Secret key updating method and device

CN121844599APending Publication Date: 2026-04-10GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
Filing Date
2023-11-13
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Traditional communication systems only support key updates once when switching user equipment, and cannot meet the key update requirements in continuous switching scenarios.

Method used

By receiving the first information indicating one or more first key information, the communication device can flexibly determine the key update method and support key update in a continuous switching scenario.

Benefits of technology

It realizes more flexible and efficient key updates during the continuous switching of user equipment, and enhances the security and business continuity of the communication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121844599A_ABST
    Figure CN121844599A_ABST
Patent Text Reader

Abstract

The invention relates to a key updating method and equipment. The method comprises: a first communication device receiving first information, the first information being used for indicating one or more pieces of first key information, the one or more pieces of first key information comprising information required for key update of the first communication device; and the first communication device determines a key updating mode based on the first information. According to the embodiment of the invention, based on one or more pieces of first key information, key updating can be carried out more flexibly.
Need to check novelty before this filing date? Find Prior Art

Description

Key updating method and device Technical Field

[0001] The present application relates to the field of communications, and more specifically, to a key updating method and device. Background Art

[0002] To further reduce handover latency and ensure service continuity, the 3rd Generation Partnership Project (3GPP) Release 18 (R18) supports a handover process based on Layer 1 / Layer 2 (L1 / L2) triggering, known as Layer 1 / Layer 2 triggered mobility (LTM). LTM enables UEs to continuously handover between configured candidate cells. Before the introduction of LTM, the traditional handover process only supported a single handover of the user equipment (UE), and key updates were also performed only once.

[0003] Summary of the Invention

[0004] The embodiments of the present application provide a key updating method and device, which can perform key updating more flexibly.

[0005] This embodiment of the present application provides a key update method, including:

[0006] A first communication device receives first information, where the first information is used to indicate one or more first key information, where the one or more first key information includes information required for key update of the first communication device;

[0007] The first communication device determines a key update method based on the first information.

[0008] This embodiment of the present application provides a key update method, including:

[0009] The second communication device sends first information, where the first information is used to indicate one or more first key information, where the one or more first key information includes information required for key update of the first communication device.

[0010] An embodiment of the present application provides a first communication device, including:

[0011] A receiving unit, configured to receive first information, where the first information is used to indicate one or more first key information, where the one or more first key information includes information required for key update of the first communication device;

[0012] The processing unit is configured to determine a key update method based on the first information.

[0013] An embodiment of the present application provides a second communication device, including:

[0014] The sending unit is configured to send first information, where the first information is used to indicate one or more first key information, and the one or more first key information includes information required for key update of the first communication device.

[0015] An embodiment of the present application provides a terminal device, comprising: a transceiver, a processor, and a memory. The memory is used to store a computer program, the transceiver is used to communicate with other devices, and the processor is used to call and execute the computer program stored in the memory, so that the terminal device performs the above-mentioned key update method.

[0016] An embodiment of the present application provides a network device, comprising: a transceiver, a processor, and a memory. The memory is used to store a computer program, the transceiver is used to communicate with other devices, and the processor is used to call and execute the computer program stored in the memory to enable the network device to perform the above-mentioned key update method.

[0017] In the embodiment of the present application, the communication device can perform key update more flexibly based on one or more received first key information. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] FIG1 is a schematic diagram of an application scenario according to an embodiment of the present application.

[0019] FIG2 is an example diagram of the specific process of LTM.

[0020] FIG3 is a schematic diagram of a security key derivation during a switching process;

[0021] FIG4 is another schematic diagram of security key derivation during the switching process;

[0022] FIG5 is a schematic flowchart of a key updating method according to an embodiment of the present application.

[0023] FIG6 is a schematic flowchart of a key updating method according to another embodiment of the present application.

[0024] FIG7 is a schematic flowchart of a key updating method according to an embodiment of the present application.

[0025] FIG8 is a schematic flowchart of a key updating method according to another embodiment of the present application.

[0026] FIG9 is a schematic flow chart of a key update including a new NCC.

[0027] 10 and 11 are schematic flow charts of key updates involving a new NCC.

[0028] FIG12 is a schematic block diagram of a first communication device according to an embodiment of the present application.

[0029] FIG13 is a schematic block diagram of a second communication device according to an embodiment of the present application.

[0030] FIG14 is a schematic block diagram of a second communication device according to another embodiment of the present application.

[0031] FIG15 is a schematic block diagram of a communication device according to an embodiment of the present application.

[0032] FIG16 is a schematic block diagram of a chip according to an embodiment of the present application.

[0033] FIG17 is a schematic block diagram of a communication system according to an embodiment of the present application. DETAILED DESCRIPTION

[0034] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0035] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: LTE system, LTE-A system, NR system, NR system evolution system, LTE-U system, NR-U system, NTN system, UMTS, WLAN, WiFi, 5G system or other communication systems.

[0036] Generally speaking, traditional communication systems support a limited number of connections and are easy to implement. However, with the development of communication technology, mobile communication systems will not only support traditional communications, but will also support, for example, D2D communication, M2M communication, MTC, V2V communication or V2X communication, and the embodiments of the present application can also be applied to these communication systems.

[0037] In one embodiment, the communication system in the embodiment of the present application can be applied to a carrier aggregation (CA) scenario, a dual connectivity (DC) scenario, and an independent (SA) networking scenario.

[0038] In one embodiment, the communication system in the embodiment of the present application can be applied to an unlicensed spectrum, wherein the unlicensed spectrum can also be considered as a shared spectrum; or, the communication system in the embodiment of the present application can also be applied to an authorized spectrum, wherein the authorized spectrum can also be considered as an unshared spectrum.

[0039] The embodiments of the present application describe various embodiments in conjunction with network devices and terminal devices, wherein the terminal device may also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device, etc.

[0040] The terminal device can be a station in a WLAN, a cellular phone, a cordless phone, a SIP phone, a WLL station, a PDA device, a handheld device with wireless communication capabilities, a computing device or other processing device connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal device in a next-generation communication system such as a NR network, or a terminal device in a future-evolved PLMN network, etc.

[0041] In an embodiment of the present application, the terminal device can be deployed on land, including indoors or outdoors, handheld, wearable or vehicle-mounted; it can also be deployed on the water surface (such as ships, etc.); it can also be deployed in the air (such as airplanes, balloons and satellites, etc.).

[0042] In the embodiments of the present application, the terminal device may be a mobile phone, a tablet computer, a computer with wireless transceiver functions, a VR terminal device, an AR terminal device, or a wireless terminal device used in industrial control, unmanned driving, telemedicine, smart grid, transportation safety, smart city, or smart home. As an example and not a limitation, in the embodiments of the present application, the terminal device may also be a wearable device. Wearable devices, also known as wearable smart devices, are a general term for wearable devices that are intelligently designed and developed using wearable technology for everyday wear, such as glasses, gloves, watches, clothing, and shoes.

[0043] In an embodiment of the present application, a network device may be a device for communicating with a mobile device. The network device may be an AP in a WLAN, an evolved base station (eNB or eNodeB) in LTE, or a relay station or access point, or a vehicle-mounted device, a wearable device, a network device (gNB) in an NR network, or a network device in a future evolved PLMN network or a network device in an NTN network. As an example and not a limitation, in an embodiment of the present application, the network device may have a mobile feature, for example, the network device may be a mobile device. Alternatively, the network device may be a satellite or balloon station. Alternatively, the network device may also be a base station located on land, water, or the like.

[0044] In an embodiment of the present application, the network device can provide services for a cell, and the terminal device communicates with the network device through the transmission resources used by the cell (for example, frequency domain resources, or spectrum resources). The cell can be a cell corresponding to the network device (for example, a base station). The cell can belong to a macro base station or a base station corresponding to a small cell. The small cells here may include: urban cells, micro cells, pico cells, femto cells, etc. These small cells have the characteristics of small coverage and low transmission power, and are suitable for providing high-speed data transmission services.

[0045] FIG1 exemplarily shows a communication system 100. The communication system includes a network device 110 and two terminal devices 120. In one embodiment, the communication system 100 may include multiple network devices 110, and each network device 110 may include other number of terminal devices 120 within its coverage area, which is not limited in this embodiment of the present application. In one embodiment, the communication system 100 may also include other network entities such as a Mobility Management Entity (MME) and an Access and Mobility Management Function (AMF), which is not limited in this embodiment of the present application. Among them, the network device may include an access network device and a core network device. That is, the wireless communication system also includes multiple core networks for communicating with the access network device. The access network device may be an evolved base station (eNB), a macro base station, a micro base station (also called a "small base station"), a pico base station, an AP, a TP, or a new generation base station (gNB) in an LTE system, an NR system, or an LAA-LTE system.

