Method and device for encryption in wireless communication

By using different key encryption methods for different PDCP entities in the 5G communication system, the security and flexibility issues of the terminal user plane radio bearer are solved, and more efficient LTM cell handover and data communication continuity are achieved.

CN120916145APending Publication Date: 2025-11-07SHANGHAI LANGBO COMM TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410545736.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-04-30
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

In 5G communication systems, the current technology of using only one key for all radio bearers in the user plane of a terminal is not secure or flexible enough, and cannot meet the needs of different PDCP entities.

Method used

Different PDCP entities are encrypted with different keys to ensure that each PDCP entity corresponds to a different DRB, and the key belongs to the security context of the master node, supporting multiple network nodes and base stations to connect to the same terminal.

Benefits of technology

It improves communication flexibility and security, supports shorter LTM cell handover latency, enhances data communication continuity and system stability, and reduces network complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120916145A_ABST
    Figure CN120916145A_ABST
Patent Text Reader

Abstract

Disclosed are a method and device for encryption in wireless communication, comprising: receiving a first signaling, the first signaling configuring a first PDCP entity and a second PDCP entity, the first PDCP entity being encrypted by using a first key, the second PDCP entity being encrypted by using a second key, both the first key and the second key belong to a security context of a master node; the first PDCP entity and the second PDCP entity are both corresponding to a DRB (Data Radio Bearer); wherein the first PDCP entity and the second PDCP entity are different from each other; the first secret key is different from the second secret key; the first secret key and the second secret key both belong to the security context of the main node, and the meaning is that the first secret key and the second secret key belong to one security context aiming at the main node, or the first secret key and the second secret key respectively belong to two security contexts aiming at the main node. The method can reduce the time delay, improves the continuity, and is safer and more flexible.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to a method for encryption in a cellular wireless communication system. BACKGROUND

[0002] The application scenarios of future wireless communication systems are increasingly diversified, and different application scenarios have different performance requirements for systems. In order to meet the different performance requirements of various application scenarios, it is decided at the 72nd plenary meeting of 3GPP (3rd Generation Partnership Project) RAN (Radio Access Network) to study New Radio (NR) (or Fifth Generation, 5G), and the NR WI (Work Item) is passed at the 75th plenary meeting of 3GPP RAN, and the standardization work of NR begins.

[0003] In communication, whether it is LTE (Long Term Evolution) or 5G NR, it involves accurate reception of reliable information, optimized energy efficiency, determination of information effectiveness, flexible resource allocation, scalable system structure, efficient non-access layer information processing, low service interruption and drop rate, support for low power consumption, which is of great significance to the normal communication of base stations and user equipment, reasonable scheduling of resources, balancing of system load. It can be said that it is the cornerstone of high throughput, meeting the communication needs of various services, improving spectrum utilization, and improving service quality. Whether it is eMBB (enhanced Mobile BroadBand), URLLC (Ultra Reliable Low Latency Communication) or eMTC (enhanced Machine Type Communication) is indispensable. At the same time, in IIoT (Industrial Internet of Things), in V2X (Vehicular to X) communication, in Device to Device communication, in unlicensed spectrum communication, in user communication quality monitoring, in network planning optimization, in TN (Territerial Network) communication, in dual connectivity system, in wireless resource management and multi-antenna codebook selection, in signaling design, neighbor management, service management, and in beamforming, there are extensive demands. The transmission mode of information is divided into broadcast and unicast, and both transmission modes are essential for 5G systems because they are very helpful in meeting the above requirements.

[0004] With the increasing complexity and scenarios of the system, higher requirements are put forward for reducing the interruption rate, reducing the delay, enhancing the reliability, enhancing the stability of the system, the flexibility of the service, and the power saving. At the same time, when designing the system, the compatibility between different systems and different versions also needs to be considered. SUMMARY

[0005] Researchers have found that in a 5G communication system, under normal circumstances, including scenarios that do not use dual connectivity, all radio bearers of the user plane of a terminal use only one key. Researchers have found that this is not secure enough and not flexible enough, and is a problem that needs to be solved.

[0006] In view of the above problems, the present application provides a solution.

[0007] It should be noted that the embodiments in any node and the features in the embodiments of the present application can be applied to any other node without conflict. The embodiments and the features in the embodiments of the present application can be combined with each other without conflict. At the same time, the method proposed in the present application can also be used to solve other problems in communication, such as problems in NR evolution and 6G system.

[0008] As an embodiment, the explanation of the terminology in the present application refers to the definition of the specification agreement TS38 series of 3GPP.

[0009] As an embodiment, the explanation of the terminology in the present application refers to the definition of the specification agreement TS37 series of 3GPP.

[0010] The present application discloses a method used in a first node for wireless communication, comprising:

[0011] Receiving first signaling, the first signaling configures a first PDCP entity and a second PDCP entity, wherein the first PDCP entity uses a first key for encryption, the second PDCP entity uses a second key for encryption, and the first key and the second key both belong to a security context of a master node (MN); the first PDCP entity and the second PDCP entity both correspond to a DRB;

[0012] Wherein, the first PDCP entity and the second PDCP entity are different; the first key and the second key are different; the meaning that the first key and the second key both belong to the security context of the master node is that the first key and the second key belong to one security context for the master node, or the first key and the second key respectively belong to two security contexts for the master node.

[0013] As an embodiment, the problem to be solved by the present application includes: how to use different keys for encryption for different PDCP entities.

[0014] As an embodiment, the benefits of the above method include: more flexible, more secure, better support for hardware sharing, better support for LTM cell switching, better support for inter-CU (inter control unit) and inter-DU (inter data unit) switching.

[0015] Specifically, according to one aspect of the present application, the first PDCP entity corresponds to a first DRB, and the second PDCP entity corresponds to a second DRB.

[0016] Specifically, according to an aspect of the present application, the peer PDCP entity of the first PDCP entity and the second PDCP entity is maintained by a same cell.

[0017] Specifically, according to an aspect of the present application, the first PDCP entity corresponds to a first DRB, the first PDCP entity corresponds to a second DRB, the first DRB and the second DRB serve a same service, and the serving the same service comprises: a same QoS flow being mapped to the first DRB and the second DRB.

[0018] Specifically, according to an aspect of the present application, first information is sent, the first information requests to release one of the first DRB and the second DRB, or the first information indicates that transmission on one of the first DRB and the second DRB is completed; wherein the first PDCP entity corresponds to a first DRB, and the first PDCP entity corresponds to a second DRB.

[0019] Specifically, according to an aspect of the present application, whether the first key and the second key belong to one security context of the master node or two security contexts of the master node depends on a generation mode of the first key and the second key.

[0020] Specifically, according to an aspect of the present application, the first signaling configures K PDCP entities, K is greater than 2, wherein the K PDCP entities comprise the first PDCP entity and the second PDCP entity, the K PDCP entities are encrypted using K keys respectively, and the K keys all belong to a security context of the master node.

[0021] Specifically, according to an aspect of the present application, the peer PDCP entity of the first PDCP entity and the second PDCP entity is maintained by a first cell and a second cell respectively.

[0022] Specifically, according to an aspect of the present application, the first cell and the second cell are a source cell and a target cell respectively.

[0023] Specifically, according to an aspect of the present application, the first PDCP entity and the second PDCP entity are served by a first RLC entity respectively.

[0024] Specifically, according to an aspect of the present application, the first PDCP entity and the second PDCP entity are served by a first RLC entity and a second RLC entity respectively.

[0025] Specifically, according to an aspect of the present application, the first node is an Internet of Things terminal.

[0026] Specifically, according to an aspect of the present application, the first node is a user equipment.

[0027] Specifically, according to an aspect of the present application, the first node is a vehicle terminal.

[0028] Specifically, according to an aspect of the present application, the first node is a mobile phone.

[0029] The present application discloses a first node used in wireless communication, comprising:

[0030] a first receiver, configured to receive first signaling, the first signaling configuring a first PDCP entity and a second PDCP entity, wherein the first PDCP entity is encrypted using a first key, the second PDCP entity is encrypted using a second key, and the first key and the second key both belong to a security context of a master node (MN) ; the first PDCP entity and the second PDCP entity both correspond to a DRB;

[0031] wherein the first PDCP entity and the second PDCP entity are different; the first key and the second key are different; and the first key and the second key both belonging to the security context of the master node means that the first key and the second key belong to one security context for the master node, or the first key and the second key respectively belong to two security contexts for the master node.

[0032] As an embodiment, compared with the conventional scheme, the present application has the following advantages:

[0033] Since different keys are controlled by different network entities, supporting different PDCP entities using different keys is beneficial to enhance flexibility, allowing a terminal to connect multiple network nodes, or allowing a base station to connect different network control entities to serve the same terminal.

[0034] Meanwhile, security is increased, and different network entities can not need to transfer keys.

[0035] The continuity of data communication is improved, and wireless bearers serving the same QoS flow or the same PDU session can use different keys.

[0036] The inter-CU and inter-Du LTM (L1L2 Triggered Mobility) cell handover can be better supported. Compared with the traditional cell handover, the LTM cell handover has shorter latency, especially the non-RACH LTM. The main difference between the non-RACH LTM and the RACH-based LTM is that the non-RACH LTM does not use and does not need the RACH procedure, which is conducive to further shortening the LTM cell handover latency; the RACH-based LTM needs the RACH procedure. However, the reconstruction of the PDCP entity and the replacement of the key weaken the advantages of the LTM, and the present application is conducive to fully exerting the advantages of the LTM and reducing the handover latency.

[0037] The present application is conducive to balancing the complexity of the network and the handover performance. BRIEF DESCRIPTION OF DRAWINGS

[0038] Other features, objects, and advantages of the present application will become more apparent from the following detailed description of non-limiting embodiments thereof, read in conjunction with the accompanying drawings:

[0039] Figure 1 A schematic diagram of receiving first signaling according to one embodiment of the present application is shown;

[0040] Figure 2 A schematic diagram of a network architecture according to one embodiment of the present application is shown;

[0041] Figure 3 A schematic diagram of an embodiment of a wireless protocol architecture of a user plane and a control plane according to one embodiment of the present application is shown;

[0042] Figure 4 A schematic diagram of a first communication device and a second communication device according to one embodiment of the present application is shown;

[0043] Figure 5 A flowchart of wireless signal transmission according to one embodiment of the present application is shown;

[0044] Figure 6 A flowchart of a first PDCP entity and a second PDCP entity according to one embodiment of the present application is shown;

[0045] Figure 7 A schematic diagram of a first PDCP entity and a second PDCP entity according to one embodiment of the present application is shown;

[0046] Figure 8The diagram illustrates whether the first key and the second key, according to an embodiment of this application, belong to one security context for the master node or two security contexts for the master node, depending on how the first key and the second key are generated.

