Control plane signaling security protection method and unit, terminal and storage medium
By generating and securely protecting control plane signaling in distributed and centralized units respectively in the 5G split architecture, the problems of control plane signaling generation and transmission latency and F1 signaling overhead are solved, achieving more efficient signaling processing and reducing complexity.
Patent Information
- Application Number
- CN202410880252.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-02
- Publication Date
- 2026-01-06
AI Technical Summary
In the 5G split architecture, the generation and transmission latency of control plane signaling is relatively long, and the F1 signaling overhead between CU and DU is large, which increases the complexity of the protocol and implementation.
In the distributed unit, control plane signaling is generated through the sub-RRC layer and protected by the key based on the distributed unit. In the centralized unit, control plane signaling is generated through the centralized RRC layer and protected by the key. Encryption and integrity protection are performed independently for each.
It reduces the generation and transmission latency of control plane signaling, lowers the signaling overhead between distributed and centralized units, and simplifies the protocol and implementation complexity.
Smart Images

Figure CN121283604A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a control plane signaling security protection method, unit, terminal, and storage medium. Background Technology
[0002] In the 5G Central Unit-Distributed Unit (CU-DU) architecture, the Restricted Radio Command (RRC) resides in the CU, and all control plane signaling (RRC signaling) is generated in the CU. It is encrypted and protected for integrity by the PDCP (Packet Data Convergence Protocol) layer within the CU, corresponding to the Signaling Radio Bearer (SRB) carrying the control plane signaling, thus ensuring control plane signaling security. Since the DU is directly responsible for physical layer resource management, many transmission-related control plane signaling decisions are made by the DU and then communicated to the CU. The CU generates the control plane signaling, processes it through the CU's PDCP layer, sends it to the DU, and then transmits it to the UE via the air interface. This approach introduces two problems: first, it increases the latency in control plane signaling generation and transmission; second, it increases the F1 signaling overhead between the CU and DU, increasing the complexity of the protocol and implementation. Summary of the Invention
[0003] Therefore, it is necessary to provide a control plane signaling security protection method, unit, terminal, storage medium, and program product that can reduce the delay in control plane signaling generation and transmission, and reduce F1 signaling overhead, in order to address the above-mentioned technical problems.
[0004] In a first aspect, this application provides a control plane signaling security protection method, applied to a first distributed unit, the method comprising:
[0005] The first control plane signaling is generated through the sub-RRC layer located in the first distributed unit;
[0006] The first control plane signaling is securely protected based on the first key.
[0007] The first key is determined based on the key of the first distributed unit.
[0008] Secondly, this application provides a control plane signaling security protection method applied to a centralized unit, comprising:
[0009] The second control plane signaling is generated through the centralized RRC layer located in the centralized unit;
[0010] The second control plane signaling after security protection is obtained, wherein the second control plane signaling after security protection is obtained by performing security protection on the second control plane signaling based on the second key;
[0011] The second key is determined based on the key of the centralized unit.
[0012] Thirdly, this application provides a control plane signaling security protection method, applied to a terminal, including:
[0013] Determine the key for the first distributed unit;
[0014] Based on the key of the first distributed unit, a first key is determined, which is used to provide security protection for control plane signaling.
[0015] Fourthly, this application also provides a first distributed unit, including a memory, a transceiver, and a processor:
[0016] Memory is used to store computer programs; transceiver is used to send and receive data under the control of the processor; processor is used to read the computer programs from memory and perform the following operations:
[0017] The first control plane signaling is generated through the sub-RRC layer located in the first distributed unit;
[0018] The first control plane signaling is securely protected based on the first key.
[0019] The first key is determined based on the key of the first distributed unit.
[0020] Fifthly, this application also provides a centralized unit, including: a memory, a transceiver, and a processor.
[0021] The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and perform the following operations:
[0022] The second control plane signaling is generated through the centralized RRC layer located in the centralized unit;
[0023] The second control plane signaling after security protection is obtained, wherein the second control plane signaling after security protection is obtained by performing security protection on the second control plane signaling based on the second key;
[0024] The second key is determined based on the key of the centralized unit.
[0025] Sixthly, this application also provides a terminal, characterized in that it includes: a memory, a transceiver, and a processor.
[0026] The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and perform the following operations:
[0027] Determine the key for the first distributed unit;
[0028] Based on the key of the first distributed unit, a first key is determined, which is used to provide security protection for control plane signaling.
[0029] In a seventh aspect, this application also provides a first distributed unit, comprising:
[0030] The generation module is used to generate first control plane signaling through the sub-RRC layer located in the first distributed unit;
[0031] A security protection module is used to provide security protection for the first control plane signaling based on the first key;
[0032] The first key is determined based on the key of the first distributed unit.
[0033] Eighthly, this application also provides a centralized unit, comprising:
[0034] A generation module is used to generate second control plane signaling through a centralized RRC layer located in the centralized unit;
[0035] The acquisition module is used to acquire the second control plane signaling after security protection, wherein the second control plane signaling after security protection is obtained by performing security protection on the second control plane signaling based on the second key;
[0036] The second key is determined based on the key of the centralized unit.
[0037] Ninthly, this application also provides a terminal, including:
[0038] The determination module is used to determine the key of the first distributed unit; based on the key of the first distributed unit, a first key is determined, and the first key is used to provide security protection for control plane signaling.
[0039] In a tenth aspect, this application also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements at least one of the following methods:
[0040] The method as described in the first aspect or any embodiment thereof;
[0041] The method as described in the second aspect or any embodiment thereof;
[0042] The method described in the third aspect or any of its embodiments.
[0043] In an eleventh aspect, this application also provides a computer program product comprising a computer program that, when executed by a processor, implements at least one of the following methods:
[0044] The method as described in the first aspect or any embodiment thereof;
[0045] The method as described in the second aspect or any embodiment thereof;
[0046] The method described in the third aspect or any of its embodiments.
[0047] In the aforementioned control plane signaling security protection method, the first distributed unit can generate first control plane signaling through a sub-RRC layer within the first distributed unit, and perform security protection on the first control plane signaling based on a first key; wherein the first key is determined based on the key of the first distributed unit. That is, the first distributed unit can generate control plane signaling itself, determine the first key based on the key of the first distributed unit, and perform security protection on the control plane signaling itself. In this way, the first distributed unit generates control plane signaling and performs security protection itself without interacting with the centralized unit, which can reduce the latency of control plane signaling generation and transmission, reduce the signaling overhead between the distributed unit and the centralized unit, and reduce the complexity of the protocol and implementation. Attached Figure Description
[0048] Figure 1 This is a schematic diagram of a 5G encryption process;
[0049] Figure 2 This is a schematic diagram of a 5G integrity protection process;
[0050] Figure 3 This is a schematic diagram of a 5G access network architecture;
[0051] Figure 4 To and Figure 3 The control plane protocol stack corresponding to the 5G access network architecture shown is shown.
[0052] Figure 5 This is a protocol stack distribution diagram for a layered access network architecture;
[0053] Figure 6 This is a schematic diagram of the protocol stack mapping for different RRC signaling in a layered access network architecture;
[0054] Figure 7 A flowchart illustrating a control plane signaling security protection method. Figure 1 ;
[0055] Figure 8 A flowchart illustrating a control plane signaling security protection method. Figure 2 ;
[0056] Figure 9 A flowchart illustrating a control plane signaling security protection method. Figure 3 ;
[0057] Figure 10 A flowchart illustrating the establishment of an SRB and the corresponding security process for a 6G-DU. Figure 1 ;
[0058] Figure 11 A flowchart illustrating the establishment of an SRB and the corresponding security process for a 6G-DU. Figure 2 ;
[0059] Figure 12 A schematic diagram of the structure of an electronic device provided in one embodiment;
[0060] Figure 13 This is a structural block diagram of a first type of distributed unit;
[0061] Figure 14 This is a structural block diagram of a centralized unit.
[0062] Figure 15 This is a structural block diagram of a terminal. Detailed Implementation
[0063] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0064] In this embodiment of the invention, the term "and / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.
[0065] In the 5G system's keys, the RRC (Radio Resource Control) signaling integrity protection key (KRRCint) is used to protect the integrity of RRC signaling, the RRC signaling encryption key (KRRCenc) is used to encrypt RRC signaling, the data plane transmission integrity protection key (KUPint) is used to protect the integrity of user plane data, and the data plane transmission encryption key (KUPenc) is used to encrypt user plane data.