[0046] To facilitate understanding of the technical solutions of the embodiments of the present application, the relevant technologies of the embodiments of the present application are described below. The following relevant technologies can be arbitrarily combined with the technical solutions of the embodiments of the present application as optional solutions, and they all fall within the protection scope of the embodiments of the present application.

[0047] 1. Long-Term Transaction (LTM)

[0048] An example of a specific LTM process is shown in Figure 2:

[0049] In simple terms, the execution steps of LTM can be divided into the following parts:

[0050] 1. LTM preparation stage:

[0051] The UE performs measurement reporting. For example, in step 1, the UE sends a measurement report to a base station, such as a gNB. The base station sends the configuration information of at least one candidate cell to the UE via a Radio Resource Control (RRC) reconfiguration message. For example, after the base station performs LTM candidate preparation, in step 2, the base station sends an RRC reconfiguration message (with LTM candidate configuration) to the UE. In step 3, the UE sends an RRC reconfiguration complete message to the base station.

[0052] 2. Early sync:

[0053] To reduce the latency of the random access (RA or RACH) process due to uplink synchronization, LTM supports early synchronization, which allows the UE to obtain the uplink timing advance (TA) of the target cell before accessing the target cell. For example, in step 4a, downlink synchronization with candidate cells is performed, and in step 4b, uplink synchronization with candidate cells is performed.

[0054] 3. LTM execution

[0055] After the LTM candidate cells are issued, the UE will continuously perform L1 measurements on the configured candidate cells to monitor their quality and report these measurements to the network. For example, in step 5, the UE sends an L1 measurement report to the gNB. The network also selects a target cell for the UE based on the measurement results reported by the UE. For example, after the base station makes an LTM decision, it may send a cell handover command (MAC CE) to the UE in step 6. In step 7, the UE and the base station may perform a random access procedure (RACH procedure).

[0056] 4. LTM completion (see step 8)

[0057] The UE switches to the target cell.

[0058] 2. Key Update During Switching

[0059] There are two types of security key derivation during the handover process, as shown in Figures 3 and 4:

[0060] Horizontal derivation (or horizontal key derivation): Based on the initial key such as K gNB / K eNB , the physical cell identifier (PCI) of the target cell and the downlink frequency to generate the target key such as K eNB* / K NG-RAN* .

[0061] Vertical derivation (or vertical key derivation): Generate the next hop key (NH) based on the next hop chaining count (NCC), and generate the target key such as K based on NH, the PCI of the target cell and the downlink frequency. eNB* / K NG-RAN* .

[0062] 1. The source base station can perform the following steps:

[0063] (1) First, generate the key K based on the target PCI and the target downlink frequency eNB* / K NG-RAN* ; If there is an unused {NH, NCC}, use NH to generate a key or as a key; if there is no unused {NH, NCC}, use the current key K gNB / K eNB .

[0064] (2) The generated K eNB* / K NG-RAN* Forward to the target base station; use K after switching eNB* / K NG-RAN* As K gNB / K eNB ; Carry the K in the switch command eNB* / K NG-RAN* of NCC.

[0065] For example, referring to Figure 4, the source S-gNB sends a handover request (HO requst) to the target side, which may include UE security capabilities, source side usage algorithm, KeNB*, NCC, etc.

[0066] 2. The target base station can perform the following steps:

[0067] The target base station will receive K eNB* / K NG-RAN* Will be K gNB / KeNB Communicate with UE; combine NCC received from source base station with K gNB / K eNB The NCC is included in the handover command and sent to the UE through the source base station; after the handover is completed, the target base station sends a path switch request to the MME.

[0068] As shown in Figure 4, the target-side T-gNB can use KeNB* as the new KeNB and associate it with the NCC. After the HO from the UE to the T-gNB is complete, the T-gNB can send a path switch request to the target AMT (T-AMT) or MME. The T-AMT can calculate the NH based on the NCC, for example, by adding 1 to the NCC to determine the corresponding NH. The T-AMT can return a path switch request ACK (which can carry {NCC, NH}) to the T-gNB. The T-gNB can save {NCC, NH} for the next handover. The T-gNB and the UE perform the intra-cell HO procedure.

[0069] 3. For UE, after receiving the handover command, it can synchronize NH according to the received NCC and calculate K eNB , and save it in association with the NCC. The specific example is as follows:

[0070] (1) If the NCC received by the UE in the handover command is the same as the current UE side K gNB / K eNB The associated NCC values ​​are equal, based on K gNB / K eNB And the target cell PCI and downlink frequency generate K eNB* / K NG-RAN* .

[0071] (2) If the NCC received by the UE in the handover command is the same as the current UE side K gNB / K eNB The associated NCC value is different. The next hop NH can be generated based on the saved NH, and the K can be generated based on the generated NH, the target cell PCI and the downlink frequency. eNB* / K NG-RAN* .

[0072] (3)UE will use the generated K eNB* / K NG-RAN* Will be K gNB / K eNB Communicate with the target base station.

[0073] The relevant LTM switching only supports scenarios where the key remains unchanged, that is, there is no need to perform key updates when the UE performs continuous switching. In order to further expand the scenarios supported by LTM, the nineteenth version (Release 19, R19) will continue to discuss inter-control unit (inter-CU) LTM, that is, scenarios where keys need to be updated. Before the introduction of LTM, the traditional switching process only supported UE switching once, and key updates were also performed only once. LTM supports continuous switching of UE between configured candidate cells. In order to support continuous switching, the embodiment of the present application provides a continuous key update solution.

[0074] FIG5 is a schematic flow chart of a key update method 500 according to an embodiment of the present application. The method may optionally be applied to the system shown in FIG1 , but is not limited thereto. The method includes at least part of the following contents.

[0075] S510. A first communication device receives first information, where the first information is used to indicate one or more first key information, and the one or more first key information includes information required for key update of the first communication device;

[0076] S520: The first communication device determines a key update method based on the first information.

[0077] In an embodiment of the present application, a first communication device may receive first information from a second communication device. The first communication device may be a terminal device such as a UE, and the second communication device may be a network device such as a base station, a control unit (CU) of a base station, or a data unit (DU) of a base station, etc. After receiving the first information, the first communication device may directly determine a key update method based on one or more first key information in the first information; or it may first store one or more first key information in the first information, and then determine a key update method based on other information and the stored one or more first key information. The first information may be underlying signaling such as MAC CE or carried by underlying signaling, or it may be high-level signaling such as RRC signaling or carried by high-level signaling.

[0078] For example, if the first information received by the terminal device from the network device is a MAC CE or is carried by a MAC CE, the key update method can be determined directly based on the one or more first key information in the MAC CE. If the first information received by the terminal device from the network device is an RRC signaling or is carried by an RRC signaling, the one or more first key information can be first stored on the terminal device, and then the key update method can be determined based on other information and the stored one or more first key information.

[0079] An example of an LTM switching process may include: the terminal device performs measurement reporting. The network device sends the configuration information of one or more LTM candidate cells to the terminal device through an RRC reconfiguration message. After the network device sends the LTM candidate cell, the terminal device can continue to perform L1 measurements on the configured candidate cell to monitor the quality of the candidate cell and report to the network device. The network device can select a target cell for the UE based on the measurement results reported by the UE. Then, the network device can send an LTM cell switching command to the terminal device through a MAC CE. The LTM cell switching command may carry one or more first key information. The first communication device of an embodiment of the present application can perform key updates more flexibly based on the received one or more first key information.

[0080] In one embodiment, the one or more first key information include information required by the first communications device to perform key updates in the case of continuous handover.

[0081] In some examples, in a continuous handover scenario, such as an LTM handover scenario, the second communications device may be a source network device, such as a source gNB, a CU of the source gNB (source gNB-CU), or a DU of the source gNB (source gNB-DU). The source cell corresponds to the CU and / or DU of the source gNB. The first information received by the terminal device from the source network device may be an LTM cell handover command. The LTM cell handover command may be carried by a MAC CE. After receiving the LTM cell handover command, the terminal device switches to the target cell. During the continuous handover process, the terminal device may continuously update the key of the target cell for each handover based on one or more first key information in the LTM cell handover command.

[0082] In one embodiment, the first key information includes at least one of the following: a key associated with the target communication device and / or the second communication device; an index of a key associated with the target communication device and / or the second communication device; an identifier of a control unit of the second communication device; an identifier of the target communication device; an identifier of a candidate cell; one or more security information; security algorithm information; whether a key needs to be updated; anti-tampering information; and encryption information.

[0083] In the embodiment of the present application, the target communication device may include a target network device such as a target base station, a CU of the target base station, a DU of the target base station, etc. The target cell corresponds to the CU and / or DU of the target base station. The candidate cell may belong to the source base station or the target base station.

