Emergency service configuration method and system
By transmitting and selecting appropriate wireless standard air integrity protection and encryption algorithms between base stations, the problem of emergency call continuity during Xn handover is solved, ensuring the emergency call capability of terminal devices when handover from 4G to 5G or from 5G to 4G, and realizing seamless transition of emergency calls.
Patent Information
- Application Number
- CN202410572779.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-09
- Publication Date
- 2025-11-11
Smart Images

Figure CN120935542A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication technology, and more specifically, to a configuration method and system for emergency services. Background Technology
[0002] Overall, similar to existing systems within the 3rd Generation Partnership Project (3GPP), the 5th Generation Mobile Communication Technology (5G) system architecture is still divided into two parts: the 5G core network (5GCore, 5GC) and the 5G access network (Next Generation Radio Access Network, NG-RAN), such as... Figure 1 As shown, 5GC includes control plane and user plane network elements. In addition to the Access and Mobility Management Function (AMF), the control plane network elements also include the Session Management Function (SMF), and the user plane network elements include the User Plane Function (UPF). However, there is no interface between the SMF and the 5G access network.
[0003] NG-RAN consists of two logical nodes: 5G base stations (the next-generation NodeB, gNB) and next-generation evolved NodeBs (ng-eNB) that can access the 5GC. The gNB serves as the protocol termination point for the control plane and user plane between the New Radio (NR) base station and the user equipment (UE), while the ng-eNB serves as the protocol termination point for the control plane and user plane between the LTE base station and the UE. Connections between gNBs, between ng-eNBs, and between gNBs and ng-eNBs are established via the Xn interface. NG-RAN connects to the 5GC via the NG interface, which is further divided into NG-C and NG-U interfaces. The NG-C interface connects to the AMF control plane, while the NG-U interface connects to the UPF user plane. The NG interface supports many-to-many connections.
[0004] When a terminal is in connected mode, the network manages its mobility through a handover process. Changes in terminal channel conditions may trigger handover, and the network may also initiate handover for load balancing purposes. When LTE and NR base stations share the same core network, the UE can perform Xn handover, i.e., inter RAT handover. Xn handover has the following characteristics: 1. The source system configures and reports the target system's measurements; 2. The source system determines access preparation and provides necessary information to the target system, such as 4G to 5G handover. Necessary messages are transmitted through a transparent Radio Resource Control (RRC) container, including the current QoS flow to DRB mapping; 3. The target system's radio resources are ready before handover; 4. The RRC reconfiguration message from the target RAT is transmitted to the source RAT through a transparent container and then passed to the UE by the source RAT in the handover command; 5. Handover between gNB and ng-eNB supports in-order and lossless handover; 6. Handover between different systems supports Xn and NG interfaces. The specific Xn handover process is as follows: Figure 2 As shown.
[0005] Emergency call service, introduced after the widespread adoption of telephone service, allows mobile users to quickly dial the nearest emergency service center to their current base station in emergency situations. Emergency calls require the network to forward the call to a specific emergency service center number. This service takes priority over other services and can be successfully made even if the user is in arrears or their service is suspended. This reflects the operator's social responsibility.
[0006] Emergency call services deployed by telecom operators have a long history, dating back to the circuit-switched domain era. In the early stages of 4G network deployment, operators typically used a Circuit Switched Fallback (CSFB) scheme for emergency calls. Specifically, the terminal initiates a regular Voice over Long Term Evolution (VoLTE) call. The Session Border Controller (SBC) configures an emergency call list and responds with a 380 message to the relevant calls. Upon receiving the message, the terminal performs a CSFB. This method is still applicable in some areas today, therefore compatibility with this network architecture still needs to be considered.
[0007] Currently, 5G emergency calls include four methods, and the 3rd Generation Partnership Project (3GPP) protocol mainly focuses on the first two methods:
[0008] Voice over New Radio (VoNR): An Emergency-Packet Data Unit (E-PDU) is established directly on the New Radio (NR) interface. The IP Multimedia Subsystem Emergency Communication Service (IMS ECC) is then completed through the E-PDU. In this case, the EM Cindicator needs to be set to True in the 5G MM Registration Accept on the network side.
[0009] Evolved Packet System Fallback (EPSFB): An attempt is made to establish an E-PDU on NR, and the network actively triggers a handover (HO) or redirection procedure to bring the User Equipment (UE) to LTE. Then, IMS ECC is completed through the Emergency Packet Data Network (E-PDN). In this case, the network sets the EM Cindicator to True in 5G MM Registration Accept.
[0010] There is a special service in emergency calls called Unverified Emergency Service (UES). UES is provided to meet regulatory requirements in certain regions, and 5G systems should support UES access. This requirement applies to all terminal devices and is only valid for service networks where UES regulations exist. Service networks located in areas where UES are prohibited should not support this feature.
[0011] The security algorithms used in 4G / 5G security are actually based on the following three algorithms: Snow 3G, Advanced Encryption Standard (AES), and ZUC.
[0012] According to TS38.331, in the current RRC messages, the 5G base station can configure the following encryption and integrity protection algorithms for the UE through RRC messages:
[0013]
[0014]
[0015] It should be noted that currently, for integrity protection algorithms, the base station side only supports nia0, nia1, nia2, and nia3, while the encryption algorithm only supports nea0, nea1, nea2, and nea3.
[0016] According to TS36.331, in the current RRC messages, the 4G base station can configure the following encryption and integrity protection algorithms for the UE through RRC messages:
[0017]
[0018] Before a terminal switches from 4G to 5G, it's difficult for the terminal to support NIA0. Since the Internet Protocol Multimedia Subsystem (IMS) service theoretically only supports up to EIA0, it's necessary to simultaneously support the 4G integrity protection method EIA0 on the 5G side. Similarly, according to protocol requirements, when an empty integrity protection algorithm is configured, an empty encryption algorithm should also be configured. Likewise, when a terminal switches from 5G to 4G, it's difficult for the terminal to support EIA0. Since the IMS service theoretically only supports up to NIA0, it's necessary to simultaneously support the 5G integrity protection method NIA0 on the 4G side. Similarly, according to protocol requirements, when an empty integrity protection algorithm is configured, an empty encryption algorithm should also be configured.
[0019] To support the inter-RAT handover described above, the current terminal and base station protocols have the following issues: 1. Terminal devices in restricted service mode cannot maintain emergency call capabilities during the Xn handover from 4G to 5G: Considering that 5G base stations cannot support EIA0 and EEA0 capabilities, emergency call users cannot be guaranteed when the terminal undergoes an Xn handover from 4G to 5G; 2. Terminals in restricted system mode cannot maintain emergency call capabilities during the Xn handover from 5G to 4G: Considering that 4G base stations cannot support NIA0 and NEA0 capabilities, emergency call users cannot be guaranteed when the terminal undergoes an Xn handover from 5G to 4G; 3. The source base station cannot transmit the terminal's support for null encryption algorithms to the target base station during the Xn handover: In the current protocol, during the Xn handover between 4G / 5G, the source base station cannot send the complete terminal security capabilities to the target base station, resulting in the terminal being unable to guarantee emergency call users' calls during the Xn handover process.
[0020] Based on the above analysis of requirements and causes, the current 3GPP Rel-15 and subsequent versions of the protocol still have deficiencies in dealing with unauthenticated emergency services. In order to ensure emergency call capabilities during Xn handover, the existing protocol needs to be enhanced to meet the needs of network deployment and optimization. Summary of the Invention
[0021] This application provides an emergency service configuration method and system to at least solve the technical problem that existing protocols cannot guarantee the continuity of emergency calls during Xn handover due to their lack of support for null integrity protection and null encryption algorithms. This results in the inability to guarantee the continuity of emergency call services for terminal devices in restricted service mode during Xn handover.
[0022] According to one aspect of the embodiments of this application, an emergency service configuration method is provided, comprising: a first base station receiving terminal security capabilities sent by a second base station, wherein the terminal security capabilities include at least one of the following: a first wireless standard spatial integrity protection algorithm, a first wireless standard spatial encryption algorithm, a second wireless standard spatial integrity protection algorithm, and a second wireless standard spatial encryption algorithm; the first base station is either a first wireless standard base station or a second wireless standard base station, and the second base station is either a first wireless standard base station or a second wireless standard base station; the first base station selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection, or the first base station selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
[0023] Optionally, the first wireless standard includes: 4G LTE (Long Term Evolution) or 5G NR (New Radio); the second wireless standard includes: 5G NR or 6G.
[0024] Optionally, if the first wireless base station is a 4G LTE base station, the first wireless base station is connected to the 5G core network, and the second wireless base station is a 5G NR base station; if the first wireless base station is a 5G NR base station, the first wireless base station is connected to the 6G core network, and the second wireless base station is a 6G base station.
[0025] Optionally, the first base station selects a first wireless standard spatial integrity protection algorithm for integrity protection and / or a first wireless standard spatial encryption algorithm for confidentiality protection, including: when the first base station is a first wireless standard base station, the first base station selects a first wireless standard spatial integrity protection algorithm for integrity protection and / or a first wireless standard spatial encryption algorithm for confidentiality protection.
[0026] Optionally, the first base station selects a second wireless standard spatial integrity protection algorithm for integrity protection and / or a second wireless standard spatial encryption algorithm for confidentiality protection, including: when the first base station is a second wireless standard base station, the first base station selects a second wireless standard spatial integrity protection algorithm for integrity protection and / or a second wireless standard spatial encryption algorithm for confidentiality protection.
[0027] Optionally, the first base station receives the terminal security capabilities sent by the second base station, including: the first base station receives the terminal security capabilities sent by the second base station through the Xn interface.
[0028] Optionally, the first base station receives the terminal security capabilities sent by the second base station, including: the first base station receives the terminal security capabilities sent by the second base station through the NG interface.
[0029] Optionally, if there is a direct connection interface between the first base station and the second base station, and the first base station and the second base station are connected to the first core network, if the first core network control plane entity allows unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions to use the null integrity protection algorithm and the null encryption algorithm, the first base station receives the first core network control plane entity's support capability for the null integrity protection algorithm and the null encryption algorithm for unauthenticated IMS emergency sessions. The first core network is a 5G core network or a 6G core network. The first core network control plane entity includes: the Access and Mobility Management Function (AMF) entity.
[0030] Optionally, the null integrity protection algorithm includes: a first wireless standard null integrity protection algorithm NIA0 and / or a second wireless standard null integrity protection algorithm EIA0; the null encryption algorithm includes: a first wireless standard null encryption algorithm NEA0 and / or a second wireless standard null encryption algorithm EEA0.
[0031] Optionally, after receiving the capability from the first core network control plane entity to provide support for the empty integrity protection algorithm and the empty encryption algorithm for unauthenticated IMS emergency sessions, the first base station supports providing emergency bearer services to terminal devices in restricted service mode; the first base station sends a first system information block (SIB) to the terminal devices in restricted service mode, wherein the first SIB includes: an IMS emergency bearer service support field.
[0032] Optionally, the IMS Emergency Bearer Service Support field is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service to terminal devices in restricted service mode. The IMS Emergency Bearer Service Support field is an enumeration type. When the IMS Emergency Bearer Service Support field is true, it means that the cell of the first base station supports providing IMS emergency bearer service to terminal devices in restricted service mode. When the IMS Emergency Bearer Service Support field is absent, it means that the cell of the first base station does not support providing IMS emergency bearer service to terminal devices in restricted service mode.
[0033] Optionally, after a terminal device in restricted service mode accesses the first base station and the IMS emergency bearer service of the terminal device in restricted service mode is activated, the first base station sends the null integrity protection algorithm and / or null encryption algorithm to the terminal device in restricted service mode through the first radio resource control (RRC) reconfiguration message.
[0034] Optionally, the first RRC reconfiguration message may also include: radio bearer configuration information, wherein the radio bearer configuration information includes: encryption algorithm and integrity protection algorithm, the encryption algorithm being used for signaling radio bearer and / or data radio bearer, and the integrity protection algorithm being used for signaling radio bearer and / or data radio bearer.
[0035] Optionally, the encryption algorithm includes: a first wireless standard null encryption algorithm and / or a second wireless standard null encryption algorithm; the integrity protection algorithm includes: a first wireless standard null integrity protection algorithm and / or a second wireless standard null integrity protection algorithm.
[0036] Optionally, when the first base station determines that a terminal device in a restricted service mode will be switched from the first base station to the second base station, the first base station sends a first handover request message to the second base station. The first handover request message includes: terminal security capabilities, which include at least one of the following: a first wireless standard null encryption algorithm and a first wireless standard null integrity protection algorithm, and / or a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm.
[0037] Optionally, if the second base station is a first wireless standard base station, and the second base station determines, based on the first handover request message, that the terminal device in the restricted service mode supports the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm, the first base station receives a first handover confirmation message sent by the second base station. The second base station is configured to send the first handover confirmation message to the first base station after receiving the first handover request message. The second base station is also configured to support the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm when the second base station is a first wireless standard base station.
[0038] Optionally, the first handover confirmation message includes: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
[0039] Optionally, the first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in restricted service mode. The new air interface handover command includes a second reconfiguration message. The terminal device in restricted service mode is used, after accessing the second base station, to perform secure configuration of the signaling radio bearer and the data radio bearer according to the second reconfiguration message, using a first radio standard air encryption algorithm and a first radio standard air integrity protection algorithm.
[0040] Optionally, if the second base station is a second wireless standard base station, and the second base station determines, based on the first handover request message, that the terminal device in the restricted service mode supports the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm, the first base station receives a first handover confirmation message sent by the second base station. The second base station is configured to send the first handover confirmation message to the first base station after receiving the first handover request message. The second base station is also configured to support the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm when the second base station is a second wireless standard base station.
[0041] Optionally, the first handover confirmation message includes: an indication that the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
[0042] Optionally, the first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in restricted service mode. The new air interface handover command includes a second reconfiguration message. The terminal device in restricted service mode is used, after accessing the second base station, to perform secure configuration of the signaling radio bearer and the data radio bearer according to the second reconfiguration message, using a second radio standard air encryption algorithm and a second radio standard air integrity protection algorithm.
[0043] Optionally, if there is no direct connection interface between the first base station and the second base station, and the first base station and the second base station are connected to the first core network, if the first core network control plane entity allows unauthenticated IMS emergency sessions to use the null integrity protection algorithm and the null encryption algorithm, the first base station receives the first core network control plane entity's support capability for the null integrity protection algorithm and the null encryption algorithm for unauthenticated IMS emergency sessions. The first core network is a 5G core network or a 6G core network. The first core network control plane entity includes: the Access and Mobility Management Function (AMF) entity.
[0044] Optionally, the null integrity protection algorithm includes: a first wireless standard null integrity protection algorithm NIA0 and / or a second wireless standard null integrity protection algorithm EIA0; the null encryption algorithm includes: a first wireless standard null encryption algorithm NEA0 and / or a second wireless standard null encryption algorithm EEA0.
[0045] Optionally, after receiving the capability from the first core network control plane entity to provide support for the empty integrity protection algorithm and the empty encryption algorithm for unauthenticated IMS emergency sessions, the first base station supports providing emergency bearer services to terminal devices in restricted service mode; the first base station sends a first system message block (SIB) to the terminal devices in restricted service mode, wherein the first SIB includes an IMS emergency bearer service support field.
[0046] Optionally, the IMS Emergency Bearer Service Support field is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service to terminal devices in restricted service mode. The IMS Emergency Bearer Service Support field is an enumeration type. When the IMS Emergency Bearer Service Support field is true, it means that the cell of the first base station supports providing IMS emergency bearer service to terminal devices in restricted service mode. When the IMS Emergency Bearer Service Support field is absent, it means that the cell of the first base station does not support providing IMS emergency bearer service to terminal devices in restricted service mode.
[0047] Optionally, after a terminal device in restricted service mode accesses the first base station and the IMS emergency bearer service of the terminal device in restricted service mode is activated, the first base station sends the null integrity protection algorithm and / or null encryption algorithm to the terminal device in restricted service mode through the first radio resource control (RRC) reconfiguration message.
[0048] Optionally, the first RRC reconfiguration message may also include: radio bearer configuration information, wherein the radio bearer configuration information includes: encryption algorithm and integrity protection algorithm, the encryption algorithm being used for signaling radio bearer and / or data radio bearer, and the integrity protection algorithm being used for signaling radio bearer and / or data radio bearer.
[0049] Optionally, the encryption algorithm includes: a first wireless standard null encryption algorithm and / or a second wireless standard null encryption algorithm; the integrity protection algorithm includes: a first wireless standard null integrity protection algorithm and / or a second wireless standard null integrity protection algorithm.
[0050] Optionally, when the first base station determines that a terminal device in a limited service mode will be switched from the first base station to the second base station, the first base station sends a first handover request message to the first core network, wherein the first core network is used to send a second handover request message to the second base station, and the second handover request message includes: the first handover request message sent by the first base station to the first core network.
[0051] Optionally, the first handover request message includes: terminal security capabilities, which include at least one of the following: a first wireless standard null encryption algorithm and a first wireless standard null integrity protection algorithm, and / or a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm.
[0052] Optionally, if the second base station is a first wireless standard base station, and the second base station determines, based on the second handover request message, that the terminal device in the restricted service mode supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, the first base station receives a first handover confirmation message sent by the first core network. The first core network is used to receive a second handover confirmation message sent by the second base station and send the first handover confirmation message from the second handover confirmation message to the first base station. The second base station is used to support the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm when the second base station is a first wireless standard base station.
[0053] Optionally, the first handover confirmation message includes: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
[0054] Optionally, the first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in restricted service mode. The new air interface handover command includes a second reconfiguration message. The terminal device in restricted service mode is used, after accessing the second base station, to perform secure configuration of the signaling radio bearer and the data radio bearer according to the second reconfiguration message, using a first radio standard air encryption algorithm and a first radio standard air integrity protection algorithm.
[0055] Optionally, if the second base station is a second wireless standard base station, and the second base station determines, based on the second handover request message, that the terminal device in the restricted service mode supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, the first base station receives a first handover confirmation message sent by the first core network. The first core network is used to receive the second handover confirmation message sent by the second base station and send the first handover confirmation message from the second handover confirmation message to the first base station. The second base station is used to support the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm when the second base station is a second wireless standard base station.
[0056] Optionally, the first handover confirmation message includes: an indication that the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
[0057] Optionally, the first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in restricted service mode. The new air interface handover command includes a second reconfiguration message. The terminal device in restricted service mode is used, after accessing the second base station, to perform secure configuration of the signaling radio bearer and the data radio bearer according to the second reconfiguration message, using a second radio standard air encryption algorithm and a second radio standard air integrity protection algorithm.
[0058] According to another aspect of the embodiments of this application, an emergency service configuration method is also provided, comprising: a second base station sending terminal security capabilities to a first base station, wherein the terminal security capabilities include at least one of the following: a first wireless standard spatial integrity protection algorithm, a first wireless standard spatial encryption algorithm, a second wireless standard spatial integrity protection algorithm, and a second wireless standard spatial encryption algorithm; the first base station is either a first wireless standard base station or a second wireless standard base station, and the second base station is either a first wireless standard base station or a second wireless standard base station; the first base station is configured to select the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection, or to select the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
[0059] Optionally, the first wireless standard includes: 4G LTE (Long Term Evolution) or 5G NR (New Radio); the second wireless standard includes: 5G NR or 6G.
[0060] Optionally, if the first wireless base station is a 4G LTE base station, the first wireless base station is connected to the 5G core network, and the second wireless base station is a 5G NR base station; if the first wireless base station is a 5G NR base station, the first wireless base station is connected to the 6G core network, and the second wireless base station is a 6G base station.
[0061] Optionally, if the second base station is a base station of the first wireless standard, the second base station selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection.
[0062] Optionally, if the second base station is a base station of the second wireless standard, the second base station selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
[0063] Optionally, the second base station sends terminal security capabilities to the first base station, including: the second base station sending terminal security capabilities to the first base station through the Xn interface, wherein the first base station is used to select a first wireless standard spatial integrity protection algorithm for integrity protection and / or a first wireless standard spatial encryption algorithm for confidentiality protection when the first base station is a first wireless standard base station; the first base station is also used to select a second wireless standard spatial integrity protection algorithm for integrity protection and / or a second wireless standard spatial encryption algorithm for confidentiality protection when the first base station is a second wireless standard base station.
