handover request message carries the first air interface key corresponding to the UE and first key validity information. The first key validity information is used to indicate whether the first air interface key is valid or invalid.
[0179] As an optional implementation manner, the first key validity information includes one or more of validity indication information, security verification information, cell identity information or NCC.
[0180] In an implementation, the first key validity information may include one or more of validity indication information, security verification information, cell identity information, or NCC. The validity indication information may indicate the validity or invalidity of the air interface key in an explicit or implicit manner. The explicit manner directly indicates the validity or invalidity of the air interface key by carrying indication information. The implicit manner indicates the validity or invalidity of the air interface key by not carrying indication information.
[0181] As an optional implementation, if the validity status of the first air interface key is invalid, before the UE is handed over from the third network element to the target network element, the first air interface key and / or second key validity information corresponding to the UE is sent to the target network element. The second key validity information is validity indication information indicating that the validity status of the first air interface key is valid.
[0182] In implementation, if the validity status of the first air interface key is invalid, the third network element decides, learns or predicts that the UE is about to disconnect from the third network element before connecting to the target network element. The third network element can send an interface message to the target network element. The interface message can carry the first air interface key and / or the second key indication information. The second key indication information indicates that the first air interface key is valid. The processing of the target network element includes but is not limited to the following: (1) The interface message does not contain the first air interface key, and the target network element directly determines that the first air interface key is valid; (2) The interface message carries the first air interface key, and the target network element directly determines that the first air interface key is valid; (3) The interface message does not contain the first air interface key, but contains the second key indication information, and the target network element determines that the first air interface key is valid; (4) The interface message contains both the first air interface key and the second key indication information, and the target network element determines that the first air interface key is valid. In this way, the target network element, as the network element to be accessed by the UE, can judge the validity status of the air interface key based on the key validity information in the handover configuration. If the air interface key is valid, the target NE can use it directly. If the air interface key is invalid, the target NE can obtain the air interface key from the NE the UE last connected to. This prevents connection interruptions and inability to quickly recover due to inconsistent air interface keys between the target NE and the UE, significantly improving the user experience.
[0183] The present application provides seven specific embodiments, which are as follows:
[0184] In the first embodiment, the UE switches from node 1 to node 2 and then re-establishes access to node 3.
[0185] In scenario A, the key update strategy adopted by nodes 1, 2, and 3 is "after each switch occurs, the target node immediately provides the updated security key to other target nodes." Figure 4The specific processing process is as follows:
[0186] In steps 401a and 401b, the UE connects to node 1 via cell 1. Node 1 sends handover request messages to nodes 2 and 3, respectively. The handover request messages carry a first air interface key and first key indication information, where the first key indication information indicates that the first air interface key is valid. The handover request messages are used to request nodes 2 and 3 to generate or update a continuous handover configuration. Cell 2 in node 2 and cell 3 in node 3 are both potential target cells or candidate cells.
[0187] Step 402a and step 402b: Node 2 and node 3 respectively feed back a handover request confirmation message to node 1. The handover request confirmation message is used to indicate that the handover request sent by node 1 is accepted.
[0188] In step 403, the UE disconnects from node 1 and connects to node 2 through cell 2. The disconnection between the UE and node 1 may be performed by the UE under the instruction of node 1 or autonomously (including the situation where the UE is disconnected when the conditions indicated by node 1 are met, and also includes the situation where the connection with node 1 is accidentally disconnected due to a radio link failure). This step is not limited. In step 403, both the UE and the network change the air interface key used. Specifically, the UE autonomously calculates the first air interface key to be used subsequently. Since in step 401a, node 1 has indicated that the first air interface key is valid, at this time, node 2 directly activates the first air interface key for cell 2 provided by node 1 in step 401a.
[0189] In step 404, because node 1 indicated in step 401a that the first air interface key is valid, node 2 determines that node 1 adopts a key update policy whereby the target node immediately provides updated security keys to other target nodes after each handover. Node 2 adopts the same key update policy. Based on this, node 2 sends an interface message to node 3. The interface message carries the second air interface key and second key indication information, which indicates that the second air interface key is valid.
[0190] In step 405, the UE is disconnected from node 2 and connects to node 3 through cell 3 on its own. The disconnection between the UE and node 2 may be controlled or caused by an unexpected failure of the wireless link, which is not limited in this step. The process of the UE connecting to node 3 through cell 3 may be a connection reestablishment process, a connection recovery process, or other similar processes, which is not limited in this step. In step 405, both the UE and the network change the air interface key used. Specifically, the UE autonomously calculates the updated second air interface key. Since in step 404, node 2 indicates that the second air interface key is valid, at this time, node 3 directly activates the second air interface key provided by node 2 in step 404.
[0191] In scenario B, the key update strategy adopted by nodes 1, 2, and 3 is "after each handover, the target node will wait until the next handover is about to occur before providing the updated security key." Figure 5 The specific processing process is as follows:
[0192] In steps 501a and 501b, the UE connects to node 1 via cell 1. Node 1 sends handover request messages to nodes 2 and 3, respectively. The handover request messages carry a first air interface key and first key indication information, where the first key indication information indicates that the first air interface key is invalid. The handover request messages are used to request nodes 2 and 3 to generate or update a continuous handover configuration. Cell 2 in node 2 and cell 3 in node 3 are both potential target cells or candidate cells.
