Processing method, communication device and storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHENZHEN TRANSSION HLDG CO LTD
- Filing Date
- 2023-09-27
- Publication Date
- 2026-04-17
AI Technical Summary
In the LTM continuous switching scenario, the key exported by the terminal device may be inaccurate, resulting in KgNB incorrectly exported.
By passing security information between the terminal device and the network device, ensure that the terminal device can export the correct key based on the latest security information. The specific steps include the terminal device receiving security information and updating the pre-configured security information based on the information to derive the key.
In the LTM continuous switching scenario, ensure that the terminal device and network device can export the key correctly, and avoid KgNB incorrect export.
Smart Images

Figure CN121890125A_ABST
Abstract
Description
Processing method, communication device and storage medium Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a processing method, communication equipment and storage medium. Background Art
[0002] In existing protocols, a terminal device obtains the NCC (nextHopChainingCount) value from the nextHopChainingCount field of the MasterKeyUpdate information element in the RRC (Radio Resource Control) reconfiguration message sent by the target gNB (base station). However, in LTM (L1 / L2 triggered Mobility) handovers, this information may be pre-configured and sent to the terminal device in advance.
[0003] In the process of conceiving and implementing this application, the inventors found that there are at least the following problems: In the existing protocol, it is not clear how to configure the security information of the terminal device during LTM switching. In the case where the security information is sent to the terminal device in advance through pre-configuration, in the scenario of continuous LTM switching, the pre-configured NCC and / or keySetChangeIndicator (used to instruct the terminal device how to obtain the new K gNB ) may not be accurate, which may cause the terminal device to derive an incorrect K gNB .
[0004] The preceding description is intended to provide general background information and does not necessarily constitute prior art. Technical Solutions
[0005] The main purpose of this application is to provide a processing method, communication equipment and storage medium, aiming to ensure that the terminal device and / or network device can derive the correct key in the scenario of continuous LTM switching.
[0006] To achieve the above objectives, the present application provides a processing method that can be applied to a terminal device (such as a mobile phone), comprising the steps of:
[0007] S3: Derive the key based on the security information.
[0008] Optionally, the security information includes at least one of the following: a key update indication, a next hop value, a key update indication index, a next hop value index, and switching scenario information.
[0009] Optionally, the method further comprises the steps of:
[0010] S2: Receive security information.
[0011] Optionally, step S2 includes:
[0012] The security information is received through at least one of a handover command triggered by layer 1 / layer 2, a medium access control information element, and a radio connection control reconfiguration message.
[0013] Optionally, the method further includes:
[0014] The handover scenario is identified by information carried in the layer 1 / layer 2 triggered mobility medium access control information element or the layer 1 / layer 2 triggered mobility pre-configuration information.
[0015] Optionally, the switching scenario includes a continuous switching scenario within a centralized unit and / or a continuous switching scenario between centralized units.
[0016] Optionally, the information carried in the layer 1 / layer 2 triggered mobility media access control information element or the layer 1 / layer 2 triggered mobility pre-configuration information includes at least one of the following: a centralized unit identifier, a distributed unit identifier, a scene direct indication, a cell group indication, and a specific information element of the centralized unit.
[0017] Optionally, step S3 includes at least one of the following:
[0018] Derives keys from security information received via Layer 1 / Layer 2 triggered handover commands or Media Access Control cells;
[0019] Derives keys through pre-configured security information;
[0020] Derive the key by switching scene information.
[0021] Optionally, the method further comprises at least one of the following:
[0022] The security information received via Layer 1 / Layer 2 triggered handover command or Media Access Control cell takes precedence over the pre-configured security information;
[0023] updating pre-configured security information according to the received security information;
[0024] When exporting keys by switching scene information, the default export of keys is performed.
[0025] Optionally, the execution of the default derivation of the key includes at least one of the following:
[0026] If the switch is within a centralized unit, the current key will continue to be used;
[0027] If it is a centralized inter-unit handover, the key is derived using the current next-hop parameters.
[0028] The present application also provides a processing method, which can be applied to a network device (such as a base station), comprising the steps of:
[0029] S1, sending security information so that the terminal device can derive a key based on the security information.
[0030] Optionally, the security information includes at least one of the following:
[0031] Key update indication, next hop value, key update indication index, next hop value index, switching scenario information.
[0032] Optionally, the sending of security information includes:
[0033] The security information is sent through at least one of a handover command triggered by layer 1 / layer 2, a medium access control information element, and a radio connection control reconfiguration message.
[0034] Optionally, the method further includes: the terminal device identifying the switching scenario through information carried in a layer 1 / layer 2 triggered mobility media access control information element or a layer 1 / layer 2 triggered mobility pre-configuration information.
[0035] Optionally, the switching scenario includes a continuous switching scenario within a centralized unit and / or a continuous switching scenario between centralized units.
[0036] Optionally, the information carried in the layer 1 / layer 2 triggered mobility media access control information element or the layer 1 / layer 2 triggered mobility pre-configuration information includes at least one of the following: a centralized unit identifier, a distributed unit identifier, a scene direct indication, a cell group indication, and a specific information element of the centralized unit.
[0037] Optionally, the terminal device derives a key based on the security information, including at least one of the following:
[0038] The terminal device derives the key from the security information received through the handover command triggered by layer 1 / layer 2 or the media access control information element;
[0039] The terminal device derives the key through pre-configured security information;
[0040] The terminal device derives the key by switching scene information.
[0041] Optionally, the method further comprises at least one of the following:
[0042] The security information received via Layer 1 / Layer 2 triggered handover command or Media Access Control cell takes precedence over the pre-configured security information;
[0043] When the terminal device exports the key by switching scene information, the default export of the key is performed.
[0044] Optionally, the execution of the default derivation of the key includes at least one of the following:
[0045] If the switch is within a centralized unit, the terminal device continues to use the current key;
[0046] If it is a centralized inter-unit handover, the terminal device uses the current next-hop parameters to derive the key.
[0047] Optionally, the method further comprises at least one of the following:
[0048] Before handover, the pre-configured security information is updated by indicating the use of a media access control element or a radio connection control reconfiguration message carrying security information;
[0049] Derive the key based on the updated security information.
[0050] The present application also provides a processing device, comprising:
[0051] The export module is used to export the key based on the security information.
[0052] The present application also provides a processing device, comprising:
[0053] The sending module is used to send security information so that the terminal device can derive the key based on the security information.
[0054] The present application also provides a communication device, comprising: a memory, a processor, and a processing program stored in the memory and executable on the processor, wherein the processing program implements the steps of any of the above-described processing methods when executed by the processor.
[0055] The communication device in this application can be a terminal device (such as a mobile phone) or a network device (such as a base station). The specific reference needs to be clarified in the context.
[0056] The present application also provides a storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps of any of the above-described processing methods are implemented.
[0057] In the technical solution of the present application, the terminal device derives the key based on the security information, ensuring that in the scenario of continuous LTM switching, the terminal device and / or network device can derive the correct key. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] The accompanying drawings herein are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present application, and together with the specification, are used to explain the principles of the present application. In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for describing the embodiments. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without inventive work.
[0059] FIG1 is a schematic diagram of the hardware structure of a mobile terminal for implementing various embodiments of the present application;
[0060] FIG2 is a diagram of a communication network system architecture provided by an embodiment of the present application;
[0061] FIG3 is a schematic diagram of the hardware structure of a controller 140 provided in this application;
[0062] FIG4 is a schematic diagram of the hardware structure of a network node 150 provided in this application;
[0063] FIG5 is a schematic flow chart of a processing method according to the first embodiment of the present application;
[0064] FIG6 is another flow chart of the processing method according to the first embodiment of the present application;
[0065] FIG7 is a schematic diagram of a signaling flow diagram illustrating communication between a terminal device and a network device according to a second embodiment of the present application;
[0066] FIG8 is a schematic diagram of a signaling flow for communication between a terminal device and a network device according to a third embodiment of the present application;
[0067] FIG9 is a schematic diagram of a signaling flow for communication between a terminal device and a network device according to a fourth embodiment of the present application;
[0068] FIG10 is a schematic flow chart of a processing method according to a fifth embodiment of the present application;
[0069] FIG11 is another flow chart of a processing method according to the fifth embodiment of the present application;
[0070] FIG12 is a schematic diagram of a signaling flow for communication between a terminal device and a network device according to a fifth embodiment of the present application;
[0071] FIG13 is a flow chart of a processing method according to a sixth embodiment of the present application;
[0072] FIG14 is a schematic diagram of the interaction flow between a network device and a terminal device according to a processing method according to a seventh embodiment of the present application;
[0073] FIG15 is a first structural diagram of a processing device provided in an embodiment of the present application;
[0074] FIG16 is a second structural diagram of a processing device provided in an embodiment of the present application;
[0075] FIG17 is a schematic diagram of the structure of the communication device provided in an embodiment of the present application.
[0076] The purpose of this application, its features, and advantages will be further described in conjunction with the embodiments and with reference to the accompanying drawings. The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and the accompanying text are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of this application to those skilled in the art by reference to specific embodiments.
[0077] Implementation Methods of the Application
[0078] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0079] It should be noted that, in this document, the terms "comprises", "includes" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element, and / or, components, features, and elements with the same name in different embodiments of the present application may have the same meaning or different meanings, and their specific meanings need to be determined by their explanation in the specific embodiment or further combined with the context of the specific embodiment.