[0047] Figure 9 A schematic diagram of a processing apparatus for a first node according to an embodiment of this application is illustrated. Implementation

[0048] The technical solution of this application will be further described in detail below with reference to the accompanying drawings. It should be noted that, unless otherwise specified, the embodiments and features in the embodiments of this application can be arbitrarily combined with each other.

[0049] Example 1

[0050] Example 1 illustrates a flowchart of receiving first signaling according to an embodiment of this application, as shown in the attached diagram. Figure 1 As shown. (Attached) Figure 1 In the diagram, each box represents a step. It is particularly important to emphasize that the order of the boxes does not represent the chronological order of the steps they represent.

[0051] In Embodiment 1, the first node in this application receives the first signaling in step 101.

[0052] The first signaling configuration includes a first PDCP entity and a second PDCP entity, wherein the first PDCP entity is encrypted using a first key, and the second PDCP entity is encrypted using a second key. Both the first key and the second key belong to the security context of the master node (MN). Both the first PDCP entity and the second PDCP entity correspond to a DRB. The first PDCP entity and the second PDCP entity are different. The first key and the second key are different. The meaning of "both the first key and the second key belong to the security context of the master node" is that the first key and the second key belong to one security context for the master node, or the first key and the second key belong to two security contexts for the master node.

[0053] As an example, the first node is UE (User Equipment).

[0054] As an example, the first node is a terminal.

[0055] As an example, those skilled in the art should understand that the source cell and the target cell refer to the source cell and the target cell during the handover process.

[0056] As an embodiment, the LTM cell switch is a cell switch triggered by L1 / L2 signaling.

[0057] As an embodiment, any operation performed at the MAC sublayer can also be understood as or referred to as the any operation performed by the MAC entity.

[0058] As an embodiment, the lower layer when the operation is performed at the MAC sublayer is the physical layer.

[0059] As an embodiment, the higher layer when the operation is performed at the MAC sublayer includes the RLC sublayer, the RRC sublayer, the PDCP sublayer.

[0060] Typically, the higher layer when the operation is performed at the MAC sublayer is the RRC sublayer.

[0061] As an embodiment, the MAC CE is the control signaling of the MAC layer, with the feature of fast speed but less reliability than the RRC signaling, the RRC signaling has the feature of more reliability but slower speed than the MAC CE, the RRC signaling cannot replace the MAC CE, and the MAC CE cannot replace the RRC signaling.

[0062] As an embodiment, the lower layer when the operation is performed at the RRC sublayer includes the physical layer, the MAC layer, the RLC sublayer, the PDCP sublayer.

[0063] As an embodiment, the higher layer when the operation is performed at the RRC sublayer includes the non-access stratum.

[0064] As an embodiment, the higher layer signaling refers to the RRC signaling or the non-access stratum.

[0065] As an embodiment, in the present application, if it is not specifically indicated that the operation is performed at the MAC sublayer, the operation is performed at the RRC sublayer.

[0066] As an embodiment, the access stratum security of the first node is activated.

[0067] As an embodiment, the access stratum (AS) includes multiple protocol layers, and the details can refer to embodiment 3.

[0068] As an embodiment, the first node is in the RRC connected state.

[0069] As an embodiment, any parameter in the present application is either configured by the network or can be generated by the first node according to an internal algorithm, for example, randomly.

[0070] As an embodiment, the value of the timer in the present application is limited and does not exceed 2560 milliseconds.

[0071] As one embodiment, the value of a timer is the running time of the timer when it is not intervened.

[0072] As one embodiment, the value of any parameter in this application, including but not limited to the value of a timer, the value of a counter, is finite, unless specifically stated otherwise.

[0073] As one sub-embodiment of this embodiment, the upper limit of the value of any parameter in this application is 1024 times of 65536.

[0074] As one sub-embodiment of this embodiment, the upper limit of the value of any parameter in this application is 65536 or 65535.

[0075] As one sub-embodiment of this embodiment, the upper limit of the value of any parameter in this application is 1024.

[0076] As one sub-embodiment of this embodiment, the upper limit of the value of any parameter in this application is 640 or 320.

[0077] As one embodiment, this application is for NR.

[0078] As one embodiment, this application is for a wireless communication network of NR evolution.

[0079] As one embodiment, a serving cell refers to a cell in which a UE camps. Performing a cell search includes that the UE searches for a suitable cell of a selected PLMN (Public Land Mobile Network) or SNPN (Stand-alone Non-Public Network), selects the suitable cell to provide available services, and monitors the control channel of the suitable cell, which is defined as camping on a cell; that is, a camped cell, with respect to the UE, is the serving cell of the UE. The benefits of camping on a cell in RRC idle state or RRC inactive state include that the UE can receive system messages from the PLMN or SNPN; if the UE wishes to establish an RRC connection or continue a suspended RRC connection after registration, the UE can do so by performing initial access on the control channel of the camped cell; the network can page the UE; and the UE can receive ETWS (Earthquake and Tsunami Warning System) and CMAS (Commercial Mobile Alert System) notifications.

[0080] As an embodiment, for a UE in RRC CONNECTED state without configured CA / DC (carrier aggregation / dual connectivity), there is only one serving cell including the primary cell. For a UE in RRC CONNECTED state with configured CA / DC (carrier aggregation / dual connectivity), serving cells refer to a set of cells including the special cell (SpCell) and all secondary cells. The primary cell (PCell) is the MCG (Master Cell Group) cell operating on the primary frequency, on which the UE performs the initial connection establishment procedure or initiates connection re-establishment. For dual connectivity operation, the special cell refers to the PCell of the MCG or the PSCell of the SCG (Secondary Cell Group); if not dual connectivity operation, the special cell refers to the PCell.

[0081] As an embodiment, the frequency on which the SCell (Secondary Cell) operates is a secondary frequency.

[0082] As an embodiment, the first node is configured only with the MCG.

[0083] As an embodiment, the individual content of the information element is referred to as a field.

[0084] As an embodiment, MR-DC (Multi-Radio Dual Connectivity) refers to dual connectivity of E-UTRA and NR nodes, or dual connectivity between two NR nodes.

[0085] As an embodiment, in MR-DC, the radio access node providing the control plane connection to the core network is the master node, which can be a master eNB, a master ng-eNB, or a master gNB.

[0086] As an embodiment, MCG refers to a set of serving cells associated with the master node in MR-DC, including the SpCell, and optionally, one or more SCells.

[0087] As an embodiment, the PCell is the SpCell of the MCG.

[0088] As an embodiment, the PSCell is the SpCell of the SCG.

[0089] As an embodiment, in MR-DC, the wireless access node that provides the UE with additional resources is the secondary node, which is not provided with a control plane connection to the core network.

[0090] As an embodiment, in MR-DC, the set of serving cells associated with the secondary node is the SCG (secondary cell group), which includes the SpCell and, optionally, one or more SCells.

[0091] As an embodiment, the SpCell is a PCell or the SpCell is a PSCell.

[0092] As an embodiment, in RRC inactive state, DC is not used.

[0093] As an embodiment, in RRC inactive state, CA is typically not used.

[0094] As an embodiment, an RRC information block refers to an information element in an RRC message.

[0095] As an embodiment, SSB can be referred to as SS\PBCH, or SS block.

[0096] As an embodiment, L1 is Layer-1 or physical layer.

[0097] As an embodiment, L2 is Layer-2.

[0098] As an embodiment, the present application is directed to networks for NR and NR evolution, such as 6G networks.

[0099] As an embodiment, one RRC information block can include one or more RRC information blocks.

[0100] As an embodiment, one RRC information block can not include any RRC information blocks, but only at least one parameter.

[0101] As an embodiment, a radio bearer includes at least a signaling radio bearer and a data radio bearer.

[0102] As an embodiment, a radio bearer is a service or an interface of a service provided by a PDCP layer to a higher layer.

[0103] As a sub-embodiment of this embodiment, the higher layer includes one of an RRC sublayer, a NAS, and a SDAP layer.

[0104] As one embodiment, the signaling radio bearer is a service or interface of a service provided by the PDCP to a higher layer.

[0105] As one sub-embodiment of this embodiment, the higher layer includes an RRC sub-layer, at least the former in the NAS.

[0106] As one embodiment, the data radio bearer is a service or interface of a service provided by the PDCP to a higher layer.

[0107] As one sub-embodiment of this embodiment, the higher layer includes an SDAP layer, at least the former in the NAS.

[0108] As one embodiment, the first node enters an RRC connected state when the first node establishes an RRC connection with a network.

[0109] As one sub-embodiment of this embodiment, the network is a radio access network (RAN).

[0110] As one embodiment, the first node is in an RRC idle state when the first node does not establish an RRC connection with a network.

[0111] As one sub-embodiment of this embodiment, the network is a radio access network (RAN).

[0112] As one embodiment, the first node enters an RRC inactive state when the first node suspends an RRC connection with a network.

[0113] As one sub-embodiment of this embodiment, the network is a radio access network (RAN).

[0114] As one embodiment, different functionalities are supported in different RRC states.

[0115] As one embodiment, only very limited functionalities are supported in the non-RRC connected state.

[0116] As one embodiment, the non-RRC connected state is or includes an RRC idle state.

[0117] As one embodiment, the non-RRC connected state is or includes an RRC inactive state.

[0118] As one embodiment, the first node is not in a limited service mode.

[0119] As one embodiment, the method and scenarios based on which the present application is proposed are not targeted at emergency services.

[0120] As one embodiment, the present application is particularly applicable to scenarios where only MCG is configured.

[0121] As an embodiment, the present application is also applicable to a scenario configured with MCG and SCG.

[0122] As an embodiment, the cell switch targeted by the present application is not a DAPS (Dual Active Protocol Stack) handover, in which the SCG of the first node needs to be released, otherwise it is technically difficult to implement, and the present application does not have such a requirement.

[0123] As an embodiment, the first signaling is RRC signaling.

[0124] As an embodiment, the first signaling is higher layer signaling.

[0125] As an embodiment, the first signaling includes a plurality of sub-signaling respectively configuring the first PDCP entity and the second PDCP entity.

[0126] As an embodiment, the first signaling includes at least one RRC message.

[0127] As an embodiment, the at least one RRC message includes an RRCReconfiguration message.

[0128] As an embodiment, the at least one RRC message includes at least one RRCReconfiguration message.