[0066] 5G encryption uses the NEA (Encryption Algorithm for 5G) algorithm. Figure 1 The diagram shown illustrates a 5G encryption process. Figure 1 As shown, the input parameters include:
[0067] 1) The key KEY is KRRCenc for SRB (Signaling Radio Bearer) and KUPenc for DRB (Data Radio Bearer), with a length of 128 bits;
[0068] 2) BEARER, the data carrier, is 5 bits long;
[0069] 3) A combination of COUNT, HFN (Hyper Frame Number), and PDCP SN, with a length of 32 bits;
[0070] 4) DIRECTION, generally set to 0 for the uplink and 1 for the downlink, with a length of 1 bit;
[0071] 5) LENGTH, the required length of the key stream.
[0072] like Figure 1 As shown, in the sender, the KEYSTREAM block output by the NEA algorithm encrypts the input data PLAINTEXT block, resulting in the encrypted data block CIPHERNTEXT. Correspondingly, in the receiver, the KEYSTREAM block output by the NEA algorithm, combined with the received CIPHERNTEXT block from the sender, can be decrypted to obtain the PLAINTEXT block.
[0073] 5G integrity protection adopts the NIA (Integrity Algorithm for 5G) algorithm. Figure 2 The diagram illustrates a 5G integrity protection process. Figure 2 As shown, the input parameters for generating MAC-I and XMAC-I using the NIA algorithm include:
[0074] 1) The key KEY is KRRCint for SRB (Signaling Radio Bearer) and KUPint for DRB (Data Radio Bearer), with a level of 128 bits;
[0075] 2) BEARER, the data carrier, is 5 bits long;
[0076] 3) A combination of COUNT, HFN (Hyper Frame Number), and PDCP SN, with a length of 32 bits;
[0077] 4) DIRECTION, generally set to 0 for the uplink and 1 for the downlink, with a length of 1 bit.
[0078] like Figure 2 As shown, MESSAGE is the input data.
[0079] Figure 3 This is a schematic diagram of a 5G access network architecture. The 5G Core Network (5GC) can communicate with the 5G Access Network (NG-RAN). The 5G Access Network can include multiple 5G base stations (5G NodeBs, gNBs). Each 5G base station can include a Centralized Unit (CU) and a Distributed Unit (DU), where a Centralized Unit can connect to multiple Distributed Units.
[0080] Figure 4 To and Figure 3 The control plane protocol stack corresponding to the 5G access network architecture shown is as follows. Figure 4 As shown, the RRC layer and the Packet Data Convergence Protocol (PDCP) layer are located in the CU. The Radio Link Control (RLC), Medium Access Control (MAC), and Physical Layer (PHY) layers are located in the DU. Figure 4 In this context, NAS stands for Non-Access Stratum, and AMF stands for Access and Mobility Management Function.
[0081] In 5G, the DU (Control Unit) is directly responsible for physical layer resource management. Many transmission-related control plane signaling decisions are made by the DU, which then notifies the CU (Control Unit). The CU generates control plane signaling, processes it through its PDCP (Physical Device Programming) layer, sends it to the DU, and finally transmits it to the UE (User Equipment) via the air interface. This approach introduces two problems: first, it increases the latency of control plane signaling generation and transmission; second, it increases the F1 signaling overhead between the CU and DU, increasing the complexity of the protocol and implementation. Therefore, we need to consider multi-level control plane signaling generation and processing methods, as well as corresponding security protection methods.
[0082] In this embodiment, the centralized unit and the distributed unit can respectively provide security protection for control plane signaling.
[0083] The security protection in this application includes one of the following: encrypting control plane signaling based on an encryption key of control plane signaling, or protecting the integrity of control plane signaling based on an integrity protection key of control plane signaling.
[0084] This application provides a layered access network architecture in its embodiments. For example, Figure 5 This is a protocol stack distribution diagram for a layered access network architecture, such as... Figure 5 As shown, in this layered access architecture (hereinafter referred to as 6G-CU and 6G-DU), both 6G-CU and 6G-DU introduce RRC layers, each responsible for generating different RRC signaling. The RRC layer located in 6G-CU (hereinafter referred to as the centralized RRC layer) is responsible for the management and control of static, semi-static, and mobility-related and large-range information across DUs; the RRC layer located in 6G-DU (hereinafter referred to as the sub-RRC layer) is responsible for the management and control of dynamic, semi-static, and mobility-related and range-based information within the DU. The centralized RRC layer and the sub-RRC layer are located in different network-side entities, and each independently generates RRC signaling. The RRC signaling generated by the centralized RRC layer and the sub-RRC layer is mapped to different Signaling Radio Bearers (SRBs) (each RRC layer can generate one or more SRBs), and each SRB is mapped to a different PDCP layer (PDCP entity).
[0085] Figure 6 This is a schematic diagram of the protocol stack mapping for different RRC signaling in a layered access network architecture.
[0086] Among them, the above Figure 5 (a) and Figure 6 In example (a), the centralized RRC corresponds to the PDCP entity in 6G-CU, while in examples 5(b) and 6(b), the centralized RRC corresponds to the PDCP entity in 6G-DU. It should be noted that, regarding the generation method of SRB and its mapping relationship with the PDCP layer in this embodiment, the mapping relationship between RLC, MAC, and the physical layer is as follows: Figure 5 and Figure 6 The above is merely an illustrative example. It still applies to other mapping relationships, such as one PDCP entity mapping to multiple RLC entities, each RLC entity mapping to one MAC entity, etc.
[0087] like Figure 5 or Figure 6 The 6G-CU and 6G-DU shown can each independently perform control plane signaling encryption and / or integrity protection. Figure 5 (a) and Figure 6 In (a) of the data, the control plane signaling carried by the SRBx corresponding to the centralized RRC is encrypted and protected for integrity in the 6G-CU, and the control plane signaling carried by the SRBy corresponding to the sub-RRC is encrypted and protected for integrity in the 6G-DU. Figure 5 (b) and Figure 6 In (b) of the diagram, the control plane signaling carried by the SRBx corresponding to the centralized RRC and the SRBy corresponding to the sub-RRC is encrypted and protected for integrity in the 6G-DU.
[0088] The control plane signaling security protection method provided in this application embodiment can be based on the above. Figure 5 and Figure 6 The layered access network architecture shown is implemented.
[0089] For example, Figure 7 A flowchart illustrating a control plane signaling security protection method. Figure 1 Applied to the first distributed unit, the method includes the following steps:
[0090] 701. The first distributed unit generates the first control plane signaling through the sub-RRC layer located in the first distributed unit.
[0091] For example, the first distributed unit can be Figure 5 (a) or Figure 6 6G-DU in (a) of the text.
[0092] The sub-RRC layer is the RRC layer located in the first distributed unit.
[0093] 702. The first distributed unit provides security protection for the first control plane signaling based on the first key.
[0094] The first key is determined based on the key of the first distributed unit.
[0095] The aforementioned first key includes one of the following: a key for encrypting control plane signaling, or a key for protecting the integrity of control plane signaling.
[0096] The aforementioned security protection includes one of the following: encrypting control plane signaling based on an encryption key for control plane signaling, or protecting the integrity of control plane signaling based on an integrity protection key for control plane signaling.
[0097] In some embodiments, when the first key is a key for encrypting control plane signaling, the first control plane signaling can be encrypted according to the first key.
[0098] In some embodiments, when the first key is a key for integrity protection of control plane signaling, the first control plane signaling can be integrity protected based on the first key.
[0099] In some embodiments, the first distributed unit can securely protect the first control plane signaling through the PDCP entity located in the first distributed unit based on the first key.
[0100] For example, such as Figure 5 or Figure 6 As shown, a PDCP entity exists in the 6G-DU. If the first distributed unit is the 6G-DU in the figure, then the first control plane signaling generated by the sub-RRC layer in the first distributed unit can be securely protected by the PDCP entity in the first distributed unit.
[0101] In some embodiments, the PDCP entity located in the first distributed unit is also used to provide security protection for the second control plane signaling generated by the centralized RRC layer, which is located in the centralized unit. For example... Figure 5 (b) or Figure 6 As shown in (b), there is a PDCP entity in the 6G-DU, but no PDCP entity in the 6G-CU. In this case, the control plane information generated by the centralized RRC layer in the 6G-CU is protected by the PDCP entity present in the 6G-DU.
[0102] In the aforementioned control plane signaling security protection method, the first distributed unit can generate first control plane signaling through a sub-RRC layer within the first distributed unit, and perform security protection on the first control plane signaling based on a first key; wherein the first key is determined based on the key of the first distributed unit. That is, the first distributed unit can generate control plane signaling itself, determine the first key based on the key of the first distributed unit, and perform security protection on the control plane signaling itself. In this way, the first distributed unit generates control plane signaling and performs security protection itself without interacting with the centralized unit, which can reduce the latency of control plane signaling generation and transmission, reduce the signaling overhead between the distributed unit and the centralized unit, and reduce the complexity of the protocol and implementation.