[0193] Step 502a and step 502b: Node 2 and node 3 respectively feed back a handover request confirmation message to node 1. The handover request confirmation message is used to indicate that the handover request sent by node 1 is accepted.
[0194] Step 503, when node 1 decides, learns or predicts that the UE is about to disconnect from node 1 and connect to node 2 through cell 2. Node 1 sends an interface message to node 2. The interface message may carry the first air interface key and / or the second key indication information, and the second key indication information indicates that the first air interface key is valid. The processing of node 2 includes but is not limited to the following: (1) The interface message in step 503 does not contain the first air interface key, and node 2 directly determines that the first air interface key provided in step 401a is valid; (2) The interface message in step 503 carries the first air interface key, and node 2 directly determines that the first air interface key is valid; (3) The interface message in step 503 does not contain the first air interface key, but contains the second key indication information, and node 2 determines that the first air interface key provided in step 501a is valid; (4) The interface message in step 503 contains both the first air interface key and the second key indication information, and node 2 determines that the first air interface key is valid.
[0195] In step 504, the UE disconnects from node 1 and connects to node 2 through cell 2. The UE's disconnection from node 1 can be performed by the UE under the instruction of node 1 or autonomously (including situations where the UE disconnects according to the conditions indicated by node 1 and the conditions are met; and also situations where the connection with node 1 is accidentally disconnected due to a radio link failure). This step is not limited. In step 503, both the UE and the network change the air interface key used. Specifically, the UE autonomously calculates the first air interface key to be used subsequently. Node 2, in accordance with the instructions of step 503, activates the first air interface key provided by node 1 in step 501a or step 503. Since node 1 did not indicate that the first air interface key was valid until step 503, node 2 determines that node 1 adopts the key update strategy of "after each handover, the target node of the handover waits until the next handover is about to occur before providing the updated security key." Node 2 also does not use the same key update strategy.
[0196] In step 505, the UE disconnects from node 2 and independently initiates a process to connect to node 3 through cell 3. The disconnection between the UE and node 2 may be controlled or caused by an unexpected failure of the radio link, which is not limited in this step. The process of the UE connecting to node 3 through cell 3 may be a connection reestablishment process, a connection recovery process, or other similar processes, which is not limited in this step. In step 505, the UE provides node 3 with information about the last time the UE connected to node 2 through cell 2. For example, the UE provides node 3 with the PCI (Physical Cell Identifier) of cell 2. It should be noted that the PCI alone cannot uniquely identify a cell in the neighboring cell list of cell 3, because there may be multiple cells with the same PCI in the neighboring cell list of cell 3, which is common in the case where "the frequencies of the SSBs (Synchronisation Signal Blocks) of these cells are different." In particular, the PCIs of cell 1 and cell 2 may be the same.
[0197] In step 506, since the last handover-related message received by node 3 was the handover request message in step 501b, and the first key indication information in the handover request message in step 501b indicates that the air interface key is invalid, node 3 sends a UE context extraction request message to node 2 based on the information provided by the UE in step 505 regarding the last connection between the UE and node 2 via cell 2. It should be noted that node 3 may not be able to determine cell 2 based on the information provided by the UE in step 505 regarding the last connection between the UE and node 2 via cell 2. Therefore, in addition to sending the UE context extraction request message to node 2, node 3 may also send the UE context extraction request message to other nodes. However, sending the UE context extraction request message to other nodes is doomed to fail.
[0198] In step 507, node 2 determines the second air interface key corresponding to the UE based on the Extract UE Context Request message sent by node 3 in step 506, and sends an Extract UE Context Response message to node 3. The Extract UE Context Response message carries the second air interface key. Node 3 then uses the second air interface key to complete the connection process with the UE and exchange signaling and / or service data with the UE using the second air interface key.
[0199] It should be noted that Node 1 and Node 2 can be different nodes or the same node. If Node 1 and Node 2 are the same node, the signaling interaction between Node 1 and Node 2 in the above scenarios A and B, as well as the inference process based on the signaling interaction, can be omitted.
[0200] In addition, the UE only changes its connected cell twice in scenarios A and B. In practice, for scenarios where the UE changes its connected cell more times, the processing procedures of the UE and the node are similar to those in scenarios A and B. In particular, the UE can also change its connected cell back and forth between multiple cells, for example, "cell 1 → cell 2 → cell 1 → cell 3".
[0201] In the second embodiment, node 1, node 2, and node 3 perform access verification on the UE through security verification information.
[0202] For scenario A in embodiment 1: Figure 4 As shown, in steps 401a and 401b, the handover request message carries, in addition to the first air interface key and first key indication information, first security verification information. The first security verification information is generated based on the air interface key used by node 1. In step 404, the interface message carries, in addition to the second air interface key and second key indication information, second security verification information. The second security verification information is also generated based on the first air interface key used by node 2. In step 405, the access request message sent by the UE carries third security verification information. The third security verification information is generated based on the first air interface key used by the UE the last time it accessed node 2. Therefore, in step 405, node 3 determines whether the third security verification information received in step 505 is identical to the second security verification information received in step 404. If they are identical, node 3 determines that the UE is allowed access. If they are not identical, node 3 determines that the UE is not allowed access.