[0129] As an embodiment, the meaning of the first signaling configuring the first PDCP entity and the second PDCP entity is that the first signaling configures the first PDCP entity, and the first signaling configures the second PDCP entity.

[0130] As an embodiment, the meaning of the first signaling configuring the first PDCP entity includes configuring a first DRB, and the first PDCP entity is the PDCP entity corresponding to the first DRB.

[0131] As an embodiment, the meaning of the first signaling configuring the first PDCP entity includes adding or modifying a first DRB, and the first PDCP entity is the PDCP entity corresponding to the first DRB.

[0132] As an embodiment, when the first signaling indicates to add the first DRB, the first node creates a corresponding PDCP entity.

[0133] As an embodiment, the meaning of the first signaling configuring the first PDCP entity includes configuring a first DRB, which includes configuring the PDCP entity corresponding to the first DRB.

[0134] As a sub-example of the embodiment, the first signaling comprises pdcp-Config configuring the first PDCP entity.

[0135] As an example, the first signaling configuring the first PDCP entity does not include configuring reestablishing the first PDCP entity.

[0136] As an example, the first signaling configuring the first PDCP entity includes configuring security of the first PDCP entity.

[0137] As an example, the first signaling configuring the first PDCP entity includes configuring security of a DRB corresponding to the first PDCP entity.

[0138] As an example, the configuring the security of the first PDCP entity includes configuring the first key.

[0139] As an example, the configuring the security of the first PDCP entity includes configuring security algorithm.

[0140] As an example, the configuring the security of the first PDCP entity includes configuring generation parameter of the first key.

[0141] As an example, the configuring the security of the first PDCP entity includes configuring generation mode of the first key.

[0142] As an example, the first signaling configuring the first PDCP entity includes configuring value of at least one timer of the first PDCP entity.

[0143] As an example, the at least one timer of the first PDCP entity includes discardTimer, and expiration of the discardTimer triggers the first PDCP entity to discard PDCP SDU associated with the discardTimer.

[0144] As an example, the configuring the security of the first PDCP entity includes configuring header compression of the first PDCP entity.

[0145] As an example, the configuring the security of the first PDCP entity includes configuring initial value of at least one state variable of the first PDCP entity.

[0146] As an example, the first signaling configuring the second PDCP entity includes configuring second DRB, and the second PDCP entity is a PDCP entity corresponding to the second DRB.

[0147] As one embodiment, the first signaling configuring the second PDCP entity includes adding or modifying a second DRB, the second PDCP entity being a PDCP entity corresponding to the second DRB.

[0148] As one embodiment, when the first signaling indicates adding the second DRB, the first node creates a corresponding PDCP entity.

[0149] As one embodiment, the first signaling configuring the second PDCP entity includes configuring a second DRB, including configuring a PDCP entity corresponding to the second DRB.

[0150] As one sub-embodiment of the embodiment, the pdcp-Config included in the first signaling configures the second PDCP entity.

[0151] As one embodiment, the first signaling configuring the second PDCP entity does not include configuring reestablishing the second PDCP entity.

[0152] As one embodiment, the first signaling configuring the second PDCP entity includes configuring security of the second PDCP entity.

[0153] As one embodiment, the first signaling configuring the second PDCP entity includes configuring security of a DRB corresponding to the second PDCP entity.

[0154] As one embodiment, the configuring the security of the second PDCP entity includes configuring the first key.

[0155] As one embodiment, the configuring the security of the second PDCP entity includes configuring a security algorithm.

[0156] As one embodiment, the configuring the security of the second PDCP entity includes configuring a generation parameter of the first key.

[0157] As one embodiment, the configuring the security of the second PDCP entity includes configuring a generation mode of the first key.

[0158] As one embodiment, the first signaling configuring the second PDCP entity includes configuring a value of at least one timer of the second PDCP entity.

[0159] As one embodiment, the at least one timer of the second PDCP entity comprises a discardTimer, and expiry of the discardTimer triggers the second PDCP entity to discard a PDCP SDU associated with the discardTimer.

[0160] As one embodiment, the configuring security of the second PDCP entity comprises configuring header compression of the second PDCP entity.

[0161] As one embodiment, the configuring security of the second PDCP entity comprises configuring initial values of at least one state variable of the second PDCP entity.

[0162] As one embodiment, at least one state variable of the second PDCP entity is derived from a state variable of the first PDCP entity.

[0163] As one embodiment, the above method has the benefit of facilitating continuity of data reception.

[0164] As one embodiment, the first signaling configuring the first PDCP entity and the second PDCP entity comprises configuring one of the first PDCP entity and the second PDCP entity as a master PDCP entity, and the other as a slave PDCP entity.

[0165] As one embodiment, the first signaling configuring the first PDCP entity and the second PDCP entity comprises the second PDCP entity being generated according to the first PDCP entity.

[0166] As one embodiment, the second PDCP entity being generated according to the first PDCP entity comprises configuration parameters of the second PDCP entity being derived from or equal to configuration parameters of the first PDCP entity.

[0167] As one embodiment, the configuration parameters of the first PDCP entity comprise length of a sequence number.

[0168] As one embodiment, the second PDCP entity being generated according to the first PDCP entity comprises at least one state variable of the second PDCP entity being derived from or equal to a value of a state variable of the first PDCP entity.

[0169] As one embodiment, the at least one state variable comprises COUNT.

[0170] As one embodiment, the second PDCP entity generates according to the first PDCP entity comprises: the second PDCP entity's at least one timer's state is equal to the first PDCP entity's one timer's state.

[0171] As one embodiment, the second PDCP entity generates according to the first PDCP entity does not comprise: a key, that is, the first key is different from the second key.

[0172] As one embodiment, the above method has the advantages of: increasing the continuity of data transmission, simplifying processing.

[0173] As one embodiment, the first signaling configures the first PDCP entity and the second PDCP entity: the first PDCP entity is configured to use encryption, and the second PDCP entity is configured to use encryption.

[0174] As one embodiment, the first key and the second key are both user plane keys.

[0175] As one embodiment, the first key and the second key are both encryption keys.

[0176] As one embodiment, the first key can also be used for decryption, for example, the first PDCP entity using the first key encryption is replaced by the first PDCP entity using the first key decryption.

[0177] As one embodiment, the second key can also be used for decryption, for example, the second PDCP entity using the second key encryption is replaced by the second PDCP entity using the second key decryption.

[0178] As one embodiment, the first key and the second key are respectively a K UPenc .

[0179] As one embodiment, the key used to derive the first key and the second key is different.

[0180] As one sub-embodiment of this embodiment, the key used to derive the first key and the second key is different refers to the key used to directly derive the first key and the key used to directly derive the second key are different.

[0181] As one embodiment, the base station related key used to derive the first key and the second key is different.

[0182] As one sub-embodiment of this embodiment, the one base station related key directly derives the first key.

[0183] As a sub-embodiment of this embodiment, the one base station related key directly derives the second key.

[0184] As an embodiment, the base station related key is K gNB .

[0185] As an embodiment, the name of the base station related key comprises K, and NB .

[0186] As an embodiment, the keys used to derive the first key and the second key are different means that the key used to derive the first key is one K gNB , and the key used to derive the second key is another K gNB .

[0187] As an embodiment, the first key and the second key are derived by the first node, rather than received over the air interface.

[0188] As an embodiment, the first key and the second key are derived from the same core network related key.

[0189] As a sub-embodiment of this embodiment, the one core network related key indirectly derives the first key.

[0190] As a sub-embodiment of this embodiment, the one core network related key indirectly derives the second key.

[0191] As a sub-embodiment of this embodiment, the core network related key is K AMF .

[0192] As a sub-embodiment of this embodiment, the name of the core network related key comprises K and the name of a core network network element.

[0193] As an embodiment, the core network related key derives two base station related keys respectively.

[0194] As an embodiment, the core network related key derives two KgNB .

[0195] As an embodiment, the first PDCP entity uses the first key for ciphering.

[0196] As an embodiment, the first PDCP entity does not use the second key for ciphering.

[0197] As an embodiment, the second PDCP entity uses the second key for ciphering.

[0198] As one embodiment, the second PDCP entity does not use the first key for encryption.

[0199] As one embodiment, the first key and the second key are different in the sense that the first key and the second key are derived from different keys.

[0200] As one embodiment, the first key and the second key are different in the sense that data encrypted by the first key cannot be decrypted by the second key.

[0201] As one embodiment, the first key and the second key are different in the sense that the first key and the second key are independent.

[0202] As one embodiment, the first key and the second key both belong to a security context of a master node in the sense that the first node has only one master node.

[0203] As one embodiment, the first key and the second key both belong to a security context of a master node in the sense that the master node is a network node that controls a MCG.

[0204] As one embodiment, the first key and the second key both belong to a security context of a master node in the sense that security-related information of the master node is stored in the security context.

[0205] As one embodiment, the security context includes an access stratum security context.

[0206] As one embodiment, the security context is established locally by the UE and a corresponding security context is established by a network serving the UE.

[0207] As one embodiment, the security context is represented as security context data stored by the UE.

[0208] As one embodiment, the security context includes AS-level encryption keys and identities of the keys.

[0209] As one embodiment, the security context includes a next hop parameter, a Next Hop Chaining Counter parameter.

[0210] As one embodiment, the security context includes an identity of a selected AS-level encryption algorithm.

[0211] As one embodiment, the security context includes security capabilities of the UE.

[0212] As one embodiment, the security context comprises a user plane security activation status.

[0213] As one embodiment, the security context comprises a counter for protection against replay attacks.

[0214] As one embodiment, the security context is for 3GPP access.

[0215] As one embodiment, the security context is established when accessing a network.

[0216] As one embodiment, the security context is determined to be established when including data that should be included.

[0217] As one embodiment, the data that should be included comprises key information and an identity of a key.

[0218] As one embodiment, the key information comprises information of the first key.

[0219] As one embodiment, the key information comprises information of the second key.

[0220] As one embodiment, the first node determines the first key by a security procedure other than the first signaling.

[0221] As one embodiment, the first node determines the second key by a security procedure other than the first signaling.

[0222] As one embodiment, the first signaling indicates or carries information in a security procedure to generate the first key and / or the second key.

[0223] As one embodiment, the first signaling carries non-access stratum signaling, the non-access stratum signaling indicating or configuring the first key and / or the second key.

[0224] As one embodiment, the first signaling configuring the first PDCP entity and the second PDCP entity comprises: the first signaling configuring the first PDCP entity and the second PDCP entity to use different keys.