[0084] For example, the key associated with the target communication device may include a target key and / or an initial key (also referred to as a mother key) associated with the target cell. The key associated with the second communication device may include a target key and / or an initial key associated with the source cell or source base station. For another example, the identifier of the control unit of the second communication device may include an identifier of the CU of the source base station. For another example, the identifier of the target communication device may include an identifier of the target cell.

[0085] In one embodiment, the security information includes the next hop link number (NCC) and the next hop information (NH) corresponding to the NCC. The NCC and NH may appear in pairs. The NCC may also be referred to as security sequence information.

[0086] In an embodiment of the present application, if the first communication device receives first key information including one or more security information, it can use the one or more security information to perform a key update and determine the target key associated with the target communication device.

[0087] In an embodiment of the present application, if the first key information received by the first communication device includes both the key associated with the target communication device and / or the second communication device and one or more security information, the key and the one or more security information can be associated. In this case, the key and the one or more security information can be used to perform a key update.

[0088] In one embodiment, the first information includes tamper-proof information and / or encryption information.

[0089] In one embodiment, the first information is integrity protected and / or encrypted.

[0090] In one embodiment, the first information is processed based on a medium access control (MAC) layer encryption algorithm and / or an integrity protection algorithm.

[0091] In one embodiment, the first information is first transmitted to the Packet Data Convergence Protocol (PDCP) layer via a MAC control element (CE) to perform at least one of encryption, integrity protection, decryption, and integrity verification, and then transmitted to the MAC layer.

[0092] In an embodiment of the present application, the security of the first information and / or the first key information therein can be improved through anti-tampering information, encrypted information, integrity protection processing, encryption processing, etc.

[0093] In one embodiment, the first information is also used to indicate at least one of the following: an identifier of a target communication device; an identifier of a candidate cell; transmission configuration indication TCI status information; timing advance TA information; and random access resources.

[0094] In an embodiment of the present application, the first information and / or the first key information may include an identifier of the target communication device, such as an identifier of the target cell, and may also include an identifier of a candidate cell. If the first information includes an identifier of the target cell, an identifier of the candidate cell, and the first key information, the identifier of the target cell and the identifier of the candidate cell may correspond to the first key information. In this case, the first key information may not include the identifier of the target cell and the identifier of the candidate cell, or may include the identifier of the target cell and the identifier of the candidate cell.

[0095] In the embodiments of the present application, the first key information may correspond to a target communication device and / or a candidate cell. For example, if a first key information includes an identifier of a target cell, the first key information may correspond to one target cell. If a first key information includes identifiers of multiple candidate cells, the first key information may correspond to multiple candidate cells.

[0096] In one embodiment, the one or more first key information is used to determine a target key, which is associated with the target communication device and / or the second communication device. For example, one first key information can be used to determine a target key for one target cell. Multiple first key information can be used to successively determine target keys for multiple target cells.

[0097] In one embodiment, the target key includes at least one of the following: NH, the second communication device key K gNB , control plane security protection key K RRCenc and user plane security protection key K UPenc For example, the first key information includes NCC, and the NH corresponding to the NCC can be used as the input for generating the target key. For another example, the second communication device key K gNB It can include the source base station key, the source base station's CU key, and the source base station's DU key. The control plane security protection key can be used for control plane signaling, data encryption and integrity protection. The user plane security protection key can be used for user plane signaling, data encryption and integrity protection. gNB , K RRCenc and K Upenc These key tags are only examples and are not limiting. In actual application scenarios, other tags can be used instead.

[0098] In one embodiment, the key update method includes at least one of the following:

[0099] In a case where the first information includes new security information and / or information indicating to perform vertical key derivation, performing vertical key derivation;

[0100] In a case where the first information does not include at least one of security information or information indicating execution of horizontal key derivation or the indicated security information is the same as security information currently used by the first communication device, horizontal key derivation is performed.

[0101] In an embodiment of the present application, if the first information is an LTM cell handover command. After receiving the LTM cell handover command, the first communications device may determine whether to perform vertical key derivation or horizontal key derivation based on the security information and / or indication information included in the LTM cell handover command. For example, if the LTM cell handover command includes new security information, such as the NCC in the LTM cell handover command is different from the NCC currently used by the first communications device, the first communications device may perform vertical key derivation. For another example, if the key derivation indication information included in the LTM cell handover command indicates the execution of vertical key derivation, the first communications device may perform vertical key derivation. For another example, if the LTM cell handover command does not include an NCC, the first communications device may perform horizontal key derivation. For another example, if the NCC included in the LTM cell handover command is the same as the NCC currently used by the first communications device, the first communications device may perform horizontal key derivation. For another example, if the key derivation indication information included in the LTM cell handover command indicates the execution of horizontal key derivation, the first communications device may perform horizontal key derivation.

[0102] In an embodiment of the present application, an example of vertical key derivation may include: first determining the NH based on the NCC in the security information, and then generating a target key based on the NH, the PCI of the target cell, and the downlink frequency. An example of horizontal key derivation may include: generating a target key based on the initial key, the PCI of the target cell, and the downlink frequency. The initial key may be the key currently in use by the communication device, and may also be referred to as the current key or the mother key.

[0103] In one embodiment, the key update method includes: performing horizontal key derivation or vertical key derivation by default after receiving the first information. In this embodiment of the present application, a default key update method can also be set after receiving the first information. Either horizontal key derivation or vertical key derivation can be performed by default.

[0104] In one embodiment, performing horizontal key derivation by default after receiving the first information includes: performing horizontal key derivation when determining to perform inter-control unit (inter-CU) layer 1 or layer 2 triggered mobility (LTM) after receiving the first information. In this embodiment of the present application, if inter-CU LTM is performed, handover between different base stations is possible. In this case, performing horizontal key derivation is applicable.

[0105] In one embodiment, if horizontal key derivation or vertical key derivation is performed by default, the method further includes: after the first communication device successfully accesses the target communication device, obtaining new security information for the next key update.

[0106] Figure 6 is a schematic flow chart of a key update method 600 according to another embodiment of the present application. The method 600 may include one or more features of the key update method described above. In one embodiment, the method further includes: S610, the first communication device stores the one or more first key information.

[0107] In an embodiment of the present application, if the one or more first key information received by the first communication device is network configuration information or carried by network configuration information, the one or more first key information can be first stored in the first communication device. The network configuration information can be high-layer signaling such as RRC signaling.

[0108] In one implementation, the first key information is stored in a terminal variable of the first communication device.

[0109] In one embodiment, the terminal variable is dedicated to storing the first key information, or the terminal variable is used to store the first key information and candidate cell configuration information. For example, the terminal variable is a UE variable. The first key information can be stored in a UE variable dedicated to storing key information, or the first key information and the candidate cell configuration information can be stored in the same UE variable.

[0110] In one embodiment, the first communication device stores the first key information, including one of the following:

[0111] After receiving the candidate cell configuration information, the first communication device stores the first key information corresponding to different candidate cells and / or the second communication device in the candidate cell configuration information into the terminal variable;

[0112] After obtaining or determining the target key, the first communication device stores the first key information corresponding to the target key in the terminal variable;

[0113] After the first communication device is successfully switched, the first key information corresponding to the target communication device and / or the second communication device is stored in the terminal variable;

[0114] The handover command received by the first communication device indicates first key information, and the first key information and / or its corresponding target key are stored in the terminal variable.

[0115] For example, a network device, such as a gNB, may preconfigure one or more first key information corresponding to different candidate cells and / or network devices to a terminal device, such as a UE. The terminal device may store one or more first key information in the received candidate cell configuration information in a UE variable. If the network device includes a serving cell or a source cell that determines a candidate cell based on the UE's measurement results and sends a handover request to the candidate cell, the candidate cell may send handover request feedback to the serving cell or the source cell. The serving cell or the source cell may forward the candidate cell configuration information to the UE. After receiving the candidate cell configuration information, the UE may store one or more first key information in the candidate cell configuration information.

[0116] For another example, if the terminal device generates a target key based on the first key information, the first key information can be stored in a UE variable. When the terminal device determines to execute LTM, it can first determine whether the target cell and / or base station has a stored target key. If so, it can use it directly. If not, the UE can generate and store the target key based on the received first key information.

[0117] For another example, if the terminal device executes LTM successfully, the first key information associated with the target cell and / or base station can be stored in the UE variable.

[0118] For another example, if the terminal device receives a switching command and the switching command indicates the first key information, the terminal device may store a key generated based on the first key information and store the generated key and / or the first key information.

[0119] In one embodiment, the key update method 600 further includes:

[0120] S620: The first communication device determines a target communication device;

[0121] S630: The first communication device performs a first action based on the target key associated with the target communication device. The first action includes at least one of the following: applying the target key; generating the target key.

[0122] For example, the terminal device determines a target cell, and applies the target key and / or generates the target key based on a target key associated with the target cell.