[0103] In some embodiments, the method for determining the key of the first distributed unit may include: obtaining the key of the centralized unit, and determining the key of the first distributed unit based on the key of the centralized unit.
[0104] In some embodiments, the method for determining the key of the first distributed unit includes:
[0105] (1) The key of the first distributed unit is the same as the key of the centralized unit, and the centralized unit is connected to the first distributed unit.
[0106] For example, the 6G-DU uses the same key as the 6G-CU. If one 6G-CU connects to multiple 6G-DUs, these 6G-DUs can use the same key. Specifically, the 6G-DU can derive the key in the same way as the 6G-CU, or the 6G-DU can directly receive the key sent by the 6G-CU.
[0107] (2) Calculate the key of the first distributed unit based on the key of the centralized unit and the parameters of the first distributed unit.
[0108] In some embodiments, the parameters of the first distributed unit include: the absolute radio frequency channel number (ARFCN) specified by the first distributed unit.
[0109] In some embodiments, the parameters of the first distributed unit include: the Transmit / Receive Point ID (TRP ID) specified by the first distributed unit, or the Physical Cell ID (PCI).
[0110] In some embodiments, the parameters of the first distributed unit include: the ARFCN and TRP ID specified by the first distributed unit.
[0111] In some embodiments, the parameters of the first distributed unit include: the ARFCN and PCI specified by the first distributed unit.
[0112] For example, the 6G-DU uses the key K6G-CU of the 6G-CU as the upper-level key, and combines it with the parameters of the 6G-DU to derive K6G-DU (i.e. the key of the 6G-DU), and thus obtains the key KRRCenc and / or KRRCint used for control plane signaling under the 6G-DU.
[0113] Both (1) and (2) above belong to the key determination of the first distributed unit based on the key of the centralized unit.
[0114] (3) Receive the key of the first distributed unit sent by the centralized unit.
[0115] For example, the 6G-CU can calculate the key K6G-DU of the 6G-DU based on the key K6G-CU of the 6G-CU. For example, the counter of the 6G-DU can be used as the input parameter for calculating K6G-DU. Different DUs can have different K6G-DUs. Then the 6G-CU can send the calculated K6G-DU to the 6G-DU.
[0116] (4) Receive the key-related parameters sent by the centralized unit, and calculate the key of the first distributed unit based on the key-related parameters sent by the centralized unit and / or the parameters of the distributed unit.
[0117] Among them, the distributed unit parameter is the counter of the first distributed unit, and the key-related parameter is used to determine the new key of the first distributed unit based on the existing key of the first distributed unit or the existing key of the centralized unit.
[0118] In some embodiments, the key-related parameters mentioned above include: Next Hop (NH), and / or, Next Hop Chaining Counter (NCC).
[0119] For example, the 6G-CU can send key-related parameters to the 6G-DU via interface signaling between the 6G-CU and 6G-DU. In this method, the 6G-DU does not need to obtain parameters from the 6G-CU.
[0120] The above embodiments provide various methods for determining the key of the first distributed unit. This application does not limit the method for determining the key of the centralized unit. For example, the key of the centralized unit can be determined using existing methods in 5G, or any other arbitrary method can be used.
[0121] In some embodiments, the first distributed unit may send the first control plane signaling after security protection to the terminal through the first signaling bearer, or receive the control plane signaling after security protection sent by the terminal through the first signaling bearer.
[0122] The first signaling bearer is the signaling bearer between the first distributed unit and the terminal, and the first key is used to provide security protection for the control plane signaling carried by the first signaling bearer.
[0123] In some embodiments, the first distributed unit may also send third control plane signaling to the terminal, the third control plane signaling being used to configure the first signaling bearer;
[0124] Wherein, the third control plane signaling is protected by the first key, or the third control plane signaling is not protected by the first key;
[0125] The third control plane signaling includes any of the following:
[0126] RRC configuration messages, RRC reconfiguration messages, and security activation commands.
[0127] The third control plane signaling includes configuration parameters related to the first distributed unit.
[0128] In some embodiments, the configuration parameters include parameters of the first distributed unit.
[0129] In some embodiments, the configuration parameters include key-related parameters, which are used to determine a new key for the first distributed unit based on the existing key of the first distributed unit or the existing key of the centralized unit.
[0130] In some embodiments, the configuration parameters include the parameters of the first distributed unit and the aforementioned key-related parameters.
[0131] In some embodiments, the first distributed unit may also carry the fourth control plane signaling sent by the receiving terminal through the first signaling;
[0132] The fourth control plane signaling is securely protected by the first key; the fourth control plane signaling includes any of the following:
[0133] RRC configuration complete message, RRC reconfiguration complete message, and security activation complete message.
[0134] In some embodiments, the fourth control plane signaling is used to notify the first signaling bearer that the configuration is complete.
[0135] In some embodiments, after determining that the key of the centralized unit has been updated, the first distributed unit may also update the key of the first distributed unit connected to the centralized unit and rebuild the signaling bearer corresponding to the first distributed unit.
[0136] For example, when the key of the 6G-CU is updated, the key of the 6G-DU connected to it must also be updated, and correspondingly, the SRB of the 6G-DU must be rebuilt.
[0137] In some embodiments, after determining that the key of the second distributed unit has been updated, the first distributed unit may also update the key of the first distributed unit that is connected to the same centralized unit as the second distributed unit, and rebuild the signaling bearer corresponding to the first distributed unit.
[0138] For example, when the key of a 6G-DU is updated: the keys of the 6G-CU corresponding to the 6G-DU and the other 6G-DUs under the 6G-CU are updated, and the SRBs of these 6G-CUs and 6G-DUs are rebuilt.
[0139] In some embodiments, after determining that the key of the second distributed unit has been updated, the first distributed unit may not update the key of the first distributed unit connected to the same centralized unit as the second distributed unit, and maintain the signaling bearer corresponding to the first distributed unit unchanged.
[0140] For example, when the key of a 6G-DU is updated: only the key of that 6G-DU is updated, the SRB under that 6G-DU is rebuilt, and the SRBs of other 6G-DUs and 6G-CUs remain unchanged.
[0141] It should be noted that, in the key update process of this application embodiment, the method of obtaining the new key can be the same as the method of determining the key of the first distributed unit and the key of the centralized unit as described above.
[0142] For example, Figure 8 A flowchart illustrating a control plane signaling security protection method. Figure 2 This method is applied to a terminal and includes:
[0143] 801. The terminal determines the key of the first distributed unit.
[0144] 802. The terminal determines the first key based on the key of the first distributed unit.
[0145] The first key is used to securely protect control plane signaling.
[0146] It should be noted that, for the terminal, the method of determining the key of the first distributed unit is similar to the method of determining the key of the first distributed unit in the above embodiment.
[0147] When the first distributed unit determines its key using the above method (1), if the key of the first distributed unit is the same as the key of the centralized unit, the terminal can use the same key for the first distributed unit and the centralized unit.
[0148] When the first distributed unit uses the above method (2) to determine the key of the first distributed unit, the terminal can use the same method as the first distributed unit to derive and determine the key of the first distributed unit, and obtain the corresponding KRRCenc and / or KRRCint.
[0149] When the first distributed unit determines the key of the first distributed unit using the above method (3) or (4), the UE can derive the key of the first distributed unit using the same method as the centralized unit in deriving the key of the first distributed unit.
[0150] In some embodiments, the terminal may receive the first control plane signaling after security protection sent by the first distributed unit through the first signaling bearer, or send the control plane signaling after security protection to the first distributed unit through the first signaling bearer.
[0151] Wherein, the first signaling bearer is a signaling bearer between the first distributed unit and the terminal, and the first key is used to provide security protection for the control plane signaling carried by the first signaling bearer.
[0152] In some embodiments, the terminal may also receive third control plane signaling sent by the first distributed unit, the third control plane signaling being used to configure the first signaling bearer;
[0153] The third control plane signaling is either protected by the first key or it is not protected.
[0154] In some embodiments, the terminal may also send a fourth control plane signaling to the first distributed unit through a first signaling bearer, the fourth control plane signaling being used to notify the first signaling bearer that the configuration is complete;
[0155] The fourth control plane signaling is securely protected by the first key; the fourth control plane signaling includes any of the following:
[0156] RRC configuration complete message, RRC reconfiguration complete message, and security activation complete message.
[0157] The terminal can perform wireless link failure detection, and can detect wireless link failures due to various reasons. The following are some examples of wireless link failure reasons:
[0158] Example 1: Control plane signaling transmission of 6G-CU fails, such as transmission failure detected based on RLC layer or timeout based on the timer corresponding to the control plane signaling. In this case, it is determined that the 6G-CU radio link has failed.