[0225] As one embodiment, the first key and the second key belonging to two security contexts for a master node respectively means that the first key belongs to a first security context for the master node and the second key belongs to a second security context for the master node.

[0226] As one embodiment, the first security context is a master security context and the second security context is a secondary security context.

[0227] As one embodiment, the first security context and the second security context comprise at least one same data.

[0228] As one embodiment, the at least one same data comprises security capability of the UE.

[0229] As one embodiment, the at least one same data comprises identification of a key.

[0230] As one embodiment, the at least one same data comprises next hop parameter.

[0231] As one embodiment, the at least one same data comprises next hop chaining counter parameter.

[0232] As one embodiment, the at least one same data comprises a counter for protection against replay attacks.

[0233] As one embodiment, the at least one same data comprises identification of an encryption algorithm at AS level.

[0234] As one embodiment, the first security context and the second security context are both for 3GPP access.

[0235] As one embodiment, at least one of the first security context and the second security context is for 3GPP 5G NR access.

[0236] As one embodiment, the second security context can exist independently of the first security context.

[0237] As one embodiment, the first security context can exist independently of the second security context.

[0238] As one embodiment, there is a dependency relationship between the second security context and the first security context.

[0239] As one embodiment, the first key and the second key respectively belong to two security contexts for a master node, and the benefits include facilitating scalability, increasing flexibility of implementation, facilitating security, and increasing data throughput.

[0240] As one embodiment, the first PDCP entity corresponds to a first DRB, and the second PDCP entity corresponds to a second DRB.

[0241] As one embodiment, the first DRB and the second DRB are configured by the same RRC signaling.

[0242] As an embodiment, the first DRB and the second DRB belong to a same DRB list.

[0243] As an embodiment, the peer PDCP entity of the first PDCP entity and the second PDCP entity is maintained by a same cell.

[0244] As an embodiment, the same cell is a PCell of the first node.

[0245] As an embodiment, the meaning that the peer PDCP entity of the first PDCP entity and the second PDCP entity is maintained by a same cell is that the peer PDCP entity of the first PDCP entity is maintained by a PCell of the first node, and the peer PDCP entity of the second PDCP entity is maintained by the PCell of the first node.

[0246] As an embodiment, the meaning that the peer PDCP entity of the first PDCP entity and the second PDCP entity is maintained by a same cell is that the peer PDCP entity of the first PDCP entity is located at a PCell of the first node, and the peer PDCP entity of the second PDCP entity is located at the PCell of the first node.

[0247] As an embodiment, the peer PDCP entity of the first PDCP entity and the second PDCP entity is controlled by different CUs.

[0248] As an embodiment, the peer PDCP entity of the first PDCP entity and the second PDCP entity is processed by different DUs.

[0249] As an embodiment, the first node is configured with only one cell group, and the one cell group is a master cell group.

[0250] As an embodiment, the peer of the first DRB and the second DRB is respectively maintained by different DUs.

[0251] As an embodiment, the peer of the first DRB and the second DRB is respectively maintained by different CUs.

[0252] As an embodiment, the first PDCP entity corresponds to a first DRB, and the second PDCP entity corresponds to a second DRB.

[0253] As an embodiment, the first PDCP entity and the second PDCP entity both correspond to a first DRB.

[0254] As an embodiment, the first key and the second key are respectively derived by different KgNBs.

[0255] As one embodiment, the key used by the SRB of the first node is derived from a key that derives one of the first key and the second key.

[0256] As one embodiment, the first node is in RRC connected state.

[0257] As one embodiment, the AS security of the first node is activated.

[0258] As one embodiment, only one security context of the security context for the MN of the first node includes the key used by the SRB.

[0259] As one sub-embodiment of the embodiment, the first node has multiple security contexts for the MN.

[0260] As one embodiment, the first PDCP entity corresponds to a first DRB, the first PDCP entity corresponds to a second DRB, and the first DRB and the second DRB serve the same service.

[0261] As one embodiment, the serving the same service includes: the same QoS flow is mapped to the first DRB and the second DRB.

[0262] As one embodiment, the serving the same service includes: the first DRB and the second DRB serve the same session.

[0263] As one embodiment, the serving the same service includes: the first DRB and the second DRB serve the same PDU session.

[0264] As one embodiment, the serving the same service includes: the first DRB and the second DRB are associated with the same QFI (QoS flow Identifier).

[0265] As one embodiment, the first signaling configures K PDCP entities, K is greater than 2, wherein the K PDCP entities include the first PDCP entity and the second PDCP entity, the K PDCP entities are respectively encrypted using K keys, and the K keys all belong to the security context of the master node.

[0266] As one embodiment, the K keys belong to the same security context of the master node of the first node.

[0267] As one embodiment, the K keys respectively belong to K security contexts of the master node of the first node.

[0268] As one embodiment, K is a positive integer.

[0269] As one embodiment, the K is no more than 16.

[0270] As one embodiment, the K is no more than 4.

[0271] As one embodiment, the K is no more than 8.

[0272] As one embodiment, the K PDCP entities serve one service.

[0273] As one embodiment, the K PDCP entities serve multiple services.

[0274] As one embodiment, the K keys are different.

[0275] As one embodiment, the K PDCP entities are different.

[0276] As one embodiment, the peer PDCP entities of the first PDCP entity and the second PDCP entity are maintained by a first cell and a second cell respectively.

[0277] As one embodiment, the first cell and the second cell are a source cell and a target cell respectively.

[0278] As one embodiment, the source cell and the target cell are a source cell and a target cell in LTM (L1L2 triggered mobility) cell handover.

[0279] As one embodiment, the LTM cell handover is a non-RACH (random access channel) LTM cell handover.

[0280] As one embodiment, the first cell and the second cell belong to the same cell group.

[0281] As one embodiment, the peer PDCP entities of the first PDCP entity and the second PDCP entity are maintained by a first cell and a second cell respectively, which has the advantage of reducing the latency of cell handover, especially LTM cell handover, improving the continuity of data, and avoiding the interruption of data transmission.

[0282] Example 2

[0283] Embodiment 2 illustrates a schematic diagram of a network architecture according to the present application, as shown in FIG. 2. Figure 2

[0284] Figure 2 ​​A diagram illustrating a network architecture 200 of a 5G NR, LTE (Long-Term Evolution), and LTE-A (Long-Term Evolution Advanced) system is shown. The 5G NR or LTE network architecture 200 can be referred to as a 5GS (5G System) / EPS (Evolved Packet System) 200 or some other suitable terminology. The 5GS / EPS 200 can include one or more UEs (User Equipment) 201, NG-RAN (Next Generation Radio Access Network) 202, 5GC (5G Core Network) / EPC (Evolved Packet Core) 210, HSS (Home Subscriber Server) / UDM (Unified Data Management) 220, and Internet services 230. The 5GS / EPS can interconnect with other access networks, but these entities / interfaces are not shown for simplicity. As shown, the 5GS / EPS provides packet-switched services, however, those skilled in the art will readily appreciate, that the various concepts presented throughout this application are extensible to networks providing circuit-switched services or other cellular networks. The NG-RAN includes an NR Node B (gNB) 203 and other gNBs 204. The gNB 203 provides user and control plane protocol terminations toward the UE 201. The gNB 203 can be connected to the other gNBs 204 via an Xn interface (e.g., backhaul). The gNB 203 can also be referred to as a base station, a base transceiver station, a radio base station, a radio transceiver, a transceiver function, a basic service set (BSS), an extended service set (ESS), a TRP (Transmission Reception Point), or some other suitable terminology. The gNB 203 provides access to the 5GC / EPC 210 for the UE 201. Examples of UEs 201 include a cellular phone, a smart phone, a session initiation protocol (SIP) phone, a laptop, a personal digital assistant (PDA), a satellite radio, a non-tethered personal branch station, a satellite mobile communication, a global positioning system, a multimedia device, a video device, a digital audio player (e.g., MP3 player), a camera, a game console, a drone, a flying vehicle, a narrow-band internet of things device, a machine type communication device, a land vehicle, a car, a wearable device, or any other similar functional device. Those skilled in the art will also readily appreciate that the UE 201 can be referred to as a mobile station, a subscriber station, a mobile unit, a subscriber unit, a wireless unit, a remote unit, a mobile device, a wireless device, a wirelessThe gNB 203 is connected to the 5GC / EPC 210 over the S1 / NG interface. The 5GC / EPC 210 includes a MME (Mobility Management Entity) / AMF (Authentication Management Field) / SMF (Session Management Function) 211, other MME / AMF / SMF 214, a S-GW (Service Gateway) / UPF (User Plane Function) 212, and a P-GW (Packet Data Network Gateway) / UPF 213. The MME / AMF / SMF 211 is a control node that handles signaling between the UE 201 and the 5GC / EPC 210. Generally, the MME / AMF / SMF 211 provides bearer and connection management. All user IP (Internet Protocal) packets are transferred through the S-GW / UPF 212, which is connected to the P-GW / UPF 213 itself. The P-GW provides UE IP address allocation and other functions. The P-GW / UPF 213 is connected to the Internet service 230. The Internet service 230 includes operator corresponding Internet protocol services, and can specifically include the Internet, an intranet, an IMS (IP Multimedia Subsystem), and a packet exchange streaming service.

[0285] As one embodiment, the first node in the present application is the UE 201.

[0286] As one embodiment, the base station of the second node in the present application is the gNB 203.

[0287] As one embodiment, the wireless link from the UE 201 to the NR Node B is an uplink.

[0288] As one embodiment, the wireless link from the NR Node B to the UE 201 is a downlink.

[0289] As one embodiment, the UE 201 is a mobile phone.

[0290] As one embodiment, the UE 201 is a special-purpose device or a special device with communication functions.

[0291] As one embodiment, the gNB 203 is a micro cell base station.

[0292] As one example, the gNB 203 is a Pico Cell base station.

[0293] As one example, the gNB 203 is a base station used in a home network.

[0294] As one example, the gNB 203 is a base station used in a private network.

[0295] As one example, the gNB 203 is a base station used in an enterprise network.