[0123] In one embodiment, the first information is network configuration information, and multiple security information in the first key information is carried by the network configuration information. The key update method includes: when the LTM process executed is inter-CU LTM, selecting the first unused security information in the order of the multiple security information to perform vertical key derivation.

[0124] In an embodiment of the present application, the network configuration information received in the first communication device may include one or more first key information. One first key information may include one or more security information. If the one or more security information include NCC1, NCC2 and NCC3, NCC2 and NCC3 are unused security information. In the case of inter-CU LTM, it is necessary to switch from Cell1 to Cell2 and then to Cell3. The first communication device can first select NCC2 to perform vertical key derivation during the process of switching from Cell1 to Cell2, and then select NCC3 to perform vertical key derivation during the process of switching from Cell2 to Cell3.

[0125] In one embodiment, the first information is an LTM cell switching command, and the key derivation indication information is carried by the LTM cell switching command, and the key derivation indication information is used to instruct the first communication device to perform horizontal key derivation or vertical key derivation. In an embodiment of the present application, the first communication device can receive the first information multiple times. For example, the first information received by the first communication device for the first time is network configuration information, and one or more first key information in the network configuration information can be saved. The first information received by the first communication device for the second time is an LTM cell switching command. If the key derivation indication information in the LTM cell switching command indicates the execution of horizontal key derivation, the first communication device can perform horizontal key derivation based on the saved one or more first key information. If the key derivation indication information in the LTM cell switching command indicates the execution of vertical key derivation, the first communication device can perform vertical key derivation based on the saved one or more first key information.

[0126] In one embodiment, the key update method includes: when the key derivation indication information indicates to perform vertical key derivation, selecting unused security information in the order of the multiple security information to perform vertical key derivation; or, determining new security information based on the used security information, and performing vertical key derivation based on the new security information.

[0127] For example, if the key derivation indication information in the LTM cell handover command indicates the execution of vertical key derivation, the first communications device may select unused security information according to the order of the stored multiple security information to perform vertical key derivation. For another example, if the key derivation indication information in the LTM cell handover command indicates the execution of vertical key derivation, the first communications device may generate new security information based on the used security information, for example, by adding 1 or 2 to the value of the currently used NCC, and then use the new NCC to perform vertical key derivation.

[0128] FIG7 is a schematic flow chart of a key update method 700 according to an embodiment of the present application. The method can optionally be applied to the system shown in FIG1 , but is not limited thereto. The method includes at least part of the following contents.

[0129] S710: The second communication device sends first information, where the first information is used to indicate one or more first key information, and the one or more first key information includes information required for key update of the first communication device.

[0130] In an embodiment of the present application, the second communication device may send the first information to the first communication device. The first communication device may be a terminal device such as a UE, and the second communication device may be a network device such as a base station, a control unit (CU) of the base station, or a data unit (DU) of the base station. After receiving the first information, the first communication device may directly determine the key update method based on one or more first key information in the first information; or it may first store one or more first key information in the first information, and then determine the key update method based on other information and the stored one or more first key information. The first information may be a MAC CE or carried by a MAC CE, and the first information may also be an RRC signaling or carried by an RRC signaling.

[0131] In one embodiment, the one or more first key information include information required by the first communications device to perform continuous key updates in the event of continuous handover.

[0132] In one embodiment, the first key information includes at least one of the following: a key associated with the target communication device and / or the second communication device; an index of a key associated with the target communication device and / or the second communication device; an identifier of the control unit of the second communication device; an identifier of the target communication device; one or more security information; security algorithm information; whether the key needs to be updated; anti-tampering information; and encryption information.

[0133] In one implementation, the security information includes the NCC and the NH corresponding to the NCC.

[0134] In one embodiment, the first information includes tamper-proof information and / or encryption information.

[0135] In one embodiment, the first information is integrity protected and / or encrypted.

[0136] In one embodiment, the first information is processed based on the MAC layer encryption algorithm and / or integrity protection algorithm; or, the first information is first transmitted to the PDCP layer via the MAC CE to perform at least one of encryption, integrity protection, decryption, and integrity verification, and then transmitted to the MAC layer.

[0137] In one embodiment, the first information is further used to indicate at least one of the following: an identifier of the target communication device; an identifier of a candidate cell; TCI status information; TA information; or a random access resource.

[0138] In one embodiment, the one or more first key information are used to determine a target key, where the target key is associated with the target communication device / the second communication device.

[0139] In one embodiment, the target key includes at least one of the following: NH, the second communication device key K gNB , control plane security protection key K RRCenc and user plane security protection key K UPenc .

[0140] For explanations and examples of the first key information, first information, target key, etc. in this embodiment, reference can be made to the relevant descriptions in the above embodiments.

[0141] In one embodiment, the method further includes: when the target communication device does not belong to the second communication device, the second communication device requests the target communication device whether to perform horizontal key derivation or vertical key derivation before sending the first information.

[0142] In an embodiment of the present application, the second communication device may determine the target communication device based on the measurement result reported by the first communication device. And subsequent processing may be performed according to the ownership of the target communication device. For example, if the CU to which the target cell belongs is different from the CU to which the source cell belongs, the target cell does not belong to the source base station. The source base station may first send a request message to the target cell to determine whether to perform horizontal key derivation or vertical key derivation. If the source base station sends a request message to the target cell and the target cell feeds back a response to perform vertical key derivation, the source base station confirms the execution of vertical key derivation. If the source base station sends a request message to the target cell and the target cell feeds back a response to perform horizontal key derivation, the source base station confirms the execution of horizontal key derivation.

[0143] In one embodiment, the second communication device sends the first information, including:

[0144] In a case where the second communication device has unused security information, the second communication device sends the first information to the first communication device, where the first information carries the unused security information.

[0145] In an embodiment of the present application, the second communication device can store one or more security information and use this security information in succession as needed for key updates. After determining the target communication device, the second communication device can determine whether it currently has unused security information. If the second communication device has unused security information, it can include one or more unused security information in the first message and send it to the first communication device. For example, the source base station carries the NCC in the handover command.

[0146] In one embodiment, the key update method further includes: the second communication device sends a request message to the target communication device, and the request message is used to instruct the target communication device to request new security information from the third communication device. In an embodiment of the present application, if the second communication device and / or the target communication device does not have unused security information, the second communication device and / or the target communication device may request new security information from a third communication device, such as AMF. After the second communication device and / or the target communication device receives the new security information issued by the AMF, it may delete the previously stored security information and subsequently use the new security information configured by the AMF. For example, the second communication device may send a request message to the target communication device. After the target communication device receives the request message, it may send security information request information to the third communication device, such as AMF. After receiving the security information request information, the third communication device may return its request for new security information to the target communication device. After the target communication device receives the new security information from the AMF or the second communication device, it may use the new security information to update the local target key.

[0147] In one embodiment, the key update method further includes: the second communication device sending new security information to the target communication device. In this embodiment of the present application, the second communication device may also send unused security information and / or new security information obtained from the AMF to the target communication device.

[0148] In one embodiment, the second communication device sends the first information, further comprising:

[0149] If the second communication device does not have any unused security information, the second communication device transmits the first information to the first communication device. If the first information includes used security information or does not include any security information, the second communication device instructs the target communication device to perform horizontal key derivation or instructs the target communication device to generate a target key for the target communication device. If the target communication device receives the instruction information for horizontal key derivation, it may generate the target key based on the initial key, the PCI, and the downlink frequency.

[0150] In one implementation, the first information is an LTM cell switching command.

[0151] In one embodiment, the LTM cell handover command includes key derivation indication information, and the key derivation indication information is used to instruct the first communication device to perform horizontal key derivation or vertical key derivation.

[0152] FIG8 is a schematic flowchart of a key update method 800 according to another embodiment of the present application. The method 800 may include one or more features of the aforementioned key update method. In one embodiment, the method further includes: S810: The second communications device stores multiple security information for inter-CU LTM.

[0153] In one embodiment, the method further includes: S820, when performing inter-CU LTM handover, the second communications device determines whether to perform horizontal key derivation or vertical key derivation. If the second communications device determines to perform horizontal key derivation, it may generate a target key based on the initial key, PCI, and downlink frequency, and then send the target key to the target communications device; or it may send an LTM cell handover command to the first communications device, instructing the first communications device to perform horizontal key derivation. If the second communications device determines to perform vertical key derivation, it may generate a target key based on the initial key, security information, PCI, and downlink frequency, and then send the target key to the target communications device; or it may send an LTM cell handover command to the first communications device, instructing the first communications device to perform vertical key derivation.

[0154] In one embodiment, the method further includes: S830: if there is unused security information, the second communication device decides to perform vertical key derivation. In this case, the second communication device may send an LTM cell handover command to the first communication device instructing the first communication device to perform vertical key derivation.