[0159] In some embodiments, when a terminal determines that the control plane signaling transmission of a centralized unit has failed, it can rebuild the signaling bearer corresponding to the centralized unit, and rebuild the signaling bearer corresponding to the first distributed unit and / or the second distributed unit connected to the centralized unit. The first distributed unit and the second distributed unit are different distributed units connected to the centralized unit.
[0160] For example, when the RRC signaling transmission of the 6G-CU fails or is lost, the UE can consider the radio link to have failed and initiate radio link reconstruction. Correspondingly, the UE releases the SRB and its configuration of the 6G-DU.
[0161] Example 2: Control plane signaling transmission of 6G-DU fails, such as transmission failure detected based on RLC layer or timeout based on the timer corresponding to the control plane signaling. In this case, it is determined that the 6G-DU radio link has failed.
[0162] Example 3: If the physical layer wireless link monitoring frequency band fails, it is determined that the 6G-DU wireless link corresponding to this wireless link has failed.
[0163] The examples of wireless link failures above represent some possible scenarios; other situations may also exist in actual cases.
[0164] In some embodiments, when the terminal determines that the control plane signaling transmission of the first distributed unit has failed, it can reconstruct the signaling bearer corresponding to the first distributed unit and send a wireless link failure notification to the centralized unit connected to the first distributed unit.
[0165] For example, when the RRC signaling transmission of a 6G-DU fails or is lost, the UE considers the radio link under that 6G-DU to have failed and can notify the network side of the 6G-DU radio link failure through the SRB associated with the 6G-CU.
[0166] In some embodiments, when the terminal determines that the control plane signaling transmission of the first distributed unit has failed, it may select another distributed unit to rebuild the signaling bearer; and send a radio link failure notification to the centralized unit connected to the first distributed unit.
[0167] In some embodiments, when the terminal determines that the control plane signaling transmission of the first distributed unit has failed, it can rebuild the signaling bearer corresponding to the first distributed unit and the signaling bearer corresponding to the centralized unit.
[0168] For example, when the RRC signaling transmission of a 6G-DU fails or is lost, and the UE considers the radio link to have failed, the UE can initiate a radio link re-establishment, releasing the SRBs and their configurations of the 6G-CU and other 6G-DUs (if any) connected to that 6G-DU. It can also initiate a connection reconstruction process, re-establishing the connection with the 6G-CU and 6G-DU, and establishing the SRBs.
[0169] For example, the network side can re-establish the connection and corresponding SRB for the terminal based on the radio link re-establishment request sent by the terminal; or, based on the 6G-DU radio link failure indication sent by the terminal, reconfigure the 6G-DU SRB for the UE and perform security configuration. Specifically, the network side can refer to 6G-DU and / or 6G-CU.
[0170] For example, Figure 9 A flowchart illustrating a control plane signaling security protection method. Figure 3This method is applied to centralized units and includes:
[0171] 901. The centralized unit generates the second control plane signaling through the centralized RRC layer located in the centralized unit.
[0172] 902. Centralized unit obtains second control plane signaling after security protection.
[0173] The second control plane signaling after security protection is obtained by protecting the second control plane signaling based on the second key; the second key is determined based on the key of the centralized unit.
[0174] In some embodiments, the second key includes one of the following: a key for encrypting control plane signaling, or a key for protecting the integrity of control plane signaling.
[0175] In some embodiments, security protection includes one of the following: encrypting control plane signaling based on an encryption key of control plane signaling, or protecting the integrity of control plane signaling based on an integrity protection key of control plane signaling.
[0176] In the aforementioned control plane signaling security protection method, the centralized unit generates the second control plane signaling through the centralized RRC layer within the centralized unit and obtains the security-protected second control plane signaling; wherein, the second key is determined based on the key of the centralized unit. That is, the centralized unit can generate control plane signaling itself, and the control plane signaling can be securely protected based on the second key. This reduces the time required to generate control plane signaling and also achieves secure protection for the control plane signaling.
[0177] In some embodiments, the centralized unit obtaining the securely protected second control plane signaling includes: the centralized unit, based on a second key, performing security protection on the second control plane signaling through a PDCP entity located within the centralized unit, thereby obtaining the securely protected second control plane signaling. That is, the centralized unit includes a PDCP entity, and the centralized unit itself performs security protection through the PDCP entity within the centralized unit. As described above. Figure 5 (a) and Figure 6 As shown in (a) of the diagram.
[0178] In the above embodiments, the centralized unit can perform security protection on its own generated control plane signaling based on the second key, thereby reducing the time required for control plane signaling security protection and eliminating the need for interaction with the distributed unit. This reduces the complexity of implementation.
[0179] In some embodiments, the second control plane signaling after the aforementioned security protection is obtained by the PDCP entity in the first distributed unit performing security protection on the second control plane signaling. That is, there is no PDCP entity in the centralized unit, and the second control plane signaling is protected by the PDCP entity in the first distributed unit, as described above. Figure 5 (b) and Figure 6 As shown in (b) of the diagram.
[0180] In the above embodiments, for cases where there is no PDCP entity in the centralized unit, security protection can be achieved by using the PDCP entity in the first distributed unit, and security protection can also be achieved for the control plane signaling generated by the centralized unit.
[0181] In some embodiments, the centralized unit may send the key of the first distributed unit and / or key-related parameters to the first distributed unit. This allows the first distributed unit to determine its own key based on the received key and / or key-related parameters.
[0182] The key of the first distributed unit is determined based on the counter of the first distributed unit; the key-related parameters are used to determine the new key of the first distributed unit in the next step based on the existing key of the first distributed unit.
[0183] In some embodiments, key-related parameters include: next hop, and / or, next hop link counter.
[0184] In some embodiments, the centralized unit may also send a second control plane signaling with security protection to the terminal via a second signaling bearer.
[0185] The second signaling bearer is a signaling bearer between the centralized unit and the terminal, and the second key is used to provide security protection for the control plane signaling carried by the second signaling bearer; the second control plane signaling is used to establish the first signaling bearer, which is a signaling bearer between the first distributed unit and the terminal.
[0186] The aforementioned second control plane signaling can be any of the following messages: RRC configuration message, RRC reconfiguration message.
[0187] In some embodiments, the second control plane signaling includes configuration parameters related to the first distributed unit, and the configuration parameters include, but are not any of the following:
[0188] The key of the centralized unit is used to determine the key of the first distributed unit;
[0189] The key of the centralized unit and the parameters of the first distributed unit, wherein the parameters of the distributed unit are the counters of the first distributed unit;
[0190] The key of the first distributed unit;
[0191] Key-related parameters are used to determine a new key for the first distributed unit based on the existing key of the first distributed unit or the existing key of the centralized unit.
[0192] In this embodiment of the application, after the centralized unit sends the above configuration parameters to the terminal through the second signaling bearer, the terminal can determine the key of the first distributed unit by means of the configuration parameters.
[0193] In some embodiments, the centralized unit can also update its key and reconstruct the signaling bearer corresponding to the centralized unit.
[0194] In some embodiments, the centralized unit may also send the updated key of the centralized unit to a first distributed unit and / or a second distributed unit connected to the centralized unit, and the updated key of the centralized unit is used by the first distributed unit and / or the second distributed unit to update the key.
[0195] For example, Figure 10 A flowchart illustrating the establishment of an SRB and the corresponding security process for a 6G-DU. Figure 1 This process may include, but is not limited to, the following steps:
[0196] 1001. The UE and 6G-CU establish a control plane signaling bearer SRBx.
[0197] For example, the aforementioned SRBx can be SRB1.
[0198] 1002: 6G-CU and 6G-DU conduct SRBy establishment negotiation.
[0199] The aforementioned SRBy establishment negotiation process is used to determine the establishment of the control plane signaling bearer SRBy between the UE and the 6G-DU.
[0200] 1003 and 6G-CU send an RRC configuration message to the UE, which carries the SRBy configuration parameter.
[0201] The RRC configuration message is used to configure SRBy. This RRC configuration message carries SRBy configuration parameters, which can be security configuration information (SecurityConfig) used to determine the 6G-DU key, i.e., the key corresponding to this SRBy.
[0202] The aforementioned RRC configuration message can also be replaced by an RRC reconfiguration message or a security activation command, and can be the aforementioned third control plane signaling.
[0203] For 1004a and 6G-DU, the key corresponding to SRBy is determined based on the SRBy configuration parameters.
[0204] 1004b. The UE determines the key corresponding to SRBy based on the SRBy configuration parameters.
[0205] The 6G-DU and UE can use the key determination method of the first distributed unit in the above embodiments to determine K6G-DU, and then determine the key KRRCenc and / or KRRCint for the control plane signaling carried by SRBy.
