Communication method, device, network element, medium, chip system and product
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HONOR DEVICE CO LTD
- Filing Date
- 2025-01-23
- Publication Date
- 2026-05-29
Smart Images

Figure CN122122946A_ABST
Abstract
Description
Communication methods, equipment, network elements, media, chip systems and products
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on January 31, 2024, with application number 202410143265.0 and application name “Communication methods, equipment, network elements, media, chip systems and products”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to a communication method, device, network element, medium, chip system and product. Background Art
[0003] Mobile communication networks provide an LTM (Layer Triggered Mobility) mechanism. Under the LTM mechanism, terminal devices can report Layer 3 (L3) measurements to the network. The network, based on the L3 measurement results, can decide whether to change the terminal's serving cell. During a serving cell change, a terminal device can switch from its original cell to a target cell. After a serving cell change, the keys between the terminal device and the network element must be synchronized to ensure secure communication.
[0004] With the current LTM mechanism, when a terminal device changes its serving cell, if the original and target cells are covered by the same base station, the key between the terminal device and the network element does not need to be changed and the original key can be used. However, if the original and target cells are covered by different base stations, the key between the terminal device and the network element needs to be updated after the terminal device changes its serving cell.
[0005] Therefore, for cell switching under the coverage of different base stations, how to achieve synchronous key update of network elements and terminal devices has become a technical problem that needs to be solved urgently. Summary of the Invention
[0006] The embodiments of the present application provide a communication method, device, network element, medium, chip system and product, which are applied to the field of communication technology to timely update the keys of the target network element and terminal device when performing cross-network element cell switching, thereby improving the security of key use during the communication process.
[0007] In a first aspect, embodiments of the present application provide a communication method. The method may be executed by a terminal device, or may be executed by a component (such as a chip or circuit) configured in the terminal device. This application does not limit this.
[0008] For example, the method includes: receiving first indication information, the first indication information is used to indicate that a key update is performed synchronously with a target network element, the first indication information is sent when performing an inter-network element cell switch, and the inter-network element cell switch refers to switching from an original cell corresponding to an original network element to a target cell corresponding to a target network element, and the original network element and the target network element are different.
[0009] Therefore, when it is determined that an inter-network element cell handover is to be performed, a first indication message is sent to both the terminal device and the target network element, so that both, under the instruction of the first indication message, synchronously perform key updates. This ensures that the key of the target network element and the key of the terminal device remain consistent. After the cell handover, the network device and the terminal device use their respective keys to transmit data or information, thereby improving the security of the communication process.
[0010] When a terminal device switches cells across network elements, it is hoped that after the terminal device changes its serving cell, the key consistency between the network element and the terminal device can be guaranteed even if the network element of the target cell changes.
[0011] In the present application, the handover scenario of the cross-network element cell handover can be any cell handover scenario, for example, it can be an LTM cell handover, that is, performing a cross-network element LTM cell handover. When performing the cross-network element LTM cell handover, the original network element sends first indication information to the target network element and the terminal device respectively. The first indication information can instruct the terminal device and the target network element to synchronously perform a key update.
[0012] Optionally, a network element may refer to a device in a network with a certain transmission function. A network element may include a base station or a centralized unit (CU). Therefore, the original network element in this application may be an original base station or an original CU, and the target network element may be a target base station or a target CU. In addition, a network element may also be a device with other hardware structures or combinations. This application does not limit the specific device type or device composition of the network element.
[0013] In the present application, the handover scenario of the cross-network element cell handover can be any cell handover scenario, for example, it can be an LTM cell handover, that is, performing a cross-network element LTM cell handover. When performing the cross-network element LTM cell handover, the original network element sends the first indication information to the target network element and the terminal device respectively.
[0014] It should be understood that the first indication information can be carried in a Media Access Control (MAC) CE (Control Element) for handover or in dedicated signaling. Transmitting the first indication information through existing MAC CE signaling can save communication resources. Using dedicated signaling to carry the first indication information can enrich the information exchange between the UE and the network element.
[0015] In conjunction with the first aspect, in some implementations of the first aspect, the first indication information includes at least one of the following:
[0016] Next hop link counter NCC, algorithm indication information.
[0017] In addition, the first indication information may also include other parameters, for example, it may include the key KgNB, so that the terminal device and the target network element use the same key.