[0203] For scenario B, if Figure 5 As shown, in steps 501a and 501b, the handover request message carries, in addition to the first air interface key and the first key indication information, first security verification information. The first security verification information is generated based on the first air interface key. In step 505, the access request message sent by the UE carries second security verification information. The second security verification information is generated based on the first air interface key used by the UE the last time it accessed node 2. In step 506, node 3 extracts the UE context message and sends the second security verification information to node 2. Accordingly, node 2 calculates third security verification information based on the first air interface key and determines whether the third security verification information is the same as the second security verification information. If they are the same, node 2 determines that the UE can access and executes step 507. If they are not the same, node 2 determines that the UE cannot access and does not execute step 507.
[0204] It should be noted that the security verification information in this embodiment is used to verify whether the access request message sent by the UE is valid. The security verification information can be called shortMAC-I or other variables.
[0205] Example 3: Node 3 is a CU / DU separated node, and cell 3 belongs to DU unit 1.
[0206] For scenario A in embodiment 1, Figure 4 On the basis of Figure 6 As shown, the CU(-CP) unit of node 3 performs the following steps between step 401b and step 402b and after step 404:
[0207] In step A1, the CU(-CP) unit of node 3 sends a UE context establishment request message or a UE context modification request message to DU unit 1. The UE context establishment request message and the UE context modification request message request DU unit 1 to prepare an underlying configuration for the UE so that the UE can use it after accessing DU unit 1. The UE context establishment request message and the UE context modification request message carry first key indication information, which indicates that the first air interface key corresponding to the underlying configuration is valid; or, equivalently, the first key indication information indicates that the UE accesses cell 3 and the underlying configuration can take effect immediately.
[0208] In step A2, the DU unit 1 feeds back a UE context establishment response message or a UE context modification response message to the CU(-CP) unit of the node 3. The UE context establishment response message and the UE context modification response message carry the underlying configuration prepared by the DU unit for the UE.
[0209] In step 405, DU unit 1 immediately applies the underlying configuration after the UE accesses cell 3. Specifically, DU unit 1 sends a DDDS frame to the CU(-CP) unit to inform the CU(-CP) unit that it can now send downlink user data to DU unit 1. The CU(-CP) unit immediately begins sending downlink user data to DU unit 1 in accordance with the DDDS instructions. The downlink user data is securely processed according to the first air interface key. Subsequently, DU unit 1 sends the downlink user data to the UE via the air interface.
[0210] For scenario B in embodiment 1, Figure 5 On the basis of Figure 7 As shown, the CU(-CP) unit of node 3 performs the following steps between step 501b and step 502b:
[0211] In step B1, the CU(-CP) unit of node 3 sends a UE context establishment request message or a UE context modification request message to DU unit 1. The UE context establishment request message and the UE context modification request message request DU unit 1 to prepare an underlying configuration for the UE so that the UE can use it after accessing DU unit 1. The UE context establishment request message and the UE context modification request message carry first key indication information, which indicates that the first air interface key corresponding to the underlying configuration is invalid; or, equivalently, the first key indication information indicates that the UE has accessed cell 3 and the underlying configuration cannot take effect immediately.
[0212] In step B2, the DU feeds back a UE context establishment response message or a UE context modification response message to the CU(-CP) unit of node 3. The UE context establishment response message and the UE context modification response message carry the underlying configuration prepared by the DU unit for the UE.
[0213] In step 505 , after the UE accesses cell 3 , DU unit 1 does not apply the underlying configuration immediately. Instead, it waits until steps 506 and 507 are completed, and then applies the underlying configuration according to the instruction of the CU(-CP) unit of node 3 .
[0214] In the fourth embodiment, node 2 changes the key update strategy.
[0215] For scenario A in embodiment 1, if Figure 4 As shown, Node 2 no longer uses the key update strategy of "after each handover, the target node immediately provides the updated security key to other target nodes." Instead, it adopts the key update strategy of "after each handover, the target node waits until the next handover is about to occur before providing the updated security key." In this case, the second key indication information carried in the interface message sent by Node 2 to Node 3 indicates that the second air interface key is invalid. The subsequent operations in Scenario A and Scenario B are interchangeable.
[0216] Embodiment 5: Determine whether the air interface key is valid through security verification information.
[0217] For scenario A and scenario B in embodiment 1, Figure 4 and Figure 5 As shown, steps 401a, 401b, 501a, 501b, and 404 do not carry key indication information, but carry security verification information. Accordingly, in steps 405 and 505, node 3 determines whether the air interface key is valid by comparing the security verification information. Specifically, in steps 405 or 505, node 3 compares the security verification information received in steps 405 or 505 with the security verification information corresponding to cell 3 received in steps 404 or 501b.
[0218] If the two are the same, the air interface key is determined to be valid, and the subsequent actions of step 405 are executed.
[0219] If the two are different, the air interface key is determined to be invalid, and the subsequent actions of step 505, as well as steps 506 and 507 are executed.