[0206] In this embodiment of the disclosure, the execution order between step 1003 and steps 1004a and 1004b is not limited. That is, step 1003 can be executed first, followed by steps 1004a and 1004b; or steps 1004a and 1004b can be executed first, followed by step 1003; or steps 1003, 1004a, and 1004b can be executed simultaneously.
[0207] 1005. The UE sends an RRC configuration complete message to the 6G-DU.
[0208] The aforementioned RRC configuration completion message can be the aforementioned fourth control plane signaling.
[0209] The aforementioned RRC configuration completion message can be encrypted and / or protected for integrity using the 6G-DU keys KRRCenc and / or KRRCint.
[0210] 1006 and 6G-DU transmit control plane signaling with the UE via SRBy.
[0211] Once SRBy is established, the 6G-DU transmits control plane signaling to the UE via SRBy. All of this control plane signaling is protected by KRRCenc and / or KRRCint.
[0212] In the above embodiments, the 6G-DU SRB is established by sending an RRC configuration message to the UE through the 6G-CU. The configuration parameters can be carried in the RRC configuration message to determine the key of the 6G-DU and further determine KRRCenc and / or KRRCint to provide security protection for the control plane signaling transmitted on SRBy.
[0213] For example, Figure 11 A flowchart illustrating the establishment of an SRB and the corresponding security process for a 6G-DU. Figure 2 This process may include, but is not limited to, the following steps:
[0214] 1101. The UE and 6G-CU establish a control plane signaling bearer SRBx.
[0215] For step 1101 above, please refer to the following: Figure 10 The relevant description of 1001 shown will not be repeated here.
[0216] 1102. The UE initiates a connection establishment request to the 6G-DU.
[0217] In some embodiments, step 1002 is an optional step, that is, this step may not be performed.
[0218] In some embodiments, the execution order between steps 1101 and 1102 described above is not limited in this application.
[0219] 1103: 6G-CU and 6G-DU conduct SRBy establishment negotiation.
[0220] For step 1103 above, please refer to the following: Figure 10 The relevant description of 1002 shown in the figure will not be repeated here.
[0221] 1104: 6G-DU sends an RRC configuration message to the UE.
[0222] The RRC configuration message is used to configure SRBy. This RRC configuration message carries SRBy configuration parameters, which can be security configuration information (Security Config) used to determine the 6G-DU key, i.e., the key corresponding to this SRBy.
[0223] The aforementioned RRC configuration message can also be replaced by an RRC reconfiguration message or a security activation command, which can be the aforementioned third control plane signaling.
[0224] The 1105a and 6G-DU determine the key corresponding to SRBy based on the SRBy configuration parameters.
[0225] 1105b. The UE determines the key corresponding to SRBy based on the SRBy configuration parameters.
[0226] 1106: The UE sends an RRC configuration complete message to the 6G-DU.
[0227] 1107 and 6G-DU transmit control plane signaling with the UE via SRBy.
[0228] For the descriptions of steps 1105a, 1105b, 1106, and 1107 above, please refer to the descriptions above. Figure 10The relevant descriptions of steps 1004a and 1004b are not repeated here.
[0229] In the above embodiments, the 6G-DU establishes its SRB by sending an RRC configuration message to the UE. The configuration parameters can be carried in the RRC configuration message to determine the key of the 6G-DU and further determine KRRCenc and / or KRRCint to provide security protection for the control plane signaling transmitted on the SRBy.
[0230] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0231] Based on the same technical concept, this application also provides a communication device. This communication device can implement at least one corresponding function of the first distributed unit, centralized unit, and terminal in the foregoing embodiments.
[0232] For example, Figure 12 This is a schematic diagram of a communication device provided in one embodiment. The electronic device includes: a memory 1201, a transceiver 1202, and a processor 1203, wherein the memory 1201, the transceiver 1202, and the processor 1203 are connected via a bus interface.
[0233] The memory 1201 is used to store computer programs; the transceiver 1202 is used to send and receive data under the control of the processor 1203.
[0234] In the case where the communication device is the first distributed unit: the processor 1203 described above is used to read the computer program in the memory 1201 and perform the following operations:
[0235] The first control plane signaling is generated through the sub-RRC layer located in the first distributed unit;
[0236] The first control plane signaling is securely protected based on the first key.
[0237] The first key is determined based on the key of the first distributed unit.
[0238] In some embodiments, the method for determining the key of the first distributed unit includes:
[0239] Obtain the key for the centralized unit;
[0240] The key of the first distributed unit is determined based on the key of the centralized unit.
[0241] In some embodiments, the processor 1203 is specifically configured to read the computer program in the memory 1201 and perform the following operations:
[0242] The process of determining the key of the first distributed unit based on the key of the centralized unit includes:
[0243] The key of the first distributed unit is the same as the key of the centralized unit, and the centralized unit is connected to the first distributed unit;
[0244] or,
[0245] Calculate the key of the first distributed unit based on the key of the centralized unit and the parameters of the first distributed unit;
[0246] or,
[0247] Receive the key of the first distributed unit sent by the centralized unit;
[0248] or,
[0249] Receive key-related parameters sent by the centralized unit, and calculate the key of the first distributed unit based on the key-related parameters sent by the centralized unit and / or the parameters of the distributed unit.
[0250] Wherein, the distributed unit parameter is the counter of the first distributed unit, and the key-related parameter is used to determine the new key of the first distributed unit based on the existing key of the first distributed unit or the existing key of the centralized unit.
[0251] In some embodiments, the parameters of the first distributed unit include:
[0252] The absolute radio frequency code number (ARFCN) specified by the first distributed unit;
[0253] And / or,
[0254] The first distributed unit specifies the Transmit / Receive Point ID (TRP ID) or the Physical Cell ID (PCI).
[0255] In some embodiments, the key-related parameters include: next hop, and / or, next hop link counter.
[0256] In some embodiments, the first key includes one of the following: a key for encrypting control plane signaling, or a key for protecting the integrity of control plane signaling;
[0257] The security protection includes one of the following: encrypting the control plane signaling based on the encryption key of the control plane signaling, or protecting the integrity of the control plane signaling based on the integrity protection key of the control plane signaling.
[0258] In some embodiments, the step of providing security protection for the first control plane signaling based on the first key includes:
[0259] Based on the first key, the first control plane signaling is securely protected by the PDCP entity located in the first distributed unit.
[0260] In some embodiments, the PDCP entity located in the first distributed unit is also used to provide security protection for the second control plane signaling generated by the centralized RRC layer, which is located in the centralized unit.
[0261] In some embodiments, the processor 1203 is further configured to read a computer program from the memory 1201 and perform the following operations:
[0262] The first control plane signaling after security protection is sent to the terminal through the first signaling bearer, or the first control plane signaling after security protection is received from the terminal through the first signaling bearer.
[0263] Wherein, the first signaling bearer is the signaling bearer between the first distributed unit and the terminal, and the first key is used to provide security protection for the control plane signaling carried by the first signaling bearer.
[0264] In some embodiments, the processor 1203 is further configured to read a computer program from the memory 1201 and perform the following operations:
[0265] Send a third control plane signaling message to the terminal, the third control plane signaling message being used to configure the first signaling bearer;
[0266] Wherein, the third control plane signaling is protected by the first key, or the third control plane signaling is not protected by the first key;
[0267] The third control plane signaling includes any of the following:
[0268] RRC configuration messages, RRC reconfiguration messages, and security activation commands.
[0269] In some embodiments, the third control plane signaling includes configuration parameters related to the first distributed unit, the configuration parameters including at least one of the following:
[0270] The parameters of the first distributed unit;
[0271] Key-related parameters are used to determine a new key for the first distributed unit based on the existing key of the first distributed unit or the existing key of the centralized unit.
[0272] In some embodiments, the processor 1203 is further configured to read a computer program from the memory 1201 and perform the following operations:
[0273] The first signaling bearer receives the fourth control plane signaling sent by the terminal, and the fourth control plane signaling is used to notify the first signaling bearer that the configuration is complete.
[0274] The fourth control plane signaling is securely protected by the first key; the fourth control plane signaling includes any of the following:
[0275] RRC configuration complete message, RRC reconfiguration complete message, and security activation complete message.
[0276] In some embodiments, the processor 1203 is further configured to read a computer program from the memory 1201 and perform the following operations:
[0277] After determining the key update of the centralized unit, the key of the first distributed unit connected to the centralized unit is updated, and the signaling bearer corresponding to the first distributed unit is reconstructed.
[0278] or,
[0279] After determining the key update of the second distributed unit, update the key of the first distributed unit that is connected to the same centralized unit as the second distributed unit, and rebuild the signaling bearer corresponding to the first distributed unit.