[0296] Example 3

[0297] Figure 3 shows a schematic diagram of an embodiment of a radio protocol architecture for the user plane 350 and control plane 300 according to an aspect of the application, as shown in Figure 1. Figure 3 Figure 3 is a schematic diagram illustrating an embodiment of a radio protocol architecture for the user plane 350 and control plane 300, as shown in Figure 1. Figure 3 ​The radio protocol architecture for the control plane 300 for a first node (UE, gNB) and a second node (gNB, UE), or between two UEs, is shown with three layers: Layer 1, Layer 2, and Layer 3. Layer 1 (LI layer) is the lowest layer and implements various PHY (Physical layer) signal processing functions. The LI layer will be referred to as the PHY 301 in this document. Layer 2 (L2 layer) 305 is above the PHY 301 and is responsible for the link between the first node and the second node, as well as between two UEs, over the PHY 301. The L2 layer 305 includes a MAC (Medium Access Control) sublayer 302, a RLC (Radio Link Control) sublayer 303, and a PDCP (Packet Data Convergence Protocol) sublayer 304, which are terminated at the second node. The PDCP sublayer 304 provides multiplexing between different radio bearers and logical channels. The PDCP sublayer 304 also provides security functions, through the encryption of data packets, and bearer configuration management. The RLC sublayer 303 provides segmentation and reassembly of upper layer data packets, retransmission of lost data packets, and reordering of data packets to compensate for out-of-order reception due to HARQ. The MAC sublayer 302 provides multiplexing between logical and transport channels. The MAC sublayer 302 is also responsible for allocating the various radio resources (e.g., resource blocks) in one cell among the UEs. The MAC sublayer 302 is also responsible for HARQ operations. The RRC (Radio Resource Control) sublayer 306 in Layer 3 (L3 layer) in the control plane 300 is responsible for obtaining radio resources (i.e., radio bearers) and configuring the lower layers using RRC signaling between the second node and the first node. The PC5-S (PC5 Signaling Protocol) sublayer 307 is responsible for the handling of the signaling protocol for the PC5 interface. The radio protocol architecture for the user plane 350 includes Layer 1 (LI layer) and Layer 2 (L2 layer), which are generally the same as the corresponding layers and sublayers in the control plane 300 for the first node and the second node in the user plane 350 for the physical layer 351, the PDCP sublayer 354 in the L2 layer 355, the RLC sublayer 353 in the L2 layer 355, and the MAC sublayer 352 in the L2 layer 355, but the PDCP sublayer 354 also provides header compression for upper layer data packets to reduce radio transmission overhead.The L2 layer 355 in the user plane 350 also includes a SDAP (Service Data Adaptation Protocol) sublayer 356, which is responsible for the mapping between a QoS flow and a data radio bearer (DRB) to support the diversity of services. SRBs can be seen as services or interfaces provided by the PDCP layer to higher layers, such as the RRC sublayer. In the NR system, SRBs include SRB1, SRB2, and SRB3, which are used to transmit different types of control signaling. SRBs are bearers between the UE and the access network for transmitting control signaling including RRC signaling. SRB1 is of particular significance to the UE, and each UE establishes an RRC connection after which there is SRB1 for transmitting RRC signaling, and most signaling is transmitted through SRB1. If SRB1 is interrupted or cannot be used, the UE must perform RRC reestablishment. SRB2 is generally used only to transmit NAS signaling or signaling related to security. The UE can not configure SRB3. Except for emergency services, the UE must establish an RRC connection with the network to perform subsequent communication. Although not shown, the first node can have several upper layers above the L2 layer 355. In addition, there are network layers (e.g., IP layers) that terminate at the P-GW on the network side and application layers that terminate at the other end of the connection (e.g., a remote UE, a server, etc.). The protocol layers can also be referred to as protocol sublayers. Figure 3 The protocol layer structure shown is general, and the nodes used in the present application can lack some protocol layers.

[0298] As an embodiment, the wireless protocol architecture in Figure 3 applies to the first node in the present application.

[0299] As an embodiment, the wireless protocol architecture in Figure 3 applies to the second node in the present application.

[0300] As an embodiment, the first signaling in the present application is generated in the RRC 306.

[0301] As an embodiment, the first information in the present application is generated in the PHY 301 or the MAC 302 or the RRC 306.

[0302] As an embodiment, the second signaling in the present application is generated in the MAC 302.

[0303] As an embodiment, the first MAC CE in the present application is generated in the MAC 302.

[0304] Example 4

[0305] Figure 4 shows a schematic diagram of a first communication device and a second communication device according to an embodiment of the application, as described in Figure 4 Figure 4. Figure 4 Figure 4 shows a schematic diagram of a first communication device 450 and a second communication device 410 communicating with each other in an access network.

[0306] The first communication device 450 comprises a controller / processor 459, a memory 460, a data source 467, a transmit processor 468, a receive processor 456, and optionally a multi-antenna transmit processor 457, a multi-antenna receive processor 458, a transmitter / receiver 454, and an antenna 452.

[0307] The second communication device 410 comprises a controller / processor 475, a memory 476, a receive processor 470, a transmit processor 416, and optionally a multi-antenna receive processor 472, a multi-antenna transmit processor 471, a transmitter / receiver 418, and an antenna 420.

[0308] In transmissions from the second communication device 410 to the first communication device 450, upper layer packets from the core network are provided to the controller / processor 475 at the second communication device 410. The controller / processor 475 implements functionality of the L2 layer. In transmissions from the second communication device 410 to the first communication device 450, the controller / processor 475 provides header compression, ciphering, packet segmentation and reordering, multiplexing between logical and transport channels, and radio resource allocation for the first communication device 450 based on various priority metrics. The controller / processor 475 is also responsible for retransmission of lost packets, and signaling to the first communication device 450. The transmit processor 416 and the multiple antenna transmit processor 471 implement various signal processing functions for the LI layer (i.e., physical layer). The transmit processor 416 implements coding and interleaving to facilitate forward error correction (FEC) at the second communication device 410, and mapping of coded bits to modulation symbols based on various modulation schemes (e.g., binary phase shift keying (BPSK), quadrature phase shift keying (QPSK), M-phase shift keying (M-PSK), M-quadrature amplitude modulation (M-QAM)). The multiple antenna transmit processor 471 performs digital spatial pre-coding of the coded and modulated symbols, including codebook-based and non-codebook-based pre-coding, and beamforming processing, to generate one or more spatial streams. The transmit processor 416 then maps to each spatial stream to the subcarriers, multiplexes the stream with reference signals (e.g., pilot) in the time and / or frequency domain, and then performs an inverse fast Fourier transform (IFFT) to generate a time-domain multicarrier symbol stream for the physical channel. The multiple antenna transmit processor 471 then performs transmit analog pre-coding / beamforming operations on the time-domain multicarrier symbol stream. Each transmitter 418 converts the baseband multicarrier symbol stream provided by the multiple antenna transmit processor 471 into a radio frequency stream, and then provides the radio frequency stream to the corresponding antenna 420.

[0309] In transmissions from the second communication device 410 to the first communication device 450, at the first communication device 450, each receiver 454 receives a signal through its respective antenna 452. Each receiver 454 recovers information modulated onto an RF carrier and provides the recovered information at baseband as a stream of symbols to a receive processor 456. The receive processor 456 and a multiple access receiver processor 458 implement various signal processing functions of the Ll layer. The multiple access receiver processor 458 performs receive analog precoding / beamforming operations on the baseband multiple access symbol streams from the receivers 454. The receive processor 456 converts the baseband multiple access symbol streams from the time-domain to the frequency domain using a Fast Fourier Transform (FFT). In the frequency domain, the physical layer data signals and the reference signals are demultiplexed from the received symbol streams, with the reference signals to be used for channel estimation and the data signals to be recovered after multiple access detection in the multiple access receiver processor 458 for any spatial streams destined for the first communication device 450. The symbols on each spatial stream are demodulated and recovered by the receive processor 456 and used to generate soft decisions. The receive processor 456 then decodes and de-interleaves the soft decisions to recover the upper layer data and control signals transmitted by the second communication device 410 on the physical channel. The upper layer data and control signals are then provided to a controller / processor 459. The controller / processor 459 implements the functions of the L2 layer. The controller / processor 459 can be associated with a memory 460 that stores program codes and data. The memory 460 can be referred to as a computer-readable medium. In transmissions from the second communication device 410 to the second communication device 450, the controller / processor 459 provides demultiplexing between transport and logical channels, packet reassembly, deciphering, header decompression, control signal processing to recover upper layer data packets from the core network. The upper layer data packets are then provided to all protocol layers above the L2 layer. Various control signals can also be provided to the L3 for L3 processing.

[0310] In the transmission from the first communication device 450 to the second communication device 410, at the first communication device 450, a data source 467 is used to provide upper layer data packets to a controller / processor 459. The data source 467 represents all protocol layers above the L2 layer. Similar to the transmit function at the second communication device 410 described in the transmission from the second communication device 410 to the first communication device 450, the controller / processor 459 implements header compression, ciphering, packet segmentation and reordering, and multiplexing between logical and transport channels based on radio resource allocations, implements L2 layer functionality for the user plane and control plane. The controller / processor 459 is also responsible for error detection, retransmission of lost packets, and signaling to the second communication device 410. A transmit processor 468 performs modulation mapping, channel coding processing, and a multi-antenna transmit processor 457 performs digital multi-antenna spatial precoding, including codebook-based precoding and non-codebook-based precoding, and beamforming processing, and then the transmit processor 468 modulates the resulting spatial streams into multi-carrier / single-carrier symbol streams, which are then provided to different antennas 452 via transmitters 454 after analog precoding / beamforming operations in the multi-antenna transmit processor 457. Each transmitter 454 first converts the baseband symbol stream provided by the multi-antenna transmit processor 457 into a radio frequency signal, and then provides the radio frequency signal to the antenna 452.

[0311] In the transmission from the first communication device 450 to the second communication device 410, the functions at the second communication device 410 are similar to the receive functions at the first communication device 450 described in the transmission from the second communication device 410 to the first communication device 450. Each receiver 418 receives a radio frequency signal through its respective antenna 420, converts the received radio frequency signal into a baseband signal, and provides the baseband signal to a multi-antenna receive processor 472 and a receive processor 470. The receive processor 470 and the multi-antenna receive processor 472 collectively implement the functionality of the L1 layer. A controller / processor 475 implements the functionality of the L2 layer. The controller / processor 475 can be associated with a memory 476 that stores program codes and data. The memory 476 can be referred to as a computer readable medium. In the transmission from the first communication device 450 to the second communication device 410, the controller / processor 475 provides demultiplexing between transport and logical channels, packet reassembly, deciphering, header decompression, control signal processing to recover upper layer data packets from the UE 450. Upper layer data packets from the controller / processor 475 can be provided to a core network.