[0018] In order to make the algorithm indication information clearly indicate the security algorithm of the terminal device, the algorithm indication information is at least one of the following:
[0019] Indication of whether to use the original security algorithm;
[0020] Whether to implement integrity protection algorithms and / or encryption algorithms;
[0021] The index of the algorithm.
[0022] Optionally, the original security algorithm refers to a security algorithm configured on the terminal device. The security algorithm may include an integrity protection algorithm and / or an encryption algorithm. The integrity protection algorithm may be used to derive KRRC-int and KUP-int. The encryption algorithm may be used to derive KRRC-enc and KUP-enc.
[0023] Optionally, the method further includes: before receiving the first indication information, further including:
[0024] Configuration information is received, where the configuration information is used to configure a security algorithm determined by a candidate network element for the terminal device based on security information of the terminal device, the candidate network element including the target network element.
[0025] In conjunction with the first aspect, in certain implementations of the first aspect, the configuration information includes at least one of the following:
[0026] A security algorithm configured for each candidate cell and terminal device;
[0027] Each candidate cell and terminal device is configured with a corresponding security algorithm set, which includes multiple security algorithms;
[0028] Each candidate cell set / group and terminal device is configured with a corresponding security algorithm;
[0029] Each candidate cell set / group and terminal device is configured with a corresponding security algorithm set, and the security algorithm set includes multiple security algorithms.
[0030] Optionally, the method may further include: carrying the security information of the terminal device in a cell handover request received by the candidate network element, where the cell handover request is provided by the original network element;
[0031] The security information of the terminal device is provided to the candidate network element by the core network element, which includes the access mobility management network element AMF. In addition, the core network element may also include the session management function network element SMF or the user plane function network element UPF.
[0032] In conjunction with the first aspect, in certain implementations of the first aspect, the security information includes at least one of the following:
[0033] The security capabilities of the terminal device, the security level of the terminal device, and the security attributes of the terminal device.
[0034] In combination with the first aspect, in certain implementations of the first aspect, the configuration information is carried in an RRC reconfiguration message, or in a media access control-control element MAC CE signaling.
[0035] In a second aspect, an embodiment of the present application provides a communication method, which can be executed by an original network element, or can also be executed by a component (such as a chip or circuit) configured in the original network element. This application does not limit this.
[0036] For example, the method includes: when performing cross-network element cell switching, sending first indication information to the target network element and the terminal device respectively, the first indication information is used to instruct the target network element and the terminal device to synchronously perform key update, and cross-network element cell switching means that the original network element where the original cell where the terminal device performs cell switching is located and the target network element where the target cell is located are different.
[0037] In conjunction with the second aspect, in some implementations of the second aspect, the first indication information includes at least one of the following:
[0038] Next hop link counter NCC, algorithm indication information.
[0039] In order to make the algorithm indication information clearly indicate the security algorithm of the terminal device, the algorithm indication information is at least one of the following:
[0040] Indication of whether to use the original security algorithm;
[0041] Whether to implement integrity protection algorithms and / or encryption algorithms;
[0042] The index of the algorithm.
[0043] In combination with the second aspect, in certain implementations of the second aspect, the first indication information is carried in a media access control-control element MAC CE or dedicated signaling for switching.
[0044] Optionally, it may also include:
[0045] Configuration information is sent to the terminal device, where the configuration information is used to configure a security algorithm determined by a candidate network element for the terminal device based on the security information of the terminal device, and the candidate network element includes a target network element.
[0046] In conjunction with the second aspect, in certain implementations of the second aspect, the configuration information includes at least one of the following:
[0047] A security algorithm configured for each candidate cell and terminal device;
[0048] Each candidate cell and terminal device is configured with a corresponding security algorithm set, which includes multiple security algorithms;
[0049] Each candidate cell set / group and terminal device is configured with a corresponding security algorithm;
[0050] Each candidate cell set / group and terminal device is configured with a corresponding security algorithm set, and the security algorithm set includes multiple security algorithms.
[0051] Optionally, the method may further include:
[0052] A cell switching request is sent to a candidate network element. The cell switching request is used to instruct the candidate network element to obtain security information of the terminal device. The security information is used to determine the security algorithm of the terminal device. The candidate network element includes the target network element.