[0280] or,
[0281] After determining that the key of the second distributed unit has been updated, the key of the first distributed unit connected to the same centralized unit as the second distributed unit is not updated, and the signaling bearer corresponding to the first distributed unit remains unchanged.
[0282] For cases where the communication device is a centralized unit: the processor 1203 described above is used to read the computer program in the memory 1201 and perform the following operations:
[0283] The second control plane signaling is generated through the centralized RRC layer located in the centralized unit;
[0284] The second control plane signaling after security protection is obtained, wherein the second control plane signaling after security protection is obtained by performing security protection on the second control plane signaling based on the second key;
[0285] The second key is determined based on the key of the centralized unit.
[0286] In some embodiments, the processor 1203 is specifically configured to read the computer program in the memory 1201 and perform the following operations:
[0287] The second control plane signaling after obtaining security protection includes:
[0288] Based on the second key, the second control plane signaling is securely protected by the PDCP entity located in the centralized unit, so as to obtain the securely protected second control plane signaling.
[0289] In some embodiments, the second control plane signaling after security protection is obtained by the PDCP entity in the first distributed unit performing security protection on the second control plane signaling.
[0290] In some embodiments, the processor 1203 is further configured to read a computer program from the memory 1201 and perform the following operations:
[0291] Send the key of the first distributed unit and / or key-related parameters to the first distributed unit;
[0292] The key of the first distributed unit is determined based on the counter of the first distributed unit; the key-related parameters are used to determine the new key of the first distributed unit in the next step based on the existing key of the first distributed unit.
[0293] In some embodiments, the key-related parameters include: next hop, and / or, next hop link counter.
[0294] In some embodiments, the second key includes one of the following: a key for encrypting control plane signaling, or a key for protecting the integrity of control plane signaling;
[0295] The security protection includes one of the following: encrypting the control plane signaling based on the encryption key of the control plane signaling, or protecting the integrity of the control plane signaling based on the integrity protection key of the control plane signaling.
[0296] In some embodiments, the processor 1203 is further configured to read a computer program from the memory 1201 and perform the following operations:
[0297] The second control plane signaling after security protection is sent to the terminal via the second signaling bearer;
[0298] Wherein, the second signaling bearer is the signaling bearer between the centralized unit and the terminal, and the second key is used to provide security protection for the control plane signaling carried by the second signaling bearer; the second control plane signaling is used to establish the first signaling bearer, and the first signaling bearer is the signaling bearer between the first distributed unit and the terminal;
[0299] The second control plane signaling includes:
[0300] RRC configuration message, RRC reconfiguration message.
[0301] In some embodiments, the second control plane signaling includes configuration parameters related to the first distributed unit, the configuration parameters including but not limited to any of the following:
[0302] The key of the centralized unit is used to determine the key of the first distributed unit;
[0303] The key of the centralized unit and the parameters of the first distributed unit, wherein the parameters of the distributed unit are the counters of the first distributed unit;
[0304] The key of the first distributed unit;
[0305] Key-related parameters are used to determine a new key for the first distributed unit based on the existing key of the first distributed unit or the existing key of the centralized unit.
[0306] In some embodiments, the processor 1203 is further configured to read a computer program from the memory 1201 and perform the following operations:
[0307] Update the key of the centralized unit and reconstruct the signaling bearer corresponding to the centralized unit;
[0308] The updated key of the centralized unit is sent to a first distributed unit and / or a second distributed unit connected to the centralized unit, and the updated key of the centralized unit is used by the first distributed unit and / or the second distributed unit to update the key.
[0309] In the case where the communication device is a terminal: the processor 1203 described above is used to read the computer program in the memory 1201 and perform the following operations:
[0310] Determine the key for the first distributed unit;
[0311] Based on the key of the first distributed unit, a first key is determined, which is used to provide security protection for control plane signaling.
[0312] In some embodiments, the method for determining the key of the first distributed unit includes:
[0313] Obtain the key for the centralized unit;
[0314] The key of the first distributed unit is determined based on the key of the centralized unit.
[0315] In some embodiments, the method for determining the key of the first distributed unit includes:
[0316] The key of the first distributed unit is the same as the key of the centralized unit, and the centralized unit is connected to the first distributed unit;
[0317] or,
[0318] The key of the first distributed unit is determined based on the key of the centralized unit and the parameters of the first distributed unit.
[0319] or,
[0320] Receive the key of the first distributed unit sent by the centralized unit;
[0321] or,
[0322] Receive key-related parameters sent by the centralized unit, and calculate the key of the first distributed unit based on the key-related parameters sent by the centralized unit and / or the parameters of the distributed unit.
[0323] Wherein, the distributed unit parameter is the counter of the first distributed unit, and the key-related parameter is used to determine the new key of the first distributed unit based on the existing key of the first distributed unit or the existing key of the centralized unit.
[0324] In some embodiments, the first key includes one of the following: a key for encrypting control plane signaling, or a key for protecting the integrity of control plane signaling;
[0325] The security protection includes one of the following: encrypting the control plane signaling based on the encryption key of the control plane signaling, or protecting the integrity of the control plane signaling based on the integrity protection key of the control plane signaling.
[0326] In some embodiments, the processor 1203 described above is further configured to read a computer program from the memory 1201 and perform the following operations:
[0327] The system receives the first control plane signaling after security protection sent by the first distributed unit through the first signaling bearer, or sends the control plane signaling after security protection to the first distributed unit through the first signaling bearer.
[0328] Wherein, the first signaling bearer is the signaling bearer between the first distributed unit and the terminal, and the first key is used to provide security protection for the control plane signaling carried by the first signaling bearer.
[0329] In some embodiments, the processor 1203 described above is further configured to read a computer program from the memory 1201 and perform the following operations:
[0330] Receive third control plane signaling sent by the first distributed unit, wherein the third control plane signaling is used to configure the first signaling bearer;
[0331] The third control plane signaling is either protected by the first key or it is not protected.
[0332] In some embodiments, the processor 1203 described above is further configured to read a computer program from the memory 1201 and perform the following operations:
[0333] The first signaling bearer sends a fourth control plane signaling message to the first distributed unit, and the fourth control plane signaling message is used to notify the first signaling bearer that the configuration is complete.
[0334] The fourth control plane signaling is securely protected by the first key; the fourth control plane signaling includes any of the following:
[0335] RRC configuration complete message, RRC reconfiguration complete message, and security activation complete message.
[0336] In some embodiments, the processor 1203 described above is further configured to read a computer program from the memory 1201 and perform the following operations:
[0337] When it is determined that the control plane signaling transmission of the centralized unit has failed, the signaling bearer corresponding to the centralized unit is rebuilt, and the signaling bearer corresponding to the first distributed unit and / or the second distributed unit connected to the centralized unit is rebuilt. The first distributed unit and the second distributed unit are different distributed units connected to the centralized unit.
[0338] or,
[0339] When it is determined that the control plane signaling transmission of the first distributed unit has failed, the signaling bearer corresponding to the first distributed unit is rebuilt; a radio link failure notification is sent to the centralized unit connected to the first distributed unit.
[0340] or,
[0341] When it is determined that the control plane signaling transmission of the first distributed unit has failed, another distributed unit is selected to rebuild the signaling bearer; a radio link failure notification is sent to the centralized unit connected to the first distributed unit;
[0342] or,
[0343] When it is determined that the control plane signaling transmission of the first distributed unit has failed, the signaling bearer corresponding to the first distributed unit and the signaling bearer corresponding to the centralized unit are rebuilt.
[0344] In one exemplary embodiment, such as Figure 13 As shown, a structural block diagram of a first distributed unit is provided, including:
[0345] Generation module 1301 is used to generate first control plane signaling through the sub-RRC layer located in the first distributed unit;
[0346] The security protection module 1302 is used to provide security protection for the first control plane signaling based on the first key;
[0347] The first key is determined based on the key of the first distributed unit.
[0348] The modules in the first distributed unit described above are exemplary. In practice, more or fewer modules may be included. The modules in the first distributed unit are used to implement the various processes of the first distributed unit in the method embodiment.
[0349] In one exemplary embodiment, such as Figure 14 As shown, a structural block diagram of a centralized unit is provided, including:
[0350] Generation module 1401 is used to generate second control plane signaling through the centralized RRC layer in the centralized unit;
[0351] The acquisition module 1402 is used to acquire the second control plane signaling after security protection, wherein the second control plane signaling after security protection is obtained by performing security protection on the second control plane signaling based on the second key;
[0352] The second key is determined based on the key of the centralized unit.
[0353] The modules in the above-described centralized unit are exemplary illustrations. In practice, more or fewer modules may be included. The modules in the above-described centralized unit are used to implement the various processes of the above-described centralized unit in the method embodiment.