[0220] The security verification information provided by the UE is calculated based on the air interface key last used by the UE before executing step 405 or step 505, that is, calculated based on the air interface key used by the UE in cell 2. In scenario A, node 2 provides node 3 with security verification information calculated using the same method in step 404; in scenario B, the security verification information in node 3's handover configuration is calculated by node 1 in step 501b based on the air interface key used by the UE in cell 1, and is therefore different from the security verification information sent by the UE in step 505.
[0221] Embodiment 6: judging whether the air interface key is valid through the cell identity information.
[0222] For scenario A and scenario B in embodiment 1, Figure 4 and Figure 5 As shown, steps 401a, 401b, 501a, 501b, and 404 do not carry key indication information, but carry cell identity information. Accordingly, in steps 405 and 505, node 3 determines whether the air interface key is valid by comparing the cell identity information. Specifically, in steps 401b and 501b, node 1 provides node 3 with the cell identity information of cell 1. For example, the physical cell identifier of cell 1. In step 404, node 2 provides node 3 with the cell identity information of cell 2. For example, the physical cell identifier of cell 2. In steps 405 and 505, the UE provides node 3 with the cell identity information of the cell to which it was last connected, that is, the cell identity information of cell 2. For example, the physical cell identifier of cell 2.
[0223] In steps 405 and 505 , node 3 compares the cell identity information received in step 404 or step 501 b with the cell identity information of the cell to which the UE was last connected, received from the UE in steps 405 and 505 .
[0224] If the two match, the air interface key is determined to be valid, and the subsequent actions of step 405 are executed.
[0225] If the two do not match, the air interface key is determined to be invalid, and the subsequent actions of step 505, as well as steps 506 and 507 are executed.
[0226] The reason we use "match / dismatch" rather than "identical / different" is because the two cell identity information compared by node 3 may be of different types. For example, the cell identity information provided by nodes 1 and 2 to the UE is the CGI (Cell Global Identifier), while the UE provides the PCI. In this case, node 3 can query the PCI of the cell indicated by the CGI in its locally stored neighboring cell list and then determine whether the cell identity information matches by comparing the two PCIs.
[0227] Embodiment 7: Determine whether the air interface key is valid through NCC information.
[0228] For scenario A and scenario B in embodiment 1, Figure 4 and Figure 5 As shown, steps 401a, 401b, 501a, 501b, and 404 do not carry key indication information, but carry the NCC. Accordingly, in steps 405 and 505, node 3 determines whether the air interface key is valid by comparing the NCC information. Specifically, in steps 401b and 501b, node 1 provides node 3 with the NCC received from the core network for the UE. The next hop value (NH) indicated by the NCC is a direct or indirect input parameter for node 1 when calculating the air interface key to be used after the UE's next handover (i.e., the air interface key used by the UE when communicating securely with node 2). In step 404, node 2 provides node 3 with the NCC received from the core network for the UE. The next hop value indicated by the NCC is a direct or indirect input parameter for node 2 when calculating the air interface key to be used after the UE's next handover (i.e., the air interface key used by the UE when communicating securely with node 3). In step 405 and step 505, the next hop value indicated by the NCC provided by the UE to node 3 is a direct or indirect input parameter for node 2 in calculating the air interface key to be activated by the UE (ie, the air interface key used by the UE when communicating with node 3).
[0229] In step 405 and step 505 , node 3 compares the NCC value received in step 404 and step 501 b with the NCC value received from the UE in step 405 and step 505 .
[0230] If the two are the same, the air interface key is determined to be valid, and the subsequent actions of step 405 are executed.
[0231] If the two are different, the air interface key is determined to be invalid, and the subsequent actions of step 505, and steps 506 and 507 are executed.
[0232] The core network will provide different NCCs to different nodes, and will only repeat from the original value if the value exceeds the upper limit.
[0233] An embodiment of the present application provides a method for processing an air interface key, in which a first network element obtains a first air interface key and first key validity information corresponding to the UE in a handover configuration corresponding to the UE; determines the validity status of the first air interface key based on the first key validity information; and determines a target air interface key corresponding to the UE based on the validity status of the first air interface key. In this way, the first network element, as the network element to be accessed by the UE, can determine the validity status of the air interface key based on the key validity information in the handover configuration. If the validity status of the air interface key is valid, the first network element can use it directly. If the validity status of the air interface key is invalid, the first network element can obtain the air interface key from the network element to which the UE last accessed. This prevents connection interruption and inability to quickly recover due to inconsistency between the air interface keys used by the RAN node and the UE, thereby greatly improving user experience.
[0234] It can be understood that the same / similar parts between the various embodiments of the above method in this specification can be referred to each other, and each embodiment focuses on the differences from other embodiments. For related parts, please refer to the description of other method embodiments.
[0235] The embodiment of the present application also provides a first network element, such as Figure 8 As shown, it includes a memory 810, a transceiver 820, and a processor 830;
[0236] The memory 810 is used to store computer programs; the transceiver 820 is used to send and receive data under the control of the processor 830; and the processor 830 is used to read the computer program in the memory 810 and perform the following operations:
[0237] In the handover configuration corresponding to the UE, obtaining the first air interface key and first key validity information corresponding to the UE;
[0238] Determining the validity status of the first air interface key according to the first key validity information;
[0239] A target air interface key corresponding to the UE is determined according to the validity status of the first air interface key.