[0312] As an embodiment, the first communication device 450 comprises at least one processor and at least one memory including a computer program code; the at least one memory and the computer program code are configured to, with the at least one processor, cause the first communication device 450 to perform at least the following: receive first signaling, the first signaling configuring a first PDCP entity and a second PDCP entity, wherein the first PDCP entity is ciphered using a first key and the second PDCP entity is ciphered using a second key, the first key and the second key both belong to a security context of a master node (MN); the first PDCP entity and the second PDCP entity both correspond to a DRB; wherein the first PDCP entity and the second PDCP entity are different; the first key and the second key are different; the meaning that the first key and the second key both belong to a security context of a master node is that the first key and the second key belong to one security context for the master node, or the first key and the second key respectively belong to two security contexts for the master node.

[0313] As an embodiment, the first communication device 450 comprises a memory storing a computer readable program, the computer readable program, when executed by at least one processor, causes the first communication device 450 to perform the following: receive first signaling, the first signaling configuring a first PDCP entity and a second PDCP entity, wherein the first PDCP entity is ciphered using a first key and the second PDCP entity is ciphered using a second key, the first key and the second key both belong to a security context of a master node (MN); the first PDCP entity and the second PDCP entity both correspond to a DRB; wherein the first PDCP entity and the second PDCP entity are different; the first key and the second key are different; the meaning that the first key and the second key both belong to a security context of a master node is that the first key and the second key belong to one security context for the master node, or the first key and the second key respectively belong to two security contexts for the master node.

[0314] As an embodiment, the first communication device 450 corresponds to the first node in the present application.

[0315] As an embodiment, the second communication device 410 corresponds to the second node in the present application.

[0316] As an embodiment, the first communication device 450 is a UE.

[0317] As an embodiment, the first communication device 450 is a mobile phone.

[0318] As one embodiment, the second communication device 450 is a relay.

[0319] As one embodiment, the second communication device 410 is a base station.

[0320] As one embodiment, receiver 454 (including antenna 452), receiver processor 456 and controller / processor 459 are used in this application to receive the first signaling.

[0321] As one embodiment, receiver 454 (including antenna 452), receiver processor 456 and controller / processor 459 are used in this application to receive the second signaling.

[0322] As one embodiment, receiver 454 (including antenna 452), receiver processor 456 and controller / processor 459 are used in this application to receive the first MAC CE.

[0323] As one embodiment, a transmitter 454 (including an antenna 452), a transmission processor 468, and a controller / processor 459 are used in this application to transmit first information.

[0324] Example 5

[0325] Example 5 illustrates a wireless signal transmission flowchart according to an embodiment of this application, as shown in the attached diagram. Figure 5 As shown. (Attached) Figure 5 In this example, U01 corresponds to the first node of this application. It should be noted that the order in this example does not limit the signal transmission order and the implementation order in this application. The steps in F51 and F52 are optional.

[0326] for First node U01 In step S5101, a first message is sent; in step S5102, a first signaling is received; in step S5103, a first PDCP PDU is received; in step S5104, a second PDCP PDU is received; in step S5105, a first message is sent; and in step S5106, a second signaling is received.

[0327] for Second node U02 In step S5201, a first message is received; in step S5202, a first signaling is sent; in step S5203, a first PDCP PDU is sent; in step S5204, a second PDCP PDU is sent; and in step S5205, a second signaling is sent.

[0328] In embodiment 5, the first signaling configures a first PDCP entity and a second PDCP entity, wherein the first PDCP entity uses a first key for encryption, the second PDCP entity uses a second key for encryption, the first key and the second key both belong to a security context of a master node (MN); the first PDCP entity and the second PDCP entity both correspond to a DRB; wherein the first PDCP entity and the second PDCP entity are different; the first key and the second key are different; the meaning that the first key and the second key both belong to a security context of a master node is that the first key and the second key belong to one security context for the master node, or the first key and the second key respectively belong to two security contexts for the master node.

[0329] As an embodiment, the second node U02 is a base station corresponding to a PCell of the first node U01.

[0330] As an embodiment, the second node U02 is a base station corresponding to a PCell of the first node U01.

[0331] As an embodiment, the second node U02 belongs to a cellular network.

[0332] As an embodiment, the second node U02 corresponds to a source cell.

[0333] As an embodiment, the second node U02 is a base station corresponding to a PCell of the first node U01.

[0334] As an embodiment, the second node U02 is a base station corresponding to a PCell of the first node U01. Figure 5 The numbering order of the steps shown is the time sequence.

[0335] As an embodiment, the first message is an RRC message or a message of a protocol layer above RRC.

[0336] As an embodiment, the meaning that the first message is an RRC message or a message of a protocol layer above RRC includes that the first message is a NAS message.

[0337] As an embodiment, the first message is user assistance information.

[0338] As an embodiment, the first message is an RRC message refers to that the first message is a UEassistanceInformation message.

[0339] As an embodiment, the first message indicates service information or QoS information of the first node U01.

[0340] As one embodiment, the first message is used by the second node U02 to determine that the first node U01 needs more resources.

[0341] As one embodiment, the more resources, e.g. belong to different frequencies, belong to different data units respectively.

[0342] As one embodiment, the different data units require using different keys, e.g. using the first key and the second key.

[0343] As one embodiment, the above method has the benefit of supporting higher throughput.

[0344] As one embodiment, the traffic information or QoS information includes latency requirement.

[0345] As one embodiment, the latency requirement is used by the second node U02 to determine that the first PDCP entity and the second PDCP entity use the first key and the second key respectively.

[0346] As one embodiment, the latency requirement is used by the second node U02 to determine that PDCP entity is not re-established during handover.

[0347] As one embodiment, the above method has the benefit of reducing handover latency, meeting QoS requirement.

[0348] As one embodiment, the first message indicates connection status or connection requirement of the first node U01.

[0349] As one embodiment, the connection status or connection requirement includes requirement of connecting with entities using different keys.

[0350] As one embodiment, the entities using different keys include logical entities.

[0351] As one embodiment, the entities using different keys include network entities.

[0352] As one embodiment, the entities using different keys include cells.

[0353] As one embodiment, the first message triggers the first signaling.

[0354] As one embodiment, the first signaling configures the first PDCP entity first, and then configures the second PDCP entity.

[0355] As one embodiment, the first message triggers the first signaling to configure the second PDCP entity.

[0356] As one embodiment, the first PDCP entity exists prior to the first message.

[0357] As one embodiment, step S5103 and step S5104 have no order requirement.

[0358] As one embodiment, the first signaling configuring the first PDCP entity comprises: the first signaling modifying a DRB corresponding to the first PDCP entity.

[0359] As one embodiment, the first PDCP PDU is processed by the first PDCP entity.

[0360] As one sub-embodiment of this embodiment, the first PDCP PDU is processed by only the first PDCP entity among the first PDCP entity and the second PDCU entity.

[0361] As one embodiment, the second PDCP PDU is processed by the second PDCP entity.

[0362] As one sub-embodiment of this embodiment, the second PDCP PDU is processed by only the second PDCP entity among the first PDCP entity and the second PDCU entity.

[0363] As one embodiment, the processing by the first PDCP entity comprises: receiving by the first PDCP entity.

[0364] As one embodiment, the processing by the first PDCP entity comprises: deciphering by the first PDCP entity.

[0365] As one embodiment, the deciphering by the first PDCP entity comprises: deciphering using the first key.

[0366] As one embodiment, the processing by the first PDCP entity comprises: delivering by the first PDCP entity to a higher layer protocol layer of a PDCP sublayer.

[0367] As one embodiment, the processing by the first PDCP entity comprises: processing header compression by the first PDCP entity.

[0368] As one embodiment, the processing by the first PDCP entity comprises: processing sequencing by the first PDCP entity.

[0369] As one embodiment, the processing by the second PDCP entity comprises: receiving by the second PDCP entity.

[0370] As one embodiment, the processing by the second PDCP entity includes deciphering by the second PDCP entity.

[0371] As one embodiment, the deciphering by the second PDCP entity includes deciphering using the second key.

[0372] As one embodiment, the processing by the second PDCP entity includes delivering by the second PDCP entity to a higher layer protocol layer of a PDCP sublayer.

[0373] As one embodiment, the processing by the second PDCP entity includes processing header compression by the second PDCP entity.

[0374] As one embodiment, the processing by the second PDCP entity includes processing sequencing by the second PDCP entity.

[0375] As one embodiment, the second PDCP PDU (protocol data unit) can also be received from other nodes.

[0376] As one embodiment, the other nodes include target cells.

[0377] As one embodiment, the first information request deactivates one of a first DRB and a second DRB.

[0378] As one embodiment, the deactivating one of the first DRB and the second DRB is the first DRB.

[0379] As one embodiment, the first information request releases one of a first DRB and a second DRB.

[0380] As one embodiment, the first information indicates completion of transmission on one of the first DRB and the second DRB.

[0381] As one embodiment, the first information includes higher layer information.

[0382] As one embodiment, the first information includes control information of a PDCP sublayer.

[0383] As one embodiment, the first information is information of a MAC sublayer or a protocol layer above the MAC sublayer.

[0384] As one embodiment, the information of the MAC sublayer includes a MAC CE (control element).

[0385] As one embodiment, the protocol layer above the MAC sublayer includes an RRC sublayer.

[0386] As one embodiment, the first information request releasing the one of the first DRB and the second DRB is the first DRB.

[0387] As one embodiment, the first PDCP entity is released along with the release of the first DRB.

[0388] As one embodiment, the first PDCP entity is for transmission.

[0389] As one embodiment, the second PDCP entity is for transmission.

[0390] As one embodiment, the first information indicating the transmission completion on one of the first DRB and the second DRB is the transmission completion on the first DRB.

[0391] As one embodiment, the transmission completion on the first DRB comprises no more data to be transmitted on the first DRB.

[0392] As one embodiment, the transmission completion on the first DRB comprises the buffer of the first PDCP entity being empty and no further data arriving.

[0393] As one embodiment, the transmission completion on the first DRB comprises the first PDCP entity having successfully transmitted all data.

[0394] As one embodiment, the transmission completion on the first DRB comprises the sequence number of the data successfully transmitted by the first PDCP entity being consecutive, i.e. no gap in the sequence number.

[0395] As one embodiment, the transmission completion on the first DRB comprises at least one state variable of the first PDCP entity not changing any more.

[0396] As one embodiment, the transmission completion on the first DRB comprises the values of two state variables of the first PDCP entity being equal.

[0397] As one embodiment, the first information is transmitted after a handover complete message transmitted by the first node.

[0398] As one embodiment, the handover complete message is an RRCReconfigurationComplete message.

[0399] As one embodiment, the meaning of the transmission completion comprises transmission completion.

[0400] As one embodiment, the meaning of the transmission completion comprises reception completion.