[0064] Optionally, the second base station sends terminal security capabilities to the first base station, including: the second base station sending terminal security capabilities to the first base station via the NG interface, wherein the first base station is used to select a first wireless standard spatial integrity protection algorithm for integrity protection and / or a first wireless standard spatial encryption algorithm for confidentiality protection when the first base station is a first wireless standard base station; the first base station is also used to select a second wireless standard spatial integrity protection algorithm for integrity protection and / or a second wireless standard spatial encryption algorithm for confidentiality protection when the first base station is a second wireless standard base station.
[0065] Optionally, when the first base station determines that a terminal device in restricted service mode will be switched from the first base station to the second base station, the second base station receives a first handover request message sent by the first base station. The first base station is configured to, when there is a direct connection interface between the first base station and the second base station, and the first base station and the second base station are connected to the first core network, if the first core network control plane entity allows unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions to use null integrity protection and null encryption algorithms, receive a message from the first core network control plane entity indicating that the first core network control plane entity provides support for null integrity protection and null encryption algorithms for unauthenticated IMS emergency sessions. The first base station is also configured to, after receiving support for null integrity protection and null encryption algorithms from the first core network control plane entity for unauthenticated IMS emergency sessions, support providing emergency bearer services to the terminal device in restricted service mode.
[0066] Optionally, the first handover request message includes: terminal security capabilities, which include at least one of the following: a first wireless standard null encryption algorithm and a first wireless standard null integrity protection algorithm, and / or a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm.
[0067] Optionally, if the second base station is a first wireless standard base station, and the second base station determines, based on the first handover request message, that the terminal device in the restricted service mode supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, the second base station sends a first handover confirmation message to the first base station after receiving the first handover request message.
[0068] Optionally, if the second base station is a base station of the first wireless standard, it supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm.
[0069] Optionally, the first handover confirmation message includes: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
[0070] Optionally, if the second base station is a second wireless standard base station, and the second base station determines that the terminal device in the restricted service mode supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, the second base station sends a first handover confirmation message to the first base station after receiving the first handover request message.
[0071] Optionally, if the second base station is a second wireless standard base station, it supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm.
[0072] Optionally, the first handover confirmation message includes: an indication that the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
[0073] Optionally, when the first base station determines that a terminal device in restricted service mode will be switched from the first base station to the second base station, the second base station receives a second handover request message sent by the first core network, wherein the first core network is used to receive a first handover request message sent by the first base station; the second handover request message includes: the first handover request message; the first base station is used to receive a message from the first core network control plane entity that provides support for the empty integrity protection algorithm and the empty encryption algorithm for unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions when there is no direct connection interface between the first base station and the second base station and the first base station and the second base station are connected to the first core network, and if the first core network control plane entity allows unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions to use the empty integrity protection algorithm and the empty encryption algorithm; the first base station is also used to support providing emergency bearer services for terminal devices in restricted service mode after receiving support for the empty integrity protection algorithm and the empty encryption algorithm from the first core network control plane entity for unauthenticated IMS emergency sessions;
[0074] Optionally, the first handover request message includes: terminal security capabilities, which include at least one of the following: a first wireless standard null encryption algorithm and a first wireless standard null integrity protection algorithm, and / or a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm.
[0075] Optionally, if the second base station is a first wireless standard base station, and the second base station determines, according to the second handover request message, that the terminal device in the restricted service mode supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, the second base station sends a second handover confirmation message to the first core network, wherein the first core network is used to send the first handover confirmation message in the second handover confirmation message to the first base station.
[0076] Optionally, if the second base station is a base station of the first wireless standard, it supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm.
[0077] Optionally, the first handover confirmation message includes: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
[0078] Optionally, if the second base station is a second wireless standard base station, and the second base station determines, according to the second handover request message, that the terminal device in the restricted service mode supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, the second base station sends a second handover confirmation message to the first core network, wherein the first core network is used to send the first handover confirmation message in the second handover confirmation message to the first base station.
[0079] Optionally, if the second base station is a second wireless standard base station, it supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm.
[0080] Optionally, the first handover confirmation message includes: an indication that the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
[0081] According to another aspect of the embodiments of this application, an emergency service configuration method is also provided, comprising: a terminal device in a restricted service mode receiving a first system message block (SIB) sent by a first base station, wherein the first SIB includes an IMS emergency bearer service support field; the first base station receiving terminal security capabilities sent by a second base station, wherein the terminal security capabilities include at least one of the following: a first wireless standard spatial integrity protection algorithm, a first wireless standard spatial encryption algorithm, a second wireless standard spatial integrity protection algorithm, and a second wireless standard spatial encryption algorithm, wherein the first base station is either a first wireless standard base station or a second wireless standard base station, and the second base station is either a first wireless standard base station or a second wireless standard base station; the first base station is further configured to select the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection, or to select the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
[0082] Optionally, the IMS Emergency Bearer Service Support field is used to indicate whether the cell of the first base station supports providing IMS Emergency Bearer Service for terminal devices in restricted service mode.
[0083] Optionally, the IMS Emergency Bearer Service Support field is an enumeration type. When the IMS Emergency Bearer Service Support field is true, it means that the cell of the first base station supports providing IMS Emergency Bearer Service for terminal devices in restricted service mode. When the IMS Emergency Bearer Service Support field is absent, it means that the cell of the first base station does not support providing IMS Emergency Bearer Service for terminal devices in restricted service mode.
[0084] Optionally, after a terminal device in restricted service mode accesses the first base station and its IMS emergency bearer service is activated, the terminal device in restricted service mode receives the null integrity protection algorithm and / or null encryption algorithm sent by the first base station through a first radio resource control (RRC) reconfiguration message. The first base station is configured to receive a first handover confirmation message sent by the second base station if the second base station is a first radio standard base station and the second base station determines that the terminal device in restricted service mode supports the first radio standard null encryption algorithm and the first radio standard null integrity protection algorithm. The first handover confirmation message includes: an indication that the second base station supports the first radio standard null encryption algorithm and the first radio standard null integrity protection algorithm; a second reconfiguration message; and second security configuration information, which includes: the first radio standard null integrity protection algorithm NIA0 and the first radio standard null encryption algorithm NEA0.
[0085] Optionally, the first RRC reconfiguration message may also include: radio bearer configuration information, wherein the radio bearer configuration information includes: encryption algorithm and integrity protection algorithm, the encryption algorithm being used for signaling radio bearer and / or data radio bearer, and the integrity protection algorithm being used for signaling radio bearer and / or data radio bearer.
[0086] Optionally, the encryption algorithm includes: a first wireless standard null encryption algorithm and / or a second wireless standard null encryption algorithm; the integrity protection algorithm includes: a first wireless standard null integrity protection algorithm and / or a second wireless standard null integrity protection algorithm.
[0087] Optionally, the terminal device in restricted service mode receives a new air interface handover command sent by the first base station, wherein the new air interface handover command includes a second reconfiguration message.
[0088] Optionally, after accessing the second base station, the terminal device in the restricted service mode, according to the second reconfiguration message, uses the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm to perform secure configuration of the signaling radio bearer and the data radio bearer.
[0089] Optionally, after a terminal device in restricted service mode accesses the first base station and its IMS emergency bearer service is activated, the terminal device in restricted service mode receives the null integrity protection algorithm and / or null encryption algorithm sent by the first base station through a first radio resource control (RRC) reconfiguration message. The first base station is configured to receive a first handover confirmation message sent by the second base station when the second base station is a second radio standard base station and the second base station determines that the terminal device in restricted service mode supports the first radio standard null encryption algorithm and the first radio standard null integrity protection algorithm. The first handover confirmation message includes: an indication that the second base station supports the second radio standard null encryption algorithm and the second radio standard null integrity protection algorithm; and a second reconfiguration message. The second reconfiguration message includes: second security configuration information, which includes: the second radio standard null integrity protection algorithm EIA0 and the second radio standard null encryption algorithm EEA0.
[0090] Optionally, the terminal device in restricted service mode receives a new air interface handover command sent by the first base station, wherein the new air interface handover command includes a second reconfiguration message.
[0091] Optionally, after accessing the second base station, the terminal device in the restricted service mode, according to the second reconfiguration message, uses the second wireless standard spatial encryption algorithm and the second wireless standard spatial integrity protection algorithm to perform secure configuration of the signaling radio bearer and the data radio bearer.
[0092] According to another aspect of the embodiments of this application, an emergency service configuration system is also provided, including: a first base station, a second base station, a terminal device, and a first core network control plane entity, wherein the first base station is communicatively connected to both the terminal device and the second base station, and is used to receive terminal security capabilities sent by the second base station, wherein the terminal security capabilities include at least one of the following: a first wireless standard spatial integrity protection algorithm, a first wireless standard spatial encryption algorithm, a second wireless standard spatial integrity protection algorithm, and a second wireless standard spatial encryption algorithm; the first base station is either a first wireless standard base station or a second wireless standard base station, and the second base station is either a first wireless standard base station or a second wireless standard base station; the first base station selects the first wireless standard spatial integrity protection algorithm for processing. The first base station may select a second wireless standard spatial integrity protection algorithm and / or a second wireless standard spatial encryption algorithm for confidentiality protection, or the first base station may select a second wireless standard spatial integrity protection algorithm for integrity protection and / or a second wireless standard spatial encryption algorithm for confidentiality protection; the terminal device is a terminal device in a restricted service mode; when the first base station and the second base station are connected to the first core network, if the first core network control plane entity allows unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions to use the spatial integrity protection algorithm and the spatial encryption algorithm, the first core network control plane entity is used to send a message to the first base station that the first core network control plane entity provides support for the spatial integrity protection algorithm and the spatial encryption algorithm for unauthenticated IMS emergency sessions.
[0093] Optionally, the first wireless standard includes: 4G LTE (Long Term Evolution) or 5G NR (New Radio); the second wireless standard includes: 5G NR or 6G.
[0094] Optionally, if the first wireless base station is a 4G LTE base station, the first wireless base station is connected to the 5G core network, and the second wireless base station is a 5G NR base station; if the first wireless base station is a 5G NR base station, the first wireless base station is connected to the 6G core network, and the second wireless base station is a 6G base station.
[0095] Optionally, if the first base station is a first wireless standard base station, the first base station selects a first wireless standard spatial integrity protection algorithm for integrity protection and / or a first wireless standard spatial encryption algorithm for confidentiality protection.
[0096] Optionally, if the first base station is a base station of the second wireless standard, the first base station selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
[0097] Optionally, the first base station receives terminal security capabilities sent by the second base station through the Xn interface.
[0098] Optionally, the first base station receives terminal security capabilities sent by the second base station via the NG interface.
[0099] Optionally, the first core network is a 5G core network or a 6G core network; the control plane entity of the first core network includes: the Access and Mobility Management Function (AMF) entity.
[0100] Optionally, if there is a direct connection interface between the first base station and the second base station, and the first base station and the second base station are connected to the first core network, if the first core network control plane entity allows unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions to use the null integrity protection algorithm and the null encryption algorithm, the first base station receives the first core network control plane entity's support capability for the null integrity protection algorithm and the null encryption algorithm for unauthenticated IMS emergency sessions.
[0101] Optionally, the null integrity protection algorithm includes: a first wireless standard null integrity protection algorithm NIA0 and / or a second wireless standard null integrity protection algorithm EIA0; the null encryption algorithm includes: a first wireless standard null encryption algorithm NEA0 and / or a second wireless standard null encryption algorithm EEA0.
[0102] Optionally, after receiving the capability from the first core network control plane entity to provide support for the empty integrity protection algorithm and the empty encryption algorithm for unauthenticated IMS emergency sessions, the first base station supports providing emergency bearer services to terminal devices in restricted service mode; the first base station sends a first system message block (SIB) to the terminal devices in restricted service mode, wherein the first SIB includes an IMS emergency bearer service support field.
[0103] Optionally, the IMS Emergency Bearer Service Support field is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service to terminal devices in restricted service mode. The IMS Emergency Bearer Service Support field is an enumeration type. When the IMS Emergency Bearer Service Support field is true, it means that the cell of the first base station supports providing IMS emergency bearer service to terminal devices in restricted service mode. When the IMS Emergency Bearer Service Support field is absent, it means that the cell of the first base station does not support providing IMS emergency bearer service to terminal devices in restricted service mode.
[0104] Optionally, the IMS Emergency Bearer Service Support field is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service to terminal devices in restricted service mode. The IMS Emergency Bearer Service Support field is an enumeration type. When the IMS Emergency Bearer Service Support field is true, it means that the cell of the first base station supports providing IMS emergency bearer service to terminal devices in restricted service mode. When the IMS Emergency Bearer Service Support field is absent, it means that the cell of the first base station does not support providing IMS emergency bearer service to terminal devices in restricted service mode.
[0105] Optionally, after a terminal device in restricted service mode accesses the first base station and the IMS emergency bearer service of the terminal device in restricted service mode is activated, the first base station sends the null integrity protection algorithm and / or null encryption algorithm to the terminal device in restricted service mode through the first radio resource control (RRC) reconfiguration message.
[0106] Optionally, the first RRC reconfiguration message may also include: radio bearer configuration information, wherein the radio bearer configuration information includes: encryption algorithm and integrity protection algorithm, the encryption algorithm being used for signaling radio bearer and / or data radio bearer, and the integrity protection algorithm being used for signaling radio bearer and / or data radio bearer.
[0107] Optionally, the encryption algorithm includes: a first wireless standard null encryption algorithm and / or a second wireless standard null encryption algorithm; the integrity protection algorithm includes: a first wireless standard null integrity protection algorithm and / or a second wireless standard null integrity protection algorithm.
[0108] Optionally, when the first base station determines that a terminal device in a restricted service mode will be switched from the first base station to the second base station, the first base station sends a first handover request message to the second base station. The first handover request message includes: terminal security capabilities, which include at least one of the following: a first wireless standard null encryption algorithm and a first wireless standard null integrity protection algorithm, and / or a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm.
[0109] Optionally, if the second base station is a first wireless standard base station, and the second base station determines, based on the first handover request message, that the terminal device in the restricted service mode supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, the first base station receives the first handover confirmation message sent by the second base station; after receiving the first handover request message, the second base station sends the first handover confirmation message to the first base station; and if the second base station is a first wireless standard base station, the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm.
[0110] Optionally, the first handover confirmation message includes: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
[0111] Optionally, the first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in restricted service mode. The new air interface handover command includes a second reconfiguration message. After the terminal device in restricted service mode accesses the second base station, it performs secure configuration of the signaling radio bearer and the data radio bearer according to the second reconfiguration message, using the first radio standard air encryption algorithm and the first radio standard air integrity protection algorithm.
[0112] Optionally, if the second base station is a second wireless standard base station, and the second base station determines, based on the first handover request message, that the terminal device in the restricted service mode supports the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm, the first base station receives the first handover confirmation message sent by the second base station; after receiving the first handover request message, the second base station sends the first handover confirmation message to the first base station; and if the second base station is a second wireless standard base station, the second base station supports the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm.
[0113] Optionally, the first handover confirmation message includes: an indication that the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
[0114] Optionally, the first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in restricted service mode. The new air interface handover command includes a second reconfiguration message. After the terminal device in restricted service mode accesses the second base station, it performs secure configuration of the signaling radio bearer and the data radio bearer according to the second reconfiguration message, using a second radio standard air encryption algorithm and a second radio standard air integrity protection algorithm.
[0115] Optionally, if there is no direct connection interface between the first base station and the second base station, and the first base station and the second base station are connected to the first core network, if the first core network control plane entity allows unauthenticated IMS emergency sessions to use the empty integrity protection algorithm and the empty encryption algorithm, the first base station receives the first core network control plane entity's support capability for the empty integrity protection algorithm and the empty encryption algorithm for unauthenticated IMS emergency sessions.
[0116] Optionally, the null integrity protection algorithm includes: a first wireless standard null integrity protection algorithm NIA0 and / or a second wireless standard null integrity protection algorithm EIA0; the null encryption algorithm includes: a first wireless standard null encryption algorithm NEA0 and / or a second wireless standard null encryption algorithm EEA0.
[0117] Optionally, after receiving the capability from the first core network control plane entity to provide support for the empty integrity protection algorithm and the empty encryption algorithm for unauthenticated IMS emergency sessions, the first base station supports providing emergency bearer services to terminal devices in restricted service mode; the first base station sends a first system message block (SIB) to the terminal devices in restricted service mode, wherein the first SIB includes an IMS emergency bearer service support field.
[0118] Optionally, the IMS Emergency Bearer Service Support field is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service to terminal devices in restricted service mode. The IMS Emergency Bearer Service Support field is an enumeration type. When the IMS Emergency Bearer Service Support field is true, it means that the cell of the first base station supports providing IMS emergency bearer service to terminal devices in restricted service mode. When the IMS Emergency Bearer Service Support field is absent, it means that the cell of the first base station does not support providing IMS emergency bearer service to terminal devices in restricted service mode.
[0119] Optionally, after a terminal device in restricted service mode accesses the first base station and the IMS emergency bearer service of the terminal device in restricted service mode is activated, the first base station sends the null integrity protection algorithm and / or null encryption algorithm to the terminal device in restricted service mode through the first radio resource control (RRC) reconfiguration message.
[0120] Optionally, the first RRC reconfiguration message may also include: radio bearer configuration information, wherein the radio bearer configuration information includes: encryption algorithm and integrity protection algorithm, the encryption algorithm being used for signaling radio bearer and / or data radio bearer, and the integrity protection algorithm being used for signaling radio bearer and / or data radio bearer.
[0121] Optionally, the encryption algorithm includes: a first wireless standard null encryption algorithm and / or a second wireless standard null encryption algorithm; the integrity protection algorithm includes: a first wireless standard null integrity protection algorithm and / or a second wireless standard null integrity protection algorithm.
[0122] Optionally, if the first base station determines that a terminal device in a limited service mode will be switched from the first base station to the second base station, the first base station sends a first handover request message to the first core network; the first core network sends a second handover request message to the second base station, the second handover request message including: the first handover request message sent by the first base station to the first core network.
[0123] Optionally, the first handover request message includes: terminal security capabilities, which include at least one of the following: a first wireless standard null encryption algorithm and a first wireless standard null integrity protection algorithm, and / or a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm.
[0124] Optionally, if the second base station is a first wireless standard base station, and the second base station determines, based on the second handover request message, that the terminal device in the restricted service mode supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, the first base station receives a first handover confirmation message sent by the first core network; the first core network receives a second handover confirmation message sent by the second base station, and sends the first handover confirmation message in the second handover confirmation message to the first base station; and the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm when the second base station is a first wireless standard base station.
[0125] Optionally, the first handover confirmation message includes: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
[0126] Optionally, the first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in restricted service mode. The new air interface handover command includes a second reconfiguration message. After the terminal device in restricted service mode accesses the second base station, it performs secure configuration of the signaling radio bearer and the data radio bearer according to the second reconfiguration message, using the first radio standard air encryption algorithm and the first radio standard air integrity protection algorithm.
[0127] Optionally, if the second base station is a second wireless standard base station, and the second base station determines, based on the second handover request message, that the terminal device in the restricted service mode supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, the first base station receives the first handover confirmation message sent by the first core network; the first core network receives the second handover confirmation message sent by the second base station, and sends the first handover confirmation message in the second handover confirmation message to the first base station; and the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm when the second base station is a second wireless standard base station.
[0128] Optionally, the first handover confirmation message includes: an indication that the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
[0129] Optionally, the first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in restricted service mode. The new air interface handover command includes a second reconfiguration message. After the terminal device in restricted service mode accesses the second base station, it performs secure configuration of the signaling radio bearer and the data radio bearer according to the second reconfiguration message, using a second radio standard air encryption algorithm and a second radio standard air integrity protection algorithm.
[0130] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided, the storage medium including a stored program, wherein the program, when running, controls the device where the storage medium is located to perform the above-mentioned emergency services configuration method.