[0354] In one exemplary embodiment, such as Figure 15 As shown, a structural block diagram of a centralized unit is provided, including:
[0355] The determination module 1501 is used to determine the key of the first distributed unit; based on the key of the first distributed unit, a first key is determined, and the first key is used to provide security protection for control plane signaling.
[0356] The modules in the terminal described above are illustrative examples. In practice, more or fewer modules may be included. The modules in the terminal described above are used to implement the various processes of the terminal in the method embodiment.
[0357] It should be noted that the module division in the embodiments of this application is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods. Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated modules described above can be implemented in hardware or as software functional modules.
[0358] If the integrated modules described above are implemented as software functional modules and sold or used as independent products, they can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application.
[0359] It should be noted that the apparatus provided in this embodiment of the invention can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.
[0360] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements all the method steps implemented in the above method embodiments.
[0361] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements all the method steps implemented in the above method embodiments.
[0362] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0363] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0364] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A method for control plane signaling security protection, the method comprising: The method is applied to a first distributed unit, and the method comprises: generating, by a sub-RRC layer in the first distributed unit, first control plane signaling; security protecting the first control plane signaling according to a first key; wherein the first key is determined based on a key of the first distributed unit.
2. The method of claim 1, wherein, The determination manner of the key of the first distributed unit comprises: obtaining a key of a centralized unit; determining the key of the first distributed unit based on the key of the centralized unit.
3. The method of claim 1, wherein, The determination manner of the key of the first distributed unit comprises: the key of the first distributed unit is the same as a key of a centralized unit, and the centralized unit is connected with the first distributed unit; or, calculating the key of the first distributed unit according to the key of the centralized unit and a parameter of the first distributed unit; or, receiving the key of the first distributed unit sent by the centralized unit; or, receiving a key-related parameter sent by the centralized unit, and calculating the key of the first distributed unit according to the key-related parameter sent by the centralized unit and / or a distributed unit parameter, wherein the distributed unit parameter is a counter of the first distributed unit, and the key-related parameter is used to determine a new key of the first distributed unit according to an existing key of the first distributed unit or an existing key of the centralized unit.
4. The method of claim 3, wherein, The parameter of the first distributed unit comprises: an absolute radio frequency channel number (ARFCN) specified by the first distributed unit; and / or, a transmission and reception point ID (TRP ID) specified by the first distributed unit, or a physical cell ID (PCI).
5. The method of claim 3, wherein, The key-related parameter comprises: a next hop, and / or, a next hop link counter.
6. The method of claim 1, wherein, The first key comprises one of: a key for encrypting control plane signaling, or a key for integrity protecting control plane signaling; The security protection comprises one of: encrypting control plane signaling based on an encryption key of the control plane signaling, or integrity protecting control plane signaling based on an integrity protection key of the control plane signaling.
7. The method of claim 1, wherein, The security protection according to the first key comprises: security protecting, by a PDCP entity in the first distributed unit, the first control plane signaling according to the first key.
8. The method of claim 1, wherein, The PDCP entity in the first distributed unit is further configured to security protect second control plane signaling generated by a centralized RRC layer, wherein the centralized RRC layer is in a centralized unit.
9. The method of claim 1, wherein, The method further comprises: sending, to a terminal, the security-protected first control plane signaling through a first signaling bearer, or receiving, from the terminal, security-protected control plane signaling through the first signaling bearer; wherein the first signaling bearer is a signaling bearer between the first distributed unit and the terminal, and the first key is used to security protect control plane signaling carried by the first signaling bearer.
10. The method of claim 9, wherein, The method further comprises: sending, to a terminal, third control plane signaling, wherein the third control plane signaling is used to configure the first signaling bearer. The third control plane signaling is protected by the first key, or the third control plane signaling is not protected. The third control plane signaling includes any one of the following: An RRC configuration message, an RRC reconfiguration message, and a security activation command.
11. The method of claim 10, wherein, The third control plane signaling includes configuration parameters related to the first distributed unit, and the configuration parameters include at least one of the following: Parameters of the first distributed unit; Key-related parameters used to determine a new key of the first distributed unit based on an existing key of the first distributed unit or an existing key of the centralized unit.
12. The method of claim 10, wherein, The method further includes: Receiving, by the first signaling bearer, fourth control plane signaling sent by the terminal, the fourth control plane signaling being used to notify the first signaling bearer of configuration completion; The fourth control plane signaling is protected by the first key; and the fourth control plane signaling includes any one of the following: An RRC configuration completion message, an RRC reconfiguration completion message, and a security activation completion message.
13. The method of claim 1, wherein, The method further includes: After determining key update of the centralized unit, updating keys of the first distributed unit connected to the centralized unit and reestablishing signaling bearers corresponding to the first distributed unit; Or, After determining key update of the second distributed unit, updating keys of the first distributed unit connected to the same centralized unit as the second distributed unit and reestablishing signaling bearers corresponding to the first distributed unit; Or, After determining key update of the second distributed unit, not updating keys of the first distributed unit connected to the same centralized unit as the second distributed unit, and maintaining signaling bearers corresponding to the first distributed unit unchanged.
14. A method for control plane signaling security protection, the method comprising: Applied to a centralized unit, the method includes: Generating, by a centralized RRC layer in the centralized unit, second control plane signaling; Obtaining the second control plane signaling after security protection, the second control plane signaling after security protection being obtained by security protection of the second control plane signaling based on a second key; The second key is determined based on a key of the centralized unit.
15. The method of claim 14, wherein, The obtaining of the second control plane signaling after security protection includes: Security protection, by a PDCP entity in the centralized unit, of the second control plane signaling based on the second key, to obtain the second control plane signaling after security protection.
16. The method of claim 14, wherein, The second control plane signaling after security protection is obtained by security protection, by a PDCP entity in a first distributed unit, of the second control plane signaling.
17. The method of claim 14, wherein, The method further includes: Sending, to the first distributed unit, a key of the first distributed unit and / or key-related parameters; The key of the first distributed unit is determined based on a counter of the first distributed unit; and the key-related parameters are used to determine a new key of the first distributed unit based on an existing key of the first distributed unit next time.
18. The method of claim 17, wherein, The key-related parameters include a next hop and / or a next hop link counter.
19. The method of claim 14, wherein, The second key comprises one of: a key for encrypting control plane signaling, or a key for integrity protection of control plane signaling. The security protection comprises one of: encryption of control plane signaling based on an encryption key of the control plane signaling, or integrity protection of control plane signaling based on an integrity protection key of the control plane signaling.
20. The method of claim 14, wherein, The method further comprises: sending the second control plane signaling after security protection to the terminal through a second signaling bearer; wherein the second signaling bearer is a signaling bearer between the centralized unit and the terminal, the second key is used for security protection of control plane signaling carried by the second signaling bearer, and the second control plane signaling is used for establishing a first signaling bearer, which is a signaling bearer between the first distributed unit and the terminal. The second control plane signaling comprises: an RRC configuration message or an RRC reconfiguration message.
21. The method of claim 20, wherein, The second control plane signaling comprises configuration parameters related to the first distributed unit, and the configuration parameters comprise any of the following: a key of the centralized unit, which is used to determine a key of the first distributed unit; a key of the centralized unit and a parameter of the first distributed unit, the parameter of the distributed unit being a counter of the first distributed unit; a key of the first distributed unit; key-related parameters, which are used to determine a new key of the first distributed unit based on an existing key of the first distributed unit or an existing key of the centralized unit.
22. The method of claim 14, wherein, The method further comprises: updating the key of the centralized unit and reestablishing a signaling bearer corresponding to the centralized unit; sending the updated key of the centralized unit to a first distributed unit connected to the centralized unit and / or a second distributed unit, the updated key of the centralized unit being used for updating the key of the first distributed unit and / or the second distributed unit.
23. A method for control plane signaling security protection, the method comprising: Applied to a terminal, the method comprises: determining a key of a first distributed unit; determining a first key based on the key of the first distributed unit, the first key being used for security protection of control plane signaling.
24. The method of claim 23, wherein, The determination of the key of the first distributed unit comprises: obtaining a key of a centralized unit; determining the key of the first distributed unit based on the key of the centralized unit.
25. The method of claim 24, wherein, The determination of the key of the first distributed unit comprises: the key of the first distributed unit is the same as the key of the centralized unit, and the centralized unit is connected to the first distributed unit; or, determining the key of the first distributed unit based on the key of the centralized unit and a parameter of the first distributed unit; or, receiving the key of the first distributed unit sent by the centralized unit; or, receiving key-related parameters sent by the centralized unit, and calculating the key of the first distributed unit based on the key-related parameters sent by the centralized unit and / or a parameter of the distributed unit, The distributed unit parameter is a counter of the first distributed unit, and the key-related parameter is used for determining a new key of the first distributed unit according to an existing key of the first distributed unit or an existing key of the centralized unit.