[0053] In conjunction with the second aspect, in certain implementations of the second aspect, the method further includes at least one of the following:
[0054] The security information of the terminal device is carried in the cell handover request;
[0055] The security information of the terminal device is provided to the candidate network element by the core network element, which includes the access mobility management network element AMF.
[0056] In conjunction with the second aspect, in certain implementations of the second aspect, the security information includes at least one of the following:
[0057] The security capabilities of the terminal device, the security level of the terminal device, and the security attributes of the terminal device.
[0058] In combination with the second aspect, in certain implementations of the second aspect, the configuration information is carried in an RRC reconfiguration message or in a media access control-control element MAC CE signaling.
[0059] In a third aspect, an embodiment of the present application provides a communication method, which can be executed by a target network element, or can also be executed by a component (such as a chip or circuit) configured in the target network element. This application does not limit this.
[0060] For example, the method includes: receiving a first indication message, the first indication message is used to indicate that a key update is performed synchronously with the terminal device, the first indication message is sent when performing an inter-network element cell switch, and the inter-network element cell switch refers to switching from an original cell corresponding to an original network element to a target cell corresponding to a target network element, and the original network element and the target network element are different.
[0061] In conjunction with the third aspect, in certain implementations of the third aspect, the first indication information includes at least one of the following:
[0062] Next hop link counter NCC, algorithm indication information.
[0063] In order to make the algorithm indication information clearly indicate the security algorithm of the terminal device, the algorithm indication information is at least one of the following:
[0064] Indication of whether to use the original security algorithm;
[0065] Whether to implement integrity protection algorithms and / or encryption algorithms;
[0066] The index of the algorithm.
[0067] In combination with the third aspect, in certain implementations of the third aspect, the first indication information is carried in a media access control-control element MAC CE or dedicated signaling for switching.
[0068] Optionally, the method may further include:
[0069] receiving a cell handover request, where the cell handover request is used to instruct a target network element to obtain security information of a terminal device;
[0070] Determine the security algorithm of the terminal device based on the security information.
[0071] Optionally, the method further comprises at least one of the following:
[0072] The security information of the terminal device is carried in the cell handover request;
[0073] The security information of the terminal device is provided by the core network elements, which include the access mobility management network element AMF.
[0074] In conjunction with the third aspect, in certain implementations of the third aspect, the security information includes at least one of the following:
[0075] The security capabilities of the terminal device, the security level of the terminal device, and the security attributes of the terminal device.
[0076] In a fourth aspect, a communication device is provided, comprising modules or units for executing the method in the first aspect and any possible implementation manner of the first aspect.
[0077] In a fifth aspect, a communication device is provided, comprising modules or units for executing the method in the second aspect and any possible implementation manner of the second aspect.
[0078] In a sixth aspect, a communication device is provided, comprising modules or units for executing the method in the third aspect and any possible implementation manner of the third aspect.
[0079] In a seventh aspect, a communication device is provided, comprising a processor. The processor is coupled to a memory and configured to execute instructions in the memory to implement the method of the first aspect and any possible implementation of the first aspect. Optionally, the device further comprises a memory. Optionally, the device further comprises a communication interface, the processor being coupled to the communication interface.
[0080] In one implementation, the communication device is a terminal device. When the device for processing the candidate cell configuration information is a terminal device, the communication interface may be a transceiver, or an input / output interface.
[0081] In another implementation, the communication device is a chip configured in a terminal device. When the device for processing the candidate cell configuration information is a chip configured in a terminal device, the communication interface may be an input / output interface.
[0082] Optionally, the transceiver may be a transceiver circuit. Optionally, the input / output interface may be an input / output circuit.
[0083] In an eighth aspect, a communication device is provided, comprising a processor. The processor is coupled to a memory and configured to execute instructions in the memory to implement the method of the second aspect and any possible implementation thereof. Optionally, the device further comprises a memory. Optionally, the device further comprises a communication interface, the processor being coupled to the communication interface.
[0084] In one implementation, the communication device is an original network element. When the communication device is an original network element, the communication interface may be a transceiver or an input / output interface.
[0085] In another implementation, the communication device is a chip configured in the original network element. When the communication device is a chip configured in the original network element, the communication interface may be an input / output interface.
[0086] Optionally, the transceiver may be a transceiver circuit. Optionally, the input / output interface may be an input / output circuit.