[0155] In one embodiment, the method further includes: S840, in the case of deciding to perform vertical key derivation, the second communication device sequentially selects unused security information in the security information list to perform vertical key derivation, and delivers the generated target key and the unused security information to the target communication device. For example, in the case of deciding to perform vertical key derivation, after the second communication device selects unused security information from the security information list, it can generate a target key based on the initial key, the selected security information, the PCI, and the downlink frequency. Then, the second communication device can deliver the generated target key and the unused security information in the security information list to the target communication device. The second communication device can also send an LTM cell switching command to the first communication device, and the LTM cell switching command can indicate the information for performing vertical key derivation and the unused security information selected from the security information list. In one embodiment, the security information includes NCC and NH.

[0156] In one implementation, the first information is carried by candidate cell configuration information sent by the second communication device to the first communication device.

[0157] In one embodiment, the method further includes: the second communication device determining a candidate cell based on the measurement result reported by the first communication device; the second communication device initiating a handover request to the candidate cell; and the second communication device receiving handover request feedback from the candidate cell.

[0158] For specific examples of the second communication device executing methods 700 and 800 in this embodiment, reference may be made to the relevant descriptions of the second communication device in the above methods 500 and 600 , which will not be repeated here for the sake of brevity.

[0159] An embodiment of the present application proposes a method for key update during a switching process, so that the UE can support continuous key update during a continuous switching process. The key update method may include any of the following methods: key update based on underlying signaling key update; key update based on UE variable storage.

[0160] Example 1: Updating keys based on underlying signaling

[0161] The following is an example of the UE executing the LTM process:

[0162] 1. The UE performs measurement reporting, and the base station sends the configuration information of at least one candidate cell to the UE via an RRC reconfiguration message.

[0163] 2. After the LTM candidate cells are issued, the UE will continuously perform L1 measurements on the configured candidate cells to monitor the quality of the candidate cells and report them to the network. The network side will also select a target cell for the UE based on the measurement results reported by the UE.

[0164] 3. The UE receives an LTM cell switch command and executes a corresponding process based on the instructions therein. The content of the LTM cell switch command includes at least one of the following:

[0165] (1) Target cell (candidate cell) identification;

[0166] (2) Target cell key information, including at least one of the following: the key associated with the target cell / network device (e.g., gNB, gNB-CU, gNB-DU): K gNB : Index of the key associated with the target cell / network device; network device identifier, such as the gNB-CU identifier; security sequence information, such as NCC (nexthop chaining count) or counter information, which can be associated with the above keys; NH; security algorithm information, such as the index associated with the security algorithm selected by the network; whether key update is required (vertical key update); tamper-proof information; encryption information.

[0167] (3)TCI state information;

[0168] (4)TA(info);

[0169] Optionally, the LTM cell handover command may carry anti-tampering (integrity protection) or encryption information. Optionally, the LTM cell handover command message itself may be encrypted and / or integrity protected. For example, the LTM cell handover command may be processed based on a MAC layer encryption and integrity protection algorithm. Alternatively, the MAC CE carrying the LTM cell handover command may be first transmitted to the PDCP layer for at least one of encryption, integrity protection, decryption, and integrity verification before being transmitted to the MAC layer.

[0170] 4. The UE determines whether / how to update the key based on the content in the LTM cell handover command.

[0171] (1) If the LTM cell handover command indicates a new NCC or other information instructing the UE to perform vertical key derivation, the UE performs vertical key derivation. See Figures 10 and 11.

[0172] (2) Otherwise, if the LTM cell handover command does not carry an NCC, or carries information for executing UE-based horizontal key derivation, or the carried NCC is the same as the one currently used by the UE, the UE executes horizontal key derivation. See Figure 9.

[0173] From the network side, network devices can perform the following steps:

[0174] The source gNB determines the target cell based on the UE's measurement reports and whether there is an unused NCC. For example, the source gNB-DU determines the target cell based on the UE's measurement results. If the target cell belongs to a different control unit (CU) than the source gNB-CU, the source gNB-CU requests the target gNB-CU whether to perform horizontal or vertical key derivation before sending the LTM cell handover command.

[0175] If there is an unused NCC (vertically derived): The source eNB includes the NCC in the handover command and instructs the target cell to request a new NCC and NH from the AMF, or directly informs the target cell of the new NCC and NH. See Figures 10 and 11.

[0176] If there is no unused NCC (horizontal derivation): the source base station carries the old (used) NCC in the handover command, instructing the target cell to perform horizontal derivation or generate a new target key K NG-RAN * indicates the target cell. See Figure 9.

[0177] (3) Optionally, the UE can also perform horizontal key derivation by default after receiving the handover command. After the UE successfully accesses the target cell, the target cell obtains the new NCC and NH when the path switch request is made, which are used for the next key update. Optionally, after receiving the handover command, the UE determines to perform inter-CULTM and performs horizontal key derivation by default. See Figure 9.

[0178] Exemplarily, the interaction process between the UE and the target cell, AMF, etc. has the following several modes.

[0179] In FIG9 , in the case where a new NCC is not included, the key update process may include the following steps:

[0180] Step 901: The UE performs measurement reporting to a source base station (or source cell).

[0181] Step 902: Handover (HO) preparation is performed between the source base station and the target base station (or target cell);

[0182] Step 903: The source base station sends RRC reconfiguration information including LTM candidate configuration to the UE.

[0183] Step 904: The UE performs L1 measurement.

[0184] Step 905: The source base station sends an LTM command (LTM command) that does not include an NCC (NCC is not included) to the UE;

[0185] Step 906: The source base station notifies the target cell Target_1 to update the key (inform target to update Key);

[0186] Step 907: The UE performs horizontal key derivation.

[0187] Step 908: The UE switches to the target cell Target_1 (switch to target cell).

[0188] Step 909: The target cell Target_1 sends a path switch request (PATH SWITCH REQUEST) to the AMF.

[0189] Step 910: The AMF returns a path switch request confirmation (PATH SWITCH REQUESTACKNOWLEDGE) to the target cell Target_1.

[0190] Step 911: The target cell Target_1 performs a key update with intra-cell HO.

[0191] In FIG10 , in the case where a new NCC is included, a key update process may include the following steps:

[0192] Step 1001: The UE performs measurement reporting to the source base station.

[0193] Step 1002: Handover preparation is performed between the source base station and the target cell;

[0194] Step 1003: The source base station sends RRC reconfiguration information including LTM candidate configuration to the UE.

[0195] Step 1004: The UE performs L1 measurement.

[0196] Step 1005: The source base station sends an LTM command including NCC / NH to the UE.

[0197] Step 1006: The source base station notifies the target cell Target_1 to update the key.

[0198] Step 1007: The UE performs vertical key derivation.

[0199] Step 1008: The target cell Target_1 sends a new NH and NCC request to the AMF.

[0200] Step 1009: The AMF returns the NH and NCC to the target cell Target_1.

[0201] Step 1010: The target cell Target_1 performs a key update.

[0202] Step 1011: The UE switches to the target cell Target_1 (switch to target cell);

[0203] Step 1012: The target cell Target_1 sends a path switching request to the AMF.

[0204] Step 1013: AMF returns a path switching request confirmation to the target cell Target_1.

[0205] In FIG11 , in the case of including a new NCC, another key update process may include the following steps:

[0206] Step 1101: The UE performs measurement reporting to the source base station.

[0207] Step 1102: Handover preparation is performed between the source base station and the target cell;

[0208] Step 1103: The source base station sends RRC reconfiguration information including LTM candidate configuration to the UE.

[0209] Step 1104: The UE performs L1 measurement.

[0210] Step 1105: The source base station sends an LTM command including NCC / NH to the UE;

[0211] Step 1106: The source base station notifies the target cell Target_1 to update the key.

[0212] Step 1107: The target cell Target_1 performs a key update.

[0213] Step 1108: The UE performs vertical key derivation.

[0214] Step 1109: The UE switches to the target cell Target_1.

[0215] Step 1110: The target cell Target_1 sends a path switching request to the AMF.

[0216] Step 1111: AMF returns a path switching request confirmation to the target cell Target_1.

[0217] Step 1112: The target cell Target_1 performs a key update when performing intra-cell HO.

[0218] Example 2: UE stores multiple keys

[0219] 1. The UE stores at least one first key information, which is used to determine a target key. The first key information includes at least one of the following: a key associated with the target cell (candidate cell) / gNB (which may be the target key); an index of the key associated with the target cell (candidate cell) / gNB; an identifier of the target cell (candidate cell) / gNB; full sequence information, such as NCC (next hop chaining count) or counter information, which may be associated with the key; NH; and a security algorithm.

[0220] Specifically, the storage method may be to store one or more first key information in a corresponding UE variable. For example, one or more first key information may be stored in a UE variable for storing key information, or one or more first key information and candidate cell configuration information may be stored in the same UE variable.

[0221] The target key is associated with the target cell / base station. Examples of target keys may include: NH, K gNB , K RRCenc and K UPenc .