[0240] As an optional implementation manner, the first key validity information includes one or more of validity indication information, security verification information, cell identity information or NCC.
[0241] As an optional implementation manner, when the first key validity information includes one or more of security verification information, cell identity information, or NCC, judging the validity status of the first air interface key according to the first key validity information includes:
[0242] The validity status of the first air interface key is determined according to the first key validity information and the second key validity information carried in the access request sent by the UE.
[0243] As an optional implementation manner, determining the target air interface key corresponding to the UE according to the validity status of the first air interface key includes:
[0244] If the validity state of the first air interface key is valid, determining the first air interface key as the target air interface key corresponding to the UE;
[0245] If the validity status of the first air interface key is invalid, a second air interface key is obtained from the network element that the UE last accessed, and the second air interface key is determined as a target air interface key corresponding to the UE.
[0246] As an optional implementation manner, the processor 830 is further configured to read the computer program in the memory and perform the following operations:
[0247] If the validity status of the first air interface key is valid, after the UE is switched this time, the third air interface key and the third key validity information corresponding to the UE are sent to other network elements;
[0248] If the validity status of the first air interface key is invalid, before the UE is handed over from the first network element to the target network element, sending the validity information of the third air interface key and the fourth key corresponding to the UE to the target network element;
[0249] The third key validity information includes one or more of validity indication information, security verification information, cell identity information or NCC, and the fourth key validity information is validity indication information indicating that the validity status of the third air interface key is valid.
[0250] As an optional implementation manner, the processor 830 is further configured to read the computer program in the memory and perform the following operations:
[0251] If the validity state of the first air interface key is valid, obtaining security verification information corresponding to the UE in the handover configuration corresponding to the UE, and determining whether the UE meets the access condition based on the obtained security verification information and the security verification information carried in the access request sent by the UE;
[0252] If the validity status of the first air interface key is invalid, the security verification information carried in the access request is sent to the network element that the UE accessed last time.
[0253] As an optional implementation manner, in the handover configuration corresponding to the UE, before obtaining the first air interface key and the first key validity information corresponding to the UE, the processor 830 is further configured to read the computer program in the memory and perform the following operations:
[0254] Receive a first air interface key and first key validity information corresponding to the UE sent by other network elements; wherein the first key validity information is validity indication information indicating whether the first air interface key is valid.
[0255] As an optional implementation manner, when the first network element is a CU unit or a CU-CP unit in a RAN node with CU / DU separation, the processor 830 is further configured to read a computer program in a memory and perform the following operations:
[0256] The first key validity information is sent to the DU unit to which the wireless cell to which the UE is to be handed over belongs.
[0257] The embodiment of the present application also provides a second network element, such as Figure 9 As shown, the second network element is a DU unit in a RAN node with CU / DU separation, including a memory 910, a transceiver 920, and a processor 930;
[0258] The memory 910 is used to store computer programs; the transceiver 920 is used to send and receive data under the control of the processor 930; and the processor 930 is used to read the computer program in the memory 910 and perform the following operations:
[0259] Receiving first key validity information corresponding to the UE, where the first key validity information is validity indication information indicating whether a first air interface key corresponding to an underlying configuration of the UE is valid;
[0260] Based on the first key validity information, an underlying configuration is applied.
[0261] As an optional implementation, based on the first key validity information, applying the underlying configuration includes:
[0262] If the first key validity information indicates that the first air interface key is valid, after the UE accesses the DU unit, the underlying configuration is applied and a DDDS frame is sent;
[0263] If the first key validity information indicates that the first air interface key is invalid, after the UE accesses the DU unit, the underlying configuration is applied according to the instruction of the CU unit or the CU-CP unit.
[0264] The embodiment of the present application also provides a third network element, such as Figure 10 As shown, it includes a memory 1010, a transceiver 1020, and a processor 1030;
[0265] The memory 1010 is used to store computer programs; the transceiver 1020 is used to send and receive data under the control of the processor 1030; and the processor 1030 is used to read the computer program in the memory 1010 and perform the following operations:
[0266] Sending a handover request message to the target network element; wherein the handover request message carries a first air interface key and first key validity information corresponding to the user equipment UE.
[0267] As an optional implementation manner, the first key validity information includes one or more of validity indication information, security verification information, cell identity information or next hop chain count value NCC.
[0268] As an optional implementation manner, the processor 1030 is further configured to read the computer program in the memory and perform the following operations:
[0269] If the validity status of the first air interface key is invalid, before the UE switches from the third network element to the target network element, the first air interface key and / or second key validity information corresponding to the UE is sent to the target network element; wherein, the second key validity information is validity indication information indicating that the validity status of the first air interface key is valid.
[0270] The embodiment of the present application provides a device for processing an air interface key, such as Figure 11 As shown, the device is applied to a first network element, and the device includes:
[0271] The acquiring unit 1110 is configured to acquire, in a handover configuration corresponding to the UE, a first air interface key and first key validity information corresponding to the UE;
[0272] The first determining unit 1120 is configured to determine a validity status of the first air interface key according to the first key validity information;
[0273] The determining unit 1130 is configured to determine a target air interface key corresponding to the UE according to a validity status of the first air interface key.