[0131] According to another aspect of the embodiments of this application, an electronic device is also provided, including: a memory and a processor, the processor being configured to run a program stored in the memory, wherein the program executes the above-described configuration method for emergency services during runtime.
[0132] According to another aspect of the embodiments of this application, a computer program is also provided, wherein when the computer program is executed by a processor, it implements the above-described configuration method for emergency services.
[0133] According to another aspect of the embodiments of this application, a computer program product is also provided, the computer program product including a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and the computer program, when executed by a processor, implements the above-mentioned configuration method for emergency services.
[0134] In this embodiment, a first base station receives terminal security capabilities transmitted by a second base station. These terminal security capabilities include at least one of the following: a first wireless standard spatial integrity protection algorithm, a first wireless standard spatial encryption algorithm, a second wireless standard spatial integrity protection algorithm, and a second wireless standard spatial encryption algorithm. The first base station is either a first wireless standard base station or a second wireless standard base station, and the second base station is either a first wireless standard base station or a second wireless standard base station. The first base station selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection; alternatively, the first base station selects the second wireless standard spatial integrity protection algorithm for integrity protection. By using confidentiality protection and / or a second wireless standard spatial encryption algorithm for confidentiality protection, the spatial integrity protection algorithm and spatial encryption algorithm are enhanced during the Xn handover process from 4G to 5G or from 5G to 4G. This achieves the technical effect of ensuring the continuity of emergency call services for terminal devices in restricted service mode during the Xn handover process from 4G to 5G or from 5G to 4G. Furthermore, it solves the technical problem that existing protocols cannot guarantee the continuity of emergency calls during the Xn handover process due to their inability to support spatial integrity protection and spatial encryption algorithms. Attached Figure Description
[0135] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0136] Figure 1 A 5G system architecture diagram is shown;
[0137] Figure 2 A flowchart of an Xn switching process is shown;
[0138] Figure 3 This is a flowchart of an emergency service configuration method according to an embodiment of this application;
[0139] Figure 4 This is a structural diagram of an emergency service configuration system according to an embodiment of this application;
[0140] Figure 5 This is a signaling interaction diagram of a configuration method based on emergency services according to an embodiment of this application;
[0141] Figure 6 This is a signaling interaction diagram of another configuration method based on emergency services according to an embodiment of this application;
[0142] Figure 7This is a hardware structure block diagram of a computer terminal for an emergency service configuration method according to an embodiment of this application. Detailed Implementation
[0143] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0144] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0145] According to an embodiment of this application, a method embodiment for configuring emergency services is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0146] Figure 3 This is a flowchart of an emergency service configuration method according to an embodiment of this application, such as... Figure 3 As shown, the method includes the following steps:
[0147] In step S302, the first base station receives the terminal security capabilities sent by the second base station, wherein the terminal security capabilities include at least one of the following: a first wireless standard air integrity protection algorithm, a first wireless standard air encryption algorithm, a second wireless standard air integrity protection algorithm, and a second wireless standard air encryption algorithm. The first base station is either a first wireless standard base station or a second wireless standard base station, and the second base station is either a first wireless standard base station or a second wireless standard base station.
[0148] In other words, the second base station sends terminal security capabilities to the first base station. These terminal security capabilities include one or more of the following: a first wireless standard's spatial integrity protection algorithm, a first wireless standard's spatial encryption algorithm, a second wireless standard's spatial integrity protection algorithm, and a second wireless standard's spatial encryption algorithm. The first base station can be either a first wireless standard base station or a second wireless standard base station, and the second base station can be either a first wireless standard base station or a second wireless standard base station.
[0149] A wireless standard refers to the technical standard or specification used in wireless network communication, which defines how wireless devices transmit data. IMS is a system composed of all functional entities capable of providing multimedia services. IMS includes a set of functional entities related to signaling and bearers. IMS utilizes packet-switched domains and multimedia bearers to implement multimedia services. This enables operators to provide their users with multimedia services based on Internet-based applications, services, and protocols. IMS is independent of the underlying IP access network; 3GPP, 3GPP2, and I-WLAN can all access the IMS system to establish associations, QoS, and billing management between Session Initiation Protocol (SIP) sessions and General Packet Radio Service (GPRS) sessions.
[0150] For example, the first wireless standard spatial integrity protection algorithm is NIA0, the first wireless standard spatial encryption algorithm is NEA0, the second wireless standard spatial integrity protection algorithm is EIA0, and the second wireless standard spatial encryption algorithm is EEA0.
[0151] Step S304: The first base station selects a first wireless standard spatial integrity protection algorithm for integrity protection and / or a first wireless standard spatial encryption algorithm for confidentiality protection; or, the first base station selects a second wireless standard spatial integrity protection algorithm for integrity protection and / or a second wireless standard spatial encryption algorithm for confidentiality protection.
[0152] According to some optional embodiments of this application, the first wireless standard includes: 4G LTE (4th generation mobile communication technology) or 5G NR (5th generation mobile communication technology); the second wireless standard includes: 5G NR or 6G. Further, when the first wireless standard base station is a 4G LTE base station, the first wireless standard base station is connected to a 5G core network, and the second wireless standard base station is a 5G NR base station connected to the 5G core network; when the first wireless standard base station is a 5G NR base station, the first wireless standard base station is connected to a 6G core network, and the second wireless standard base station is a 6G base station connected to the 6G core network.
[0153] Preferably, the first base station selects a first wireless standard spatial integrity protection algorithm for integrity protection and / or a first wireless standard spatial encryption algorithm for confidentiality protection, which can be achieved by the following method: when the first base station is a first wireless standard base station, the first base station selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection. Furthermore, the first base station selects a second wireless standard spatial integrity protection algorithm for integrity protection and / or a second wireless standard spatial encryption algorithm for confidentiality protection, which can be achieved by the following method: when the first base station is a second wireless standard base station, the first base station selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
[0154] The first base station can receive terminal security capabilities sent by the second base station through the following method: the first base station receives terminal security capabilities sent by the second base station via the Xn interface. Alternatively, it can receive terminal security capabilities sent by the second base station via the NG interface.
[0155] It is worth noting that the emergency service configuration method provided in this application can be applied to both Xn and NG handover. Specifically, when applied to Xn handover, the second base station can be a first wireless standard base station (i.e., the first and second base stations use the same wireless standard); the second base station can also be a second wireless standard base station (i.e., the first and second base stations use different wireless standards). When applied to NG handover, the second base station can be a first wireless standard base station (i.e., the first and second base stations use the same wireless standard); the second base station can also be a second wireless standard base station (i.e., the first and second base stations use different wireless standards). The configuration methods for emergency services in different scenarios are described in detail below.
[0156] According to some alternative embodiments of this application, if there is a direct connection interface between the first base station and the second base station, and the first base station and the second base station are connected to the first core network, if the first core network control plane entity allows unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions to use the null integrity protection algorithm and the null encryption algorithm, the first base station receives the first core network control plane entity's support capability for the null integrity protection algorithm and the null encryption algorithm for unauthenticated IMS emergency sessions.
[0157] For example, the direct connection between the first base station and the second base station is the Xn interface.
[0158] Preferably, the first core network is a 5G core network or a 6G core network. The control plane entities of the first core network include: the Access and Mobility Management Function (AMF) entity. The spatial integrity protection algorithm includes: a first radio standard spatial integrity protection algorithm NIA0 and / or a second radio standard spatial integrity protection algorithm EIA0; the spatial encryption algorithm includes: a first radio standard spatial encryption algorithm NEA0 and / or a second radio standard spatial encryption algorithm EEA0.
[0159] Understandably, after receiving support from the first core network control plane entity for empty integrity protection and empty encryption algorithms for unauthenticated IMS emergency sessions, the first base station can support providing emergency bearer services to terminal devices in restricted service mode. Further, the first base station sends a first system message block (SIB) to the terminal device in restricted service mode, wherein the first SIB includes an IMS emergency bearer service support field. The IMS emergency bearer service support field indicates whether the cell of the first base station supports providing IMS emergency bearer services to terminal devices in restricted service mode; the IMS emergency bearer service support field is an enumeration type. When the IMS emergency bearer service support field is true, it indicates that the cell of the first base station supports providing IMS emergency bearer services to terminal devices in restricted service mode; when the IMS emergency bearer service support field is absent, it indicates that the cell of the first base station does not support providing IMS emergency bearer services to terminal devices in restricted service mode.
[0160] Furthermore, after a terminal device in restricted service mode accesses the first base station and its IMS emergency bearer service is activated, the first base station sends a null integrity protection algorithm and / or a null encryption algorithm to the terminal device in restricted service mode via a first Radio Resource Control (RRC) reconfiguration message. The first RRC reconfiguration message includes, but is not limited to, radio bearer configuration information, which includes, but is not limited to, encryption algorithms and integrity protection algorithms. The encryption algorithms are used for signaling radio bearers and / or data radio bearers, and the integrity protection algorithms are used for signaling radio bearers and / or data radio bearers. Preferably, the encryption algorithms include, but are not limited to, a first radio standard null encryption algorithm and / or a second radio standard null encryption algorithm; the integrity protection algorithms include, but are not limited to, a first radio standard null integrity protection algorithm and / or a second radio standard null integrity protection algorithm.
[0161] Furthermore, when the first base station determines that the terminal device in the restricted service mode will be switched from the first base station to the second base station, the first base station sends a first handover request message to the second base station. The first handover request message includes: terminal security capabilities, which include at least one of the following: a first wireless standard air encryption algorithm and a first wireless standard air integrity protection algorithm, and / or a second wireless standard air encryption algorithm and a second wireless standard air integrity protection algorithm.
[0162] The following sections will provide detailed explanations of two scenarios: the second base station is a base station using the first wireless standard, and the second base station is a base station using the second wireless standard.
[0163] When the second base station is a base station of the first wireless standard, and the second base station determines, based on the first handover request message, that the terminal device in the restricted service mode supports the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm, the first base station receives a first handover confirmation message sent by the second base station. The second base station is configured to send the first handover confirmation message to the first base station after receiving the first handover request message. The second base station is also configured to support the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm when the second base station is a base station of the first wireless standard.
[0164] Preferably, the first handover confirmation message includes: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
[0165] Furthermore, the first base station triggers a new air interface handover command, sending the command to the terminal device in restricted service mode. This command includes a second reconfiguration message. It is understood that after accessing the second base station, the terminal device in restricted service mode can, based on the second reconfiguration message, employ the first radio standard air encryption algorithm and the first radio standard air integrity protection algorithm to securely configure the signaling radio bearer and data radio bearer.
[0166] When the second base station is a base station of the second wireless standard, and the second base station determines, based on the first handover request message, that the terminal device in the restricted service mode supports the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm, the first base station receives a first handover confirmation message sent by the second base station. The second base station is configured to send the first handover confirmation message to the first base station after receiving the first handover request message. The second base station is also configured to support the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm when the second base station is a base station of the second wireless standard.
[0167] Preferably, the first handover confirmation message includes: an indication that the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
[0168] Furthermore, the first base station triggers a new air interface handover command, sending the command to the terminal device in restricted service mode. This command includes a second reconfiguration message. It is understood that the terminal device in restricted service mode, after accessing the second base station, can use the second reconfiguration message to perform secure configuration of the signaling and data radio bearers using a second radio standard air encryption algorithm and a second radio standard air integrity protection algorithm to do so.
[0169] As some optional embodiments of this application, in the case where there is no direct connection interface between the first base station and the second base station, and the first base station and the second base station are connected to the first core network, if the first core network control plane entity allows unauthenticated IMS emergency sessions to use the empty integrity protection algorithm and the empty encryption algorithm, the first base station receives the first core network control plane entity's support capability for the empty integrity protection algorithm and the empty encryption algorithm for unauthenticated IMS emergency sessions.
[0170] For example, when there is no direct connection between the first base station and the second base station, there is an NG interface between the first base station and the second base station.
[0171] Preferably, the first core network is a 5G core network or a 6G core network; the control plane entity of the first core network includes: the Access and Mobility Management Function (AMF) entity. The spatial integrity protection algorithm includes: a first radio standard spatial integrity protection algorithm NIA0 and / or a second radio standard spatial integrity protection algorithm EIA0; the spatial encryption algorithm includes: a first radio standard spatial encryption algorithm NEA0 and / or a second radio standard spatial encryption algorithm EEA0.
[0172] Understandably, after receiving support from the first core network control plane entity for empty integrity protection and empty encryption algorithms for unauthenticated IMS emergency sessions, the first base station supports providing emergency bearer services to terminal devices in restricted service mode. Further, the first base station sends a first system message block (SIB) to the terminal device in restricted service mode, wherein the first SIB includes an IMS emergency bearer service support field. The IMS emergency bearer service support field indicates whether the cell of the first base station supports providing IMS emergency bearer services to terminal devices in restricted service mode; the IMS emergency bearer service support field is an enumeration type. When the IMS emergency bearer service support field is true, it indicates that the cell of the first base station supports providing IMS emergency bearer services to terminal devices in restricted service mode; when the IMS emergency bearer service support field is absent, it indicates that the cell of the first base station does not support providing IMS emergency bearer services to terminal devices in restricted service mode.
[0173] Furthermore, after a terminal device in restricted service mode accesses the first base station and its IMS emergency bearer service is activated, the first base station sends a null integrity protection algorithm and / or a null encryption algorithm to the terminal device in restricted service mode via a first Radio Resource Control (RRC) reconfiguration message. The first RRC reconfiguration message further includes radio bearer configuration information, which includes an encryption algorithm and an integrity protection algorithm. The encryption algorithm is used for signaling radio bearers and / or data radio bearers, and the integrity protection algorithm is used for signaling radio bearers and / or data radio bearers. Preferably, the encryption algorithms include, but are not limited to, a first radio standard null encryption algorithm and / or a second radio standard null encryption algorithm; the integrity protection algorithms include, but are not limited to, a first radio standard null integrity protection algorithm and / or a second radio standard null integrity protection algorithm.
[0174] Furthermore, when the first base station determines that a terminal device in a restricted service mode will be switched from the first base station to the second base station, the first base station sends a first handover request message to the first core network. The first core network then sends a second handover request message to the second base station, the second handover request message including the first handover request message sent by the first base station to the first core network. Preferably, the first handover request message includes, but is not limited to, terminal security capabilities, which include at least one of the following: a first wireless standard null encryption algorithm and a first wireless standard null integrity protection algorithm, and / or a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm.
[0175] The following sections will provide detailed explanations of two scenarios: the second base station is a base station using the first wireless standard, and the second base station is a base station using the second wireless standard.
[0176] When the second base station is a base station of the first wireless standard, and the second base station determines, according to the second handover request message, that the terminal device in the restricted service mode supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, the first base station receives a first handover confirmation message sent by the first core network. The first core network is used to receive a second handover confirmation message sent by the second base station and send the first handover confirmation message from the second handover confirmation message to the first base station. The second base station is used to support the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm when the second base station is a base station of the first wireless standard.
[0177] Preferably, the first handover confirmation message includes: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
[0178] Furthermore, the first base station triggers a new air interface handover command, sending the command to the terminal device in restricted service mode. This command includes a second reconfiguration message. It is understood that the terminal device in restricted service mode, after accessing the second base station, can use the second reconfiguration message to securely configure the signaling and data radio bearers using the first radio standard air encryption algorithm and the first radio standard air integrity protection algorithm.
[0179] When the second base station is a base station of the second wireless standard, and the second base station determines, according to the second handover request message, that the terminal device in the restricted service mode supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, the first base station receives a first handover confirmation message sent by the first core network. The first core network is used to receive a second handover confirmation message sent by the second base station and send the first handover confirmation message from the second handover confirmation message to the first base station. The second base station is used to support the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm when the second base station is a base station of the second wireless standard.
[0180] Preferably, the first handover confirmation message includes: an indication that the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
[0181] Furthermore, the first base station triggers a new air interface handover command, sending the command to the terminal device in restricted service mode. This command includes a second reconfiguration message. It is understood that the terminal device in restricted service mode, after accessing the second base station, can use the second reconfiguration message to perform secure configuration of the signaling and data radio bearers using a second radio standard air encryption algorithm and a second radio standard air integrity protection algorithm to do so.
[0182] In the above steps, the first base station receives the terminal security capabilities sent by the second base station. These terminal security capabilities include at least one of the following: a first wireless standard spatial integrity protection algorithm, a first wireless standard spatial encryption algorithm, a second wireless standard spatial integrity protection algorithm, and a second wireless standard spatial encryption algorithm. The first base station is either a first wireless standard base station or a second wireless standard base station, and the second base station is either a first wireless standard base station or a second wireless standard base station. The first base station selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection, or the first base station selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection. This achieves the purpose of enhancing the spatial integrity protection algorithm and spatial encryption algorithm during the Xn handover process from 4G to 5G or from 5G to 4G, thereby achieving the technical effect of ensuring the continuity of emergency call services for terminal devices in restricted service mode during the Xn handover process from 4G to 5G or from 5G to 4G.
[0183] In some preferred embodiments of this application, a specific process is provided for a terminal device in limited service mode to switch from a first 5G base station gNB to a second 4G base station ng-eNB via the Xn interface, wherein both the first 5G base station gNB and the second 4G base station ng-eNB are connected to 5GC.
[0184] Step 1: The terminal device receives an SIB1 message sent by the first base station. This SIB1 message indicates whether the cell of the first base station supports providing IMS emergency bearer service to terminal devices in limited service mode. The SIB1 message includes, but is not limited to, the following information: an IMS Emergency Support field, where "true" indicates support and "absent" indicates no support. The IMS Emergency Support field can also be referred to as the IMS Emergency Bearer Service Support field.
[0185] Step 2: The terminal device sends a first capability reporting message (UE CapabilityInformation) to the first base station. The first capability reporting message is used to indicate the terminal device's support capability for IMS emergency bearer service in restricted service mode. The first capability reporting message includes, but is not limited to, the following information: IMS emergency call support field (when this field exists, it indicates that the terminal device supports IMS emergency call); NIA0, NEA0; EIA0, EEA0; NIA0, NEA0, EIA0, EEA0.
[0186] Step 3: After the terminal device connects to the first base station and the IMS emergency service is activated, the first base station sends the first radio standard's null integrity protection algorithm (NIA0) and / or the first radio standard's null encryption algorithm (NEA0) to the terminal device through a first RRC Reconfiguration message. This first RRC Reconfiguration message includes, but is not limited to, the following information: Radio bearer configuration: For each radio bearer configuration, the following content is included: Encryption algorithm: Indicates the encryption algorithm used for signaling radio bearers (SRBs) and data radio bearers (DRBs), specifically including NEA0 and EEA0; Integrity protection algorithm: Indicates the integrity protection algorithm used for signaling radio bearers, specifically including NIA0 and EIA0.
[0187] Step 4: When the first base station decides to switch the terminal device from the first base station to the second base station based on the measurement and reporting results, the first base station sends a first handover request message (HANDOVER REQUEST) to the second base station. The first handover request message includes the terminal device's support capability for the IMS emergency bearer service in restricted service mode (UE SecurityCapabilities). Specifically, the first handover request message includes, but is not limited to, one or more of the following information: EIA0, EEA0; NIA0, NEA0, EIA0, EEA0.
[0188] Step 5-1: When the second base station is a base station supporting a second wireless standard (i.e., the first and second base stations use different wireless standards), the second base station supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm. Based on the first handover request message, the second base station learns that the terminal device supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm (EEA0, EIA0). At this time, the second base station allows the terminal device to access the second base station. Therefore, the second base station sends a first handover confirmation message to the first base station. This first handover confirmation message includes: an indication that the second base station supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm, and a second reconfiguration message (sent by the second base station to the terminal device). This second reconfiguration message contains second security configuration information, which includes, but is not limited to, the following information: the second wireless standard's null integrity protection algorithm and the second wireless standard's null encryption algorithm.
[0189] Step 6-1: After the first base station receives the first handover confirmation message sent by the second base station, it sends the second reconfiguration message in the first handover confirmation message to the terminal device. The second reconfiguration message sent to the terminal device includes, but is not limited to, the following information: EIA0, EEA0.