[0080] It should be understood that although the terms "first," "second," "third," etc. may be used herein to describe various information, such information should not be limited to these terms. These terms are used solely to distinguish information of the same type from one another. For example, without departing from the scope of this disclosure, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the term "if," as used herein, may be interpreted as "upon," "when," or "in response to a determination." Furthermore, as used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context indicates otherwise. It should be further understood that the terms "comprising" and "including" indicate the presence of the recited features, steps, operations, elements, components, items, types, and / or groups, but do not preclude the presence, occurrence, or addition of one or more other features, steps, operations, elements, components, items, types, and / or groups. The terms "or," "and / or," "including at least one of the following," etc., as used herein, may be interpreted as inclusive, meaning any one or any combination. For example, “comprising at least one of the following: A, B, C” means “any of the following: A; B; C; A and B; A and C; B and C; A and B and C”; and for another example, “A, B or C” or “A, B and / or C” means “any of the following: A; B; C; A and B; A and C; B and C; A and B and C”. An exception to this definition will occur only when a combination of elements, functions, steps or operations are inherently mutually exclusive in some manner.
[0081] It should be understood that, although the various steps in the flowchart in the embodiment of the present application are shown in sequence according to the indication of the arrows, these steps are not necessarily performed in sequence in the order indicated by the arrows. Unless clearly stated herein, the execution of these steps is not strictly limited in order, and they can be performed in other orders. Moreover, at least a portion of the steps in the figure may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily performed at the same time, but can be performed at different times, and their execution order is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of other steps or sub-steps or stages of other steps.
[0082] As used herein, the words "if" and "if" may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to the determination" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)," depending on the context.
[0083] It should be noted that in this article, step codes such as S1 and S2 are used for the purpose of expressing the corresponding content more clearly and concisely, and do not constitute a substantial restriction on the order. When implementing the step, those skilled in the art may execute S2 first and then S1, etc., but these should all be within the scope of protection of this application.
[0084] It should be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application.
[0085] In the subsequent description, the use of suffixes such as "module", "component" or "unit" to represent elements is only for the purpose of facilitating the description of the present application and has no specific meaning. Therefore, "module", "component" or "unit" can be used interchangeably.
[0086] The communication device in this application can be a terminal device (such as a mobile phone) or a network device (such as a base station). The specific reference needs to be clarified based on the context.
[0087] The terminal device may be implemented in various forms. For example, the terminal device described in this application may include intelligent terminal devices such as mobile phones, tablet computers, laptop computers, PDAs, portable media players (PMPs), navigation devices, wearable devices, smart bracelets, pedometers, and other fixed terminal devices such as digital TVs and desktop computers.
[0088] The subsequent description will be made using a mobile terminal as an example. Those skilled in the art will understand that, in addition to components specifically used for mobile purposes, the configuration according to the embodiments of the present application can also be applied to fixed-type terminal devices.
[0089] Please refer to Figure 1, which is a schematic diagram of the hardware structure of a mobile terminal for implementing various embodiments of the present application. The mobile terminal 100 may include components such as an RF (Radio Frequency) unit 101, a WiFi module 102, an audio output unit 103, an A / V (Audio / Video) input unit 104, a sensor 105, a display unit 106, a user input unit 107, an interface unit 108, a memory 109, a processor 110, and a power supply 111. Those skilled in the art will understand that the mobile terminal structure shown in Figure 1 does not limit the mobile terminal. The mobile terminal may include more or fewer components than shown, or may combine certain components, or arrange the components differently.
[0090] The following is a detailed introduction to the various components of the mobile terminal in conjunction with Figure 1:
[0091] The RF unit 101 can be used to send and receive information or receive signals during calls. Specifically, it receives downlink information from the base station and transmits it to the processor 110 for processing. It also transmits uplink data to the base station. Typically, the RF unit 101 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, and / or other components. Furthermore, the RF unit 101 can communicate with the network and other devices via wireless communication. The above-mentioned wireless communications can use any communication standard or protocol, including but not limited to GSM (Global System of Mobile communication), GPRS (General Packet Radio Service), CDMA2000 (Code Division Multiple Access 2000), WCDMA (Wideband Code Division Multiple Access), TD-SCDMA (Time Division-Synchronous Code Division Multiple Access), FDD-LTE (Frequency Division Duplexing-Long Term Evolution), TDD-LTE (Time Division Duplexing-Long Term Evolution), 5G and 6G, etc.
[0092] WiFi is a short-range wireless transmission technology. A mobile terminal, through WiFi module 102, enables users to send and receive emails, browse web pages, and access streaming media, providing wireless broadband Internet access. Although FIG1 illustrates WiFi module 102, it is understood that it is not a required component of the mobile terminal and can be omitted as needed without altering the essence of the invention.
[0093] The audio output unit 103 can convert audio data received by the RF unit 101 or the WiFi module 102 or stored in the memory 109 into an audio signal and output it as sound when the mobile terminal 100 is in a call signal reception mode, a talk mode, a recording mode, a voice recognition mode, a broadcast reception mode, or the like. Furthermore, the audio output unit 103 can also provide audio output related to a specific function performed by the mobile terminal 100 (e.g., a call signal reception sound, a message reception sound, etc.). The audio output unit 103 may include a speaker, a buzzer, or the like.
[0094] The A / V input unit 104 is used to receive audio or video signals. The A / V input unit 104 may include a graphics processing unit (GPU) 1041 and a microphone 1042. The GPU 1041 processes image data of still images or videos captured by an image capture device (e.g., a camera) in video capture mode or image capture mode. The processed image frames may be displayed on the display unit 106. The image frames processed by the GPU 1041 may be stored in the memory 109 (or other storage medium) or transmitted via the RF unit 101 or the WiFi module 102. The microphone 1042 may receive sound (audio data) in operating modes such as a phone call mode, a recording mode, and a voice recognition mode, and may process such sound into audio data. In the phone call mode, the processed audio (voice) data may be converted into a format that can be transmitted to a mobile communication base station via the RF unit 101. The microphone 1042 may implement various types of noise cancellation (or suppression) algorithms to eliminate (or suppress) noise or interference generated during the reception and transmission of audio signals.
[0095] The mobile terminal 100 also includes at least one sensor 105, such as a light sensor, a motion sensor, and other sensors. Optionally, the light sensor includes an ambient light sensor and a proximity sensor. Optionally, the ambient light sensor can adjust the brightness of the display panel 1061 according to the brightness of the ambient light, and the proximity sensor can turn off the display panel 1061 and / or the backlight when the mobile terminal 100 is moved to the ear. As a type of motion sensor, the accelerometer sensor can detect the magnitude of acceleration in all directions (generally three axes), and can detect the magnitude and direction of gravity when stationary. It can be used for applications that recognize the posture of the mobile phone (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc.; as for other sensors that can be configured in the mobile phone, such as fingerprint sensors, pressure sensors, iris sensors, molecular sensors, gyroscopes, barometers, hygrometers, thermometers, infrared sensors, etc., they will not be described here.
[0096] The display unit 106 is used to display information input by the user or information provided to the user. The display unit 106 may include a display panel 1061, which may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), or the like.
[0097] The user input unit 107 can be used to receive input digital or character information and generate key signal input related to user settings and function control of the mobile terminal. Optionally, the user input unit 107 may include a touch panel 1071 and other input devices 1072. The touch panel 1071, also known as a touch screen, can collect user touch operations on or near it (such as operations performed by the user using a finger, stylus, or any other suitable object or accessory on or near the touch panel 1071) and drive corresponding connected devices according to a pre-set program. The touch panel 1071 may include two parts: a touch detection device and a touch controller. Optionally, the touch detection device detects the user's touch direction and detects the signal generated by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device and converts it into touch point coordinates, which are then sent to the processor 110. It can also receive and execute commands sent by the processor 110. And / or, the touch panel 1071 can be implemented using various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch panel 1071, the user input unit 107 may further include other input devices 1072. Optionally, the other input devices 1072 may include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control keys, power keys, etc.), a trackball, a mouse, a joystick, etc., and the specifics are not limited here.
[0098] Optionally, the touch panel 1071 may overlay the display panel 1061. When the touch panel 1071 detects a touch operation on or near it, it transmits the information to the processor 110 to determine the type of touch event. The processor 110 then provides a corresponding visual output on the display panel 1061 based on the type of touch event. Although in FIG1 , the touch panel 1071 and the display panel 1061 are shown as two separate components to implement the input and output functions of the mobile terminal, in some embodiments, the touch panel 1071 and the display panel 1061 may be integrated to implement the input and output functions of the mobile terminal, which is not limited to this specific embodiment.
[0099] The interface unit 108 serves as an interface through which at least one external device can be connected to the mobile terminal 100. For example, the external device may include a wired or wireless headset port, an external power supply (or battery charger) port, a wired or wireless data port, a memory card port, a port for connecting a device with an identification module, an audio input / output (I / O) port, a video I / O port, a headphone port, etc. The interface unit 108 may be used to receive input (e.g., data information, power, etc.) from an external device and transmit the received input to one or more elements within the mobile terminal 100 or may be used to transmit data between the mobile terminal 100 and an external device.
[0100] Memory 109 can be used to store software programs and various data. Memory 109 may primarily include a program storage area and a data storage area. Optionally, the program storage area may store an operating system and at least one application required for a function (such as a sound playback function or an image playback function); the data storage area may store data generated based on the use of the mobile phone (such as audio data, a phone book, etc.). Furthermore, / or, memory 109 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0101] Processor 110 is the control center of the mobile terminal, connecting all components of the mobile terminal using various interfaces and circuits. By running or executing software programs and / or modules stored in memory 109 and accessing data stored in memory 109, it executes various functions of the mobile terminal and processes data, thereby providing overall monitoring of the mobile terminal. Processor 110 may include one or more processing units; preferably, processor 110 may integrate an application processor and a modem processor. Optionally, the application processor primarily handles the operating system, user interface, and application programs, while the modem processor primarily handles wireless communications. It is understood that the modem processor may not be integrated into processor 110.