[0401] As an embodiment, the meaning of the transmission completion comprises: the sequence number of the PDCP PDU is continuous.

[0402] As an embodiment, the meaning of the transmission completion comprises: the next expected received PDCP PDU is the sequence number after the sequence number of all currently received PDCP PDUs.

[0403] As an embodiment, the second signaling is RRC signaling.

[0404] As a sub-embodiment of this embodiment, the RRC signaling is RRCReconfiguration.

[0405] As an embodiment, the second signaling releases the first PDCP entity.

[0406] As an embodiment, the second signaling releases the first DRB.

[0407] As an embodiment, the second signaling releases the DRB corresponding to the first PDCP entity.

[0408] As an embodiment, step S5105 is after step S5103.

[0409] As an embodiment, the benefits of the above method comprise: increasing flexibility, saving power, saving resources, and reducing complexity.

[0410] As an embodiment, the rate of data transmission is indicated between the first PDCP entity and the second PDCP entity through information indication.

[0411] As an embodiment, the other PDCP entity discards PDCP SDU is indicated between the first PDCP entity and the second PDCP entity through information indication.

[0412] As an embodiment, the first PDCP entity using the first key decryption failure will not cause the second PDCP entity to be reestablished.

[0413] As an embodiment, the above method has the benefit of reducing the probability of disconnection.

[0414] As an embodiment, the second PDCP entity using the second key decryption failure will cause the first PDCP entity to be reestablished.

[0415] As an embodiment, the above method has the benefit of ensuring the normal operation of the second PDCP entity.

[0416] As one embodiment, the first node U01 can further receive a handover command to trigger the handover.

[0417] As one embodiment, the handover command comprises a first MAC CE, the first MAC CE triggering the LTM cell handover.

[0418] As one embodiment, the first PDCP PDU and the second PDCP PDU are associated.

[0419] As one embodiment, the first PDCP PDU carries a first PDCP SDU, the second PDCP PDU carries a second PDCP SDU.

[0420] As one embodiment, the first PDCP SDU generates the second PDCP SDU.

[0421] As one embodiment, the second key is deactivated after being obtained by the first node U01, the activation of the second key depending on at least one condition being fulfilled.

[0422] As one embodiment, the at least one condition being fulfilled comprises a radio link failure occurring.

[0423] As one embodiment, the at least one condition being fulfilled comprises a handover failure occurring.

[0424] As one embodiment, the at least one condition being fulfilled comprises a compatibility failure occurring.

[0425] As one embodiment, the at least one condition being fulfilled comprises a cell handover occurring.

[0426] As one embodiment, the at least one condition being fulfilled comprises a key failure in the first security context occurring.

[0427] As one embodiment, the at least one condition being fulfilled comprises a decryption failure using the first key.

[0428] As one embodiment, the at least one condition being fulfilled comprises a failure of an integrity protection verification using an integrity protection key associated with the first key.

[0429] As one embodiment, the at least one condition being fulfilled comprises an access to an unsecure network.

[0430] As one embodiment, the at least one condition being fulfilled comprises a discovery of a possible security state.

[0431] As one embodiment, the at least one condition being fulfilled comprises an entry into a roaming state.

[0432] As an embodiment, the above method has the benefit of more secure and reliable communication.

[0433] Example 6

[0434] Embodiment 6 illustrates a schematic diagram of a first PDCP entity and a second PDCP entity according to an embodiment of the present application, as shown in FIG. 6. Figure 6

[0435] As an embodiment, the first PDCP entity and the second PDCP entity are served by a first RLC entity respectively.

[0436] As an embodiment, the first RLC entity corresponds to a first RLC bearer.

[0437] As an embodiment, the logical channel identity associated with the first RLC bearer includes a first logical channel identity.

[0438] As an embodiment, the logical channel identity associated with the first RLC bearer includes a second logical channel identity.

[0439] As an embodiment, the first logical channel identity and the second logical channel identity are associated with the first PDCP entity and the second PDCP entity respectively.

[0440] As an embodiment, the first RLC bearer has the benefit of better serving and distinguishing the first PDCP entity and the second PDCP entity by associating two logical channel identities.

[0441] As an embodiment, the first PDCP entity and the second PDCP entity both use the first RLC bearer when transmitting PDCP PDUs.

[0442] As an embodiment, the first PDCP entity and the second PDCP entity both serve the same service.

[0443] As an embodiment, the first RLC bearer uses acknowledgement mode.

[0444] As an embodiment, the first RLC bearer uses non-acknowledgement mode.

[0445] As an embodiment, the first PDCP entity corresponds to a first cell, and the second PDCP entity corresponds to a second cell.

[0446] ​As an embodiment, the peer PDCP entity of the first PDCP entity is maintained by a first cell, and the peer PDCP entity of the second PDCP entity is maintained by a second cell.

[0447] As an embodiment, the first cell is a source cell, and the second cell is a target cell.

[0448] As an embodiment, the first cell and the second cell belong to a same cell group.

[0449] As an embodiment, the first cell and the second cell use different radio resources.

[0450] As an embodiment, only one of the first PDCP entity and the second PDCP entity uses AI (artificial intelligence) to predict data volume.

[0451] As an embodiment, only one of the first PDCP entity and the second PDCP entity uses AI to predict latency.

[0452] As an embodiment, the first signaling configures the first RLC entity.

[0453] As an embodiment, the first signaling configures the first RLC entity, including configuring the first RLC bearer.

[0454] As an embodiment, one RLC bearer corresponds to only one RLC entity.

[0455] As an embodiment, the first signaling configures the first RLC entity, including configuring the first RLC bearer to serve the first DRB and the second DRB.

[0456] As an embodiment, the protocol header of the PDCP PDU generated by the first PDCP entity and the PDCP PDU generated by the second PDCP entity includes a first field, which indicates which PDCP entity generates a PDCP PDU or associates which DRB.

[0457] As an embodiment, the benefits of both the first PDCP entity and the second PDCP entity being served by the first RLC bearer include ensuring data continuity, and in the process of switching, especially in LTM cell switching, being carried by the same first RLC bearer is conducive to smoother switching.

[0458] Example 7

[0459] Embodiment 7 illustrates a schematic diagram of the first PDCP entity and the second PDCP entity according to an embodiment of the present application, as shown in FIG. 7.Figure 7 as shown.

[0460] As an embodiment, the first PDCP entity and the second PDCP entity are served by a first RLC entity and a second RLC entity respectively.

[0461] As an embodiment, the first RLC entity corresponds to a first RLC bearer.

[0462] As an embodiment, the second RLC entity corresponds to a second RLC bearer.

[0463] As an embodiment, the first PDCP entity and the second PDCP entity being served by a first RLC entity and a second RLC entity respectively includes that the first PDCP entity is served by the first RLC bearer and the second PDCP entity is served by the second RLC bearer.

[0464] As an embodiment, the first PDCP entity and the second PDCP entity being served by a first RLC entity and a second RLC entity respectively includes that the first DRB is served by the first RLC bearer and the second DRB is served by the second RLC bearer.

[0465] As an embodiment, the logical channel identity associated with the first RLC bearer includes a first logical channel identity.

[0466] As an embodiment, the logical channel identity associated with the second RLC bearer includes a second logical channel identity.

[0467] As an embodiment, the first logical channel identity and the second logical channel identity are associated with the first PDCP entity and the second PDCP entity respectively.

[0468] As an embodiment, the first PDCP entity transmits PDCP PDUs through the first RLC bearer.

[0469] As an embodiment, the second PDCP entity transmits PDCP PDUs through the second RLC bearer.

[0470] As an embodiment, the first RLC bearer uses an acknowledgement mode and the second RLC bearer uses an acknowledgement mode.

[0471] As an embodiment, the first RLC bearer uses an acknowledgement mode and the second RLC bearer uses a non-acknowledgement mode.

[0472] As an embodiment, the first PDCP entity corresponds to a first cell and the second PDCP entity corresponds to a second cell.

[0473] As one embodiment, the peer PDCP entity of the first PDCP entity is maintained by a first cell, and the peer PDCP entity of the second PDCP entity is maintained by a second cell.

[0474] As one embodiment, the first cell is a source cell, and the second cell is a target cell.

[0475] As one embodiment, the first cell and the second cell belong to a same cell group.

[0476] As one embodiment, the first cell and the second cell use different radio resources.

[0477] As one embodiment, only one of the first PDCP entity and the second PDCP entity uses AI (artificial intelligence) to predict data volume.

[0478] As one embodiment, only one of the first PDCP entity and the second PDCP entity uses AI to predict latency.

[0479] As one embodiment, the first signaling configures the first RLC entity. The first signaling configures the second RLC entity.

[0480] As one embodiment, the first signaling configures the first RLC entity, including configuring the first RLC bearer.

[0481] As one embodiment, the second signaling configures the second RLC entity, including configuring the second RLC bearer.

[0482] As one embodiment, one RLC bearer corresponds to only one RLC entity.

[0483] As one embodiment, the first signaling configures the first RLC entity, including configuring the first RLC bearer to serve the first DRB.

[0484] As one embodiment, the first signaling configures the first RLC entity, including configuring the first RLC bearer to serve at least a first one of the first DRB and the second DRB.

[0485] As one embodiment, the first signaling configures the first RLC entity, including configuring the first RLC bearer.

[0486] As one embodiment, the first signaling configures the second RLC entity, including configuring the second RLC bearer to serve the second DRB.

[0487] As one embodiment, the second RLC entity is generated by the first RLC entity.

[0488] As one embodiment, the first node sends the first information.

[0489] As one embodiment, the first information indicates to release the first PDCP entity, or the first information indicates to release the first DRB.

[0490] As one embodiment, the first information indicates to deactivate the first PDCP entity, or the first information indicates to deactivate the first DRB.

[0491] As one embodiment, the first information indicates that transmission of the first PDCP entity is completed, or the first information indicates that transmission of the first DRB is completed.

[0492] As one embodiment, the first RLC entity is released along with the release of the first PDCP entity.

[0493] As one embodiment, the first RLC entity is released along with the release of the first DRB.

[0494] As one embodiment, the first PDCP entity and the second PDCP entity serve the same data service.

[0495] As one embodiment, the first PDCP entity and the second PDCP entity serve the same QoS flow.

[0496] As one embodiment, the first PDCP entity and the second PDCP entity serve the same XR service.

[0497] Example 8

[0498] Embodiment 8 illustrates a diagram showing whether the first key and the second key belong to one security context for the master node or two security contexts for the master node depending on the generation manner of the first key and the second key according to one embodiment of the present application, as shown in FIG. 8. Figure 8

[0499] As one embodiment, whether the first key and the second key belong to one security context for the master node or two security contexts for the master node is determined by the first node itself.