[0274] As an optional implementation manner, the first key validity information includes one or more of validity indication information, security verification information, cell identity information or NCC.
[0275] As an optional implementation manner, when the first key validity information includes one or more of security verification information, cell identity information, or NCC, the first judgment unit is specifically configured to:
[0276] The validity status of the first air interface key is determined according to the first key validity information and the second key validity information carried in the access request sent by the UE.
[0277] As an optional implementation manner, the determining unit is specifically configured to:
[0278] If the validity state of the first air interface key is valid, determining the first air interface key as the target air interface key corresponding to the UE;
[0279] If the validity status of the first air interface key is invalid, a second air interface key is obtained from the network element that the UE last accessed, and the second air interface key is determined as a target air interface key corresponding to the UE.
[0280] As an optional embodiment, the device further includes:
[0281] The first sending unit is configured to send, if the validity state of the first air interface key is valid, a third air interface key and third key validity information corresponding to the UE to other network elements after the UE is switched this time;
[0282] The second sending unit is configured to send, if the validity state of the first air interface key is invalid, the third air interface key and the fourth key validity information corresponding to the UE to the target network element before the UE is switched from the first network element to the target network element;
[0283] The third key validity information includes one or more of validity indication information, security verification information, cell identity information or NCC, and the fourth key validity information is validity indication information indicating that the validity status of the third air interface key is valid.
[0284] As an optional embodiment, the device further includes:
[0285] The second judgment unit is configured to obtain security verification information corresponding to the UE in the handover configuration corresponding to the UE if the validity state of the first air interface key is valid, and determine whether the UE meets the access condition based on the obtained security verification information and the security verification information carried in the access request sent by the UE;
[0286] The third sending unit is configured to send the security verification information carried in the access request to the network element that the UE last accessed if the validity status of the first air interface key is invalid.
[0287] As an optional embodiment, the device further includes:
[0288] The receiving unit is configured to receive a first air interface key and first key validity information corresponding to the UE sent by other network elements; wherein the first key validity information is validity indication information indicating whether the first air interface key is valid.
[0289] As an optional implementation manner, when the first network element is a CU unit or a CU-CP unit in a RAN node with CU / DU separation, the apparatus further includes:
[0290] The fourth sending unit is configured to send the first key validity information to the DU unit to which the wireless cell to which the UE is to be switched belongs.
[0291] The embodiment of the present application provides a device for processing an air interface key, such as Figure 12 As shown, the device is applied to a second network element, which is a DU unit in a RAN node with CU / DU separation; the device includes:
[0292] The receiving unit 1210 is configured to receive first key validity information corresponding to the UE, where the first key validity information is validity indication information indicating whether a first air interface key corresponding to an underlying configuration of the UE is valid;
[0293] The applying unit 1220 is configured to apply the underlying configuration according to the first key validity information.
[0294] As an optional implementation manner, the application unit is specifically configured to:
[0295] If the first key validity information indicates that the first air interface key is valid, after the UE accesses the DU unit, the underlying configuration is applied and a DDDS frame is sent;
[0296] If the first key validity information indicates that the first air interface key is invalid, after the UE accesses the DU unit, the underlying configuration is applied according to the instruction of the CU unit or the CU-CP unit.
[0297] The embodiment of the present application provides a device for processing an air interface key, such as Figure 13 As shown, the device is applied to a third network element, and the device includes:
[0298] The first sending unit 1310 is configured to send a handover request message to a target network element; wherein the handover request message carries a first air interface key and first key validity information corresponding to the UE.
[0299] As an optional implementation manner, the first key validity information includes one or more of validity indication information, security verification information, cell identity information or NCC.
[0300] As an optional embodiment, the device further includes:
[0301] The second sending unit is used to send the first air interface key and / or second key validity information corresponding to the UE to the target network element before the UE switches from the third network element to the target network element if the validity status of the first air interface key is invalid; wherein the second key validity information is validity indication information indicating that the validity status of the first air interface key is valid.
[0302] An embodiment of the present application provides a communication system, comprising a first network element, a second network element, and a third network element. The first network element executes the steps of the method for processing an air interface key executed by the first network element, the second network element executes the steps of the method for processing an air interface key executed by the second network element, and the third network element executes the steps of the method for processing an air interface key executed by the third network element.
[0303] It should be noted that the division of units in the embodiments of the present application is schematic and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0304] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) or a processor to execute all or part of the steps of the method described in each embodiment of the present application.
[0305] It should be noted here that the above-mentioned device provided by the embodiment of the present invention can implement all the method steps implemented by the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects that are the same as the method embodiment in this embodiment will not be described in detail here.
[0306] An embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the above-mentioned air interface key processing method are implemented.
[0307] The processor-readable storage medium can be any available medium or data storage device that can be accessed by the processor, including but not limited to magnetic storage (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO)), optical storage (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (such as ROMs, EPROMs, EEPROMs, non-volatile memories (NANDFLASH), solid-state drives (SSDs)), etc.
[0308] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage and optical storage, etc.) that contain computer-usable program code.
[0309] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0310] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the processor-readable memory produce an article of manufacture comprising an instruction device that implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0311] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.