[0102] The mobile terminal 100 may also include a power supply 111 (such as a battery) for supplying power to various components. Preferably, the power supply 111 may be logically connected to the processor 110 through a power management system, thereby managing functions such as charging, discharging, and power consumption through the power management system.
[0103] Although not shown in FIG. 1 , the mobile terminal 100 may further include a Bluetooth module, etc., which will not be described in detail here.
[0104] To facilitate understanding of the embodiments of the present application, the communication network system on which the mobile terminal of the present application is based is described below.
[0105] Please refer to Figure 2, which is a communication network system architecture diagram provided in an embodiment of the present application. The communication network system is an NR (New Radio) system of universal mobile communication technology. The NR system includes UE (User Equipment) 201, E-UTRAN (Evolved UMTS Terrestrial Radio Access Network) 202, EPC (Evolved Packet Core) 203 and the operator's IP service 204, which are connected in sequence.
[0106] Optionally, UE201 may be the above-mentioned terminal device 100, which will not be described in detail here.
[0107] E-UTRAN 202 includes eNodeB 2021 and other eNodeBs 2022 . Optionally, eNodeB 2021 may be connected to other eNodeBs 2022 via a backhaul (eg, an X2 interface). eNodeB 2021 is connected to EPC 203 , and eNodeB 2021 may provide access from UE 201 to EPC 203 .
[0108] EPC 203 may include an MME (Mobility Management Entity) 2031, an HSS (Home Subscriber Server) 2032, other MMEs 2033, an SGW (Serving Gate Way) 2034, a PGW (PDN Gate Way) 2035, and a PCRF (Policy and Charging Rules Function) 2036. Optionally, MME 2031 is a control node that processes signaling between UE 201 and EPC 203, providing bearer and connection management. HSS 2032 provides registers for managing functions such as the Home Location Register (not shown) and stores user-specific information such as service features and data rates. All user data can be sent through SGW2034, PGW2035 can provide IP address allocation and other functions for UE 201, PCRF2036 is the policy and charging control policy decision point for service data flow and IP bearer resources, and it selects and provides available policy and charging control decisions for the policy and charging execution function unit (not shown in the figure).
[0109] The IP service 204 may include the Internet, an intranet, an IMS (IP Multimedia Subsystem), or other IP services.
[0110] Although the above introduction takes the LTE system as an example, those skilled in the art should know that this application is not only applicable to the LTE system, but can also be applied to other wireless communication systems, such as GSM, CDMA2000, WCDMA, TD-SCDMA, 5G and future new network systems (such as 6G), etc., which are not limited here.
[0111] FIG3 is a schematic diagram of the hardware structure of a controller 140 provided in this application. The controller 140 includes a memory 1401 and a processor 1402. The memory 1401 is used to store program instructions, and the processor 1402 is used to call the program instructions in the memory 1401 to execute the steps performed by the controller in the first embodiment of the above method. The implementation principles and beneficial effects are similar and will not be repeated here.
[0112] Optionally, the controller further includes a communication interface 1403, which can be connected to the processor 1402 via a bus 1404. The processor 1402 can control the communication interface 1403 to implement the receiving and sending functions of the controller 140.
[0113] Figure 4 is a schematic diagram of the hardware structure of a network node 150 provided in this application. Network node 150 includes: a memory 1501 and a processor 1502. Memory 1501 is used to store program instructions, and processor 1502 is used to call the program instructions in memory 1501 to execute the steps performed by the first node in the first embodiment of the above method. The implementation principles and beneficial effects are similar and will not be repeated here.
[0114] Optionally, the controller further includes a communication interface 1503, which can be connected to the processor 1502 via a bus 1504. The processor 1502 can control the communication interface 1503 to implement the receiving and sending functions of the network node 150.
[0115] The integrated modules implemented in the form of software function modules can be stored in a computer-readable storage medium. The software function modules stored in a storage medium include a number of instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) or a processor to execute some of the steps of the methods of various embodiments of the present application.
[0116] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a storage medium or transmitted from one storage medium to another storage medium. For example, the computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state drive solid state disk, SSD), etc.
[0117] Based on the above-mentioned mobile terminal hardware structure and communication network system, various embodiments of the present application are proposed.
[0118] Technical terms involved in the embodiments of this application:
[0119] LTM: L1 / L2 triggered Mobility, layer 1 / layer 2 triggered mobility;
[0120] UE: User Equipment;
[0121] NCC: NextHopChainingCount, next hop value (key association parameter);
[0122] MAC CE: MAC Control Element, media access control element;
[0123] AMF: Access and Mobility Management Function, access and mobility management function;
[0124] NH: Next Hop parameter, next hop parameter (key-related parameter);
[0125] CU: Centralized Unit, centralized unit;
[0126] CU ID: centralized unit identification;
[0127] intra-CU: centralized intra-unit switching;
[0128] inter-CU: centralized inter-unit switching;
[0129] DU: Distributed Unit, distributed unit;
[0130] DU ID: Distributed unit identifier.
[0131] First embodiment
[0132] 5 , which is a flow chart of a processing method according to a first embodiment of the present application, the processing method according to the embodiment of the present application can be applied to a terminal device (such as a mobile phone), and includes the following steps:
[0133] S3: The terminal device derives the key based on the security information.
[0134] Optionally, the security information includes at least one of the following: a key update indication, a next hop value, a key update indication index, a next hop value index, and switching scenario information.
[0135] Optionally, the derived key may be derived by using a formula, or derived by directly reading or obtaining the key.
[0136] Optionally, the application scenario of the solution of this embodiment may include: a scenario of continuous LTM switching.
[0137] Optionally, in a scenario of continuous LTM switching, that is, during a switching process that is continuous or more than once, the LTM switching information preconfigured by the network device for the terminal device does not change.
[0138] This embodiment defines the configuration of security information so that the terminal device can receive correct security information and then derive the key based on the security information, ensuring that the terminal device can derive the correct key in the scenario of continuous LTM switching.
[0139] Optionally, the security information is provided by a network device.
[0140] Optionally, the network device includes: a source base station and a target base station.
[0141] Optionally, in the scenario of LTM continuous switching, the terminal device measures and reports information of the current serving cell and / or adjacent cell to the source base station. The source base station decides to configure the LTM cell based on the measurement information reported by the terminal device and sends a switching request to the candidate cell. Optionally, the switching request carries an indication of LTM switching, which includes but is not limited to security information such as the key and security algorithm used in the source cell.
[0142] Optionally, the candidate base station prepares the resources required for pre-configuring the candidate cell and sends them to the source cell through a handover request confirmation message; the source base station sends the pre-configuration information of the LTM candidate cell (i.e., some necessary information required for handover) to the terminal device through an RRC reconfiguration message. Optionally, the pre-configuration information may include delta configuration and / or reference configuration.
[0143] Optionally, some necessary information required for candidate cell switching includes but is not limited to scenario judgment information such as CU ID and DU ID.
[0144] Optionally, some necessary information required for candidate cell switching includes but is not limited to security keys, algorithm information, etc.
[0145] Optionally, the terminal device successfully receives the RRC reconfiguration message. Optionally, the RRC reconfiguration message includes pre-configuration information, and responds to successful reception through an RRC reconfiguration completion message.
[0146] Optionally, the terminal device performs measurement reporting on a pre-configured LTM candidate cell, and the source base station decides to perform LTM switching on a certain candidate cell based on the information measured and reported by the terminal device.
[0147] Optionally, the source base station carries security information through at least one transmission method including a handover command triggered by layer 1 / layer 2, a media access control element, and an RRC reconfiguration message, so that the terminal device derives a key based on the received security information.
[0148] Optionally, the source base station sends an LTM MAC CE to the terminal device. Optionally, the LTM MAC CE includes part of the handover information, a configuration index of the candidate cell, and optionally, security information that needs to be updated.
[0149] Optionally, the source base station sends security information that needs to be updated to the target base station.
[0150] Optionally, the terminal device performs handover to the target cell according to the LTM MAC CE and pre-configured information.
[0151] Optionally, the terminal device implements a security mechanism based on the received security information and derives a key.
[0152] Optionally, if the LTM MAC CE includes security information, the terminal device implements a security mechanism according to the security information in the MAC CE.
[0153] Optionally, as shown in FIG6 , before step S3, the method further includes the steps of:
[0154] S2: The terminal device receives security information.
[0155] The terminal device receives security information through at least one of a handover command triggered by layer 1 / layer 2, a media access control information element, and a radio connection control reconfiguration message.
[0156] Optionally, the handover command triggered by layer 1 / layer 2, the media access control information element, and the radio connection control reconfiguration message may be delivered by the network device through a system message, which is not specifically limited in this embodiment.
[0157] Optionally, the terminal device derives the key from security information received through a handover command triggered by layer 1 / layer 2 or a media access control element.
[0158] Optionally, the terminal device derives the key through pre-configured security information.
[0159] Optionally, the terminal device derives the key by switching scene information.
[0160] Optionally, the priority of the security information received by the terminal device through the handover command triggered by layer 1 / layer 2 or the media access control element is higher than the pre-configured security information.
[0161] Optionally, the terminal device identifies the switching scenario through information carried in a layer 1 / layer 2 triggered mobility media access control information element or a layer 1 / layer 2 triggered mobility pre-configuration information.