26. The method of claim 25, wherein, The first key includes one of a key used for encrypting control plane signaling or a key used for integrity protection of control plane signaling. The security protection includes one of encryption of control plane signaling based on an encryption key of the control plane signaling or integrity protection of control plane signaling based on an integrity protection key of the control plane signaling.
27. The method of claim 25, wherein, The method further includes: receiving, through a first signaling bearer, first control plane signaling that is sent by the first distributed unit and is subjected to security protection, or sending, through the first signaling bearer, control plane signaling that is sent to the first distributed unit and is subjected to security protection; The first signaling bearer is a signaling bearer between the first distributed unit and a terminal, and the first key is used for security protection of control plane signaling carried by the first signaling bearer.
28. The method of claim 27, wherein, The method further includes: receiving third control plane signaling that is sent by the first distributed unit and is used for configuring the first signaling bearer; The third control plane signaling is subjected to security protection by the first key, or the third control plane signaling is not subjected to security protection.
29. The method of claim 28, wherein, The method further includes: sending, through the first signaling bearer, fourth control plane signaling to the first distributed unit, the fourth control plane signaling being used for notifying completion of configuration of the first signaling bearer; The fourth control plane signaling is subjected to security protection by the first key; and the fourth control plane signaling includes one of the following: an RRC configuration completion message, an RRC reconfiguration completion message, or a security activation completion message.
30. The method of claim 23, wherein, The method further includes: when it is determined that control plane signaling transmission of the centralized unit fails, reestablishing a signaling bearer corresponding to the centralized unit, reestablishing a signaling bearer corresponding to the first distributed unit and / or a second distributed unit connected to the centralized unit, the first distributed unit and the second distributed unit being different distributed units connected to the centralized unit; or, when it is determined that control plane signaling transmission of the first distributed unit fails, reestablishing a signaling bearer corresponding to the first distributed unit and sending a radio link failure notification to a centralized unit connected to the first distributed unit; or, when it is determined that control plane signaling transmission of the first distributed unit fails, selecting another distributed unit to reestablish a signaling bearer and sending a radio link failure notification to a centralized unit connected to the first distributed unit; or, when it is determined that control plane signaling transmission of the first distributed unit fails, reestablishing a signaling bearer corresponding to the first distributed unit and a signaling bearer corresponding to the centralized unit.
31. A first distributed unit, comprising: include: a memory, a transceiver, and a processor: The memory is configured to store a computer program; the transceiver is configured to transceive data under control of the processor; and the processor is configured to read the computer program in the memory and perform the following operations: generating, by a sub-RRC layer in the first distributed unit, first control plane signaling; security protecting the first control plane signaling according to a first key; wherein the first key is determined based on a key of the first distributed unit.
32. The first distributed unit of claim 31, wherein, The determination manner of the key of the first distributed unit comprises: obtaining a key of a centralized unit; determining the key of the first distributed unit based on the key of the centralized unit.
33. The first distributed unit of claim 32, wherein, The processor is specifically configured to read the computer program in the memory and perform the following operations: The determination of the key of the first distributed unit based on the key of the centralized unit comprises: The key of the first distributed unit is the same as the key of the centralized unit, and the centralized unit is connected with the first distributed unit; or, calculating the key of the first distributed unit according to the key of the centralized unit and a parameter of the first distributed unit; or, receiving the key of the first distributed unit sent by the centralized unit; or, receiving a key-related parameter sent by the centralized unit, and calculating the key of the first distributed unit according to the key-related parameter sent by the centralized unit and / or a distributed unit parameter, wherein the distributed unit parameter is a counter of the first distributed unit, and the key-related parameter is used to determine a new key of the first distributed unit according to an existing key of the first distributed unit or an existing key of the centralized unit.
34. The first distributed unit of claim 33, wherein, The parameter of the first distributed unit comprises: an absolute radio frequency channel number (ARFCN) specified by the first distributed unit; and / or, a transmission and reception point ID (TRP ID) or a physical cell ID (PCI) specified by the first distributed unit.
35. The first distributed unit of claim 33, wherein, The key-related parameter comprises: a next hop and / or a next hop link counter.
36. The first distributed unit of claim 31, wherein, The first key comprises one of: a key for encrypting control plane signaling or a key for integrity protecting control plane signaling; The security protection comprises one of: encrypting control plane signaling based on an encryption key of the control plane signaling or integrity protecting control plane signaling based on an integrity protection key of the control plane signaling.
37. The first distributed unit of claim 31, wherein, The security protection according to the first key comprises: security protecting the first control plane signaling by a PDCP entity in the first distributed unit according to the first key.
38. The first distributed unit of claim 31, wherein, The PDCP entity in the first distributed unit is further configured to security protect second control plane signaling generated by a centralized RRC layer, wherein the centralized RRC layer is in a centralized unit.
39. The first distributed unit of claim 31, wherein, The processor is further configured to read the computer program in the memory and perform the following operations: sending the security-protected first control plane signaling to a terminal through a first signaling bearer or receiving the security-protected first control plane signaling sent by the terminal through the first signaling bearer; wherein the first signaling bearer is a signaling bearer between the first distributed unit and the terminal, and the first key is used to security protect control plane signaling carried by the first signaling bearer.
40. The first distributed unit of claim 39, wherein, The processor is further configured to read the computer program in the memory and perform the following operations: sending third control plane signaling to the terminal, the third control plane signaling being used for configuring the first signaling bearer; wherein the third control plane signaling is secured by the first key, or the third control plane signaling is not secured. The third control plane signaling includes any one of the following: an RRC configuration message, an RRC reconfiguration message, or a security activation command.
41. The first distributed unit of claim 40, wherein, The third control plane signaling includes configuration parameters related to the first distributed unit, and the configuration parameters include at least one of the following: parameters of the first distributed unit; key-related parameters used for determining a new key of the first distributed unit based on an existing key of the first distributed unit or an existing key of the centralized unit.
42. The first distributed unit of claim 40, wherein, The processor is further configured to read the computer program in the memory and perform the following operations: receiving fourth control plane signaling sent by the terminal through the first signaling bearer, the fourth control plane signaling being used for notifying that the configuration of the first signaling bearer is completed; wherein the fourth control plane signaling is secured by the first key; and the fourth control plane signaling includes any one of the following: an RRC configuration completion message, an RRC reconfiguration completion message, or a security activation completion message.
43. The first distributed unit of claim 31, wherein, The processor is further configured to read the computer program in the memory and perform the following operations: after determining that the key of the centralized unit is updated, updating the key of the first distributed unit connected to the centralized unit and reestablishing the signaling bearer corresponding to the first distributed unit; or, after determining that the key of the second distributed unit is updated, updating the key of the first distributed unit connected to the same centralized unit as the second distributed unit and reestablishing the signaling bearer corresponding to the first distributed unit; or, after determining that the key of the second distributed unit is updated, not updating the key of the first distributed unit connected to the same centralized unit as the second distributed unit, and maintaining the signaling bearer corresponding to the first distributed unit unchanged.
44. A central unit, comprising: comprising: a memory, a transceiver, and a processor: the memory is configured to store a computer program; the transceiver is configured to transceive data under the control of the processor; the processor is configured to read the computer program in the memory and perform the method of any one of claims 14 to 22.
45. A terminal, comprising: comprising: a memory, a transceiver, and a processor: the memory is configured to store a computer program; the transceiver is configured to transceive data under the control of the processor; the processor is configured to read the computer program in the memory and perform the method of any one of claims 23 to 30.
46. A first distributed unit, comprising: comprising: a generating module configured to generate first control plane signaling through a sub-RRC layer in the first distributed unit; a security protection module configured to secure the first control plane signaling according to a first key; wherein the first key is determined based on a key of the first distributed unit.
47. A central unit, comprising: comprising: generating, by a centralized RRC layer in the centralized unit, second control plane signaling; obtaining, by the obtaining module, the second control plane signaling after security protection, the second control plane signaling after security protection being obtained by security protection of the second control plane signaling based on a second key. The second key is determined based on a key of the centralized unit.
48. A terminal, characterized by comprising: determining, by the determining module, a key of a first distributed unit; determining, based on the key of the first distributed unit, a first key, the first key being used for security protection of control plane signaling.
49. A computer-readable storage medium, comprising: The computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the method in any one of claims 1 to 30.
50. A computer program product, characterised in that, The computer program product comprises a computer program, and the computer program is executed by the processor to implement the method in any one of claims 1 to 30.