Claims
1. A method for processing an air interface key, characterized in that: The method is applied to a first network element, and the method includes: In a handover configuration corresponding to a user equipment UE, obtaining a first air interface key and first key validity information corresponding to the UE; Determining, according to the first key validity information, a validity status of the first air interface key; Determine a target air interface key corresponding to the UE according to a validity status of the first air interface key.
2. The method according to claim 1, characterized in that The first key validity information includes one or more of validity indication information, security verification information, cell identity information or next hop chain count value NCC.
3. The method according to claim 2, characterized in that In a case where the first key validity information includes one or more of security verification information, cell identity information, or NCC, the determining, according to the first key validity information, a validity status of the first air interface key includes: The validity status of the first air interface key is determined according to the first key validity information and the second key validity information carried in the access request sent by the UE.
4. The method according to claim 1, wherein The determining, according to the validity status of the first air interface key, a target air interface key corresponding to the UE includes: If the validity state of the first air interface key is valid, determining the first air interface key as a target air interface key corresponding to the UE; If the validity status of the first air interface key is invalid, obtaining a second air interface key from the network element that the UE last accessed, and determining the second air interface key as a target air interface key corresponding to the UE.
5. The method according to claim 1, wherein The method further comprises: If the validity state of the first air interface key is valid, after the UE is switched this time, sending the third air interface key and third key validity information corresponding to the UE to other network elements; If the validity state of the first air interface key is invalid, before the UE is handed over from the first network element to the target network element, sending validity information of a third air interface key and a fourth key corresponding to the UE to the target network element; The third key validity information includes one or more of validity indication information, security verification information, cell identity information or NCC, and the fourth key validity information is validity indication information indicating that the validity status of the third air interface key is valid.
6. The method according to claim 1, characterized in that After determining the validity status of the first air interface key according to the first key validity information, the method further includes: If the validity state of the first air interface key is valid, obtaining security verification information corresponding to the UE in the handover configuration corresponding to the UE, and determining whether the UE meets the access condition according to the obtained security verification information and the security verification information carried in the access request sent by the UE; If the validity status of the first air interface key is invalid, the security verification information carried in the access request is sent to the network element that the UE last accessed.
7. The method according to claim 1, characterized in that Before obtaining the first air interface key and first key validity information corresponding to the UE in the handover configuration corresponding to the UE, the method further includes: Receive the first air interface key and first key validity information corresponding to the UE sent by other network elements.
8. The method according to claim 7, characterized in that In a case where the first network element is a CU unit or a central unit control plane CU-CP unit in a radio access network RAN node with separate central unit / distributed unit CU / DU, the method further includes: The first key validity information is sent to the DU unit to which the wireless cell to which the UE is to be switched belongs; wherein the first key validity information is validity indication information indicating whether the first air interface key is valid.
9. A method for processing an air interface key, characterized in that: The method is applied to a second network element, where the second network element is a DU unit in a radio access network RAN node with a separate central unit / distributed unit CU / DU. The method includes: Receiving first key validity information corresponding to a user terminal UE; wherein the first key validity information is validity indication information indicating whether a first air interface key corresponding to an underlying configuration of the UE is valid; The underlying configuration is applied according to the first key validity information.
10. The method according to claim 9, characterized in that The applying the underlying configuration according to the first key validity information includes: If the first key validity information indicates that the first air interface key is valid, after the UE accesses the DU unit, applying the underlying configuration and sending a downlink data transmission status DDDS frame; If the first key validity information indicates that the first air interface key is invalid, after the UE accesses the DU unit, the underlying configuration is applied according to the instruction of the CU unit or the CU-CP unit.
11. A method for processing an air interface key, characterized in that: The method is applied to a third network element, and the method includes: Sending a handover request message to the target network element; wherein the handover request message carries a first air interface key and first key validity information corresponding to the user equipment UE.
12. The method according to claim 11, characterized in that The first key validity information includes one or more of validity indication information, security verification information, cell identity information or next hop chain count value NCC.
13. The method according to claim 11, characterized in that The method further comprises: If the validity status of the first air interface key is invalid, before the UE switches from the third network element to the target network element, the first air interface key and / or second key validity information corresponding to the UE is sent to the target network element; wherein, the second key validity information is validity indication information indicating that the validity status of the first air interface key is valid.
14. A first network element, characterized in that: including memory, transceiver and processor; The memory is used to store a computer program; the transceiver is used to send and receive data under the control of the processor; and the processor is used to read the computer program in the memory and perform the following operations: In a handover configuration corresponding to a user equipment UE, obtaining a first air interface key and first key validity information corresponding to the UE; Determining, according to the first key validity information, a validity status of the first air interface key; Determine a target air interface key corresponding to the UE according to a validity status of the first air interface key.
15. The first network element according to claim 14, characterized in that: The first key validity information includes one or more of validity indication information, security verification information, cell identity information or next hop chain count value NCC.
16. The first network element according to claim 15, characterized in that: In a case where the first key validity information includes one or more of security verification information, cell identity information, or NCC, the determining, according to the first key validity information, a validity status of the first air interface key includes: The validity status of the first air interface key is determined according to the first key validity information and the second key validity information carried in the access request sent by the UE.