[0162] Optionally, the switching scenario includes a continuous switching scenario within a centralized unit and / or a continuous switching scenario between centralized units.
[0163] Optionally, the information carried in the layer 1 / layer 2 triggered mobility media access control information element or the layer 1 / layer 2 triggered mobility pre-configuration information includes at least one of the following: a centralized unit identifier, a distributed unit identifier, a scene direct indication, a cell group indication, and a specific information element of the centralized unit.
[0164] Optionally, the terminal device updates pre-configured security information according to the received security information.
[0165] Since the existing protocol has not defined how to configure the security information of the terminal device during LTM switching, when the security information is sent to the terminal device in a pre-configured manner, in the scenario of continuous LTM switching, the pre-configured NCC value may not be accurate and needs to be updated, otherwise it may cause the terminal device to export an incorrect KgNB, and / or in the scenario of continuous LTM switching, the value of keySetChangeIndicator may be inaccurate.
[0166] This embodiment uses the above solution to define the configuration of security information so that the terminal device can receive correct security information and derive the key based on the security information, ensuring that the terminal device and / or network device can derive the correct key in the scenario of continuous LTM switching.
[0167] Second embodiment
[0168] Based on the first embodiment of the present application, this embodiment further discloses the processing method in the aforementioned embodiment, mainly carrying security information through LTM MAC CE so that the terminal device can derive the key based on the security information.
[0169] Optionally, the security information is carried by LTM MAC CE and sent by the network device to the terminal device.
[0170] Optionally, the security information is directly carried by the LTM MAC CE or an index is carried by the LTM MAC CE.
[0171] Optionally, the security information includes at least one of the following: a key update indication, a next hop value, a key update indication index, and a next hop value index.
[0172] Optionally, the network device includes: a source base station and a target base station.
[0173] Optionally, the source base station sends the locally stored security information to the target base station before sending the LTM MAC CE, and carries the NCC value and keySetChangeIndicator value that need to be updated in the LTM MAC CE sent to the terminal device, which requires a total of 4 bits. After receiving the new NCC value, the terminal device will overwrite the NCC value configured in the pre-configuration information.
[0174] Optionally, the source base station sends the locally stored security information to the target base station before sending the LTM MAC CE, and carries the index of the NCC value and keySetChangeIndicator value that need to be updated in the LTM MAC CE sent to the terminal device. Optionally, the terminal device and the base station both configure the index list locally, and the terminal device will index the correct NCC value and keySetChangeIndicator value in the local list according to the received index value.
[0175] Optionally, as shown in FIG7 , the signaling process implemented by the terminal device communicating with the network device in this embodiment includes the following steps:
[0176] Step 1: The terminal device measures and reports information of the current serving cell and / or adjacent cell to the source base station;
[0177] Step 2: The source base station decides to configure an LTM cell based on the measurement information reported by the terminal device and sends a handover request to the candidate cell. Optionally, the handover request carries an LTM handover instruction, including but not limited to security information such as the key and security algorithm used in the source cell.
[0178] Step 3: The candidate base station prepares and pre-configures the resources required for the candidate cell and sends it to the source cell via a handover request confirmation message;
[0179] Step 4: The source base station sends the pre-configuration information of the LTM candidate cell (i.e., the necessary information required for handover) to the terminal device through an RRC reconfiguration message. Optionally, the pre-configuration information may include delta configuration and / or reference configuration.
[0180] Optionally, some necessary information required for candidate cell handover includes but is not limited to scenario determination information such as CU ID and DU ID;
[0181] Optionally, some necessary information required for candidate cell switching includes but is not limited to security keys, algorithm information, etc.
[0182] Step 5: The terminal device successfully receives the RRC reconfiguration message, optionally including preconfiguration information, and responds to the successful reception via an RRC reconfiguration complete message;
[0183] Step 6: The terminal device measures and reports the pre-configured LTM candidate cells. The source base station decides to perform LTM handover on a candidate cell based on the information measured and reported by the terminal device.
[0184] Step 7: The source base station sends the LTM MAC CE to the terminal device;
[0185] Optionally, the LTM MAC CE includes part of the handover information, the configuration index of the candidate cell, and optionally, security information that needs to be updated.
[0186] Optionally, the configuration index of the candidate cell includes: a cell that needs to be switched and part of the switching information.
[0187] Optionally, the handover indicated by the source base station may be an LTM continuous handover (ie, during a handover process that is continuous or greater than once, the LTM handover information preconfigured for the terminal device does not change).
[0188] Step 8: The source base station sends the security information that needs to be updated to the target base station;
[0189] Step 9: The terminal device performs handover to the target cell according to the LTM MAC CE and pre-configured information;
[0190] Optionally, the terminal device obtains pre-configuration information according to the configuration index of the candidate cell.
[0191] Optionally, if the LTM MAC CE includes security information, the terminal device implements a security mechanism according to the security information in the MAC CE.
[0192] Optionally, the security information may be indicated directly or through an index. If it is an index, the terminal device needs to index the corresponding security information in a locally stored list according to the index value.
[0193] Optionally, the terminal device implements a security mechanism based on the received security information and derives a key.
[0194] Optionally, after completing the handover, the terminal device notifies the target cell of the completion of the handover by sending an RRC reconfiguration completion message to the target cell.
[0195] In this embodiment, through the above solution, the network device carries security information through the LTM MAC CE, and the terminal device derives the key based on the security information, ensuring that the terminal device and / or network device can derive the correct key in the scenario of continuous LTM switching.
[0196] Third embodiment
[0197] Based on any of the above embodiments of the present application, this embodiment further discloses the processing method in the above embodiments, and carries security information through a new MAC CE.
[0198] Optionally, the security information is carried by a new MAC CE and sent by the network device to the terminal device.
[0199] Optionally, the security information is directly carried by a new MAC CE or an index is carried by a new MAC CE.
[0200] Optionally, the security information includes at least one of the following: a key update indication, a next hop value, a key update indication index, and a next hop value index.
[0201] Optionally, the network device includes: a source base station and a target base station.
[0202] Optionally, the source base station sends the locally stored security information to the target base station before sending the LTM MAC CE. After each successful switch of the terminal device to the target base station, the target base station (new source base station) modifies or updates the NCC value and keySetChangeIndicator value previously pre-configured for the terminal device through a new MAC CE.
[0203] Optionally, a new security information MAC CE (security information media access control element) is shown in Table 1 below:
[0204] Table 1 Security Information MAC CE
[0205] Optionally, Candidateindex indicates a set of pre-configured candidate configurations and uses 4 bits.
[0206] Optionally, Keysetind indicates a new keySetChangeIndicator value, using 1 bit.
[0207] Optionally, NCC indicates a new NCC value, using 3 bits.
[0208] Optionally, the target base station (new source base station) carries security information via a new MAC CE and directly indicates it to the terminal device. After receiving the new NCC value, the terminal device will overwrite the NCC value configured in the pre-configuration information.
[0209] Optionally, the target base station (new source base station) carries the index of the NCC value and keySetChangeIndicator value that need to be updated in the new MAC CE. Optionally, the terminal device and the base station are locally configured with an index list, and the terminal device will index the correct NCC value and keySetChangeIndicator value in the local list according to the received index value.
[0210] Optionally, as shown in FIG8 , the signaling process implemented by the terminal device communicating with the network device in this embodiment includes:
[0211] Step 1: The terminal device measures and reports information of the current serving cell and / or adjacent cell to the source base station;
[0212] Step 2: The source base station decides to configure an LTM cell based on the measurement information reported by the terminal device and sends an LTM handover request to the candidate cell. Optionally, the LTM handover request includes but is not limited to security information such as the key and security algorithm used in the source cell.
[0213] Step 3: The candidate base station prepares resources required for pre-configuring the candidate cell and sends a handover request confirmation message to the source cell;
[0214] Step 4: The source base station sends the pre-configuration information of the LTM candidate cell (i.e., the necessary information required for handover) to the terminal device through an RRC reconfiguration message. Optionally, the pre-configuration information may include delta configuration and / or reference configuration.
[0215] Optionally, some necessary information required for candidate cell switching includes but is not limited to scenario judgment information such as CU ID and DU ID.
[0216] Optionally, some necessary information required for candidate cell switching includes but is not limited to security keys, algorithm information, etc.
[0217] Step 5: The terminal device successfully receives the RRC reconfiguration message. Optionally, the RRC reconfiguration message includes pre-configuration information, and responds to the successful reception through an RRC reconfiguration complete message.
[0218] Step 6: The terminal device measures and reports the pre-configured LTM candidate cells. The source base station decides to perform LTM handover on a candidate cell based on the information measured and reported by the terminal device.
[0219] Step 7: The source base station updates the security information pre-configured for the terminal device by sending a MAC CE carrying security information to the terminal device;
[0220] Optionally, the security information may be a direct indication or an index. If it is an index, the terminal device needs to index the corresponding security information in a locally stored list according to the index value.
[0221] In step 8, the source base station sends an LTM MAC CE to the terminal device, which optionally includes some switching information and the configuration index of the candidate cell. The switching indicated by the source base station can be an LTM continuous switching (that is, the LTM switching information pre-configured for the terminal device does not change during more than one consecutive switching process).
[0222] Step 9: The source base station sends the security information that needs to be updated to the target base station;
[0223] Optionally, the terminal device implements a security mechanism based on the received security information and derives a key.
[0224] Step 10: The terminal device performs handover to the target cell according to the LTM MAC CE and pre-configured information. After completing the handover, the terminal device notifies the target cell of the completion of the handover by sending an RRC reconfiguration complete message to the target cell.