[0190] Step 7-1: The terminal device completes the configuration of the integrity protection algorithm and encryption algorithm according to the second security configuration information, and after updating the key according to these algorithms, it accesses the second base station. After accessing the second base station, the terminal device performs security configuration on the signaling radio bearer and data radio bearer according to the second security configuration information, namely the second wireless standard empty encryption algorithm and the second wireless standard empty integrity protection algorithm.
[0191] As some other preferred embodiments of this application, a specific process is provided for a terminal device in limited service mode to switch from a first 5G base station gNB to a second 4G base station ng-eNB via the Xn interface, wherein both the first 5G base station gNB and the second 4G base station ng-eNB are connected to 5GC.
[0192] Step 1: The terminal device receives the SIB1 message sent by the first base station. The SIB1 message is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service for terminal devices in restricted service mode. The SIB1 message includes, but is not limited to, the following information: the IMS Emergency Support field, where "true" indicates support and "absent" indicates no support.
[0193] Step 2: The terminal device sends a first capability reporting message (UE CapabilityInformation) to the first base station. The first capability reporting message is used to indicate the terminal device's support capability for IMS emergency bearer service in restricted service mode. The first capability reporting message includes, but is not limited to, the following information: IMS emergency call support field (when this field exists, it indicates that the terminal device supports IMS emergency call); NIA0, NEA0; EIA0, EEA0; NIA0, NEA0, EIA0, EEA0.
[0194] Step 3: After the terminal device connects to the first base station and the IMS emergency service is activated, the first base station sends the first radio standard's null integrity protection algorithm (NIA0) and / or the first radio standard's null encryption algorithm (NEA0) to the terminal device through a first RRC Reconfiguration message. The first RRC Reconfiguration message includes, but is not limited to, the following information: Radio bearer configuration: For each radio bearer configuration, the following content is included: Encryption algorithm: Indicates the encryption algorithm used for SRBs and DRBs, specifically including NEA0 and EEA0; Integrity protection algorithm: Indicates the integrity protection algorithm used for signaling radio bearers, specifically including NIA0 and EIA0.
[0195] Step 4: When the first base station decides to switch the terminal device from the first base station to the second base station based on the measurement and reporting results, the first base station sends a first handover request message (HANDOVER REQUEST) to the second base station. The first handover request message includes the terminal device's support capability for the IMS emergency bearer service in restricted service mode (UE SecurityCapabilities). Specifically, the first handover request message includes, but is not limited to, one or more of the following information: EIA0, EEA0; NIA0, NEA0, EIA0, EEA0.
[0196] Step 5: When the second base station is a base station of the first wireless standard (i.e., the first and second base stations use the same wireless standard), the second base station supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm. The second base station learns from the first handover request message that the terminal device supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm (NEA0, NIA0). At this time, the second base station allows the terminal device to access the second base station. Therefore, the second base station sends a first handover confirmation message to the first base station. This first handover confirmation message includes: an indication that the second base station supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm, and a second reconfiguration message (sent by the second base station to the terminal device). This second reconfiguration message contains second security configuration information, which includes, but is not limited to, the following information: the first wireless standard's null integrity protection algorithm and the first wireless standard's null encryption algorithm.
[0197] Step 6: After the first base station receives the first handover confirmation message sent by the second base station, it sends the second reconfiguration message in the first handover confirmation message to the terminal device. The second reconfiguration message sent to the terminal device includes, but is not limited to, the following information: NEA0, NIA0.
[0198] Step 7: The terminal device completes the configuration of the integrity protection algorithm and encryption algorithm according to the second security configuration information, and after updating the key according to these algorithms, it connects to the second base station. After connecting to the second base station, the terminal device performs security configuration on the signaling radio bearer and data radio bearer according to the second security configuration information, namely the first wireless standard empty encryption algorithm and the first wireless standard empty integrity protection algorithm.
[0199] In some preferred embodiments, a specific process is provided for a terminal device in limited service mode to switch from a first 4G base station eNB to a second 5G base station gNB via the Xn interface, wherein both the first 4G base station eNB and the second 5G base station gNB are connected to 5GC.
[0200] Step 1: The terminal device receives the SIB1 message sent by the first base station. The SIB1 message is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service for terminal devices in restricted service mode. The SIB1 message includes, but is not limited to, the following information: the IMS Emergency Support field, where "true" indicates support and "absent" indicates no support.
[0201] Step 2: The terminal device sends a first capability reporting message (UE CapabilityInformation) to the first base station. The first capability reporting message is used to indicate the terminal device's support capability for IMS emergency bearer service in restricted service mode. The first capability reporting message includes, but is not limited to, the following information: IMS emergency call support field (when this field exists, it indicates that the terminal device supports IMS emergency call); EIA0, EEA0; EIA0, EEA0, NIA0, NEA0.
[0202] Step 3: After the terminal device connects to the first base station and the IMS emergency service is activated, the first base station sends the first radio standard's empty integrity protection algorithm (EIA0) and / or the first radio standard's empty encryption algorithm (NEA0) to the terminal device through a first RRC Reconfiguration message. The first RRC Reconfiguration message includes, but is not limited to, the following information: Radio bearer configuration: For each radio bearer configuration, the following content is included: Encryption algorithm: Indicates the encryption algorithm used for SRBs and DRBs, specifically including NEA0 and EEA0; Integrity protection algorithm: Indicates the integrity protection algorithm used for signaling radio bearers, specifically including NIA0 and EIA0.
[0203] Step 4: When the first base station decides to switch the terminal device from the first base station to the second base station based on the measurement and reporting results, the first base station sends a first handover request message (HANDOVER REQUEST) to the second base station. The first handover request message includes the terminal device's support capability for the IMS emergency bearer service in restricted service mode (UE SecurityCapabilities). Specifically, the first handover request message includes, but is not limited to, one or more of the following information: NIA0, NEA0; NIA0, NEA0, EIA0, EEA0.
[0204] Step 5-1: When the second base station is a base station supporting a second wireless standard (i.e., the first and second base stations use different wireless standards), the second base station supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm. Based on the first handover request message, the second base station learns that the terminal device supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm. At this time, the second base station allows the terminal device to access the second base station. Therefore, the second base station sends a first handover confirmation message to the first base station. This first handover confirmation message includes: an indication that the second base station supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm, and a second reconfiguration message (sent by the second base station to the terminal device). This second reconfiguration message contains second security configuration information, which includes, but is not limited to, the following information: the second wireless standard's null integrity protection algorithm and the second wireless standard's null encryption algorithm.
[0205] Step 6-1: After the first base station receives the first handover confirmation message sent by the second base station, it sends the second security configuration information in the first handover confirmation message to the terminal device. The second security configuration information sent to the terminal device includes, but is not limited to, the following information: second wireless standard air encryption algorithm and second wireless standard air integrity protection algorithm.
[0206] Step 7-1: The terminal device completes the configuration of the integrity protection algorithm and encryption algorithm according to the second security configuration information. After updating the key according to these algorithms, it connects to the second base station. After connecting to the second base station, the terminal device performs security configuration on the signaling radio bearer and data radio bearer according to the second security configuration information, namely the second wireless standard empty encryption algorithm and the second wireless standard empty integrity protection algorithm.
[0207] According to some preferred embodiments of this application, a specific process is provided for a terminal device in limited service mode to switch from a first 4G base station eNB to a second 5G base station gNB via the Xn interface, wherein both the first 4G base station eNB and the second 5G base station gNB are connected to 5GC.
[0208] Step 1: The terminal device receives the SIB1 message sent by the first base station. The SIB1 message is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service for terminal devices in restricted service mode. The SIB1 message includes, but is not limited to, the following information: the IMS Emergency Support field, where "true" indicates support and "absent" indicates no support.
[0209] Step 2: The terminal device sends a first capability reporting message (UE CapabilityInformation) to the first base station. The first capability reporting message is used to indicate the terminal device's support capability for IMS emergency bearer service in restricted service mode. The first capability reporting message includes, but is not limited to, the following information: IMS emergency call support field (when this field exists, it indicates that the terminal device supports IMS emergency call); EIA0, EEA0; EIA0, EEA0, NIA0, NEA0.
[0210] Step 3: After the terminal device connects to the first base station and the IMS emergency service is activated, the first base station sends the first radio standard's empty integrity protection algorithm (EIA0) and / or the first radio standard's empty encryption algorithm (NEA0) to the terminal device through a first RRC Reconfiguration message. The first RRC Reconfiguration message includes, but is not limited to, the following information: Radio bearer configuration: For each radio bearer configuration, the following content is included: Encryption algorithm: Indicates the encryption algorithm used for SRBs and DRBs, specifically including NEA0 and EEA0; Integrity protection algorithm: Indicates the integrity protection algorithm used for signaling radio bearers, specifically including NIA0 and EIA0.
[0211] Step 4: When the first base station decides to switch the terminal device from the first base station to the second base station based on the measurement and reporting results, the first base station sends a first handover request message (HANDOVER REQUEST) to the second base station. The first handover request message includes the terminal device's support capability for the IMS emergency bearer service in restricted service mode (UE SecurityCapabilities). Specifically, the first handover request message includes, but is not limited to, one or more of the following information: NIA0, NEA0; NIA0, NEA0, EIA0, EEA0.
[0212] Step 5: When the second base station is a base station of the first wireless standard (i.e., the first and second base stations use the same wireless standard), the second base station supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm. The second base station learns from the first handover request message that the terminal device supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm. At this time, the second base station allows the terminal device to access the second base station. Therefore, the second base station sends a first handover confirmation message to the first base station. This first handover confirmation message includes: an indication that the second base station supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm, and a second reconfiguration message (sent by the second base station to the terminal device). This second reconfiguration message contains second security configuration information, which includes, but is not limited to, the following information: the first wireless standard's null integrity protection algorithm and the first wireless standard's null encryption algorithm.
[0213] Step 6: After the first base station receives the first handover confirmation message sent by the second base station, it sends the second security configuration information in the first handover confirmation message to the terminal device. The second security configuration information sent to the terminal device includes, but is not limited to, the following information: first wireless standard air encryption algorithm and first wireless standard air integrity protection algorithm.
[0214] Step 7: The terminal device completes the configuration of the integrity protection algorithm and encryption algorithm according to the second security configuration information. After updating the key according to these algorithms, it connects to the second base station. After connecting to the second base station, the terminal device performs security configuration on the signaling radio bearer and data radio bearer according to the second security configuration information, namely the first wireless standard empty encryption algorithm and the first wireless standard empty integrity protection algorithm.
[0215] In some preferred embodiments of this application, a specific process is provided for a terminal device in limited service mode to switch from a first 5G base station gNB to a second 4G base station ng-eNB via an NG interface, wherein both the first 5G base station gNB and the second 4G base station ng-eNB are connected to 5GC.
[0216] Step 1: The terminal device receives the SIB1 message sent by the first base station. The SIB1 message is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service for terminal devices in restricted service mode. The SIB1 message includes, but is not limited to, the following information: the IMS Emergency Support field, where "true" indicates support and "absent" indicates no support.
[0217] Step 2: The terminal device sends a first capability reporting message (UE CapabilityInformation) to the first base station. The first capability reporting message is used to indicate the terminal device's support capability for IMS emergency bearer service in restricted service mode. The first capability reporting message includes, but is not limited to, the following information: IMS emergency call support field (when this field exists, it indicates that the terminal device supports IMS emergency call); NIA0, NEA0; EIA0, EEA0; NIA0, NEA0, EIA0, EEA0.
[0218] Step 3: After the terminal device connects to the first base station and the IMS emergency service is activated, the first base station sends the first radio standard's null integrity protection algorithm (NIA0) and / or the first radio standard's null encryption algorithm (NEA0) to the terminal device through a first RRC Reconfiguration message. The first RRC Reconfiguration message includes, but is not limited to, the following information: Radio bearer configuration: For each radio bearer configuration, the following content is included: Encryption algorithm: Indicates the encryption algorithm used for SRBs and DRBs, specifically including NEA0 and EEA0; Integrity protection algorithm: Indicates the integrity protection algorithm used for signaling radio bearers, specifically including NIA0 and EIA0.
[0219] Step 4: When the first base station decides to switch the terminal device from the first base station to the second base station based on the measurement and reporting results, the first base station sends a first handover request message (HANDOVER REQUEST) to the first core network. The first handover request message includes the terminal device's support capability for the IMS emergency bearer service in restricted service mode (UE SecurityCapabilities). Specifically, the first request message includes, but is not limited to, one or more of the following information: NIA0, NEA0; EIA0, EEA0.
[0220] Step 5-1: When the second base station is a base station supporting a second wireless standard (i.e., the first and second base stations use different wireless standards), the second base station supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm. Based on the second handover request message, the second base station learns that the terminal device supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm (EEA0, EIA0). At this time, the second base station allows the terminal device to access the second base station. Therefore, the second base station sends a second handover confirmation message to the core network. After receiving the second handover confirmation message, the core network sends a first handover confirmation message to the first base station. The second handover confirmation message includes the first handover confirmation message sent to the first base station. This first handover confirmation message includes: an indication that the second base station supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm, and a second reconfiguration message (sent by the second base station to the terminal device). This second reconfiguration message includes a second security configuration, which includes, but is not limited to, the following information: the second wireless standard's null integrity protection algorithm and the second wireless standard's null encryption algorithm.
[0221] Step 6-1: After the first base station receives the first handover confirmation message sent by the core network, it sends the second reconfiguration message in the first handover confirmation message to the terminal device. The second reconfiguration message sent to the terminal device includes, but is not limited to, the following information: second security configuration information, wherein the second security configuration information includes, but is not limited to, the following information: EIA0, EEA0.
[0222] Step 7-1: The terminal device completes the configuration of the integrity protection algorithm and encryption algorithm according to the second security configuration information, and after updating the key according to these algorithms, it accesses the second base station. After accessing the second base station, the terminal device performs security configuration on the signaling radio bearer and data radio bearer according to the second security configuration information, namely the second wireless standard empty encryption algorithm and the second wireless standard empty integrity protection algorithm.
[0223] As some other preferred embodiments of this application, a specific process is provided for a terminal device in limited service mode to switch from a first 5G base station gNB to a second 4G base station ng-eNB via an NG interface, wherein both the first 5G base station gNB and the second 4G base station ng-eNB are connected to 5GC.
[0224] Step 1: The terminal device receives the SIB1 message sent by the first base station. The SIB1 message is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service for terminal devices in restricted service mode. The SIB1 message includes, but is not limited to, the following information: the IMS Emergency Support field, where "true" indicates support and "absent" indicates no support.
[0225] Step 2: The terminal device sends a first capability reporting message (UE CapabilityInformation) to the first base station. The first capability reporting message is used to indicate the terminal device's support capability for IMS emergency bearer service in restricted service mode. The first capability reporting message includes, but is not limited to, the following information: IMS emergency call support field (when this field exists, it indicates that the terminal device supports IMS emergency call); NIA0, NEA0; EIA0, EEA0; NIA0, NEA0, EIA0, EEA0.
[0226] Step 3: After the terminal device connects to the first base station and the IMS emergency service is activated, the first base station sends the first radio standard's null integrity protection algorithm (NIA0) and / or the first radio standard's null encryption algorithm (NEA0) to the terminal device through a first RRC Reconfiguration message. The first RRC Reconfiguration message includes, but is not limited to, the following information: Radio bearer configuration: For each radio bearer configuration, the following content is included: Encryption algorithm: Indicates the encryption algorithm used for SRBs and DRBs, specifically including NEA0 and EEA0; Integrity protection algorithm: Indicates the integrity protection algorithm used for signaling radio bearers, specifically including NIA0 and EIA0.
[0227] Step 4: When the first base station decides to switch the terminal device from the first base station to the second base station based on the measurement and reporting results, the first base station sends a first handover request message (HANDOVER REQUEST) to the first core network. The first handover request message includes the terminal device's support capability for the IMS emergency bearer service in restricted service mode (UE SecurityCapabilities). Specifically, the first request message includes, but is not limited to, one or more of the following information: NIA0, NEA0; EIA0, EEA0.
[0228] Step 5: When the second base station is a base station of the first wireless standard (i.e., the first and second base stations use the same wireless standard), the second base station supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm. The second base station learns from the second handover request message that the terminal device supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm (NEA0, NIA0). At this time, the second base station allows the terminal device to access the second base station. Therefore, the second base station sends a second handover confirmation message to the core network. After receiving the second handover confirmation message, the core network sends a first handover confirmation message to the first base station. The second handover confirmation message includes the first handover confirmation message sent to the first base station. The first handover confirmation message includes: an indication that the second base station supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm, and a second reconfiguration message (sent by the second base station to the terminal device). The second reconfiguration message includes a second security configuration, which includes, but is not limited to, the following information: the first wireless standard's null integrity protection algorithm and the first wireless standard's null encryption algorithm.
[0229] Step 6: After the first base station receives the first handover confirmation message sent by the core network, it sends the second reconfiguration message in the first handover confirmation message to the terminal device. The second reconfiguration message sent to the terminal device includes, but is not limited to, the following information: second security configuration information, wherein the second security configuration information includes, but is not limited to, the following information: NEA0, NIA0.
[0230] Step 7: The terminal device completes the configuration of the integrity protection algorithm and encryption algorithm according to the second security configuration information, and after updating the key according to these algorithms, it connects to the second base station. After connecting to the second base station, the terminal device performs security configuration on the signaling radio bearer and data radio bearer according to the second security configuration information, namely the first wireless standard empty encryption algorithm and the first wireless standard empty integrity protection algorithm.
[0231] In some preferred embodiments, a specific process is provided for a terminal device in limited service mode to switch from a first 4G base station eNB to a second 5G base station gNB via an NG interface, wherein both the first 4G base station eNB and the second 5G base station gNB are connected to the 5GC.
[0232] Step 1: The terminal device receives the SIB1 message sent by the first base station. The SIB1 message is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service for terminal devices in restricted service mode. The SIB1 message includes, but is not limited to, the following information: the IMS Emergency Support field, where "true" indicates support and "absent" indicates no support.
[0233] Step 2: The terminal device sends a first capability reporting message (UE CapabilityInformation) to the first base station. The first capability reporting message is used to indicate the terminal device's support capability for IMS emergency bearer service in restricted service mode. The first capability reporting message includes, but is not limited to, the following information: IMS emergency call support field (when this field exists, it indicates that the terminal device supports IMS emergency call); EIA0, EEA0; EIA0, EEA0, NIA0, NEA0.
[0234] Step 3: After the terminal device connects to the first base station and the IMS emergency service is activated, the first base station sends the first radio standard's null integrity protection algorithm (NIA0) and / or the first radio standard's null encryption algorithm (NEA0) to the terminal device through a first RRC Reconfiguration message. The first RRC Reconfiguration message includes, but is not limited to, the following information: Radio bearer configuration: For each radio bearer configuration, the following content is included: Encryption algorithm: Indicates the encryption algorithm used for SRBs and DRBs, specifically including NEA0 and EEA0; Integrity protection algorithm: Indicates the integrity protection algorithm used for signaling radio bearers, specifically including NIA0 and EIA0.
[0235] Step 4: When the first base station decides to switch the terminal device from the first base station to the second base station based on the measurement and reporting results, the first base station sends a first handover request message (HANDOVER REQUEST) to the first core network. The first handover request message includes the terminal device's support capability for the IMS emergency bearer service in restricted service mode (UE SecurityCapabilities). Specifically, the first request message includes, but is not limited to, one or more of the following information: NIA0, NEA0; NIA0, NEA0, EIA0, EEA0.
[0236] Step 5-1: When the second base station is a base station supporting a second wireless standard (i.e., the first and second base stations use different wireless standards), the second base station supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm. The second base station learns from the second handover request message that the terminal device supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm. At this time, the second base station allows the terminal device to access the second base station. Therefore, the second base station sends a second handover confirmation message to the core network. After receiving the second handover confirmation message, the core network sends a first handover confirmation message to the first base station. The second handover confirmation message includes the first handover confirmation message sent to the first base station. The first handover confirmation message includes: an indication that the second base station supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm, and a second reconfiguration message (sent by the second base station to the terminal device). The second reconfiguration message includes a second security configuration, which includes, but is not limited to, the following information: the second wireless standard's null integrity protection algorithm and the second wireless standard's null encryption algorithm.