17. The first network element according to claim 14, characterized in that: The determining, according to the validity status of the first air interface key, a target air interface key corresponding to the UE includes: If the validity state of the first air interface key is valid, determining the first air interface key as a target air interface key corresponding to the UE; If the validity status of the first air interface key is invalid, obtaining a second air interface key from the network element that the UE last accessed, and determining the second air interface key as a target air interface key corresponding to the UE.
18. The first network element according to claim 14, characterized in that: The processor is further configured to read the computer program in the memory and perform the following operations: If the validity state of the first air interface key is valid, after the UE is switched this time, sending the third air interface key and third key validity information corresponding to the UE to other network elements; If the validity state of the first air interface key is invalid, before the UE is handed over from the first network element to the target network element, sending validity information of a third air interface key and a fourth key corresponding to the UE to the target network element; The third key validity information includes one or more of validity indication information, security verification information, cell identity information or NCC, and the fourth key validity information is validity indication information indicating that the validity status of the third air interface key is valid.
19. The first network element according to claim 14, characterized in that The processor is further configured to read the computer program in the memory and perform the following operations: If the validity state of the first air interface key is valid, obtaining security verification information corresponding to the UE in the handover configuration corresponding to the UE, and determining whether the UE meets the access condition according to the obtained security verification information and the security verification information carried in the access request sent by the UE; If the validity status of the first air interface key is invalid, the security verification information carried in the access request is sent to the network element that the UE last accessed.
20. The first network element according to claim 14, wherein: Before obtaining the first air interface key and the first key validity information corresponding to the UE in the handover configuration corresponding to the UE, the processor is further configured to read the computer program in the memory and perform the following operations: Receive the first air interface key and first key validity information corresponding to the UE sent by other network elements.
21. The first network element according to claim 20, characterized in that: In a case where the first network element is a CU unit or a central unit control plane CU-CP unit in a radio access network RAN node with separate central unit / distributed unit CU / DU, the processor is further configured to read a computer program in the memory and perform the following operations: The first key validity information is sent to the DU unit to which the wireless cell to which the UE is to be switched belongs; wherein the first key validity information is validity indication information indicating whether the first air interface key is valid.
22. A second network element, characterized in that: The second network element is a DU unit in a radio access network RAN node with a separate central unit / distributed unit CU / DU, and the second network element includes a memory, a transceiver and a processor; The memory is used to store a computer program; the transceiver is used to send and receive data under the control of the processor; and the processor is used to read the computer program in the memory and perform the following operations: Receiving first key validity information corresponding to a user terminal UE; wherein the first key validity information is validity indication information indicating whether a first air interface key corresponding to an underlying configuration of the UE is valid; The underlying configuration is applied according to the first key validity information.
23. The second network element according to claim 22, characterized in that: The applying the underlying configuration according to the first key validity information includes: If the first key validity information indicates that the first air interface key is valid, after the UE accesses the DU unit, applying the underlying configuration and sending a downlink data transmission status DDDS frame; If the first key validity information indicates that the first air interface key is invalid, after the UE accesses the DU unit, the underlying configuration is applied according to the instruction of the CU unit or the CU-CP unit.
24. A third network element, characterized in that: including memory, transceiver and processor; The memory is used to store a computer program; the transceiver is used to send and receive data under the control of the processor; and the processor is used to read the computer program in the memory and perform the following operations: Sending a handover request message to the target network element; wherein the handover request message carries a first air interface key and first key validity information corresponding to the user equipment UE.
25. The third network element according to claim 24, characterized in that: The first key validity information includes one or more of validity indication information, security verification information, cell identity information or next hop chain count value NCC.
26. The third network element according to claim 24, characterized in that: The processor is further configured to read the computer program in the memory and perform the following operations: If the validity status of the first air interface key is invalid, before the UE switches from the third network element to the target network element, the first air interface key and / or second key validity information corresponding to the UE is sent to the target network element; wherein, the second key validity information is validity indication information indicating that the validity status of the first air interface key is valid.
27. A device for processing an air interface key, characterized in that: The device is applied to a first network element, and includes: An acquiring unit, configured to acquire, in a handover configuration corresponding to a user equipment UE, a first air interface key and first key validity information corresponding to the UE; A first judging unit, configured to judge a validity status of the first air interface key according to the first key validity information; The determining unit is configured to determine a target air interface key corresponding to the UE according to a validity status of the first air interface key.
28. An air interface key processing device, characterized in that: The device is applied to a second network element, which is a DU unit in a radio access network RAN node with a separate central unit / distributed unit CU / DU; the device includes: A receiving unit, configured to receive first key validity information corresponding to a user terminal UE; wherein the first key validity information is validity indication information indicating whether a first air interface key corresponding to an underlying configuration of the UE is valid; An application unit, configured to apply the underlying configuration according to the first key validity information.
29. An air interface key processing device, characterized in that: The device is applied to a third network element, and includes: The first sending unit is configured to send a handover request message to a target network element; wherein the handover request message carries a first air interface key and first key validity information corresponding to the user equipment UE.
30. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method of any one of claims 1 to 8, or claims 9 to 10, or claims 11 to 13 are implemented.