[0225] In this embodiment, through the above solution, the network device carries security information through the new MAC CE, and the terminal device derives the key based on the security information, ensuring that the terminal device and / or network device can derive the correct key in the scenario of continuous LTM switching.
[0226] Fourth embodiment
[0227] Based on any of the above embodiments of the present application, this embodiment further discloses the processing method in the above embodiments, and the terminal device derives the key by switching scene information.
[0228] Optionally, the security information is carried by an LTM MAC CE and / or a radio connection control reconfiguration message and sent by the network device to the terminal device.
[0229] Optionally, the security information includes switching scene information.
[0230] Optionally, the terminal device identifies the switching scenario through information carried in a layer 1 / layer 2 triggered mobility media access control information element or a layer 1 / layer 2 triggered mobility pre-configuration information.
[0231] Optionally, the switching scenario includes a continuous switching scenario within a centralized unit and / or a continuous switching scenario between centralized units.
[0232] Optionally, the information carried in the layer 1 / layer 2 triggered mobility media access control information element or the layer 1 / layer 2 triggered mobility pre-configuration information includes at least one of the following: a centralized unit identifier, a distributed unit identifier, a scene direct indication, a cell group indication, and a specific information element of the centralized unit.
[0233] Optionally, when the terminal device derives the key by switching scenario information, a default derivation of the key is performed.
[0234] Optionally, the execution of the default derivation of the key includes at least one of the following:
[0235] If the switch is within a centralized unit, the current key will continue to be used;
[0236] If it is a centralized inter-unit handover, the key is derived using the current next-hop parameters.
[0237] Optionally, the terminal device and the network device are configured with the same access layer key derivation strategy corresponding to different handover scenarios.
[0238] Optionally, the terminal device identifies whether the current switching scenario is an intra-CU or inter-CU scenario through information carried in the MAC CE sent by the network device.
[0239] Optionally, the identification of the handover scenario may be obtained based on information in the MAC CE or pre-configuration, including but not limited to DU-ID, CU-ID or direct indication.
[0240] Optionally, if the scenario is an intra-CU continuous switching scenario, the terminal device does not change the currently used key.
[0241] Optionally, if it is an inter-CU continuous switching scenario, the terminal device chooses to use the current NH to derive the new KgNB (i.e. vertical derivation) by default, and the source base station also uses the same strategy to derive the key, which will not be repeated here.
[0242] Optionally, when a KAMF change occurs, the network device side should update the security information in the LTM pre-configuration through a MAC CE or RRCReconfiguration message carrying security information.
[0243] Optionally, the network device includes: a source base station and a target base station.
[0244] Optionally, as shown in FIG9 , taking the network device including a source base station and a target base station as an example, the signaling process implemented by the terminal device communicating with the network device in this embodiment includes the following steps:
[0245] Step 1: The terminal device measures and reports information of the current serving cell and / or adjacent cell to the source base station;
[0246] Step 2: The source base station decides to configure an LTM cell based on the measurement information reported by the terminal device and sends an LTM handover request to the candidate cell. The LTM handover request includes but is not limited to security information such as the key and security algorithm used in the source cell.
[0247] Step 3: The candidate base station prepares and pre-configures the resources required for the candidate cell and sends it to the source cell via a handover request confirmation message;
[0248] Step 4: The source base station sends the pre-configuration information of the LTM candidate cell (i.e., the necessary information required for handover) to the terminal device through an RRC reconfiguration message. Optionally, the pre-configuration information may include delta configuration and / or reference configuration.
[0249] Optionally, some necessary information required for candidate cell switching includes but is not limited to scenario judgment information such as CU ID and DU ID.
[0250] Optionally, some necessary information required for candidate cell switching includes but is not limited to security keys, algorithm information, etc.
[0251] Step 5: The terminal device successfully receives the RRC reconfiguration message and responds to the successful reception through an RRC reconfiguration completion message; optionally, the RRC reconfiguration message includes pre-configuration information.
[0252] Step 6: The terminal device measures and reports the pre-configured LTM candidate cells. The source base station decides to perform LTM handover on a candidate cell based on the information measured and reported by the terminal device.
[0253] Step 7: The source base station sends an LTM MAC CE to the terminal device. Optionally, the LTM MAC CE includes some handover information, a configuration index of a candidate cell, etc.
[0254] Step 8: The terminal device performs LTM switching and identifies whether the current switching scenario is intra-CU (within CU) or inter-CU (between CU) through the LTM MAC CE sent by the base station or the information carried in the pre-configuration:
[0255] Optionally, if it is an intra-CU continuous switching scenario, the terminal device does not change the currently used key in security implementation.
[0256] Optionally, if it is an inter-CU continuous switching scenario, the terminal device chooses to use the NH value to derive the new KgNB by default in the security implementation, and increases the NCC value by 1 after the key is successfully derived.
[0257] Optionally, the terminal device may identify the switching scenario through LTM pre-configuration information or LTM MAC CE.
[0258] Optionally, the information carried in the LTM pre-configuration information or LTM MAC CE includes but is not limited to CU ID, DU ID, scene direct indication, cell group indication and / or CU specific information element, etc.
[0259] Optionally, when a KAMF change occurs, the base station side should update the security information in the LTM pre-configuration before switching through a MAC CE or RRCReconfiguration message carrying security information.
[0260] Optionally, the handover indicated by the source base station may be an LTM continuous handover (ie, the LTM handover information preconfigured for the terminal device does not change during a handover process that is continuous or greater than one time).
[0261] Optionally, the terminal device derives a key based on the received security information.
[0262] Optionally, after completing the handover, the terminal device notifies the target cell of the completion of the handover by sending an RRC reconfiguration completion message to the target cell.
[0263] In this embodiment, through the above solution, the terminal device derives the key based on the security information, which includes the switching scenario information, to ensure that the terminal device and / or network device can derive the correct key in the scenario of continuous LTM switching.
[0264] Fifth embodiment
[0265] The fifth embodiment of the present application proposes a processing method, which mainly relates to a solution for rapid recovery of LTM continuous switching failure.
[0266] 10 , which is a flow chart of a processing method according to a fifth embodiment of the present application, the processing method according to the embodiment of the present application can be applied to a terminal device (such as a mobile phone), and includes the following steps:
[0267] S30: The terminal device performs recovery of the switching failure according to the security information.
[0268] Optionally, the security information includes at least one of the following: a key update indication, a next hop value, a key update indication index, and a next hop value index.
[0269] Optionally, the application scenario of the solution of this embodiment includes: a scenario of continuous LTM switching.
[0270] Optionally, in a scenario of continuous LTM switching, that is, during a switching process that is continuous or more than once, the LTM switching information preconfigured by the network device for the terminal device does not change.
[0271] This embodiment defines the configuration of security information so that the terminal device can quickly recover and switch to the candidate cell according to the security information when the LTM continuous switching fails, ensuring that the terminal device can perform rapid recovery of the switching failure in the LTM continuous switching scenario.
[0272] Optionally, the terminal device may further implement a security mechanism based on the security information to derive a key, thereby ensuring that the terminal device and / or network device can derive a correct key in a scenario where the LTM is continuously switched.
[0273] Optionally, the derived key may be derived by using a formula, or derived by directly reading or obtaining the key.
[0274] Optionally, the security information is provided by a network device. Optionally, the network device includes: a source base station and a target base station.
[0275] Optionally, as shown in FIG11 , before step S30, the method further includes the steps of:
[0276] S20: The terminal device receives the security information.
[0277] Optionally, the terminal device receives security information through at least one of a handover command triggered by layer 1 / layer 2, a media access control information element, and a radio connection control reconfiguration message.
[0278] Optionally, the handover command triggered by layer 1 / layer 2, the media access control information element, and the radio connection control reconfiguration message may be delivered by the network device through a system message, which is not specifically limited in this embodiment.
[0279] Optionally, step S30 includes at least one of the following:
[0280] Perform handover failure recovery via Layer 1 / Layer 2 triggered handover commands or security information received in MAC cells;
[0281] Perform switchover failure recovery using preconfigured security information.
[0282] Optionally, before step S30, the method further includes the steps of:
[0283] S21, the terminal device performs LTM switching according to the switching indication information.
[0284] S22: After the LTM handover fails, cell selection is performed.
[0285] Optionally, the switching indication information includes: LTM MAC CE and / or pre-configured switching information.
[0286] Optionally, the terminal device performs LTM switching according to the switching indication information, and performs cell selection after the current LTM switching fails.
[0287] Optionally, when the selected cell is an LTM candidate cell, fast recovery is performed according to the security information, switching to the selected candidate cell is performed, and a security mechanism is implemented according to the security information to derive a key.
[0288] Optionally, when the selected cell is not an LTM candidate cell, the existing RRC-reestablishment and cell selection reselection process is performed, that is, the key is updated using the existing technology.
[0289] Optionally, as shown in FIG12 , taking the network device including: a source base station and a target base station as an example, the signaling process implemented by the terminal device communicating with the network device in this embodiment includes the following steps:
[0290] Step 1: The terminal device measures and reports information of the current serving cell and / or adjacent cell to the source base station;
[0291] Step 2: The source base station decides to configure an LTM cell based on the measurement information reported by the terminal device, and sends an LTM handover request to the candidate cell. Optionally, the LTM handover request includes but is not limited to security information such as the key and security algorithm used in the source cell.