[0222] The conditions for the UE to store the first key information include one of the following:

[0223] (1) The UE receives candidate cell configuration information. The network can pre-configure key information corresponding to different candidate cells / gNBs to the UE. The specific implementation is as follows: The serving cell (or source cell) performs handover preparation based on the UE's measurement report, including determining the candidate cell and initiating a handover request to the candidate cell. The source cell receives the handover request feedback sent by the candidate cell and forwards the candidate cell configuration information to the UE. The UE receives the candidate cell configuration information, which includes at least one first key information. Each first key information can be associated with a cell / base station. After receiving the candidate cell configuration information, the UE can execute the key information storage process.

[0224] (2) After obtaining / determining the first key information, the UE stores it in a UE variable. Specifically, the UE stores the first key information after generating the key. When the UE determines to execute LTM, it first determines whether the target cell or base station has a stored key. If so, it can be used directly. If not, the UE generates a key based on the first key information and stores it.

[0225] (3) Handover completion: After the UE successfully executes LTM, the first key information associated with the target cell / base station is stored in the UE variable.

[0226] (4) Receiving a handover command: The UE receives a handover command. If the handover command indicates the first key information, the UE stores the key or generates and stores the key based on the first key information.

[0227] 2. The UE determines a target cell and performs a first action based on a target key associated with the target cell. The first action includes at least one of the following: applying a key; generating a key.

[0228] 3. If the network configuration received by the UE includes multiple NCC values, after storing N NCCs, the process of performing key update is as follows:

[0229] Method 1: The UE determines whether the LTM process being executed is inter-CULTM. If so, it selects the first unused NCC in sequence to perform vertical derivation.

[0230] Method 2: The UE receives an LTM cell handover command and determines whether to perform horizontal or vertical derivation based on the indication information in the LTM cell handover command. For example, if the indication information is 0, horizontal derivation is performed, and if the indication information is 1, vertical derivation is performed. In other words, the UE sequentially selects an unused NCC from the NCC list to perform vertical derivation.

[0231] On the network side, the source base station or its control unit (e.g., source gNB-CU, or simply sourceCU) maintains multiple NCC values ​​for inter-CU LTM. When performing inter-CU LTM handover, the source CU decides whether to perform horizontal or vertical derivation, or, if there is an unused {NCC, NH} pair, perform vertical derivation.

[0232] If the sourceCU determines to perform vertical derivation, it sequentially selects unused {NCC, NH} pairs from the NCC list. It performs vertical derivation based on the NH and submits the generated new key and other unused {NCC, NH} pairs to the control unit of the target cell or target base station (e.g., target gNB-CU, or simply target CU).

[0233] In another implementation, the UE does not need to maintain multiple NCCs. Based on the indication in the LTM cell handover command, the UE determines whether to perform horizontal or vertical derivation. If vertical derivation is performed, the UE determines a new NCC value based on the current NCC value + 1 (or other value) and performs vertical derivation based on the NH corresponding to the new NCC.

[0234] FIG12 is a schematic block diagram of a first communication device 1200 according to an embodiment of the present application. The first communication device 1200 may include:

[0235] The receiving unit 1201 is configured to receive first information, where the first information is used to indicate one or more first key information, where the one or more first key information includes information required for key update of the first communication device;

[0236] The processing unit 1202 is configured to determine a key update method based on the first information.

[0237] In one embodiment, the one or more first key information include information required by the first communications device to perform key updates in the case of continuous handover.

[0238] In one embodiment, the key update method performed by the processing unit 1202 includes at least one of the following:

[0239] In a case where the first information includes new security information and / or information indicating to perform vertical key derivation, performing vertical key derivation;

[0240] In a case where the first information does not include at least one of security information or information indicating execution of horizontal key derivation or the indicated security information is the same as security information currently used by the first communication device, horizontal key derivation is performed.

[0241] In one embodiment, the key update method executed by the processing unit 1202 includes: performing horizontal key derivation or vertical key derivation by default after receiving the first information.

[0242] In one embodiment, the processing unit 1202 is further configured to obtain new security information for the next key update after successfully accessing the target communication device.

[0243] In one embodiment, the processing unit 1202 performs horizontal key derivation by default after receiving the first information, including: after receiving the first information, determining whether to execute inter-CU layer 1 or layer 2 triggering mobility LTM between control units, performing horizontal key derivation.

[0244] In one implementation, the first information is an LTM cell switching command.

[0245] In one implementation, the processing unit 1202 is further configured to store the one or more first key information.

[0246] In one embodiment, the processing unit 1202 stores the first key information, including one of the following:

[0247] After receiving the candidate cell configuration information, storing the first key information corresponding to different candidate cells and / or the second communication device in the candidate cell configuration information into the terminal variable;

[0248] After obtaining or determining the target key, storing the first key information corresponding to the target key in the terminal variable;

[0249] After the switching is successful, the first key information corresponding to the target communication device and / or the second communication device is stored in the terminal variable;

[0250] The received switching command indicates the first key information, and the first key information and / or its corresponding target key is stored in the terminal variable.

[0251] In one embodiment, the processing unit 1202 is further configured to: determine a target communication device; perform a first action based on a target key associated with the target communication device, the first action comprising at least one of: applying the target key; generating the target key.

[0252] In one embodiment, the first information is network configuration information, and multiple security information in the first key information is carried by the network configuration information. The key update method executed by the processing unit includes: when the LTM process executed is inter-CU LTM, the first unused security information is selected in the order of the multiple security information to perform vertical key derivation.

[0253] In one implementation, the first information is an LTM cell handover command, and the key derivation indication information is carried by the LTM cell handover command. The key derivation indication information is used to instruct the first communication device to perform horizontal key derivation or vertical key derivation.

[0254] In one embodiment, the key update method executed by the processing unit 1202 includes: when the key derivation indication information indicates to perform vertical key derivation, selecting unused security information in the order of the multiple security information to perform vertical key derivation; or, determining new security information based on the used security information, and performing vertical key derivation based on the new security information.

[0255] In one implementation, the first key information is stored in a terminal variable of the first communication device.

[0256] In one implementation, the terminal variable is dedicated to storing the first key information, or the terminal variable is used to store the first key information and candidate cell configuration information.

[0257] In one embodiment, the first key information includes at least one of the following: a key associated with the target communication device and / or the second communication device; an index of a key associated with the target communication device and / or the second communication device; an identifier of a control unit of the second communication device; an identifier of the target communication device; an identifier of a candidate cell; one or more security information; security algorithm information; whether a key needs to be updated; anti-tampering information; and encryption information.

[0258] In one implementation, the security information includes an NCC and next hop information NH corresponding to the NCC.

[0259] In one embodiment, the first information includes tamper-proof information and / or encryption information.

[0260] In one embodiment, the first information is integrity protected and / or encrypted.

[0261] In one embodiment, the first information is processed based on the MAC layer encryption algorithm and / or integrity protection algorithm; or, the first information is first transmitted to the PDCP layer via the MAC CE to perform at least one of encryption, integrity protection, decryption, and integrity verification, and then transmitted to the MAC layer.

[0262] In one embodiment, the first information is further used to indicate at least one of the following: an identifier of a target communication device; an identifier of a candidate cell; TCI status information; timing advance TA information; and random access resources.

[0263] In one embodiment, the one or more first key information are used to determine a target key, where the target key is associated with the target communication device and / or the second communication device.

[0264] In one embodiment, the target key includes at least one of the following: NH, the second communication equipment key KgNB, the control plane security protection key KRRCenc and the user plane security protection key KUPenc.

[0265] The first communication device 1200 of the embodiment of the present application can implement the corresponding functions of the terminal device in the aforementioned method embodiment. The processes, functions, implementation methods and beneficial effects corresponding to the various modules (sub-modules, units or components, etc.) in the first communication device 1200 can be found in the corresponding descriptions in the above-mentioned method embodiments, which will not be repeated here. It should be noted that the functions described in the various modules (sub-modules, units or components, etc.) in the first communication device 1200 of the application embodiment can be implemented by different modules (sub-modules, units or components, etc.) or by the same module (sub-module, unit or component, etc.).

[0266] FIG13 is a schematic block diagram of a second communication device 1300 according to an embodiment of the present application. The second communication device 1300 may include:

[0267] The sending unit 1301 is configured to send first information, where the first information is used to indicate one or more first key information, and the one or more first key information includes information required for key update of the first communication device.

[0268] In one embodiment, the one or more first key information include information required by the first communications device to perform key updates in the case of continuous handover.

[0269] FIG14 is a schematic block diagram of a second communication device 1400 according to another embodiment of the present application. The second communication device 1400 may include one or more features of the second communication device described above. In one embodiment, the second communication device further includes:

[0270] The processing unit 1401 is configured to request the target communication device whether to perform horizontal key derivation or vertical key derivation before sending the first information when the target communication device does not belong to the second communication device.