[0500] ​As one embodiment, when the generation of one of the first key and the second key depends on the other, the first key and the second key belong to one security context for the master node, otherwise, the first key and the second key belong to two security contexts for the master node.

[0501] As one embodiment, the above method has the advantage of facilitating management and modification.

[0502] As one embodiment, when the first key and the second key are derived from the same key, the first key and the second key belong to one security context for the master node, and when the first key and the second key are derived from different keys, the first key and the second key belong to two security contexts for the master node.

[0503] As one embodiment, the same key refers to the same K gNB .

[0504] As one embodiment, the different keys refer to different K gNB .

[0505] As one embodiment, the above method has the advantage of facilitating management and modification.

[0506] As one embodiment, when the first key and the second key are obtained by the security mechanism of the 5G system, the first key and the second key belong to one security context for the master node, and when the first key and the second key are obtained by the security mechanism outside the 5G system, the first key and the second key belong to two security contexts for the master node.

[0507] As one embodiment, the system outside the 5G system includes a 6G system.

[0508] As one embodiment, when the first key and the second key are both indicated by the TN network, the first key and the second key belong to one security context for the master node, and when the first key and the second key are indicated by the TN network and the NTN network, the first key and the second key belong to two security contexts for the master node.

[0509] As one embodiment, when the first key and the second key are both indicated by the NTN network, the first key and the second key belong to one security context for the master node, and when the first key and the second key are indicated by the TN network and the NTN network, the first key and the second key belong to two security contexts for the master node.

[0510] As one embodiment, when one of the first key and the second key is a temporary key, the first key and the second key belong to one security context for the master node, when both the first key and the second key are non-temporary keys, the first key and the second key belong to two security contexts for the master node.

[0511] As one embodiment, when both the first key and the second key are generated by the same pseudo-random sequence, the first key and the second key belong to one security context for the master node, when the first key and the second key are generated by different pseudo-random sequences, the first key and the second key belong to two security contexts for the master node.

[0512] As one embodiment, the same pseudo-random sequence includes pseudo-random sequences of the same generation mode.

[0513] As one embodiment, the different pseudo-random sequences include pseudo-random sequences of different generation modes.

[0514] As one embodiment, whether the first key and the second key belong to one security context for the master node or belong to two security contexts for the master node is indicated by the network.

[0515] As one embodiment, the network indicates the benefit of matching the corresponding security context of the network.

[0516] Example 9

[0517] Embodiment 9 illustrates a structural block diagram of a processing apparatus in a first node according to one embodiment of the present application; as shown in the accompanying Figure 9 Embodiment 9 illustrates a structural block diagram of a processing apparatus in a first node according to one embodiment of the present application; as shown in the accompanying Figure 9 In the accompanying drawings, the processing apparatus 900 in the first node includes a first receiver 901 and a first transmitter 902.

[0518] In embodiment 9, the first receiver 901 receives first signaling, the first signaling configuring a first PDCP entity and a second PDCP entity, wherein the first PDCP entity uses a first key for encryption, the second PDCP entity uses a second key for encryption, and the first key and the second key both belong to a security context of a master node (MN); the first PDCP entity and the second PDCP entity both correspond to a DRB;

[0519] The first PDCP entity and the second PDCP entity are different; the first key and the second key are different; the first key and the second key belonging to the security context of the master node means that the first key and the second key belong to one security context for the master node, or the first key and the second key belong to two security contexts for the master node respectively.

[0520] As an embodiment, the first PDCP entity corresponds to a first DRB, the first PDCP entity corresponds to a second DRB, the first DRB and the second DRB serve the same service, and the serving the same service includes that the same QoS flow is mapped to the first DRB and the second DRB.

[0521] As an embodiment, the first transmitter 902 transmits first information, the first information requests to release one of the first DRB and the second DRB, or the first information indicates that the transmission on one of the first DRB and the second DRB is completed.

[0522] The first PDCP entity corresponds to a first DRB, and the first PDCP entity corresponds to a second DRB.

[0523] As an embodiment, whether the first key and the second key belong to one security context for the master node or belong to two security contexts for the master node depends on the generation mode of the first key and the second key.

[0524] As an embodiment, the first signaling configures K PDCP entities, K is greater than 2, wherein the K PDCP entities include the first PDCP entity and the second PDCP entity, the K PDCP entities are encrypted using K keys respectively, and the K keys all belong to the security context of the master node.

[0525] As an embodiment, the opposite end PDCP entities of the first PDCP entity and the second PDCP entity are maintained by a first cell and a second cell respectively.

[0526] As an embodiment, the first cell and the second cell are a source cell and a target cell respectively.

[0527] As an embodiment, the first PDCP entity and the second PDCP entity are served by a first RLC entity respectively.

[0528] As an embodiment, the first PDCP entity and the second PDCP entity are served by a first RLC entity and a second RLC entity respectively.

[0529] As an embodiment, the first PDCP entity corresponds to a first DRB, and the second PDCP entity corresponds to a second DRB.

[0530] As an embodiment, the peer PDCP entity of the first PDCP entity and the second PDCP entity is maintained by a same cell.

[0531] As an embodiment, the first node is a user equipment (UE).

[0532] As an embodiment, the first node is a mobile phone.

[0533] As an embodiment, the first node is a low latency enabled communication device.

[0534] As an embodiment, the first node is an industrial communication device.

[0535] As an embodiment, the first node is an Internet of Things terminal or an industrial Internet of Things terminal.

[0536] As an embodiment, the first receiver 901 includes at least one of the antenna 452, the receiver 454, the receive processor 456, the multi-antenna receive processor 458, the controller / processor 459, the memory 460, or the data source 467 in embodiment 4.

[0537] As an embodiment, the first transmitter 902 includes at least one of the antenna 452, the transmitter 454, the transmit processor 468, the multi-antenna transmit processor 457, the controller / processor 459, the memory 460, or the data source 467 in embodiment 4.

[0538] Those skilled in the art can understand that all or part of the steps in the foregoing method can be instructed by programs to the relevant hardware, and the programs can be stored in a computer readable storage medium, such as a read-only memory, a hard disk, an optical disk or the like. Alternatively, all or part of the steps of the foregoing embodiments can also be implemented using one or more integrated circuits. Correspondingly, each module unit in the foregoing embodiments can be implemented in the form of hardware or in the form of a software function module, and the present application is not limited to any specific form of combination of software and hardware. The user equipment, terminal and UE in the present application include but are not limited to unmanned aerial vehicles, communication modules on unmanned aerial vehicles, remote control aircraft, aircraft, small aircraft, mobile phones, tablet computers, notebooks, vehicle-mounted communication devices, wireless sensors, network cards, Internet of Things terminals, RFID terminals, NB-IoT terminals, MTC (Machine Type Communication) terminals, eMTC (enhanced MTC) terminals, data cards, network cards, vehicle-mounted communication devices, low-cost mobile phones, low-cost tablet computers, satellite communication devices, ship communication devices, NTN user equipment and the like wireless communication devices. The base station or system equipment in the present application includes but is not limited to macro cellular base stations, micro cellular base stations, home base stations, relay base stations, gNB (NR NodeB) NR NodeB, TRP (Transmitter Receiver Point), NTN base station, satellite equipment, flight platform equipment and the like wireless communication devices.

[0539] The present application can be implemented in other specified forms without departing from the core or essential characteristics thereof. Therefore, the presently disclosed embodiments should in no way be considered as descriptive rather than limiting. The scope of the application is determined by the appended claims rather than the preceding description, and all modifications within the equivalent meaning and range of the claims are considered to be included therein.

Claims

1. A first node used for encryption in wireless communication, wherein, Comprising: a first receiver, configured to receive first signaling, the first signaling configuring a first PDCP entity and a second PDCP entity, wherein the first PDCP entity is encrypted using a first key and the second PDCP entity is encrypted using a second key, and the first key and the second key both belong to a security context of a master node (MN); the first PDCP entity and the second PDCP entity both correspond to a DRB; wherein the first PDCP entity and the second PDCP entity are different, the first key and the second key are different, and the meaning that the first key and the second key both belong to a security context of a master node is that the first key and the second key belong to one security context of the master node or the first key and the second key belong to two security contexts of the master node respectively.

2. The first node of claim 1, wherein: the first PDCP entity corresponds to a first DRB and the first PDCP entity corresponds to a second DRB, and the first DRB and the second DRB serve a same service, and the serving a same service comprises that a same QoS flow is mapped to the first DRB and the second DRB.

3. The first node of claim 1 or 2, wherein, Comprising: a first transmitter, configured to send first information, the first information requesting to release one of a first DRB and a second DRB or the first information indicating that transmission on one of the first DRB and the second DRB is completed; wherein the first PDCP entity corresponds to a first DRB and the first PDCP entity corresponds to a second DRB.

4. The first node of any one of claims 1 to 3, wherein whether the first key and the second key belong to one security context of a master node or belong to two security contexts of the master node depends on a generation manner of the first key and the second key.

5. The first node of any one of claims 1 to 4, wherein the first signaling configures K PDCP entities, K is greater than 2, wherein the K PDCP entities comprise the first PDCP entity and the second PDCP entity, and the K PDCP entities are encrypted using K keys respectively, and the K keys all belong to a security context of a master node.

6. The first node of any one of claims 1 to 5, wherein opposite end PDCP entities of the first PDCP entity and the second PDCP entity are maintained by a first cell and a second cell respectively.

7. The first node of claim 6, wherein: the first cell and the second cell are a source cell and a target cell respectively.

8. The first node of claim 6 or 7, wherein: the first PDCP entity and the second PDCP entity are served by a first RLC entity respectively.

9. The first node of claim 6 or 7, wherein: ​ ​ ​ The first PDCP entity and the second PDCP entity are respectively served by a first RLC entity and a second RLC entity.

10. A method in a first node used for encryption in wireless communication, wherein, Comprise: Receiving first signaling, the first signaling configures a first PDCP entity and a second PDCP entity, wherein the first PDCP entity uses a first key for encryption, and the second PDCP entity uses a second key for encryption, and the first key and the second key both belong to a security context of a master node (MN); The first PDCP entity and the second PDCP entity both correspond to a DRB; Wherein, the first PDCP entity and the second PDCP entity are different; the first key and the second key are different; the meaning that the first key and the second key both belong to the security context of the master node is that the first key and the second key belong to one security context for the master node, or the first key and the second key respectively belong to two security contexts for the master node.