[0292] Step 3: The candidate base station prepares and pre-configures the resources required for the candidate cell and sends it to the source cell via a handover request confirmation message;
[0293] Step 4: The source base station sends the pre-configuration information of the LTM candidate cell (i.e., the necessary information required for handover) to the terminal device through an RRC reconfiguration message. Optionally, the pre-configuration information may include delta configuration and / or reference configuration.
[0294] Optionally, some necessary information required for candidate cell switching includes but is not limited to scenario judgment information such as CU ID and DU ID.
[0295] Optionally, some necessary information required for candidate cell switching includes but is not limited to security keys, algorithm information, etc.
[0296] Step 5: The terminal device successfully receives the RRC reconfiguration message and responds to the successful reception through an RRC reconfiguration completion message; optionally, the RRC reconfiguration message includes pre-configuration information.
[0297] Step 6: The terminal device measures and reports the pre-configured LTM candidate cells. The source base station decides to perform LTM handover on a candidate cell based on the information measured and reported by the terminal device.
[0298] Step 7: The source base station sends an LTM MAC CE to the terminal device. Optionally, the LTM MAC CE includes some handover information, configuration indexes of candidate cells and / or security information, etc.
[0299] Optionally, before sending the LTM MAC CE, the source base station may send a new MAC CE carrying security information to the terminal device to update the pre-configured security information;
[0300] Optionally, in the new MAC CE carrying security information, the security information may be indicated directly or through an index. If it is an index, the terminal device needs to index the corresponding security information in a locally stored list according to the index value.
[0301] In step 8, the terminal device performs handover to the target cell according to the LTM MAC CE and pre-configured handover information. Optionally, the pre-configured handover information is obtained by the terminal device through a configuration index of the candidate cell.
[0302] Optionally, if the LTM MAC CE includes security information, the terminal device implements a security mechanism according to the security information in the MAC CE.
[0303] Optionally, the security information may be indicated directly or through an index. If it is an index, the terminal device needs to index the corresponding security information in a locally stored list according to the index value.
[0304] Optionally, if the terminal device fails to switch, the terminal device performs a quick recovery of the switching failure based on the security information.
[0305] In step 9, the terminal device performs cell selection. If the selected cell is a candidate cell configured in the pre-configuration, the terminal device performs a fast recovery to the selected candidate cell.
[0306] Optionally, if the LTM MAC CE or security information MAC CE received by the terminal device before the quick recovery of the switching failure carries the security information of the target cell for quick recovery, the quick recovery of the switching failure is performed with the security information in the LTM MAC CE or security information MAC CE as the highest priority.
[0307] In this embodiment, through the above solution, the terminal device performs recovery after a switching failure based on security information, ensuring that in the scenario of continuous LTM switching, the terminal device and / or network device can quickly recover after a switching failure.
[0308] Sixth embodiment
[0309] 13 , which is a flow chart of a processing method according to a sixth embodiment of the present application, the processing method according to the embodiment of the present application can be applied to a network device (such as a base station), and includes the following steps:
[0310] S1: The network device sends security information so that the terminal device can derive a key based on the security information.
[0311] Optionally, the security information includes at least one of the following:
[0312] Key update indication, next hop value, key update indication index, next hop value index, switching scenario information.
[0313] Optionally, the network device sends the security information via at least one of a layer 1 / layer 2 triggered handover command, a media access control information element, and a radio connection control reconfiguration message.
[0314] The key may be derived by a formula, or may be derived by directly reading or obtaining the key.
[0315] Optionally, the application scenario of the solution of this embodiment may include: a scenario of continuous LTM switching.
[0316] Optionally, in a scenario of continuous LTM switching, that is, during a switching process that is continuous or more than once, the LTM switching information preconfigured by the network device for the terminal device does not change.
[0317] Optionally, the network device includes: a source base station and a target base station.
[0318] Optionally, in the scenario of LTM continuous switching, the terminal device measures and reports information of the current serving cell and / or adjacent cell to the source base station. The source base station decides to configure the LTM cell based on the measurement information reported by the terminal device and sends a switching request to the candidate cell. Optionally, the switching request carries an indication of LTM switching, which includes but is not limited to security information such as the key and security algorithm used in the source cell.
[0319] Optionally, the candidate base station prepares the resources required for pre-configuring the candidate cell and sends them to the source cell through a handover request confirmation message; the source base station sends the pre-configuration information of the LTM candidate cell (i.e., some necessary information required for handover) to the terminal device through an RRC reconfiguration message. Optionally, the pre-configuration information may include delta configuration and / or reference configuration.
[0320] Optionally, some necessary information required for candidate cell switching includes but is not limited to scenario judgment information such as CU ID and DU ID.
[0321] Optionally, some necessary information required for candidate cell switching includes but is not limited to security keys, algorithm information, etc.
[0322] Optionally, the terminal device successfully receives the RRC reconfiguration message. Optionally, the RRC reconfiguration message includes pre-configuration information, and responds to successful reception through an RRC reconfiguration completion message.
[0323] Optionally, the terminal device performs measurement reporting on a pre-configured LTM candidate cell, and the source base station decides to perform LTM switching on a certain candidate cell based on the information measured and reported by the terminal device.
[0324] Optionally, the source base station carries security information through at least one transmission method including a handover command triggered by layer 1 / layer 2, a media access control element, and an RRC reconfiguration message, so that the terminal device derives a key based on the received security information.
[0325] Optionally, the source base station sends an LTM MAC CE to the terminal device, which optionally includes part of the handover information, the configuration index of the candidate cell, and optionally also includes security information that needs to be updated.
[0326] Optionally, the source base station sends security information that needs to be updated to the target base station. The terminal device performs handover to the target cell according to the LTM MAC CE and pre-configured information.
[0327] Optionally, the terminal device implements a security mechanism based on the received security information and derives a key.
[0328] Optionally, if the LTM MAC CE includes security information, the terminal device implements a security mechanism according to the security information in the MAC CE.
[0329] Optionally, the terminal device identifies the switching scenario through information carried in a layer 1 / layer 2 triggered mobility media access control information element or a layer 1 / layer 2 triggered mobility pre-configuration information.
[0330] Optionally, the switching scenario includes a continuous switching scenario within a centralized unit and / or a continuous switching scenario between centralized units.
[0331] Optionally, the information carried in the layer 1 / layer 2 triggered mobility media access control information element or the layer 1 / layer 2 triggered mobility pre-configuration information includes at least one of the following: a centralized unit identifier, a distributed unit identifier, a scene direct indication, a cell group indication, and a specific information element of the centralized unit.
[0332] Optionally, the terminal device derives a key based on the security information, including at least one of the following:
[0333] The terminal device derives the key from the security information received through the handover command triggered by layer 1 / layer 2 or the media access control information element;
[0334] The terminal device derives the key through pre-configured security information;
[0335] The terminal device derives the key by switching scene information.
[0336] Optionally, the priority of the security information received by the terminal device through the handover command triggered by layer 1 / layer 2 or the media access control element is higher than the pre-configured security information.
[0337] Optionally, when the terminal device derives the key by switching scenario information, a default derivation of the key is performed.
[0338] Optionally, the terminal device performs default derivation of the key, including at least one of the following:
[0339] If the switch is within a centralized unit, the terminal device continues to use the current key;
[0340] If it is a centralized inter-unit handover, the terminal device uses the current next-hop parameters to derive the key.
[0341] Optionally, before switching, the terminal device updates pre-configured security information through a media access control element or a radio connection control reconfiguration message that carries security information, and derives a key based on the updated security information.
[0342] This embodiment defines the configuration of security information through the above scheme. The network device sends security information so that the terminal device can receive the correct security information, and then derive the key based on the security information, ensuring that in the scenario of continuous LTM switching, the terminal device and / or network device can derive the correct key.
[0343] Seventh embodiment
[0344] 14 , which is a schematic diagram of an interaction flow between a network device and a terminal device according to a processing method according to a seventh embodiment, the seventh embodiment of the present application proposes a processing method, comprising the steps of:
[0345] S1: The network device sends security information so that the terminal device can derive a key based on the security information;
[0346] S2: The terminal device receives security information;
[0347] S3: The terminal device derives the key based on the security information.
[0348] Optionally, the security information includes at least one of the following:
[0349] Key update indication, next hop value, key update indication index, next hop value index, switching scenario information.
[0350] Optionally, the derived key may be derived by using a formula, or derived by directly reading or obtaining the key.
[0351] Optionally, the network device sends security information through at least one of a switching command triggered by layer 1 / layer 2, a media access control element, and a wireless connection control reconfiguration message, and the terminal device receives security information through at least one of a switching command triggered by layer 1 / layer 2, a media access control element, and a wireless connection control reconfiguration message.
[0352] Optionally, the application scenario of the solution of this embodiment may include: a scenario of continuous LTM switching.
[0353] Optionally, in a scenario of continuous LTM switching, that is, during a switching process that is continuous or more than once, the LTM switching information preconfigured by the network device for the terminal device does not change.
[0354] Optionally, the network device includes: a source base station and a target base station.
[0355] Optionally, in the scenario of LTM continuous switching, the terminal device measures and reports information of the current serving cell and / or adjacent cell to the source base station. The source base station decides to configure the LTM cell based on the measurement information reported by the terminal device and sends a switching request to the candidate cell. Optionally, the switching request carries an indication of LTM switching, which includes but is not limited to security information such as the key and security algorithm used in the source cell.
[0356] Optionally, the candidate base station prepares the resources required for pre-configuring the candidate cell and sends them to the source cell through a handover request confirmation message; the source base station sends the pre-configuration information of the LTM candidate cell (i.e., some necessary information required for handover) to the terminal device through an RRC reconfiguration message. Optionally, the pre-configuration information may include delta configuration and / or reference configuration.