[0237] Step 6-1: After receiving the first handover confirmation message from the core network, the first base station sends the second reconfiguration message from the first handover confirmation message to the terminal device. The second reconfiguration message sent to the terminal device includes, but is not limited to, the following information: second security configuration information, which includes, but is not limited to, the following information: a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm. Step 7-1: The terminal device configures the integrity protection algorithm and encryption algorithm according to the second security configuration information. After updating the key according to these algorithms, it accesses the second base station. After accessing the second base station, it performs security configuration on the signaling radio bearer and data radio bearer of the terminal device according to the second security configuration information, namely the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm.
[0238] According to some preferred embodiments of this application, a specific process is provided for a terminal device in limited service mode to switch from a first 4G base station eNB to a second 5G base station gNB via an NG interface, wherein both the first 4G base station eNB and the second 5G base station gNB are connected to 5GC.
[0239] Step 1: The terminal device receives the SIB1 message sent by the first base station. The SIB1 message is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service for terminal devices in restricted service mode. The SIB1 message includes, but is not limited to, the following information: the IMS Emergency Support field, where "true" indicates support and "absent" indicates no support.
[0240] Step 2: The terminal device sends a first capability reporting message (UE CapabilityInformation) to the first base station. The first capability reporting message is used to indicate the terminal device's support capability for IMS emergency bearer service in restricted service mode. The first capability reporting message includes, but is not limited to, the following information: IMS emergency call support field (when this field exists, it indicates that the terminal device supports IMS emergency call); EIA0, EEA0; EIA0, EEA0, NIA0, NEA0.
[0241] Step 3: After the terminal device connects to the first base station and the IMS emergency service is activated, the first base station sends the first radio standard's null integrity protection algorithm (NIA0) and / or the first radio standard's null encryption algorithm (NEA0) to the terminal device through a first RRC Reconfiguration message. The first RRC Reconfiguration message includes, but is not limited to, the following information: Radio bearer configuration: For each radio bearer configuration, the following content is included: Encryption algorithm: Indicates the encryption algorithm used for SRBs and DRBs, specifically including NEA0 and EEA0; Integrity protection algorithm: Indicates the integrity protection algorithm used for signaling radio bearers, specifically including NIA0 and EIA0.
[0242] Step 4: When the first base station decides to switch the terminal device from the first base station to the second base station based on the measurement and reporting results, the first base station sends a first handover request message (HANDOVER REQUEST) to the first core network. The first handover request message includes the terminal device's support capability for the IMS emergency bearer service in restricted service mode (UE SecurityCapabilities). Specifically, the first request message includes, but is not limited to, one or more of the following information: NIA0, NEA0; NIA0, NEA0, EIA0, EEA0.
[0243] Step 5: When the second base station is a base station of the first wireless standard (i.e., the first and second base stations use the same wireless standard), the second base station supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm. The second base station learns from the second handover request message that the terminal device supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm (NEA0, NIA0). At this time, the second base station allows the terminal device to access the second base station. Therefore, the second base station sends a second handover confirmation message to the core network. After receiving the second handover confirmation message, the core network sends a first handover confirmation message to the first base station. The second handover confirmation message includes the first handover confirmation message sent to the first base station. The first handover confirmation message includes: an indication that the second base station supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm, and a second reconfiguration message (sent by the second base station to the terminal device). The second reconfiguration message includes a second security configuration, which includes, but is not limited to, the following information: the first wireless standard's null integrity protection algorithm and the first wireless standard's null encryption algorithm.
[0244] Step 6: After the first base station receives the first handover confirmation message sent by the core network, it sends the second reconfiguration message in the first handover confirmation message to the terminal device. The second reconfiguration message sent to the terminal device includes, but is not limited to, the following information: second security configuration information, wherein the second security configuration information includes, but is not limited to, the following information: first wireless standard air encryption algorithm and first wireless standard air integrity protection algorithm.
[0245] Step 7: The terminal device completes the configuration of the integrity protection algorithm and encryption algorithm according to the second security configuration information, and after updating the key according to these algorithms, it connects to the second base station. After connecting to the second base station, the terminal device performs security configuration on the signaling radio bearer and data radio bearer according to the second security configuration information, namely the first wireless standard empty encryption algorithm and the first wireless standard empty integrity protection algorithm.
[0246] As can be seen from the above embodiments, the method provided in this application supports the ability of EIA0 and EEA0 during the Xn handover process, enabling terminals in restricted system mode to maintain emergency call capability for the 4G system during the 5G to 4G Xn handover process; the method provided in this application supports the ability of NIA0 and NEA0 during the Xn handover process, enabling terminals in restricted system mode to maintain emergency call capability for the 5G system during the 4G / 5G to 5G Xn handover process; the method provided in this application supports the source base station sending the terminal's support capability for NIA0, NEA0, EIA0, and EEA0 to the target base station during the Xn handover process, and after the terminal completes the 4G to 5G or 5G to 4G Xn handover, the target base station sends its own base station-related (NIA0 and NEA0) or (EIA0 and EEA0) data to the terminal, supporting the terminal to maintain emergency call user communication during the system handover process.
[0247] In summary, the method provided in this application is based on modifications to existing protocols, has good forward compatibility, and is easy to deploy and implement in networks.
[0248] This application provides another method for configuring emergency services, applied to a second base station, which includes the following steps:
[0249] The second base station sends terminal security capabilities to the first base station. Specifically, the terminal security capabilities include at least one of the following: a first wireless standard air integrity protection algorithm, a first wireless standard air encryption algorithm, a second wireless standard air integrity protection algorithm, and a second wireless standard air encryption algorithm. The first base station is either a first wireless standard base station or a second wireless standard base station, and the second base station is either a first wireless standard base station or a second wireless standard base station.
[0250] The first base station is used to select a first wireless standard spatial integrity protection algorithm for integrity protection and / or a first wireless standard spatial encryption algorithm for confidentiality protection, or to select a second wireless standard spatial integrity protection algorithm for integrity protection and / or a second wireless standard spatial encryption algorithm for confidentiality protection.
[0251] Preferably, the first wireless standard includes: 4G LTE (4th generation mobile communication technology) or 5G NR (5th generation mobile communication technology). The second wireless standard includes: 5G NR or 6G. It is worth noting that when the first wireless standard base station is a 4G LTE base station, the first wireless standard base station is connected to the 5G core network, and the second wireless standard base station is a 5G NR base station; when the first wireless standard base station is a 5G NR base station, the first wireless standard base station is connected to the 6G core network, and the second wireless standard base station is a 6G base station.
[0252] It is understandable that, when the second base station is a base station of the first wireless standard, the second base station selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection. Similarly, when the second base station is a base station of the second wireless standard, the second base station selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
[0253] According to some optional embodiments of this application, the second base station can send terminal security capabilities to the first base station via the following method: the second base station sends the terminal security capabilities to the first base station through the Xn interface. Alternatively, the second base station can also send terminal security capabilities to the first base station via the NG interface.
[0254] Furthermore, if the first base station is a base station of a first wireless standard, it selects a first wireless standard spatial integrity protection algorithm for integrity protection and / or a first wireless standard spatial encryption algorithm for confidentiality protection. Additionally, if the first base station is a base station of a second wireless standard, it selects a second wireless standard spatial integrity protection algorithm for integrity protection and / or a second wireless standard spatial encryption algorithm for confidentiality protection.
[0255] Furthermore, if the first base station determines that a terminal device in restricted service mode will be switched from the first base station to the second base station, the second base station receives a first handover request message sent by the first base station. If there is a direct connection interface between the first base station and the second base station, and both base stations are connected to the first core network, and if the first core network control plane entity allows unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions to use the null integrity protection algorithm and the null encryption algorithm, the first core network control plane entity receiving the message from the first core network control plane entity indicating its support for the null integrity protection algorithm and the null encryption algorithm for unauthenticated IMS emergency sessions...
[0256] It is understood that after receiving support from the first core network control plane entity for the null integrity protection algorithm and null encryption algorithm for unauthenticated IMS emergency sessions, the first base station supports providing emergency bearer services to terminal devices in restricted service mode. Preferably, the above first handover request message includes, but is not limited to, terminal security capabilities. The terminal security capabilities include at least one of the following: a first wireless standard null encryption algorithm and a first wireless standard null integrity protection algorithm, and / or a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm.
[0257] Furthermore, if the second base station is a base station of the first wireless standard, and the second base station determines, based on the first handover request message, that the terminal device in the restricted service mode supports the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm, the second base station sends a first handover confirmation message to the first base station after receiving the first handover request message. It is understood that the second base station supports the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm when the second base station is a base station of the first wireless standard. Preferably, the first handover confirmation message includes: an indication that the second base station supports the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the first wireless standard null integrity protection algorithm NIA0 and the first wireless standard null encryption algorithm NEA0.
[0258] Furthermore, if the second base station is a base station of the second wireless standard, and the second base station determines that the terminal device in the restricted service mode supports the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm, the second base station sends a first handover confirmation message to the first base station after receiving the first handover request message. It is understood that, when the second base station is a base station of the second wireless standard, the second base station supports the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm. Preferably, the first handover confirmation message includes: an indication that the second base station supports the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the second wireless standard null integrity protection algorithm EIA0 and the second wireless standard null encryption algorithm EEA0.
[0259] Furthermore, if the first base station determines that a terminal device in limited service mode will be switched from the first base station to the second base station, the second base station receives a second handover request message sent by the first core network. The first core network receives a first handover request message sent by the first base station. Preferably, the second handover request message includes, but is not limited to, the first handover request message.
[0260] If there is no direct connection between the first base station and the second base station, and both base stations are connected to the first core network, and if the first core network control plane entity allows unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions to use the null integrity protection algorithm and null encryption algorithm, the first core network control plane entity receiving the message from the first core network control plane entity providing support for the null integrity protection algorithm and null encryption algorithm for unauthenticated IMS emergency sessions will, upon receiving the first core network control plane entity's message regarding support for the null integrity protection algorithm and null encryption algorithm for unauthenticated IMS emergency sessions, support providing emergency bearer services to terminal devices in restricted service mode.
[0261] Preferably, the first handover request message includes, but is not limited to, terminal security capabilities. These terminal security capabilities include at least one of the following: a first wireless standard null encryption algorithm and a first wireless standard null integrity protection algorithm, and / or a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm.
[0262] Furthermore, if the second base station is a base station of the first wireless standard, and the second base station determines, based on the second handover request message, that the terminal device in the restricted service mode supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, the second base station sends a second handover confirmation message to the first core network. The first core network then sends the first handover confirmation message from the second handover confirmation message to the first base station.
[0263] It is understood that, when the second base station is a base station of the first wireless standard, it supports the first wireless standard spatial encryption algorithm and the first wireless standard spatial integrity protection algorithm. Preferably, the first handover confirmation message includes, but is not limited to: an indication that the second base station supports the first wireless standard spatial encryption algorithm and the first wireless standard spatial integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the first wireless standard spatial integrity protection algorithm NIA0 and the first wireless standard spatial encryption algorithm NEA0.
[0264] Furthermore, if the second base station is a base station for the second wireless standard, and the second base station determines, based on the second handover request message, that the terminal device in the restricted service mode supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, the second base station sends a second handover confirmation message to the first core network. The first core network then sends the first handover confirmation message from the second handover confirmation message to the first base station.
[0265] It is understood that, when the second base station is a base station supporting the second wireless standard, it supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm. Preferably, the first handover confirmation message includes, but is not limited to: an indication that the second base station supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm, and a second reconfiguration message. The second reconfiguration message includes, but is not limited to: second security configuration information, which includes, but is not limited to: the second wireless standard's null integrity protection algorithm EIA0 and the second wireless standard's null encryption algorithm EEA0.
[0266] This application provides another method for configuring emergency services on terminal devices, which includes the following steps:
[0267] A terminal device in limited service mode receives a first system message block (SIB) sent by a first base station, wherein...
[0268] The first SIB includes: an IMS emergency bearer service support field; the first base station is used to receive terminal security capabilities sent by the second base station, wherein the terminal security capabilities include at least one of the following: a first wireless standard air integrity protection algorithm, a first wireless standard air encryption algorithm, a second wireless standard air integrity protection algorithm, and a second wireless standard air encryption algorithm, wherein the first base station is either a first wireless standard base station or a second wireless standard base station, and the second base station is either a first wireless standard base station or a second wireless standard base station.
[0269] The first base station selects a first wireless standard spatial integrity protection algorithm for integrity protection and / or a first wireless standard spatial encryption algorithm for confidentiality protection, or selects a second wireless standard spatial integrity protection algorithm for integrity protection and / or a second wireless standard spatial encryption algorithm for confidentiality protection.
[0270] Preferably, the IMS Emergency Bearer Service Support field is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service to terminal devices in restricted service mode. The IMS Emergency Bearer Service Support field is an enumeration type; when the field is true, it indicates that the cell of the first base station supports providing IMS emergency bearer service to terminal devices in restricted service mode; when the field is absent, it indicates that the cell of the first base station does not support providing IMS emergency bearer service to terminal devices in restricted service mode.
[0271] According to some alternative embodiments of this application, after a terminal device in restricted service mode accesses the first base station and its IMS emergency bearer service is activated, the terminal device in restricted service mode receives the null integrity protection algorithm and / or null encryption algorithm sent by the first base station through a first radio resource control (RRC) reconfiguration message. If the second base station is a first radio standard base station, and the second base station determines that the terminal device in restricted service mode supports the first radio standard null encryption algorithm and the first radio standard null integrity protection algorithm, then the first base station receives a first handover confirmation message sent by the second base station.
[0272] Preferably, the first handover confirmation message includes, but is not limited to: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm; and a second reconfiguration message, which includes, but is not limited to: second security configuration information, which includes, but is not limited to: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
[0273] Preferably, the first RRC reconfiguration message further includes: radio bearer configuration information, wherein the radio bearer configuration information includes, but is not limited to: encryption algorithms and integrity protection algorithms, wherein the encryption algorithms are used for signaling radio bearers and / or data radio bearers, and the integrity protection algorithms are used for signaling radio bearers and / or data radio bearers. The encryption algorithms include, but are not limited to: a first radio standard null encryption algorithm and / or a second radio standard null encryption algorithm; the integrity protection algorithms include, but are not limited to: a first radio standard null integrity protection algorithm and / or a second radio standard null integrity protection algorithm.
[0274] Furthermore, the terminal device in restricted service mode receives a new air interface handover command sent by the first base station, wherein the new air interface handover command includes a second reconfiguration message.
[0275] Furthermore, after the terminal device in restricted service mode accesses the second base station, it uses the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm to perform secure configuration of the signaling radio bearer and the data radio bearer according to the second reconfiguration message.
[0276] Further, after a terminal device in restricted service mode accesses the first base station and its IMS emergency bearer service is activated, the terminal device in restricted service mode receives the null integrity protection algorithm and / or null encryption algorithm sent by the first base station through a first radio resource control (RRC) reconfiguration message. If the second base station is a second radio standard base station, and the second base station determines that the terminal device in restricted service mode supports the first radio standard null encryption algorithm and the first radio standard null integrity protection algorithm, the first base station receives a first handover confirmation message sent by the second base station. Preferably, the first handover confirmation message includes, but is not limited to: an indication that the second base station supports the second radio standard null encryption algorithm and the second radio standard null integrity protection algorithm, and a second reconfiguration message. The second reconfiguration message includes, but is not limited to: second security configuration information, which includes, but is not limited to: the second radio standard null integrity protection algorithm EIA0 and the second radio standard null encryption algorithm EEA0.
[0277] Furthermore, the terminal device in restricted service mode receives a new air interface handover command sent by the first base station, wherein the new air interface handover command includes a second reconfiguration message.
[0278] Furthermore, after the terminal device in restricted service mode accesses the second base station, it uses the second wireless standard spatial encryption algorithm and the second wireless standard spatial integrity protection algorithm to perform secure configuration of the signaling radio bearer and the data radio bearer according to the second reconfiguration message.
[0279] Figure 4 This is a structural diagram of an emergency service configuration system according to an embodiment of this application, such as... Figure 4 As shown, the system includes: a first base station 40, a second base station 42, a terminal device 44, and a first core network control plane entity 46, wherein,
[0280] The first base station 40 is communicatively connected to the terminal device 44 and the second base station 42, respectively, and is used to receive terminal security capabilities sent by the second base station 42. The terminal security capabilities include at least one of the following: a first wireless standard spatial integrity protection algorithm, a first wireless standard spatial encryption algorithm, a second wireless standard spatial integrity protection algorithm, and a second wireless standard spatial encryption algorithm. The first base station 40 is either a first wireless standard base station or a second wireless standard base station, and the second base station 42 is either a first wireless standard base station or a second wireless standard base station. The first base station 40 selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection, or the first base station 40 selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
[0281] Terminal device 44 is a terminal device 44 in a restricted service mode.
[0282] When the first base station 40 and the second base station 42 are connected to the first core network, if the first core network control plane entity 46 allows unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions to use the null integrity protection algorithm and the null encryption algorithm, the first core network control plane entity 46 is used to send a message to the first base station 40 that the first core network control plane entity 46 provides support for the null integrity protection algorithm and the null encryption algorithm for unauthenticated IMS emergency sessions.
[0283] According to some optional embodiments of this application, the first wireless standard includes: 4G LTE (4th generation mobile communication technology) or 5G NR (5th generation mobile communication technology); the second wireless standard includes: 5G NR or 6G. Further, when the first wireless standard base station is a 4G LTE base station, the first wireless standard base station is connected to a 5G core network, and the second wireless standard base station is a 5G NR base station; when the first wireless standard base station is a 5G NR base station, the first wireless standard base station is connected to a 6G core network, and the second wireless standard base station is a 6G base station.
[0284] Preferably, the first base station 40 selects a first wireless standard spatial integrity protection algorithm for integrity protection and / or a first wireless standard spatial encryption algorithm for confidentiality protection. This can be achieved by the following method: when the first base station 40 is a first wireless standard base station, the first base station 40 selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection. Furthermore, the first base station 40 selects a second wireless standard spatial integrity protection algorithm for integrity protection and / or a second wireless standard spatial encryption algorithm for confidentiality protection. This can be achieved by the following method: when the first base station 40 is a second wireless standard base station, the first base station 40 selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
[0285] The first base station 40 can receive terminal security capabilities sent by the second base station 42 through the following method: The first base station 40 receives the terminal security capabilities sent by the second base station 42 through the Xn interface. Alternatively, it can be achieved by the first base station 40 receiving the terminal security capabilities sent by the second base station 42 through the NG interface.
[0286] It is worth noting that the emergency service configuration method provided in this application can be applied to both Xn and NG handover. Specifically, when applied to Xn handover, the second base station 42 can be a first wireless standard base station (i.e., the first base station 40 and the second base station 42 use the same wireless standard); the second base station 42 can also be a second wireless standard base station (i.e., the first base station 40 and the second base station 42 use different wireless standards). When applied to NG handover, the second base station 42 can be a first wireless standard base station (i.e., the first base station 40 and the second base station 42 use the same wireless standard); the second base station 42 can also be a second wireless standard base station (i.e., the first base station 40 and the second base station 42 use different wireless standards). The configuration methods for emergency services in different scenarios are described in detail below.
[0287] According to some alternative embodiments of this application, if there is a direct connection interface between the first base station 40 and the second base station 42, and the first base station 40 and the second base station 42 are connected to the first core network, if the first core network control plane entity 46 allows unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions to use the null integrity protection algorithm and the null encryption algorithm, the first base station 40 receives the first core network control plane entity 46's support capability for the null integrity protection algorithm and the null encryption algorithm for unauthenticated IMS emergency sessions.
[0288] For example, the direct connection between the first base station 40 and the second base station 42 is the Xn interface.