[0271] In one implementation, the sending unit 1301 is configured to send the first information to the first communication device when the second communication device has unused security information, where the first information carries the unused security information.

[0272] In one embodiment, the sending unit 1301 is further configured to send request information to the target communication device, where the request information is used to instruct the target communication device to request new security information from a third communication device; or to send new security information to the target communication device.

[0273] In one embodiment, the sending unit 1301 is also used to send the first information to the first communication device when there is no unused security information on the second communication device, and to instruct the target communication device to perform horizontal key derivation or to instruct the target communication device to generate a target key of the target communication device when the first information includes used security information or does not include security information.

[0274] In one implementation, the first information is an LTM cell switching command.

[0275] In one embodiment, the LTM cell handover command includes key derivation indication information, and the key derivation indication information is used to instruct the first communication device to perform horizontal key derivation or vertical key derivation.

[0276] In one embodiment, the processing unit 1401 is further configured to store multiple security information for inter-CU LTM.

[0277] In one embodiment, the processing unit 1401 is further configured to determine whether to perform horizontal key derivation or vertical key derivation when performing inter-CU LTM switching.

[0278] In one embodiment, the processing unit 1401 is further configured to determine to perform vertical key derivation when there is unused security information.

[0279] In one embodiment, the processing unit 1401 is also used to select unused security information in the security information list in order to perform vertical key derivation when deciding to perform vertical key derivation, and submit the generated target key and unused security information to the target communication device.

[0280] In one embodiment, the security information includes NCC and NH.

[0281] In one implementation, the first information is carried by candidate cell configuration information sent by the second communication device to the first communication device.

[0282] In one embodiment, the processing unit 1401 is further configured to determine a candidate cell based on the measurement result reported by the first communication device;

[0283] The sending unit 1301 is further configured to initiate a handover request to the candidate cell;

[0284] As shown in FIG14 , the second communication device further includes a receiving unit 1202 configured to receive a handover request feedback from the candidate cell.

[0285] In one embodiment, the first key information includes at least one of the following: a key associated with the target communication device and / or the second communication device; an index of a key associated with the target communication device and / or the second communication device; an identifier of the control unit of the second communication device; an identifier of the target communication device; one or more security information; security algorithm information; whether the key needs to be updated; anti-tampering information; and encryption information.

[0286] In one implementation, the security information includes the NCC and the NH corresponding to the NCC.

[0287] In one embodiment, the first information includes tamper-proof information and / or encryption information.

[0288] In one embodiment, the first information is integrity protected and / or encrypted.

[0289] In one embodiment, the first information is processed based on the MAC layer encryption algorithm and / or integrity protection algorithm; or, the first information is first transmitted to the PDCP layer via the MAC CE to perform at least one of encryption, integrity protection, decryption, and integrity verification, and then transmitted to the MAC layer.

[0290] In one embodiment, the first information is further used to indicate at least one of the following: an identifier of the target communication device; an identifier of a candidate cell; TCI status information; TA information; or a random access resource.

[0291] In one embodiment, the one or more first key information are used to determine a target key, where the target key is associated with the target communication device / the second communication device.

[0292] In one embodiment, the target key includes at least one of the following: NH, the second communication equipment key KgNB, the control plane security protection key KRRCenc and the user plane security protection key KUPenc.

[0293] The second communication devices 1300 and 1400 of the embodiments of the present application can implement the corresponding functions of the network devices in the aforementioned methods 700 and 800. The processes, functions, implementation methods and beneficial effects corresponding to the various modules (sub-modules, units or components, etc.) in the second communication devices 1300 and 1400 can be found in the corresponding descriptions in the above-mentioned method embodiments, which will not be repeated here. It should be noted that the functions described in the various modules (sub-modules, units or components, etc.) in the second communication devices 1300 and 1400 of the embodiment of the application can be implemented by different modules (sub-modules, units or components, etc.) or by the same module (sub-module, unit or component, etc.).

[0294] Figure 15 is a schematic structural diagram of a communication device 1500 according to an embodiment of the present application. The communication device 1500 includes a processor 1510, which can call and execute a computer program from a memory to enable the communication device 1500 to implement the method in the embodiment of the present application.

[0295] In one embodiment, the communication device 1500 may further include a memory 1520. The processor 1510 may call and execute a computer program from the memory 1520 to enable the communication device 1500 to implement the method in the embodiment of the present application.

[0296] The memory 1520 may be a separate device independent of the processor 1510 , or may be integrated into the processor 1510 .

[0297] In one embodiment, the communication device 1500 may further include a transceiver 1530 , and the processor 1510 may control the transceiver 1530 to communicate with other devices. Specifically, the transceiver 1530 may send information or data to other devices, or receive information or data sent by other devices.

[0298] The transceiver 1530 may include a transmitter and a receiver. The transceiver 1530 may further include an antenna, and the number of antennas may be one or more.

[0299] In one embodiment, the communication device 1500 may be the first communication device of the embodiment of the present application, and the communication device 1500 may implement the corresponding processes implemented by the first communication device in each method of the embodiment of the present application. For the sake of brevity, they will not be repeated here.

[0300] In one embodiment, the communication device 1500 may be the second communication device of the embodiment of the present application, and the communication device 1500 may implement the corresponding processes implemented by the second communication device in each method of the embodiment of the present application. For the sake of brevity, they will not be repeated here.

[0301] 16 is a schematic structural diagram of a chip 1600 according to an embodiment of the present application. The chip 1600 includes a processor 1610, which can call and execute a computer program from a memory to implement the method according to the embodiment of the present application.

[0302] In one embodiment, the chip 1600 may further include a memory 1620. The processor 1610 may call and execute a computer program from the memory 1620 to implement the method executed by the first communication device or the second communication device in the embodiment of the present application.

[0303] The memory 1620 may be a separate device independent of the processor 1610 , or may be integrated into the processor 1610 .

[0304] In one embodiment, the chip 1600 may further include an input interface 1630. The processor 1610 may control the input interface 1630 to communicate with other devices or chips, and specifically, may obtain information or data sent by other devices or chips.

[0305] In one embodiment, the chip 1600 may further include an output interface 1640. The processor 1610 may control the output interface 1640 to communicate with other devices or chips, and specifically, may output information or data to other devices or chips.

[0306] In one embodiment, the chip can be applied to the first communication device in the embodiment of the present application, and the chip can implement the corresponding processes implemented by the first communication device in each method of the embodiment of the present application. For the sake of brevity, it will not be repeated here.

[0307] In one embodiment, the chip can be applied to the second communication device in the embodiment of the present application, and the chip can implement the corresponding processes implemented by the second communication device in each method of the embodiment of the present application. For the sake of brevity, it will not be repeated here.

[0308] The chips used in the first communication device and the second communication device may be the same chip or different chips.

[0309] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0310] The processor mentioned above may be a general-purpose processor, DSP, FPGA, ASIC or other programmable logic device, transistor logic device, discrete hardware component, etc. The general-purpose processor mentioned above may be a microprocessor or any conventional processor, etc.

[0311] The memory mentioned above may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. The non-volatile memory may be a ROM, PROM, EPROM, EEPROM, or flash memory. The volatile memory may be a RAM.

[0312] It should be understood that the above-mentioned memories are exemplary and not restrictive. For example, the memories in the embodiments of the present application may also be SRAM, DRAM, SDRAM, DDR SDRAM, ESDRAM, SLDRAM, and DR RAM, etc. In other words, the memories in the embodiments of the present application are intended to include, but are not limited to, these and any other suitable types of memories.

[0313] FIG17 is a schematic block diagram of a communication system 1700 according to an embodiment of the present application. The communication system 1700 includes a first communication device 1710 and a second communication device 1720 .

[0314] The first communication device 1710 is configured to receive first information indicating one or more first key information, wherein the one or more first key information include information required for key update of the first communication device; and determine a key update method based on the first information.

[0315] The second communication device 1720 is configured to send the first information.

[0316] The first communication device 1710 can be used to implement the corresponding functions implemented by the first communication device in the above method, and the second communication device 1720 can be used to implement the corresponding functions implemented by the second communication device in the above method. For the sake of brevity, they are not described here in detail.

[0317] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function in accordance with the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).

[0318] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0319] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0320] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included within the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A key updating method, include: A first communication device receives first information, where the first information is used to indicate one or more first key information, and the one or more first key information includes information required for key update of the first communication device; The first communication device determines a key update method based on the first information.

2. The method according to claim 1, in, The one or more first key information include information required by the first communication device to perform key update in case of continuous handover.

3. The method according to claim 1 or 2, in, The key update method includes at least one of the following: In case the first information includes new security information and / or information indicating to perform vertical key derivation, performing vertical key derivation; In a case where the first information does not include at least one of security information or information indicating execution of horizontal key derivation or the indicated security information is the same as security information currently used by the first communication device, horizontal key derivation is performed.