[0357] Optionally, some necessary information required for candidate cell switching includes but is not limited to scenario judgment information such as CU ID and DU ID.
[0358] Optionally, some necessary information required for candidate cell switching includes but is not limited to security keys, algorithm information, etc.
[0359] Optionally, the terminal device successfully receives the RRC reconfiguration message. Optionally, the RRC reconfiguration message includes pre-configuration information, and responds to successful reception through an RRC reconfiguration completion message.
[0360] Optionally, the terminal device performs measurement reporting on a pre-configured LTM candidate cell, and the source base station decides to perform LTM switching on a certain candidate cell based on the information measured and reported by the terminal device.
[0361] Optionally, the source base station carries security information through at least one transmission method including a handover command triggered by layer 1 / layer 2, a media access control element, and an RRC reconfiguration message, so that the terminal device derives a key based on the received security information.
[0362] Optionally, the source base station sends an LTM MAC CE to the terminal device, which optionally includes part of the handover information, the configuration index of the candidate cell, and optionally also includes security information that needs to be updated.
[0363] Optionally, the source base station sends security information that needs to be updated to the target base station. The terminal device performs handover to the target cell according to the LTM MAC CE and pre-configured information.
[0364] Optionally, the terminal device implements a security mechanism based on the received security information and derives a key.
[0365] Optionally, if the LTM MAC CE includes security information, the terminal device implements a security mechanism according to the security information in the MAC CE.
[0366] Optionally, the terminal device identifies the switching scenario through information carried in a layer 1 / layer 2 triggered mobility media access control information element or a layer 1 / layer 2 triggered mobility pre-configuration information.
[0367] Optionally, the switching scenario includes a continuous switching scenario within a centralized unit and / or a continuous switching scenario between centralized units.
[0368] Optionally, the information carried in the layer 1 / layer 2 triggered mobility media access control information element or the layer 1 / layer 2 triggered mobility pre-configuration information includes at least one of the following: a centralized unit identifier, a distributed unit identifier, a scene direct indication, a cell group indication, and a specific information element of the centralized unit.
[0369] Optionally, the terminal device derives a key based on the security information, including at least one of the following:
[0370] The terminal device derives the key from the security information received through the handover command triggered by layer 1 / layer 2 or the media access control information element;
[0371] The terminal device derives the key through pre-configured security information;
[0372] The terminal device derives the key by switching scene information.
[0373] Optionally, the priority of the security information received by the terminal device through the handover command triggered by layer 1 / layer 2 or the media access control element is higher than the pre-configured security information.
[0374] Optionally, when the terminal device derives the key by switching scenario information, a default derivation of the key is performed.
[0375] Optionally, the terminal device performs default derivation of the key, including at least one of the following:
[0376] If the switch is within a centralized unit, the terminal device continues to use the current key;
[0377] If it is a centralized inter-unit handover, the terminal device uses the current next-hop parameters to derive the key.
[0378] Optionally, before switching, the terminal device updates pre-configured security information through a media access control element or a radio connection control reconfiguration message that carries security information, and derives a key based on the updated security information.
[0379] This embodiment defines the configuration of security information through the above scheme. The network device sends security information so that the terminal device can receive the correct security information, and then derive the key based on the security information, ensuring that in the scenario of continuous LTM switching, the terminal device and / or network device can derive the correct key.
[0380] Please refer to Figure 15, which is a schematic diagram of the structure of a processing device provided in an embodiment of the present application. The device can be installed in or is the terminal device in the above-mentioned method embodiment. The processing device shown in Figure 15 can be used to perform some or all of the functions in the method embodiment described in the above embodiment. As shown in Figure 15, the device 110 includes:
[0381] The export module 111 is configured to export a key according to security information.
[0382] Optionally, the security information includes at least one of the following: a key update indication, a next hop value, a key update indication index, a next hop value index, and switching scenario information.
[0383] Optionally, the derived key may be derived by using a formula, or derived by directly reading or obtaining the key.
[0384] Optionally, the device further comprises:
[0385] The receiving module is used to receive security information.
[0386] Optionally, the device further comprises:
[0387] The security information is received through at least one of a handover command triggered by layer 1 / layer 2, a medium access control information element, and a radio connection control reconfiguration message.
[0388] Optionally, the device further comprises:
[0389] The handover scenario is identified by information carried in the layer 1 / layer 2 triggered mobility medium access control information element or the layer 1 / layer 2 triggered mobility pre-configuration information.
[0390] Optionally, the switching scenario includes a continuous switching scenario within a centralized unit and / or a continuous switching scenario between centralized units.
[0391] Optionally, the information carried in the layer 1 / layer 2 triggered mobility media access control information element or the layer 1 / layer 2 triggered mobility pre-configuration information includes at least one of the following: a centralized unit identifier, a distributed unit identifier, a scene direct indication, a cell group indication, and a specific information element of the centralized unit.
[0392] Optionally, the device further comprises at least one of the following:
[0393] Derives keys from security information received via Layer 1 / Layer 2 triggered handover commands or Media Access Control cells;
[0394] Derives keys through pre-configured security information;
[0395] Derive the key by switching scene information.
[0396] Optionally, the device further comprises at least one of the following:
[0397] The security information received via Layer 1 / Layer 2 triggered handover command or Media Access Control cell takes precedence over the pre-configured security information;
[0398] updating pre-configured security information according to the received security information;
[0399] When exporting keys by switching scene information, the default export of keys is performed.
[0400] Optionally, the execution of the default derivation of the key includes at least one of the following:
[0401] If the switch is within a centralized unit, the current key will continue to be used;
[0402] If it is a centralized inter-unit handover, the key is derived using the current next-hop parameters.
[0403] The processing device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar and will not be repeated here.
[0404] Please refer to Figure 16, which is a second structural diagram of a processing device provided in an embodiment of the present application. The device can be installed in or is the network device in the above method embodiment. As shown in Figure 16, the processing device 120 includes:
[0405] The sending module 121 is used to send security information so that the terminal device can derive a key based on the security information.
[0406] Optionally, the security information includes at least one of the following:
[0407] Key update indication, next hop value, key update indication index, next hop value index, switching scenario information.
[0408] Optionally, the derived key may be derived by using a formula, or derived by directly reading or obtaining the key.
[0409] Optionally, the sending of security information includes:
[0410] The security information is sent through at least one of a handover command triggered by layer 1 / layer 2, a medium access control information element, and a radio connection control reconfiguration message.
[0411] Optionally, the apparatus further includes: the terminal device identifying the switching scenario through information carried in a layer 1 / layer 2 triggered mobility media access control information element or a layer 1 / layer 2 triggered mobility pre-configuration information.
[0412] Optionally, the switching scenario includes a continuous switching scenario within a centralized unit and / or a continuous switching scenario between centralized units.
[0413] Optionally, the information carried in the layer 1 / layer 2 triggered mobility media access control information element or the layer 1 / layer 2 triggered mobility pre-configuration information includes at least one of the following: a centralized unit identifier, a distributed unit identifier, a scene direct indication, a cell group indication, and a specific information element of the centralized unit.
[0414] Optionally, the terminal device derives a key based on the security information, including at least one of the following:
[0415] The terminal device derives the key from the security information received through the handover command triggered by layer 1 / layer 2 or the media access control information element;
[0416] The terminal device derives the key through pre-configured security information;
[0417] The terminal device derives the key by switching scene information.
[0418] Optionally, the device further comprises at least one of the following:
[0419] The security information received via Layer 1 / Layer 2 triggered handover command or Media Access Control cell takes precedence over the pre-configured security information;
[0420] When the terminal device exports the key by switching scene information, the default export of the key is performed.
[0421] Optionally, the execution of the default derivation of the key includes at least one of the following:
[0422] If the switch is within a centralized unit, the terminal device continues to use the current key;
[0423] If it is a centralized inter-unit handover, the terminal device uses the current next-hop parameters to derive the key.
[0424] Optionally, the device further comprises at least one of the following:
[0425] Before handover, the pre-configured security information is updated by indicating the use of a media access control element or a radio connection control reconfiguration message carrying security information;
[0426] Derive the key based on the updated security information.
[0427] The processing device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar and will not be repeated here.
[0428] Refer to Figure 17, which is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. As shown in Figure 17, the communication device 140 described in this embodiment can be the terminal device (or component that can be used for a terminal device) or network device (or component that can be used for a network device) mentioned in the aforementioned method embodiment. Communication device 140 can be used to implement the methods corresponding to the terminal device or network device described in the aforementioned method embodiment. For details, please refer to the description of the aforementioned method embodiment.
[0429] The communication device 140 may include one or more processors 141, also referred to as processing units, which may perform certain control or processing functions. Processor 141 may be a general-purpose processor or a dedicated processor. For example, it may be a baseband processor or a central processing unit. The baseband processor may be used to process communication protocols and communication data, while the central processing unit may be used to control the communication device, execute software programs, and process software program data.
[0430] Optionally, the processor 141 may also store instructions 143 or data (eg, intermediate data). Optionally, the instructions 143 may be executed by the processor 141, so that the communication device 140 executes the method corresponding to the terminal device or network device described in the above method embodiment.
[0431] Optionally, the communication device 140 may include a circuit that can implement the functions of sending, receiving, or communicating in the aforementioned method embodiments.
[0432] Optionally, the communication device 140 may include one or more memories 142 , on which instructions 144 may be stored. The instructions may be executed on the processor 141 , so that the communication device 140 performs the method described in the above method embodiment.