[0289] Preferably, the first core network is a 5G core network or a 6G core network. The first core network control plane entity 46 includes: an Access and Mobility Management Function (AMF) entity. The spatial integrity protection algorithm includes: a first radio standard spatial integrity protection algorithm NIA0 and / or a second radio standard spatial integrity protection algorithm EIA0; the spatial encryption algorithm includes: a first radio standard spatial encryption algorithm NEA0 and / or a second radio standard spatial encryption algorithm EEA0.
[0290] Understandably, after receiving support from the first core network control plane entity 46 for the null integrity protection algorithm and null encryption algorithm for unauthenticated IMS emergency sessions, the first base station 40 can support providing emergency bearer services to the terminal device 44 in restricted service mode. Further, the first base station 40 sends a first system message block (SIB) to the terminal device 44 in restricted service mode, wherein the first SIB includes an IMS emergency bearer service support field. The IMS emergency bearer service support field indicates whether the cell of the first base station 40 supports providing IMS emergency bearer services to the terminal device 44 in restricted service mode; the IMS emergency bearer service support field is an enumeration type, where a true value indicates that the cell of the first base station 40 supports providing IMS emergency bearer services to the terminal device 44 in restricted service mode, and an absent value indicates that the cell of the first base station 40 does not support providing IMS emergency bearer services to the terminal device 44 in restricted service mode.
[0291] Furthermore, after the terminal device 44 in restricted service mode accesses the first base station 40 and its IMS emergency bearer service is activated, the first base station 40 sends a null integrity protection algorithm and / or a null encryption algorithm to the terminal device 44 in restricted service mode via a first Radio Resource Control (RRC) reconfiguration message. The first RRC reconfiguration message includes, but is not limited to, radio bearer configuration information, which includes, but is not limited to, encryption algorithms and integrity protection algorithms. The encryption algorithms are used for signaling radio bearers and / or data radio bearers, and the integrity protection algorithms are used for signaling radio bearers and / or data radio bearers. Preferably, the encryption algorithms include, but are not limited to, a first radio standard null encryption algorithm and / or a second radio standard null encryption algorithm; the integrity protection algorithms include, but are not limited to, a first radio standard null integrity protection algorithm and / or a second radio standard null integrity protection algorithm.
[0292] Furthermore, when the first base station 40 determines that the terminal device 44 in the restricted service mode will be switched from the first base station 40 to the second base station 42, the first base station 40 sends a first handover request message to the second base station 42. The first handover request message includes: terminal security capabilities, which include at least one of the following: a first wireless standard null encryption algorithm and a first wireless standard null integrity protection algorithm, and / or a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm.
[0293] The following sections will provide detailed explanations of two scenarios: the second base station 42 being a base station of the first wireless standard and the second base station 42 being a base station of the second wireless standard.
[0294] When the second base station 42 is a first wireless standard base station, and the second base station 42 determines, based on the first handover request message, that the terminal device 44 in the restricted service mode supports the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm, the first base station 40 receives a first handover confirmation message sent by the second base station 42. The second base station 42 is used to send the first handover confirmation message to the first base station 40 after receiving the first handover request message. The second base station 42 is also used to support the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm when the second base station 42 is a first wireless standard base station.
[0295] Preferably, the first handover confirmation message includes: an indication that the second base station 42 supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
[0296] Furthermore, the first base station 40 triggers a new air interface handover command, sending the command to the terminal device 44 in restricted service mode. This new air interface handover command includes a second reconfiguration message. It is understood that after accessing the second base station 42, the terminal device 44 in restricted service mode can, based on the second reconfiguration message, employ the first radio standard air encryption algorithm and the first radio standard air integrity protection algorithm to securely configure the signaling radio bearer and data radio bearer.
[0297] When the second base station 42 is a second wireless standard base station, and the second base station 42 determines, based on the first handover request message, that the terminal device 44 in the restricted service mode supports the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm, the first base station 40 receives a first handover confirmation message sent by the second base station 42. The second base station 42 is used to send the first handover confirmation message to the first base station 40 after receiving the first handover request message. The second base station 42 is also used to support the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm when the second base station 42 is a second wireless standard base station.
[0298] Preferably, the first handover confirmation message includes: an indication that the second base station 42 supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
[0299] Furthermore, the first base station 40 triggers a new air interface handover command, sending the command to the terminal device 44 in restricted service mode. This new air interface handover command includes a second reconfiguration message. It is understood that the terminal device 44 in restricted service mode, after accessing the second base station 42, can, according to the second reconfiguration message, perform secure configuration of the signaling radio bearer and data radio bearer using a second radio standard air encryption algorithm and a second radio standard air integrity protection algorithm.
[0300] As some optional embodiments of this application, in the case where there is no direct connection interface between the first base station 40 and the second base station 42, and the first base station 40 and the second base station 42 are connected to the first core network, if the first core network control plane entity 46 allows unauthenticated IMS emergency sessions to use the null integrity protection algorithm and the null encryption algorithm, the first base station 40 receives the first core network control plane entity 46's support capability for the null integrity protection algorithm and the null encryption algorithm for unauthenticated IMS emergency sessions.
[0301] For example, when there is no direct connection between the first base station 40 and the second base station 42, there is an NG interface between the first base station 40 and the second base station 42.
[0302] Preferably, the first core network is a 5G core network or a 6G core network; the first core network control plane entity 46 includes: an Access and Mobility Management Function entity (AMF). The spatial integrity protection algorithm includes: a first radio standard spatial integrity protection algorithm (NIA0) and / or a second radio standard spatial integrity protection algorithm (EIA0); the spatial encryption algorithm includes: a first radio standard spatial encryption algorithm (NEA0) and / or a second radio standard spatial encryption algorithm (EEA0).
[0303] Understandably, after receiving support from the first core network control plane entity 46 for the null integrity protection algorithm and null encryption algorithm for unauthenticated IMS emergency sessions, the first base station 40 supports providing emergency bearer services to the terminal device 44 in restricted service mode. Further, the first base station 40 sends a first system message block (SIB) to the terminal device 44 in restricted service mode, wherein the first SIB includes an IMS emergency bearer service support field. The IMS emergency bearer service support field indicates whether the cell of the first base station 40 supports providing IMS emergency bearer services to the terminal device 44 in restricted service mode; the IMS emergency bearer service support field is an enumeration type, where a true value indicates that the cell of the first base station 40 supports providing IMS emergency bearer services to the terminal device 44 in restricted service mode, and an absent value indicates that the cell of the first base station 40 does not support providing IMS emergency bearer services to the terminal device 44 in restricted service mode.
[0304] Furthermore, after the terminal device 44 in restricted service mode accesses the first base station 40 and its IMS emergency bearer service is activated, the first base station 40 sends a null integrity protection algorithm and / or a null encryption algorithm to the terminal device 44 in restricted service mode via a first Radio Resource Control (RRC) reconfiguration message. The first RRC reconfiguration message further includes radio bearer configuration information, which includes an encryption algorithm and an integrity protection algorithm. The encryption algorithm is used for signaling radio bearers and / or data radio bearers, and the integrity protection algorithm is used for signaling radio bearers and / or data radio bearers. Preferably, the encryption algorithms include, but are not limited to, a first radio standard null encryption algorithm and / or a second radio standard null encryption algorithm; the integrity protection algorithms include, but are not limited to, a first radio standard null integrity protection algorithm and / or a second radio standard null integrity protection algorithm.
[0305] Further, when the first base station 40 determines that the terminal device 44 in restricted service mode will be switched from the first base station 40 to the second base station 42, the first base station 40 sends a first handover request message to the first core network. The first core network then sends a second handover request message to the second base station 42. The second handover request message includes the first handover request message sent by the first base station 40 to the first core network. Preferably, the first handover request message includes, but is not limited to, terminal security capabilities, which include at least one of the following: a first wireless standard null encryption algorithm and a first wireless standard null integrity protection algorithm, and / or a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm.
[0306] The following sections will provide detailed explanations of two scenarios: the second base station 42 being a base station of the first wireless standard and the second base station 42 being a base station of the second wireless standard.
[0307] When the second base station 42 is a first wireless standard base station, and the second base station 42 determines, according to the second handover request message, that the terminal device 44 in the restricted service mode supports the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm, the first base station 40 receives a first handover confirmation message sent by the first core network. The first core network is used to receive a second handover confirmation message sent by the second base station 42 and send the first handover confirmation message from the second handover confirmation message to the first base station 40. The second base station 42 is used to support the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm when the second base station 42 is a first wireless standard base station.
[0308] Preferably, the first handover confirmation message includes: an indication that the second base station 42 supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, which includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
[0309] Furthermore, the first base station 40 triggers a new air interface handover command, sending the command to the terminal device 44 in restricted service mode. This new air interface handover command includes a second reconfiguration message. It is understood that the terminal device 44 in restricted service mode, after accessing the second base station 42, can, according to the second reconfiguration message, perform secure configuration of the signaling radio bearer and data radio bearer using a first radio standard air encryption algorithm and a first radio standard air integrity protection algorithm.
[0310] When the second base station 42 is a base station of the second wireless standard, and the second base station 42 determines, according to the second handover request message, that the terminal device 44 in the restricted service mode supports the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm, the first base station 40 receives a first handover confirmation message sent by the first core network. The first core network is used to receive the second handover confirmation message sent by the second base station 42 and send the first handover confirmation message in the second handover confirmation message to the first base station 40. The second base station 42 is used to support the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm when the second base station 42 is a base station of the second wireless standard.
[0311] Preferably, the first handover confirmation message includes: an indication that the second base station 42 supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
[0312] Furthermore, the first base station 40 triggers a new air interface handover command, sending the command to the terminal device 44 in restricted service mode. This new air interface handover command includes a second reconfiguration message. It is understood that the terminal device 44 in restricted service mode, after accessing the second base station 42, can, according to the second reconfiguration message, perform secure configuration of the signaling radio bearer and data radio bearer using a second radio standard air encryption algorithm and a second radio standard air integrity protection algorithm.
[0313] It should be noted that, Figure 4 Preferred embodiments of the shown examples can be found in [reference needed]. Figure 3 The relevant descriptions of the embodiments shown will not be repeated here.
[0314] In summary, the above system achieves the goal of enhancing the empty integrity protection algorithm and empty encryption algorithm during the Xn handover process from 4G to 5G or from 5G to 4G, thereby ensuring the continuity of emergency call services for terminal devices in restricted service mode during the Xn handover process from 4G to 5G or from 5G to 4G.
[0315] Figure 5 This is a signaling interaction diagram of a configuration method based on emergency services according to an embodiment of this application. Figure 5 It provides a signaling interaction process for terminal devices to hand over between the first base station and the second base station based on the Xn interface, such as... Figure 5 As shown, the specific steps include the following.
[0316] Step 1: The terminal device receives the SIB1 message sent by the first base station. The SIB1 message is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service for terminal devices in restricted service mode. The SIB1 message includes, but is not limited to, the following information: the IMS Emergency Support field, where "true" indicates support and "absent" indicates no support.
[0317] Step 2: The terminal device sends a first capability reporting message (UE CapabilityInformation) to the first base station. The first capability reporting message is used to indicate the terminal device's support capability for IMS emergency bearer service in restricted service mode. The first capability reporting message includes, but is not limited to, the following information: IMS emergency call support field (when this field exists, it indicates that the terminal device supports IMS emergency call); NIA0, NEA0; EIA0, EEA0; NIA0, NEA0, EIA0, EEA0.
[0318] Step 3: After the terminal device connects to the first base station and the IMS emergency service is activated, the first base station sends the first radio standard's null integrity protection algorithm (NIA0) and / or the first radio standard's null encryption algorithm (NEA0) to the terminal device through a first RRC Reconfiguration message. The first RRC Reconfiguration message includes, but is not limited to, the following information: Radio bearer configuration: For each radio bearer configuration, the following content is included: Encryption algorithm: Indicates the encryption algorithm used for SRBs and DRBs, specifically including NEA0 and EEA0; Integrity protection algorithm: Indicates the integrity protection algorithm used for signaling radio bearers, specifically including NIA0 and EIA0.
[0319] Step 4: When the first base station decides to switch the terminal device from the first base station to the second base station based on the measurement and reporting results, the first base station sends a first handover request message (HANDOVER REQUEST) to the second base station. The first handover request message includes the terminal device's support capability for the IMS emergency bearer service in restricted service mode (UE SecurityCapabilities). Specifically, the first handover request message includes, but is not limited to, one or more of the following information: EIA0, EEA0; NIA0, NEA0, EIA0, EEA0.
[0320] It is worth noting that the second base station can be a base station of the first wireless standard (i.e., the first base station and the second base station use the same wireless standard); the second base station can also be a base station of the second wireless standard (i.e., the first base station and the second base station use different wireless standards).
[0321] When a terminal device in limited service mode is switched from a first 5G base station gNB to a second 4G base station ng-eNB via the Xn interface, and the second base station is a base station of the first wireless standard, the specific configuration method is as follows:
[0322] Step 5: When the second base station is a base station of the first wireless standard (i.e., the first and second base stations use the same wireless standard), the second base station supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm. The second base station learns from the first handover request message that the terminal device supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm (NEA0, NIA0). At this time, the second base station allows the terminal device to access the second base station. Therefore, the second base station sends a first handover confirmation message to the first base station. This first handover confirmation message includes: an indication that the second base station supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm, and a second reconfiguration message (sent by the second base station to the terminal device). This second reconfiguration message contains second security configuration information, which includes, but is not limited to, the following information: the first wireless standard's null integrity protection algorithm and the first wireless standard's null encryption algorithm.
[0323] Step 6: After the first base station receives the first handover confirmation message sent by the second base station, it sends the second reconfiguration message in the first handover confirmation message to the terminal device. The second reconfiguration message sent to the terminal device includes, but is not limited to, the following information: NEA0, NIA0.
[0324] Step 7: The terminal device completes the configuration of the integrity protection algorithm and encryption algorithm according to the second security configuration information, and after updating the key according to these algorithms, it connects to the second base station. After connecting to the second base station, the terminal device performs security configuration on the signaling radio bearer and data radio bearer according to the second security configuration information, namely the first wireless standard empty encryption algorithm and the first wireless standard empty integrity protection algorithm.
[0325] When a terminal device in limited service mode is switched from a first 5G base station gNB to a second 4G base station ng-eNB via the Xn interface, and the second base station is a base station of the second wireless standard, the specific configuration method is as follows:
[0326] Step 5-1: When the second base station is a base station supporting a second wireless standard (i.e., the first and second base stations use different wireless standards), the second base station supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm. Based on the first handover request message, the second base station learns that the terminal device supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm (EEA0, EIA0). At this time, the second base station allows the terminal device to access the second base station. Therefore, the second base station sends a first handover confirmation message to the first base station. This first handover confirmation message includes: an indication that the second base station supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm, and a second reconfiguration message (sent by the second base station to the terminal device). This second reconfiguration message contains second security configuration information, which includes, but is not limited to, the following information: the second wireless standard's null integrity protection algorithm and the second wireless standard's null encryption algorithm.
[0327] Step 6-1: After the first base station receives the first handover confirmation message sent by the second base station, it sends the second reconfiguration message in the first handover confirmation message to the terminal device. The second reconfiguration message sent to the terminal device includes, but is not limited to, the following information: EIA0, EEA0.
[0328] Step 7-1: The terminal device completes the configuration of the integrity protection algorithm and encryption algorithm according to the second security configuration information, and after updating the key according to these algorithms, it accesses the second base station. After accessing the second base station, the terminal device performs security configuration on the signaling radio bearer and data radio bearer according to the second security configuration information, namely the second wireless standard empty encryption algorithm and the second wireless standard empty integrity protection algorithm.
[0329] It should be noted that, Figure 5 Preferred embodiments of the shown examples can be found in [reference needed]. Figure 3 The relevant descriptions of the embodiments shown will not be repeated here.
[0330] Figure 6 This is a signaling interaction diagram of another configuration method based on emergency services according to an embodiment of this application. Figure 6 It provides a signaling interaction process for terminal equipment to hand over between the first base station and the second base station based on the NG interface, such as... Figure 6 As shown, the specific steps include the following.
[0331] Step 1: The terminal device receives the SIB1 message sent by the first base station. The SIB1 message is used to indicate whether the cell of the first base station supports providing IMS emergency bearer service for terminal devices in restricted service mode. The SIB1 message includes, but is not limited to, the following information: the IMS Emergency Support field, where "true" indicates support and "absent" indicates no support.
[0332] Step 2: The terminal device sends a first capability reporting message (UE CapabilityInformation) to the first base station. The first capability reporting message is used to indicate the terminal device's support capability for IMS emergency bearer service in restricted service mode. The first capability reporting message includes, but is not limited to, the following information: IMS emergency call support field (when this field exists, it indicates that the terminal device supports IMS emergency call); NIA0, NEA0; EIA0, EEA0; NIA0, NEA0, EIA0, EEA0.
[0333] Step 3: After the terminal device connects to the first base station and the IMS emergency service is activated, the first base station sends the first radio standard's null integrity protection algorithm (NIA0) and / or the first radio standard's null encryption algorithm (NEA0) to the terminal device through a first RRC Reconfiguration message. The first RRC Reconfiguration message includes, but is not limited to, the following information: Radio bearer configuration: For each radio bearer configuration, the following content is included: Encryption algorithm: Indicates the encryption algorithm used for SRBs and DRBs, specifically including NEA0 and EEA0; Integrity protection algorithm: Indicates the integrity protection algorithm used for signaling radio bearers, specifically including NIA0 and EIA0.
[0334] Step 4: When the first base station decides to switch the terminal device from the first base station to the second base station based on the measurement and reporting results, the first base station sends a first handover request message (HANDOVER REQUEST) to the first core network. The first handover request message includes the terminal device's support capability for the IMS emergency bearer service in restricted service mode (UE SecurityCapabilities). Specifically, the first request message includes, but is not limited to, one or more of the following information: NIA0, NEA0; EIA0, EEA0.
[0335] It is worth noting that the second base station can be a base station of the first wireless standard (i.e., the first base station and the second base station use the same wireless standard); the second base station can also be a base station of the second wireless standard (i.e., the first base station and the second base station use different wireless standards).
[0336] When a terminal device in limited service mode is switched from a first 5G base station gNB to a second 4G base station ng-eNB via the NG interface, and the second base station is a base station of the first wireless standard, the specific configuration method is as follows:
[0337] Step 5: When the second base station is a base station of the first wireless standard (i.e., the first and second base stations use the same wireless standard), the second base station supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm. The second base station learns from the second handover request message that the terminal device supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm (NEA0, NIA0). At this time, the second base station allows the terminal device to access the second base station. Therefore, the second base station sends a second handover confirmation message to the core network. After receiving the second handover confirmation message, the core network sends a first handover confirmation message to the first base station. The second handover confirmation message includes the first handover confirmation message sent to the first base station. The first handover confirmation message includes: an indication that the second base station supports the first wireless standard's null encryption algorithm and the first wireless standard's null integrity protection algorithm, and a second reconfiguration message (sent by the second base station to the terminal device). The second reconfiguration message includes a second security configuration, which includes, but is not limited to, the following information: the first wireless standard's null integrity protection algorithm and the first wireless standard's null encryption algorithm.
[0338] Step 6: After the first base station receives the first handover confirmation message sent by the core network, it sends the second reconfiguration message in the first handover confirmation message to the terminal device. The second reconfiguration message sent to the terminal device includes, but is not limited to, the following information: second security configuration information, wherein the second security configuration information includes, but is not limited to, the following information: NEA0, NIA0.
[0339] Step 7: The terminal device completes the configuration of the integrity protection algorithm and encryption algorithm according to the second security configuration information, and after updating the key according to these algorithms, it connects to the second base station. After connecting to the second base station, the terminal device performs security configuration on the signaling radio bearer and data radio bearer according to the second security configuration information, namely the first wireless standard empty encryption algorithm and the first wireless standard empty integrity protection algorithm.