4. The method according to claim 1 or 2, in, The key update method includes: performing horizontal key derivation or vertical key derivation by default after receiving the first information.

5. The method according to claim 4, in, The method further includes: after the first communication device successfully accesses the target communication device, acquiring new security information for the next key update.

6. The method according to claim 4 or 5, in, After receiving the first information, a horizontal key derivation is performed by default, including: After receiving the first information, when it is determined that inter-CU layer 1 or layer 2 triggered mobility LTM is executed between control units, horizontal key derivation is performed.

7. The method according to any one of claims 1 to 6, in, The first information is an LTM cell switching command.

8. The method according to any one of claims 1 to 7, in, The first key information includes at least one of the following: a key associated with the target communication device and / or the second communication device; an index of a key associated with the target communication device and / or the second communication device; an identifier of a control unit of the second communication device; an identifier of the target communication device; an identifier of a candidate cell; one or more security information; security algorithm information; whether a key needs to be updated; anti-tampering information; and encryption information.

9. The method according to any one of claims 1 to 8, in, The first information includes tamper-proof information and / or encryption information.

10. The method according to any one of claims 1 to 8, in, The first information is integrity protected and / or encrypted.

11. The method according to claim 10, in, The first information is processed based on the media access control MAC layer encryption algorithm and / or integrity protection algorithm; or, the first information is first transmitted to the packet data convergence protocol PDCP layer through the MAC control element CE to perform at least one of encryption, integrity protection, decryption, and integrity verification, and then transmitted to the MAC layer.

12. The method according to any one of claims 1 to 11, in, The one or more first key information are used to determine a target key, where the target key is associated with the target communication device and / or the second communication device.

13. The method according to claim 12, in, The target key includes at least one of the following: NH, a second communication device key K gNB , control plane security protection key K RRCenc and user plane security protection key K UPenc .

14. A key updating method, include: The second communication device sends first information, where the first information is used to indicate one or more first key information, and the one or more first key information includes information required for the first communication device to update the key.

15. The method according to claim 14, in, The one or more first key information include information required by the first communication device to perform key update in case of continuous handover.

16. The method according to claim 14 or 15, in, The method further includes: when the target communication device does not belong to the second communication device, the second communication device requests the target communication device whether to perform horizontal key derivation or vertical key derivation before sending the first information.

17. The method according to claim 14 or 15, in, The second communication device sends the first information, comprising: when the second communication device has unused security information, the second communication device sends the first information to the first communication device, wherein the first information carries the unused security information.

18. The method according to claim 17, in, The method further comprises: The second communication device sends request information to the target communication device, where the request information is used to instruct the target communication device to request new security information from the third communication device; or The second communication device sends new security information to the target communication device.

19. The method according to claim 14 or 15, in, The second communication device sends the first information, which also includes: when there is no unused security information on the second communication device, the second communication device sends the first information to the first communication device, and when the first information includes used security information or does not include security information, instructs the target communication device to perform horizontal key derivation or instructs the target communication device to generate a target key of the target communication device.

20. The method according to any one of claims 14 to 19, wherein the first information is a LTM cell switching command.

21. The method according to claim 20, in, The LTM cell switching command includes key derivation indication information, and the key derivation indication information is used to instruct the first communication device to perform horizontal key derivation or vertical key derivation.

22. The method according to claim 20, in, The method further includes: the second communication device storing a plurality of safety information for inter-CUL™.

23. The method according to claim 20, in, The method further comprises at least one of the following: In case of performing inter-CULTM handover, the second communication device decides to perform horizontal key derivation or vertical key derivation; In the presence of unused security information, the second communications device decides to perform a vertical key derivation.

24. The method according to claim 23, in, The method further includes: in case of deciding to perform vertical key derivation, the second communication device sequentially selects unused security information in the security information list to perform vertical key derivation, and delivers the generated target key and the unused security information to the target communication device.

25. The method according to any one of claims 14 to 24, in, The first key information includes at least one of the following: a key associated with the target communication device and / or the second communication device; an index of a key associated with the target communication device and / or the second communication device; an identifier of a control unit of the second communication device; an identifier of the target communication device; one or more security information; security algorithm information; whether a key needs to be updated; anti-tampering information; and encryption information.

26. The method according to any one of claims 14 to 25, in, The first information includes tamper-proof information and / or encryption information.

27. The method according to any one of claims 14 to 25, in, The first information is integrity protected and / or encrypted.

28. The method according to claim 27, in, The first information is processed based on the MAC layer encryption algorithm and / or integrity protection algorithm; or, the first information is first transmitted to the PDCP layer through the MAC CE to perform at least one of encryption, integrity protection, decryption, and integrity verification, and then transmitted to the MAC layer.

29. The method according to any one of claims 14 to 28, in, The one or more first key information are used to determine a target key, where the target key is associated with a target communication device / a second communication device.

30. The method according to claim 29, in, The target key includes at least one of the following: NH, a second communication device key K gNB , control plane security protection key K RRCenc and user plane security protection key K UPenc .

31. A first communication device, include: A receiving unit, configured to receive first information, wherein the first information is used to indicate one or more first key information, wherein the one or more first key information includes information required for key update of the first communication device; A processing unit is used to determine a key update method based on the first information.

32. The first communication device according to claim 31, in, The one or more first key information include information required by the first communication device to perform key update in case of continuous handover.

33. The first communication device according to claim 31 or 32, in, The key update method performed by the processing unit includes at least one of the following: In case the first information includes new security information and / or information indicating to perform vertical key derivation, performing vertical key derivation; In a case where the first information does not include at least one of security information or information indicating execution of horizontal key derivation or the indicated security information is the same as security information currently used by the first communication device, horizontal key derivation is performed.

34. The first communication device according to claim 31 or 32, in, The key updating method executed by the processing unit includes: executing horizontal key derivation or vertical key derivation by default after receiving the first information.

35. The first communication device according to claim 34, in, The processing unit is also used to obtain new security information for the next key update after successfully accessing the target communication device.

36. The first communication device according to claim 34 or 35, in, The processing unit performs horizontal key derivation by default after receiving the first information, including: after receiving the first information, it is determined that when inter-CU layer 1 or layer 2 between control units triggers mobility LTM, horizontal key derivation is performed.

37. A second communication device, include: The sending unit is used to send first information, where the first information is used to indicate one or more first key information, and the one or more first key information includes information required for key update of the first communication device.

38. The second communication device according to claim 37, in, The one or more first key information include information required by the first communication device to perform key update in case of continuous handover.

39. The second communication device according to claim 37 or 38, in, The second communication device further includes: The processing unit is configured to request the target communication device whether to perform horizontal key derivation or vertical key derivation before sending the first information when the target communication device does not belong to the second communication device.

40. The second communication device according to claim 37 or 38, in, The sending unit is used for: In the case that the second communication device has unused security information, the first information is sent to the first communication device, where the first information carries the unused security information.

41. The second communication device according to claim 40, in, The sending unit is further configured to send request information to the target communication device, wherein the request information is used to instruct the target communication device to request new security information from a third communication device; or to send new security information to the target communication device.

42. The second communication device according to claim 37 or 38, in, The sending unit is further used to send the first information to the first communication device when there is no unused security information on the second communication device, and to instruct the target communication device to perform horizontal key derivation or to instruct the target communication device to generate a target key of the target communication device when the first information includes used security information or does not include security information.

43. The second communication device according to any one of claims 37 to 42, wherein the first information is a LTM cell switching command.

44. The second communication device according to claim 43, in, The LTM cell switching command includes key derivation indication information, and the key derivation indication information is used to instruct the first communication device to perform horizontal key derivation or vertical key derivation.

45. The second communication device according to claim 43, in, The processing unit is further configured to store a plurality of security information for the inter-CU LTM.

46. ​​The second communication device according to claim 43, in, The processing unit is further configured to perform at least one of the following: when performing inter-CU LTM switching, deciding to perform horizontal key derivation or vertical key derivation; when there is unused security information, deciding to perform vertical key derivation.

47. The second communication device according to claim 46, in, The processing unit is also used to select unused security information in the security information list in order to perform vertical key derivation when deciding to perform vertical key derivation, and submit the generated target key and the unused security information to the target communication device.

48. A first communication device, include: A transceiver, a processor and a memory, wherein the memory is used to store a computer program, the transceiver is used to communicate with other devices, and the processor is used to call and run the computer program stored in the memory so that the first communication device executes the method as described in any one of claims 1 to 13.

49. A second communication device, include: A transceiver, a processor and a memory, wherein the memory is used to store a computer program, the transceiver is used to communicate with other devices, and the processor is used to call and run the computer program stored in the memory so that the second communication device executes the method as described in any one of claims 14 to 30.