[0433] Optionally, data may also be stored in the memory 142. The processor 141 and the memory 142 may be provided separately or integrated together.
[0434] Optionally, the communication device 140 may further include a transceiver 145 and / or an antenna 146. The processor 141 may be referred to as a processing unit, and controls the communication device 140 (terminal device, core network device, or wireless access network device). The transceiver 145 may be referred to as a transceiver unit, transceiver, transceiver circuit, or transceiver, and is used to implement the transceiver functions of the communication device 140.
[0435] Optionally, if the communication device 140 is used to implement operations corresponding to the terminal device in the above embodiments, for example, the transceiver 145 can receive security information; and the processor 141 can derive a key based on the security information.
[0436] Optionally, the specific implementation process of the processor 141 and the transceiver 145 can refer to the relevant description of the above embodiments, and will not be repeated here.
[0437] Optionally, if the communication device 140 is used to implement operations corresponding to the network devices in the above embodiments, for example, the transceiver 145 may send security information so that the terminal device derives a key based on the security information.
[0438] Optionally, the specific implementation process of the processor 141 and the transceiver 145 can refer to the relevant description of the above embodiments, and will not be repeated here.
[0439] The processor 141 and transceiver 145 described in this application may be implemented on an IC (Integrated Circuit), an analog integrated circuit, an RFIC (Radio Frequency Integrated Circuit), a mixed-signal integrated circuit, an ASIC (Application Specific Integrated Circuit), a PCB (Printed Circuit Board), an electronic device, etc. The processor 141 and transceiver 145 may also be manufactured using various integrated circuit process technologies, such as CMOS (Complementary Metal Oxide Semiconductor), NMOS (N Metal-Oxide-Semiconductor), PMOS (Positive Channel Metal Oxide Semiconductor), BJT (Bipolar Junction Transistor), bipolar CMOS (BiCMOS), silicon germanium (SiGe), gallium arsenide (GaAs), etc.
[0440] In this application, a communication device may be a terminal device (such as a mobile phone) or a network device (such as a base station), and the specific definition needs to be determined based on the context. In addition, the terminal device can be implemented in various forms. For example, the terminal devices described in this application may include mobile terminals such as mobile phones, tablet computers, laptop computers, PDAs, portable media players (PMPs), navigation devices, wearable devices, smart bracelets, pedometers, etc., as well as fixed terminal devices such as digital TVs and desktop computers.
[0441] Although the communication device is described above by taking a terminal device or a network device as an example, the scope of the communication device described in this application is not limited to the above-mentioned terminal device or network device, and the structure of the communication device may not be limited to Figure 16. The communication device may be an independent device or may be part of a larger device.
[0442] An embodiment of the present application further provides a communication system, including: a terminal device as in any of the above embodiments; and a network device as in any of the above embodiments.
[0443] An embodiment of the present application also provides a communication device, including a memory and a processor, wherein a processing program is stored in the memory, and when the processing program is executed by the processor, the steps of the processing method in any of the above embodiments are implemented.
[0444] The communication device in this application can be a terminal device (such as a mobile phone) or a network device (such as a base station). The specific reference needs to be clarified based on the context.
[0445] An embodiment of the present application further provides a storage medium having a processing program stored thereon. When the processing program is executed by a processor, the steps of the processing method in any of the above embodiments are implemented.
[0446] In the embodiments of the communication device and storage medium provided in the embodiments of the present application, all technical features of any of the above-mentioned processing method embodiments may be included. The expanded and explained contents of the specification are basically the same as those of the embodiments of the above-mentioned methods and will not be repeated here.
[0447] An embodiment of the present application further provides a computer program product, which includes computer program code. When the computer program code runs on a computer, the computer executes the methods in the various possible implementation modes described above.
[0448] An embodiment of the present application also provides a chip, including a memory and a processor, wherein the memory is used to store computer programs, and the processor is used to call and run the computer programs from the memory, so that a device equipped with the chip executes the methods in the various possible implementation modes as described above.
[0449] It is understood that the above scenarios are merely examples and do not limit the application scenarios of the technical solutions provided in the embodiments of this application. The technical solutions of this application can also be applied to other scenarios. For example, those skilled in the art will appreciate that with the evolution of system architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application will also be applicable to similar technical problems.
[0450] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0451] The steps in the method of the embodiment of the present application can be adjusted in order, combined and deleted according to actual needs.
[0452] The units in the device of the embodiment of the present application can be merged, divided and deleted according to actual needs.
[0453] In this application, the same or similar terminology, technical solutions and / or application scenario descriptions are generally only described in detail the first time they appear. When they appear again later, they are generally not repeated for the sake of brevity. When understanding the technical solutions and other contents of this application, for the same or similar terminology, technical solutions and / or application scenario descriptions that are not described in detail later, you can refer to the previous relevant detailed descriptions.
[0454] In this application, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0455] The various technical features of the technical solution of this application can be combined arbitrarily. In order to make the description concise, not all possible combinations of the various technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0456] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as above, and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, controlled terminal device, or network device, etc.) to execute the method of each embodiment of the present application.
[0457] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a storage medium or transmitted from one storage medium to another storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium can be a magnetic medium (e.g., a floppy disk, a storage disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state storage disk Solid State Disk (SSD)).
[0458] The above are only preferred embodiments of the present application and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.
Claims
1. A processing method, wherein: Includes steps: S3: derive a key based on the security information.
2. The method according to claim 1, wherein: The security information includes at least one of the following: a key update indication, a next hop value, a key update indication index, a next hop value index, and switching scenario information.
3. The method according to claim 2, wherein: The method further comprises the steps of: S2: Receive security information.
4. The method according to claim 3, wherein: The step S2 comprises: The security information is received through at least one of a handover command triggered by layer 1 / layer 2, a medium access control information element, and a radio connection control reconfiguration message.
5. The method according to claim 4, wherein: The method further comprises: The handover scenario is identified by information carried in the layer 1 / layer 2 triggered mobility medium access control information element or the layer 1 / layer 2 triggered mobility pre-configuration information.
6. The method according to claim 5, wherein: The switching scenario includes a continuous switching scenario within a centralized unit and / or a continuous switching scenario between centralized units; and / or, The information carried in the layer 1 / layer 2 triggered mobility media access control information element or the layer 1 / layer 2 triggered mobility pre-configuration information includes at least one of the following: a centralized unit identifier, a distributed unit identifier, a scene direct indication, a cell group indication, and a specific information element of a centralized unit.
7. The method according to claim 1, wherein: The step S3 includes at least one of the following: Derivation of keys from security information received via Layer 1 / Layer 2 triggered handover commands or MAC cells; Export keys through pre-configured security information; Export the key by switching scene information.
8. The method according to claim 7, wherein: Also includes at least one of the following: The security information received via a Layer 1 / Layer 2 triggered handover command or a Media Access Control cell takes precedence over the pre-configured security information; updating pre-configured security information according to the received security information; When exporting keys by switching scene information, the default export of keys is performed.
9. The method according to claim 8, wherein: The execution key default derivation includes at least one of the following: If the switch is within a centralized unit, the current key continues to be used; If it is a centralized inter-unit handover, the key is derived using the current next-hop parameters.
10. A processing method, wherein: Includes steps: S1, sending security information so that the terminal device can derive a key based on the security information.
11. The method according to claim 10, wherein the security information comprises at least one of the following: Key update indication, next hop change value, key update indication index, next hop change value index, switching scenario information.
12. The method according to claim 11, wherein sending security information comprises: The security information is sent through at least one of a handover command triggered by layer 1 / layer 2, a medium access control information element, and a radio connection control reconfiguration message.
13. The method according to claim 12, wherein: Also includes: The terminal device identifies the switching scenario through the information carried in the mobility media access control information element triggered by layer 1 / layer 2 or the mobility pre-configuration information triggered by layer 1 / layer 2.
14. The method according to claim 13, wherein: The switching scenario includes a continuous switching scenario within a centralized unit and / or a continuous switching scenario between centralized units; and / or, The information carried in the layer 1 / layer 2 triggered mobility media access control information element or the layer 1 / layer 2 triggered mobility pre-configuration information includes at least one of the following: a centralized unit identifier, a distributed unit identifier, a scene direct indication, a cell group indication, and a specific information element of a centralized unit.
15. The method according to claim 10, wherein: The terminal device derives a key according to the security information, including at least one of the following: The terminal device derives the key from the security information received through the handover command triggered by layer 1 / layer 2 or the media access control information element; The terminal device derives the key through the pre-configured security information; The terminal device derives the key by switching scene information.
16. The method according to claim 15, wherein: Also includes at least one of the following: The security information received via a Layer 1 / Layer 2 triggered handover command or a Media Access Control cell takes precedence over the pre-configured security information; When the terminal device exports the key by switching the scene information, the default export of the key is performed.
17. The method according to claim 16, wherein: The execution key default derivation includes at least one of the following: If the switch is within a centralized unit, the terminal device continues to use the current key; If it is a centralized inter-unit handover, the terminal device uses the current next-hop parameters to derive the key.
18. The method according to claim 10, wherein: Also includes at least one of the following: Before switching, the pre-configured security information is updated by indicating a media access control element or a radio connection control reconfiguration message carrying security information; Derive the key based on the updated security information.
19. A communication device, wherein: include: A memory and a processor, wherein a processing program is stored in the memory, and when the processing program is executed by the processor, the processing method according to claim 1 or 10 is implemented.
20. A storage medium, wherein: The storage medium stores a computer program, and when the computer program is executed by the processor, the processing method according to claim 1 or 10 is implemented.