[0340] When a terminal device in limited service mode is switched from a first 5G base station gNB to a second 4G base station ng-eNB via the NG interface, and the second base station is a base station of the second wireless standard, the specific configuration method is as follows:
[0341] Step 5-1: When the second base station is a base station supporting a second wireless standard (i.e., the first and second base stations use different wireless standards), the second base station supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm. Based on the second handover request message, the second base station learns that the terminal device supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm (EEA0, EIA0). At this time, the second base station allows the terminal device to access the second base station. Therefore, the second base station sends a second handover confirmation message to the core network. After receiving the second handover confirmation message, the core network sends a first handover confirmation message to the first base station. The second handover confirmation message includes the first handover confirmation message sent to the first base station. This first handover confirmation message includes: an indication that the second base station supports the second wireless standard's null encryption algorithm and the second wireless standard's null integrity protection algorithm, and a second reconfiguration message (sent by the second base station to the terminal device). This second reconfiguration message includes a second security configuration, which includes, but is not limited to, the following information: the second wireless standard's null integrity protection algorithm and the second wireless standard's null encryption algorithm.
[0342] Step 6-1: After the first base station receives the first handover confirmation message sent by the core network, it sends the second reconfiguration message in the first handover confirmation message to the terminal device. The second reconfiguration message sent to the terminal device includes, but is not limited to, the following information: second security configuration information, wherein the second security configuration information includes, but is not limited to, the following information: EIA0, EEA0.
[0343] Step 7-1: The terminal device completes the configuration of the integrity protection algorithm and encryption algorithm according to the second security configuration information, and after updating the key according to these algorithms, it accesses the second base station. After accessing the second base station, the terminal device performs security configuration on the signaling radio bearer and data radio bearer according to the second security configuration information, namely the second wireless standard empty encryption algorithm and the second wireless standard empty integrity protection algorithm.
[0344] It should be noted that, Figure 6 Preferred embodiments of the shown examples can be found in [reference needed]. Figure 3 The relevant descriptions of the embodiments shown will not be repeated here.
[0345] Combination Figure 5 and Figure 6As can be seen from the preferred embodiments shown, the method provided in this application supports the ability of EIA0 and EEA0 during the Xn handover process, enabling terminals in restricted system mode to maintain emergency call capability for the 4G system during the 5G to 4G Xn handover process; the method provided in this application supports the ability of NIA0 and NEA0 during the Xn handover process, enabling terminals in restricted system mode to maintain emergency call capability for the 5G system during the 4G / 5G to 5G Xn handover process; the method provided in this application supports the source base station sending the terminal's support capability for NIA0, NEA0, EIA0, and EEA0 to the target base station during the Xn handover process, and after the terminal completes the 4G to 5G or 5G to 4G Xn handover, the target base station sends its own base station-related (NIA0 and NEA0) or (EIA0 and EEA0) data to the terminal, supporting the terminal to maintain emergency call user communication during the system handover process.
[0346] In summary, the method provided in this application is based on modifications to existing protocols, has good forward compatibility, and is easy to deploy and implement in networks.
[0347] Figure 7 A hardware block diagram of a computer terminal for implementing an emergency service configuration method is shown. Figure 7 As shown, the computer terminal 70 may include one or more processors 702 (shown as 702a, 702b, ..., 702n in the figure) 702 (processor 702 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 704 for storing data, and a transmission module 706 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 7 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, the computer terminal 70 may also include... Figure 7 The more or fewer components shown, or having the same Figure 7 The different configurations shown.
[0348] It should be noted that the aforementioned one or more processors 702 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 70. As involved in the embodiments of this application, the data processing circuits serve as processor control (e.g., selection of a variable resistor termination path connected to an interface).
[0349] The memory 704 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the emergency service configuration method in this embodiment. The processor 702 executes various functional applications and data processing by running the software programs and modules stored in the memory 704, thereby implementing the aforementioned emergency service configuration method. The memory 704 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 704 may further include memory remotely located relative to the processor 702, and these remote memories can be connected to the computer terminal 70 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0350] The transmission module 706 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 70. In one example, the transmission module 706 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission module 706 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.
[0351] The display may be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 70.
[0352] It should be noted here that, in some optional embodiments, the above... Figure 7 The computer terminal shown may include hardware elements (including circuitry), software elements (including computer code stored on a computer-readable medium), or a combination of both hardware and software elements. It should be noted that... Figure 7 This is only one instance of a specific particular instance, and is intended to illustrate the types of components that may exist in the aforementioned computer terminal.
[0353] It should be noted that, Figure 7 The computer terminal shown is used to execute Figure 3 The configuration method for the emergency services shown above also applies to this electronic device, and will not be repeated here.
[0354] This application also provides a non-volatile storage medium, which includes a stored program, wherein the program, when running, controls the device where the storage medium is located to execute the above-mentioned emergency services configuration method.
[0355] A non-volatile storage medium performs the following function: A first base station receives terminal security capabilities sent by a second base station, wherein the terminal security capabilities include at least one of the following: a first wireless standard spatial integrity protection algorithm, a first wireless standard spatial encryption algorithm, a second wireless standard spatial integrity protection algorithm, and a second wireless standard spatial encryption algorithm; the first base station is either a first wireless standard base station or a second wireless standard base station, and the second base station is either a first wireless standard base station or a second wireless standard base station; the first base station selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection, or the first base station selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
[0356] This application also provides an electronic device, including a memory and a processor, wherein the processor is used to run a program stored in the memory, wherein the program executes the above-mentioned emergency service configuration method during runtime.
[0357] The processor is used to run a program that performs the following functions: a first base station receives terminal security capabilities sent by a second base station, wherein the terminal security capabilities include at least one of the following: a first wireless standard spatial integrity protection algorithm, a first wireless standard spatial encryption algorithm, a second wireless standard spatial integrity protection algorithm, and a second wireless standard spatial encryption algorithm; the first base station is either a first wireless standard base station or a second wireless standard base station, and the second base station is either a first wireless standard base station or a second wireless standard base station; the first base station selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection, or the first base station selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
[0358] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0359] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0360] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0361] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0362] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0363] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to related technologies, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0364] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A method for configuring emergency services, characterized in that, include: The first base station receives terminal security capabilities sent by the second base station, wherein the terminal security capabilities include at least one of the following: a first wireless standard air integrity protection algorithm, a first wireless standard air encryption algorithm, a second wireless standard air integrity protection algorithm, and a second wireless standard air encryption algorithm, wherein the first base station is a first wireless standard base station or a second wireless standard base station, and the second base station is a first wireless standard base station or a second wireless standard base station. The first base station selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection, or... The first base station selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
2. The method according to claim 1, characterized in that, include: The first wireless standard includes: 4G LTE (Long Term Evolution) or 5G NR (New Radio); The second wireless standard includes: 5G NR (New Radio) or 6G (Sixth Generation Radio).
3. The method according to claim 2, characterized in that, include: When the first wireless base station is a 4G LTE base station, the first wireless base station is connected to the 5G core network, and the second wireless base station is a 5G NR base station. When the first wireless base station is a 5G NR base station, the first wireless base station is connected to the 6G core network, and the second wireless base station is a 6G base station.
4. The method according to claim 1, characterized in that, The first base station selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection, including: When the first base station is the first wireless standard base station, the first base station selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection.
5. The method according to claim 1, characterized in that, The first base station selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection, including: When the first base station is the second wireless standard base station, the first base station selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
6. The method according to claim 1, characterized in that, The first base station receives terminal security capabilities sent by the second base station, including: The first base station receives the terminal security capabilities sent by the second base station through the Xn interface.
7. The method according to claim 1, characterized in that, The first base station receives terminal security capabilities sent by the second base station, including: The first base station receives the terminal security capabilities sent by the second base station via the NG interface.
8. The method according to any one of claims 1 to 7, characterized in that, include: In the case where there is a direct connection interface between the first base station and the second base station, and the first base station and the second base station are connected to the first core network, if the first core network control plane entity allows unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions to use the null integrity protection algorithm and the null encryption algorithm, the first base station receives a message from the first core network control plane entity stating that the first core network control plane entity provides support for the null integrity protection algorithm and the null encryption algorithm for unauthenticated IMS emergency sessions. The first core network is a 5G core network or a 6G core network; The first core network control plane entity includes: Access and Mobility Management Function (AMF) entity.
9. The method according to claim 8, characterized in that, include: The air integrity protection algorithm includes: a first wireless standard air integrity protection algorithm NIA0 and / or a second wireless standard air integrity protection algorithm EIA0; The empty encryption algorithm includes: a first wireless standard empty encryption algorithm NEA0 and / or a second wireless standard empty encryption algorithm EEA0.
10. The method according to claim 8, characterized in that, include: After receiving the first core network control plane entity's support for empty integrity protection algorithm and empty encryption algorithm for unauthenticated IMS emergency sessions, the first base station supports providing emergency bearer services for terminal devices in restricted service mode. The first base station sends a first system message block (SIB) to the terminal device in the restricted service mode, wherein the first SIB includes an IMS emergency bearer service support field.
11. The method according to claim 10, characterized in that, include: The IMS Emergency Bearer Service Support field is used to indicate whether the cell of the first base station supports providing IMS Emergency Bearer Service for the terminal device in the restricted service mode; The IMS Emergency Bearer Service Support field is an enumeration type. When the IMS Emergency Bearer Service Support field is true, it means that the cell of the first base station supports providing IMS Emergency Bearer Service for the terminal device in the restricted service mode. When the IMS Emergency Bearer Service Support field is absent, it means that the cell of the first base station does not support providing IMS Emergency Bearer Service for the terminal device in the restricted service mode.
12. The method according to claim 10, characterized in that, include: After the terminal device in restricted service mode accesses the first base station and the IMS emergency bearer service of the terminal device in restricted service mode is activated, the first base station sends the null integrity protection algorithm and / or the null encryption algorithm to the terminal device in restricted service mode through a first radio resource control (RRC) reconfiguration message.
13. The method according to claim 12, characterized in that, include: The first RRC reconfiguration message further includes: radio bearer configuration information, wherein the radio bearer configuration information includes: encryption algorithm and integrity protection algorithm, wherein the encryption algorithm is used for signaling radio bearer and / or data radio bearer, and the integrity protection algorithm is used for signaling radio bearer and / or data radio bearer.
14. The method according to claim 13, characterized in that, include: The encryption algorithm includes: the first wireless standard empty encryption algorithm and / or the second wireless standard empty encryption algorithm; The integrity protection algorithm includes: the first wireless standard air integrity protection algorithm and / or the second wireless standard air integrity protection algorithm.
15. The method according to claim 12, characterized in that, include: When the first base station determines to switch the terminal device in restricted service mode from the first base station to the second base station, the first base station sends a first handover request message to the second base station. The first handover request message includes the terminal security capabilities, which include at least one of the following: a first wireless standard null encryption algorithm and a first wireless standard null integrity protection algorithm, and / or a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm.
16. The method according to claim 15, characterized in that, include: When the second base station is the first wireless standard base station, and the second base station determines, based on the first handover request message, that the terminal device in restricted service mode supports the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm, the first base station receives a first handover confirmation message sent by the second base station, wherein... The second base station is used to send the first handover confirmation message to the first base station after receiving the first handover request message; The second base station is also used to support the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm when the second base station is a first wireless standard base station.
17. The method according to claim 16, characterized in that, include: The first handover confirmation message includes: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
18. The method according to claim 17, characterized in that, include: The first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in the limited service mode, wherein, The new air interface handover command includes: the second reconfiguration message; The terminal device in restricted service mode is used, after accessing the second base station, to perform secure configuration of the signaling radio bearer and data radio bearer according to the second reconfiguration message, using the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm.
19. The method according to claim 15, characterized in that, include: When the second base station is a base station for the second wireless standard, and the second base station determines, based on the first handover request message, that the terminal device in the restricted service mode supports the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm, the first base station receives a first handover confirmation message sent by the second base station, wherein... The second base station is used to send the first handover confirmation message to the first base station after receiving the first handover request message; The second base station is also used to support the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm when the second base station is a second wireless standard base station.
20. The method according to claim 19, characterized in that, include: The first handover confirmation message includes: an indication that the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
21. The method according to claim 20, characterized in that, include: The first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in the limited service mode, wherein, The new air interface handover command includes: the second reconfiguration message; The terminal device in restricted service mode is used, after accessing the second base station, to perform secure configuration of the signaling radio bearer and data radio bearer according to the second reconfiguration message, using the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm.
22. The method according to any one of claims 1 to 7, characterized in that, include: In the case where there is no direct connection between the first base station and the second base station, and the first base station and the second base station are connected to the first core network, if the first core network control plane entity allows unauthenticated IMS emergency sessions to use the null integrity protection algorithm and the null encryption algorithm, the first base station receives the first core network control plane entity's support capability for the null integrity protection algorithm and the null encryption algorithm for unauthenticated IMS emergency sessions. Here, the first core network is a 5G core network or a 6G core network. The first core network control plane entity includes: Access and Mobility Management Function (AMF) entity.
23. The method according to claim 22, characterized in that, include: The air integrity protection algorithm includes: a first wireless standard air integrity protection algorithm NIA0 and / or a second wireless standard air integrity protection algorithm EIA0; The empty encryption algorithm includes: a first wireless standard empty encryption algorithm NEA0 and / or a second wireless standard empty encryption algorithm EEA0.
24. The method according to claim 22, characterized in that, include: After receiving the first core network control plane entity's support for empty integrity protection algorithm and empty encryption algorithm for unauthenticated IMS emergency sessions, the first base station supports providing emergency bearer services for terminal devices in restricted service mode. The first base station sends a first system message block (SIB) to the terminal device in the restricted service mode, wherein the first SIB includes an IMS emergency bearer service support field.
25. The method according to claim 24, characterized in that, include: The IMS Emergency Bearer Service Support field is used to indicate whether the cell of the first base station supports providing IMS Emergency Bearer Service for the terminal device in the restricted service mode; The IMS Emergency Bearer Service Support field is an enumeration type. When the IMS Emergency Bearer Service Support field is true, it means that the cell of the first base station supports providing IMS Emergency Bearer Service for the terminal device in the restricted service mode. When the IMS Emergency Bearer Service Support field is absent, it means that the cell of the first base station does not support providing IMS Emergency Bearer Service for the terminal device in the restricted service mode.
26. The method according to claim 24, characterized in that, include: After the terminal device in restricted service mode accesses the first base station and the IMS emergency bearer service of the terminal device in restricted service mode is activated, the first base station sends the null integrity protection algorithm and / or the null encryption algorithm to the terminal device in restricted service mode through a first radio resource control (RRC) reconfiguration message.
27. The method according to claim 26, characterized in that, include: The first RRC reconfiguration message further includes: radio bearer configuration information, wherein the radio bearer configuration information includes: encryption algorithm and integrity protection algorithm, wherein the encryption algorithm is used for signaling radio bearer and / or data radio bearer, and the integrity protection algorithm is used for signaling radio bearer and / or data radio bearer.
28. The method according to claim 27, characterized in that, include: The encryption algorithm includes: the first wireless standard empty encryption algorithm and / or the second wireless standard empty encryption algorithm; The integrity protection algorithm includes: the first wireless standard air integrity protection algorithm and / or the second wireless standard air integrity protection algorithm.
29. The method according to claim 26, characterized in that, include: When the first base station determines that the terminal device in limited service mode should be switched from the first base station to the second base station, the first base station sends a first handover request message to the first core network, wherein... The first core network is used to send a second handover request message to the second base station, the second handover request message including: the first handover request message sent by the first base station to the first core network.
30. The method according to claim 29, characterized in that, include: The first handover request message includes: the terminal security capability, which includes at least one of the following: the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm, and / or the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm.
31. The method according to claim 29, characterized in that, include: When the second base station is the first wireless standard base station, and the second base station determines, based on the second handover request message, that the terminal device in restricted service mode supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, the first base station receives a first handover confirmation message sent by the first core network, wherein... The first core network is used to receive the second handover confirmation message sent by the second base station, and to send the first handover confirmation message in the second handover confirmation message to the first base station; The second base station is used to support the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm when the second base station is a first wireless standard base station.
32. The method according to claim 31, characterized in that, include: The first handover confirmation message includes: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
33. The method according to claim 32, characterized in that, include: The first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in the limited service mode, wherein, The new air interface handover command includes: the second reconfiguration message; The terminal device in restricted service mode is used, after accessing the second base station, to perform secure configuration of the signaling radio bearer and data radio bearer according to the second reconfiguration message, using the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm.
34. The method according to claim 29, characterized in that, include: When the second base station is a base station for the second wireless standard, and the second base station determines, based on the second handover request message, that the terminal device in the restricted service mode supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, the first base station receives a first handover confirmation message sent by the first core network, wherein... The first core network is used to receive the second handover confirmation message sent by the second base station, and send the first handover confirmation message in the second handover confirmation message to the first base station; The second base station is used to support the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm when the second base station is a second wireless standard base station.
35. The method according to claim 34, characterized in that, include: The first handover confirmation message includes: an indication that the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
36. The method according to claim 35, characterized in that, include: The first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in the limited service mode, wherein, The new air interface handover command includes: the second reconfiguration message; The terminal device in restricted service mode is used, after accessing the second base station, to perform secure configuration of the signaling radio bearer and data radio bearer according to the second reconfiguration message, using the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm.
37. A method for configuring emergency services, characterized in that, include: The second base station sends terminal security capabilities to the first base station, wherein... The terminal security capabilities include at least one of the following: a first wireless standard air integrity protection algorithm, a first wireless standard air encryption algorithm, a second wireless standard air integrity protection algorithm, and a second wireless standard air encryption algorithm, wherein the first base station is a first wireless standard base station or a second wireless standard base station, and the second base station is the first wireless standard base station or the second wireless standard base station. The first base station is used to select the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection, or to select the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
38. The method according to claim 37, characterized in that, include: The first wireless standard includes: 4G LTE (Long Term Evolution) or 5G NR (New Radio); The second wireless standard includes: 5G NR (New Radio) or 6G (Sixth Generation Radio).
39. The method according to claim 38, characterized in that, include: When the first wireless base station is a 4G LTE base station, the first wireless base station is connected to the 5G core network, and the second wireless base station is a 5G NR base station. When the first wireless base station is a 5G NR base station, the first wireless base station is connected to the 6G core network, and the second wireless base station is a 6G base station.
40. The method according to claim 38, characterized in that, include: When the second base station is the first wireless standard base station, the second base station selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection.
41. The method according to claim 38, characterized in that, include: When the second base station is the second wireless standard base station, the second base station selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
42. The method according to claim 38, characterized in that, The second base station sends terminal security capabilities to the first base station, including: The second base station sends the terminal security capabilities to the first base station via the Xn interface, wherein, The first base station is used to select the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection when the first base station is the first wireless standard base station. The first base station is further configured to, when the first base station is a base station of the second wireless standard, select the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
43. The method according to claim 38, characterized in that, The second base station sends terminal security capabilities to the first base station, including: The second base station sends the terminal security capabilities to the first base station via the NG interface, wherein, The first base station is used to select the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection when the first base station is the first wireless standard base station. The first base station is further configured to, when the first base station is a base station of the second wireless standard, select the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
44. The method according to any one of claims 37 to 43, characterized in that, include: If the first base station determines that a terminal device in limited service mode needs to be switched from the first base station to the second base station, the second base station receives a first handover request message sent by the first base station, wherein... The first base station is used to receive the first core network control plane entity's support capability for the empty integrity protection algorithm and empty encryption algorithm for unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions when there is a direct connection interface between the first base station and the second base station and the first base station and the second base station are connected to the first core network. The first base station is also configured to provide emergency bearer services to terminal devices in restricted service mode after receiving the first core network control plane entity's support capability for providing empty integrity protection algorithms and empty encryption algorithms for unauthenticated IMS emergency sessions.
45. The method according to claim 44, characterized in that, include: The first handover request message includes: the terminal security capability, which includes at least one of the following: a first wireless standard null encryption algorithm and a first wireless standard null integrity protection algorithm, and / or a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm.
46. The method according to claim 45, characterized in that, include: If the second base station is the first wireless standard base station, and the second base station determines, based on the first handover request message, that the terminal device in the restricted service mode supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, the second base station sends the first handover confirmation message to the first base station after receiving the first handover request message.
47. The method according to claim 46, characterized in that, include: When the second base station is a base station of the first wireless standard, it supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm.
48. The method according to claim 46, characterized in that, include: The first handover confirmation message includes: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
49. The method according to claim 45, characterized in that, include: When the second base station is the second wireless standard base station, and the second base station determines that the terminal device in the restricted service mode supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, the second base station sends a first handover confirmation message to the first base station after receiving the first handover request message.
50. The method according to claim 49, characterized in that, include: When the second base station is a base station of the second wireless standard, it supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm.
51. The method according to claim 49, characterized in that, include: The first handover confirmation message includes: an indication that the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
52. The method according to any one of claims 37 to 43, characterized in that, include: If the first base station determines that a terminal device in limited service mode needs to be switched from the first base station to the second base station, the second base station receives a second handover request message sent by the first core network, wherein... The first core network is used to receive the first handover request message sent by the first base station; The second handover request message includes: the first handover request message; The first base station is used to receive the first core network control plane entity's support capability for the empty integrity protection algorithm and empty encryption algorithm for unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions when there is no direct connection interface between the first base station and the second base station and the first base station and the second base station are connected to the first core network. The first base station is also configured to provide emergency bearer services to terminal devices in restricted service mode after receiving the first core network control plane entity's support capability for providing empty integrity protection algorithms and empty encryption algorithms for unauthenticated IMS emergency sessions.
53. The method according to claim 52, characterized in that, include: The first handover request message includes: the terminal security capability, which includes at least one of the following: the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm, and / or the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm.
54. The method according to claim 52, characterized in that, include: When the second base station is the first wireless standard base station, and the second base station determines, according to the second handover request message, that the terminal device in the restricted service mode supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, the second base station sends the second handover confirmation message to the first core network, wherein the first core network is used to send the first handover confirmation message in the second handover confirmation message to the first base station.
55. The method according to claim 54, characterized in that, include: When the second base station is a base station of the first wireless standard, it supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm.
56. The method according to claim 54, characterized in that, include: The first handover confirmation message includes: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
57. The method according to claim 52, characterized in that, include: When the second base station is the second wireless standard base station, and the second base station determines, according to the second handover request message, that the terminal device in the restricted service mode supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, the second base station sends the second handover confirmation message to the first core network, wherein the first core network is used to send the first handover confirmation message in the second handover confirmation message to the first base station.
58. The method according to claim 57, characterized in that, include: When the second base station is a base station of the second wireless standard, it supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm.
59. The method according to claim 57, characterized in that, include: The first handover confirmation message includes: an indication that the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
60. A method for configuring emergency services, characterized in that, include: A terminal device in limited service mode receives a first system message block (SIB) sent by a first base station, wherein... The first SIB includes: IMS Emergency Bearer Service Support field; The first base station is used to receive terminal security capabilities sent by the second base station, wherein the terminal security capabilities include at least one of the following: a first wireless standard air integrity protection algorithm, a first wireless standard air encryption algorithm, a second wireless standard air integrity protection algorithm, and a second wireless standard air encryption algorithm, wherein the first base station is a first wireless standard base station or a second wireless standard base station, and the second base station is the first wireless standard base station or the second wireless standard base station. The first base station is further configured to select the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection, or to select the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
61. The method according to claim 60, characterized in that, include: The IMS Emergency Bearer Service Support field is used to indicate whether the cell of the first base station supports providing IMS Emergency Bearer Service to the terminal device in the restricted service mode.
62. The method according to claim 61, characterized in that, include: The IMS Emergency Bearer Service Support field is an enumeration type. When the IMS Emergency Bearer Service Support field is true, it means that the cell of the first base station supports providing IMS Emergency Bearer Service for the terminal device in the restricted service mode. When the IMS Emergency Bearer Service Support field is absent, it means that the cell of the first base station does not support providing IMS Emergency Bearer Service for the terminal device in the restricted service mode.
63. The method according to claim 60, characterized in that, include: After the terminal device in restricted service mode accesses the first base station and the IMS emergency bearer service of the terminal device in restricted service mode is activated, the terminal device in restricted service mode receives the null integrity protection algorithm and / or the null encryption algorithm sent by the first base station through a first radio resource control (RRC) reconfiguration message. The first base station is configured to receive a first handover confirmation message sent by the second base station when the second base station is the first radio standard base station and the second base station determines that the terminal device in restricted service mode supports the first radio standard null encryption algorithm and the first radio standard null integrity protection algorithm. The first handover confirmation message includes: an indication that the second base station supports the first radio standard null encryption algorithm and the first radio standard null integrity protection algorithm; a second reconfiguration message; the second reconfiguration message includes: second security configuration information; the second security configuration information includes: the first radio standard null integrity protection algorithm NIA0 and the first radio standard null encryption algorithm NEA0.
64. The method according to claim 63, characterized in that, include: The first RRC reconfiguration message further includes: radio bearer configuration information, wherein the radio bearer configuration information includes: encryption algorithm and integrity protection algorithm, wherein the encryption algorithm is used for signaling radio bearer and / or data radio bearer, and the integrity protection algorithm is used for signaling radio bearer and / or data radio bearer.
65. The method according to claim 64, characterized in that, include: The encryption algorithm includes: the first wireless standard empty encryption algorithm and / or the second wireless standard empty encryption algorithm; The integrity protection algorithm includes: the first wireless standard air integrity protection algorithm and / or the second wireless standard air integrity protection algorithm.
66. The method according to claim 63, characterized in that, include: The terminal device in restricted service mode receives a new air interface handover command sent by the first base station, wherein the new air interface handover command includes: the second reconfiguration message.
67. The method according to claim 66, characterized in that, include: After the terminal device in restricted service mode accesses the second base station, it performs secure configuration of the signaling radio bearer and data radio bearer according to the second reconfiguration message, using the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm.
68. The method according to claim 60, characterized in that, include: After the terminal device in restricted service mode accesses the first base station and the IMS emergency bearer service of the terminal device in restricted service mode is activated, the terminal device in restricted service mode receives the null integrity protection algorithm and / or the null encryption algorithm sent by the first base station through a first radio resource control (RRC) reconfiguration message. The first base station is configured to receive a first handover confirmation message sent by the second base station when the second base station is the second radio standard base station and the second base station determines that the terminal device in restricted service mode supports the first radio standard null encryption algorithm and the first radio standard null integrity protection algorithm. The first handover confirmation message includes: an indication that the second base station supports the second radio standard null encryption algorithm and the second radio standard null integrity protection algorithm; and a second reconfiguration message. The second reconfiguration message includes: second security configuration information, which includes: the second radio standard null integrity protection algorithm EIA0 and the second radio standard null encryption algorithm EEA0.
69. The method according to claim 68, characterized in that, include: The terminal device in restricted service mode receives a new air interface handover command sent by the first base station, wherein the new air interface handover command includes: the second reconfiguration message.
70. The method according to claim 69, characterized in that, include: After the terminal device in restricted service mode accesses the second base station, it performs secure configuration of the signaling radio bearer and data radio bearer according to the second reconfiguration message, using the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm.
71. An emergency service configuration system, characterized in that, include: The first base station, the second base station, terminal equipment, and the first core network control plane entity, among which... The first base station is communicatively connected to the terminal device and the second base station respectively, and is used to receive terminal security capabilities sent by the second base station. The terminal security capabilities include at least one of the following: a first wireless standard air integrity protection algorithm, a first wireless standard air encryption algorithm, a second wireless standard air integrity protection algorithm, and a second wireless standard air encryption algorithm. The first base station is either a first wireless standard base station or a second wireless standard base station, and the second base station is either the first wireless standard base station or the second wireless standard base station. The first base station selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection; or, the first base station selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection. The terminal device is a terminal device in a limited service mode; When the first base station and the second base station are connected to the first core network, if the first core network control plane entity allows unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions to use the null integrity protection algorithm and the null encryption algorithm, the first core network control plane entity is used to send a message to the first base station that the first core network control plane entity provides support for the null integrity protection algorithm and the null encryption algorithm for unauthenticated IMS emergency sessions.
72. The system according to claim 71, characterized in that, include: The first wireless standard includes: 4G LTE (Long Term Evolution) or 5G NR (New Radio); The second wireless standard includes: 5G NR (New Radio) or 6G (Sixth Generation Radio).
73. The system according to claim 72, characterized in that, include: When the first wireless base station is a 4G LTE base station, the first wireless base station is connected to the 5G core network, and the second wireless base station is a 5G NR base station. When the first wireless base station is a 5G NR base station, the first wireless base station is connected to the 6G core network, and the second wireless base station is a 6G base station.
74. The system according to claim 72, characterized in that, include: When the first base station is the first wireless standard base station, the first base station selects the first wireless standard spatial integrity protection algorithm for integrity protection and / or the first wireless standard spatial encryption algorithm for confidentiality protection.
75. The system according to claim 72, characterized in that, include: When the first base station is the second wireless standard base station, the first base station selects the second wireless standard spatial integrity protection algorithm for integrity protection and / or the second wireless standard spatial encryption algorithm for confidentiality protection.
76. The system according to claim 72, characterized in that, include: The first base station receives the terminal security capabilities sent by the second base station through the Xn interface.
77. The system according to claim 72, characterized in that, include: The first base station receives the terminal security capabilities sent by the second base station via the NG interface.
78. The system according to claim 72, characterized in that, include: The first core network is a 5G core network or a 6G core network; The first core network control plane entity includes: Access and Mobility Management Function (AMF) entity.
79. The system according to any one of claims 71 to 78, characterized in that, include: In the case where there is a direct connection interface between the first base station and the second base station, and the first base station and the second base station are connected to the first core network, if the first core network control plane entity allows unauthenticated Internet Protocol Multimedia Subsystem (IMS) emergency sessions to use the null integrity protection algorithm and the null encryption algorithm, the first base station receives the first core network control plane entity's support capability for the null integrity protection algorithm and the null encryption algorithm for unauthenticated IMS emergency sessions.
80. The system according to claim 79, characterized in that, include: The air integrity protection algorithm includes: a first wireless standard air integrity protection algorithm NIA0 and / or a second wireless standard air integrity protection algorithm EIA0; The empty encryption algorithm includes: a first wireless standard empty encryption algorithm NEA0 and / or a second wireless standard empty encryption algorithm EEA0.
81. The system according to claim 79, characterized in that, include: After receiving the first core network control plane entity's support for empty integrity protection algorithm and empty encryption algorithm for unauthenticated IMS emergency sessions, the first base station supports providing emergency bearer services for terminal devices in restricted service mode. The first base station sends a first system message block (SIB) to the terminal device in the restricted service mode, wherein the first SIB includes an IMS emergency bearer service support field.
82. The system according to claim 81, characterized in that, include: The IMS Emergency Bearer Service Support field is used to indicate whether the cell of the first base station supports providing IMS Emergency Bearer Service for the terminal device in the restricted service mode; The IMS Emergency Bearer Service Support field is an enumeration type. When the IMS Emergency Bearer Service Support field is true, it means that the cell of the first base station supports providing IMS Emergency Bearer Service for the terminal device in the restricted service mode. When the IMS Emergency Bearer Service Support field is absent, it means that the cell of the first base station does not support providing IMS Emergency Bearer Service for the terminal device in the restricted service mode.
83. The system according to claim 81, characterized in that, include: The IMS Emergency Bearer Service Support field is used to indicate whether the cell of the first base station supports providing IMS Emergency Bearer Service for the terminal device in the restricted service mode; The IMS Emergency Bearer Service Support field is an enumeration type. When the IMS Emergency Bearer Service Support field is true, it means that the cell of the first base station supports providing IMS Emergency Bearer Service for the terminal device in the restricted service mode. When the IMS Emergency Bearer Service Support field is absent, it means that the cell of the first base station does not support providing IMS Emergency Bearer Service for the terminal device in the restricted service mode.
84. The system according to claim 81, characterized in that, include: After the terminal device in restricted service mode accesses the first base station and the IMS emergency bearer service of the terminal device in restricted service mode is activated, the first base station sends the null integrity protection algorithm and / or the null encryption algorithm to the terminal device in restricted service mode through a first radio resource control (RRC) reconfiguration message.
85. The system according to claim 84, characterized in that, include: The first RRC reconfiguration message further includes: radio bearer configuration information, wherein the radio bearer configuration information includes: encryption algorithm and integrity protection algorithm, wherein the encryption algorithm is used for signaling radio bearer and / or data radio bearer, and the integrity protection algorithm is used for signaling radio bearer and / or data radio bearer.
86. The system according to claim 85, characterized in that, include: The encryption algorithm includes: the first wireless standard empty encryption algorithm and / or the second wireless standard empty encryption algorithm; The integrity protection algorithm includes: the first wireless standard air integrity protection algorithm and / or the second wireless standard air integrity protection algorithm.
87. The system according to claim 85, characterized in that, include: When the first base station determines to switch the terminal device in restricted service mode from the first base station to the second base station, the first base station sends a first handover request message to the second base station. The first handover request message includes the terminal security capabilities, which include at least one of the following: a first wireless standard null encryption algorithm and a first wireless standard null integrity protection algorithm, and / or a second wireless standard null encryption algorithm and a second wireless standard null integrity protection algorithm.
88. The system according to claim 87, characterized in that, include: When the second base station is the first wireless standard base station, and the second base station determines, based on the first handover request message, that the terminal device in the restricted service mode supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, the first base station receives the first handover confirmation message sent by the second base station. After receiving the first handover request message, the second base station sends the first handover confirmation message to the first base station; When the second base station is a base station of the first wireless standard, it supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm.
89. The system according to claim 88, characterized in that, include: The first handover confirmation message includes: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
90. The system according to claim 89, characterized in that, include: The first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in the restricted service mode, wherein the new air interface handover command includes: the second reconfiguration message; After the terminal device in restricted service mode accesses the second base station, it performs secure configuration of the signaling radio bearer and data radio bearer according to the second reconfiguration message, using the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm.
91. The system according to claim 87, characterized in that, include: When the second base station is the second wireless standard base station, and the second base station determines, according to the first handover request message, that the terminal device in the restricted service mode supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, the first base station receives the first handover confirmation message sent by the second base station. After receiving the first handover request message, the second base station sends the first handover confirmation message to the first base station; When the second base station is a second wireless standard base station, it supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm.
92. The system according to claim 91, characterized in that, include: The first handover confirmation message includes: an indication that the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
93. The system according to claim 92, characterized in that, include: The first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in the restricted service mode, wherein the new air interface handover command includes: the second reconfiguration message; After the terminal device in restricted service mode accesses the second base station, it performs secure configuration of the signaling radio bearer and data radio bearer according to the second reconfiguration message, using the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm.
94. The system according to any one of claims 71 to 78, characterized in that, include: In the case where there is no direct connection between the first base station and the second base station, and the first base station and the second base station are connected to the first core network, if the first core network control plane entity allows unauthenticated IMS emergency sessions to use the null integrity protection algorithm and the null encryption algorithm, the first base station receives the first core network control plane entity's support capability for the null integrity protection algorithm and the null encryption algorithm for unauthenticated IMS emergency sessions.
95. The system according to claim 94, characterized in that, include: The air integrity protection algorithm includes: a first wireless standard air integrity protection algorithm NIA0 and / or a second wireless standard air integrity protection algorithm EIA0; The empty encryption algorithm includes: a first wireless standard empty encryption algorithm NEA0 and / or a second wireless standard empty encryption algorithm EEA0.
96. The system according to claim 94, characterized in that, include: After receiving the first core network control plane entity's support for empty integrity protection algorithm and empty encryption algorithm for unauthenticated IMS emergency sessions, the first base station supports providing emergency bearer services for terminal devices in restricted service mode. The first base station sends a first system message block (SIB) to the terminal device in the restricted service mode, wherein the first SIB includes an IMS emergency bearer service support field.
97. The system according to claim 96, characterized in that, include: The IMS Emergency Bearer Service Support field is used to indicate whether the cell of the first base station supports providing IMS Emergency Bearer Service for the terminal device in the restricted service mode; The IMS Emergency Bearer Service Support field is an enumeration type. When the IMS Emergency Bearer Service Support field is true, it means that the cell of the first base station supports providing IMS Emergency Bearer Service for the terminal device in the restricted service mode. When the IMS Emergency Bearer Service Support field is absent, it means that the cell of the first base station does not support providing IMS Emergency Bearer Service for the terminal device in the restricted service mode.
98. The system according to claim 96, characterized in that, include: After the terminal device in restricted service mode accesses the first base station and the IMS emergency bearer service of the terminal device in restricted service mode is activated, the first base station sends the null integrity protection algorithm and / or the null encryption algorithm to the terminal device in restricted service mode through a first radio resource control (RRC) reconfiguration message.
99. The system according to claim 98, characterized in that, include: The first RRC reconfiguration message further includes: radio bearer configuration information, wherein the radio bearer configuration information includes: encryption algorithm and integrity protection algorithm, wherein the encryption algorithm is used for signaling radio bearer and / or data radio bearer, and the integrity protection algorithm is used for signaling radio bearer and / or data radio bearer.
100. The system according to claim 99, characterized in that, include: The encryption algorithm includes: the first wireless standard empty encryption algorithm and / or the second wireless standard empty encryption algorithm; The integrity protection algorithm includes: the first wireless standard air integrity protection algorithm and / or the second wireless standard air integrity protection algorithm.
101. The system according to claim 98, characterized in that, include: If the first base station determines that the terminal device in the restricted service mode should be switched from the first base station to the second base station, the first base station sends a first handover request message to the first core network; The first core network sends a second handover request message to the second base station, the second handover request message including: the first handover request message sent by the first base station to the first core network.
102. The system according to claim 101, characterized in that, include: The first handover request message includes: the terminal security capability, which includes at least one of the following: the first wireless standard null encryption algorithm and the first wireless standard null integrity protection algorithm, and / or the second wireless standard null encryption algorithm and the second wireless standard null integrity protection algorithm.
103. The system according to claim 101, characterized in that, include: When the second base station is the first wireless standard base station, and the second base station determines, according to the second handover request message, that the terminal device in the restricted service mode supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, the first base station receives the first handover confirmation message sent by the first core network. The first core network receives the second handover confirmation message sent by the second base station, and sends the first handover confirmation message in the second handover confirmation message to the first base station; When the second base station is a base station of the first wireless standard, it supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm.
104. The system according to claim 103, characterized in that, include: The first handover confirmation message includes: an indication that the second base station supports the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the first wireless standard air integrity protection algorithm NIA0 and the first wireless standard air encryption algorithm NEA0.
105. The system according to claim 104, characterized in that, include: The first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in the restricted service mode, wherein the new air interface handover command includes: the second reconfiguration message; After the terminal device in restricted service mode accesses the second base station, it performs secure configuration of the signaling radio bearer and data radio bearer according to the second reconfiguration message, using the first wireless standard air encryption algorithm and the first wireless standard air integrity protection algorithm.
106. The system according to claim 101, characterized in that, include: When the second base station is the second wireless standard base station, and the second base station determines, according to the second handover request message, that the terminal device in the restricted service mode supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, the first base station receives the first handover confirmation message sent by the first core network. The first core network receives the second handover confirmation message sent by the second base station, and sends the first handover confirmation message in the second handover confirmation message to the first base station; When the second base station is a base station of the second wireless standard, it supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm.
107. The system according to claim 106, characterized in that, include: The first handover confirmation message includes: an indication that the second base station supports the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm, and a second reconfiguration message, wherein the second reconfiguration message includes: second security configuration information, and the second security configuration information includes: the second wireless standard air integrity protection algorithm EIA0 and the second wireless standard air encryption algorithm EEA0.
108. The system according to claim 107, characterized in that, include: The first base station triggers a new air interface handover command and sends the new air interface handover command to the terminal device in the restricted service mode, wherein the new air interface handover command includes: the second reconfiguration message; After the terminal device in restricted service mode accesses the second base station, it performs secure configuration of the signaling radio bearer and data radio bearer according to the second reconfiguration message, using the second wireless standard air encryption algorithm and the second wireless standard air integrity protection algorithm.