[0087] In a ninth aspect, a communication device is provided, comprising a processor. The processor is coupled to a memory and configured to execute instructions in the memory to implement the method of the third aspect and any possible implementation thereof. Optionally, the device further comprises a memory. Optionally, the device further comprises a communication interface, the processor being coupled to the communication interface.
[0088] In one implementation, the communication device is a target network element. When the communication device is a target network element, the communication interface may be a transceiver, or an input / output interface.
[0089] In another implementation, the communication device is a chip configured in the target network element. When the communication device is a chip configured in the target network element, the communication interface may be an input / output interface.
[0090] Optionally, the transceiver may be a transceiver circuit. Optionally, the input / output interface may be an input / output circuit.
[0091] In a tenth aspect, a processor is provided, comprising: an input circuit, an output circuit, and a processing circuit. The processing circuit is configured to receive a signal via the input circuit and transmit a signal via the output circuit, so that the processor executes the method of the first aspect, the second aspect, or the third aspect, and any possible implementation of the first aspect, the second aspect, or the third aspect.
[0092] In a specific implementation, the processor may be one or more chips, the input circuit may be an input pin, the output circuit may be an output pin, and the processing circuit may be a transistor, a gate circuit, a trigger, or various logic circuits. The input signal received by the input circuit may be, for example, but not limited to, received and input by a receiver, and the signal output by the output circuit may be, for example, but not limited to, output to and transmitted by a transmitter. The input circuit and the output circuit may be the same circuit, which functions as an input circuit and an output circuit at different times. The embodiments of the present application do not limit the specific implementation of the processor and various circuits.
[0093] In an eleventh aspect, a processing device is provided, comprising a processor and a memory. The processor is configured to read instructions stored in the memory and receive signals via a receiver and transmit signals via a transmitter to perform the method of the first, second, or third aspect, and any possible implementation of the first, second, or third aspect.
[0094] Optionally, there are one or more processors and one or more memories.
[0095] Optionally, the memory may be integrated with the processor, or the memory may be provided separately from the processor.
[0096] In the specific implementation process, the memory can be a non-transitory memory, such as a read-only memory (ROM), which can be integrated with the processor on the same chip or can be set on different chips. The embodiments of the present application do not limit the type of memory and the setting method of the memory and the processor.
[0097] It should be understood that related data interaction processes, such as sending indication information, can be the process of outputting indication information from the processor, and receiving capability information can be the process of receiving input capability information from the processor. Specifically, data output by the processor can be output to the transmitter, and input data received by the processor can be received from the receiver. The transmitter and receiver can be collectively referred to as a transceiver.
[0098] The processing device in the aforementioned aspect 12 may be one or more chips. The processor in the processing device may be implemented in hardware or software. When implemented in hardware, the processor may be a logic circuit, an integrated circuit, or the like; when implemented in software, the processor may be a general-purpose processor implemented by reading software code stored in a memory, which may be integrated into the processor or located independently of the processor.
[0099] In the thirteenth aspect, an embodiment of the present application provides a terminal device, including a processor, a memory and a transceiver, the transceiver is used to send and receive data, the memory is used to store code instructions, and the processor is used to run the code instructions. When executing the code instructions stored in the memory, the processor is used to instruct the terminal device to execute the method described in the above-mentioned first aspect and any possible implementation method of the first aspect.
[0100] In the fourteenth aspect, an embodiment of the present application provides a network device, including a processor, a memory and a transceiver, the transceiver is used to send and receive data, the memory is used to store code instructions, and the processor is used to run the code instructions. When executing the code instructions stored in the memory, the processor is used to instruct the terminal device to execute the method described in the above-mentioned second aspect and any possible implementation method of the second aspect or the third aspect and any possible implementation method of the third aspect.
[0101] In the fifteenth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program or instruction is stored. When the computer program or instruction is run on a computer, the computer executes the method described in the first aspect, the second aspect, the third aspect, and any possible implementation of the first aspect, the second aspect, and the third aspect.
[0102] In a sixteenth aspect, the present application provides a chip or chip system, comprising at least one processor and a communication interface, wherein the communication interface and the at least one processor are interconnected via a line, and the at least one processor is configured to execute a computer program or instruction to perform the method of the first aspect, the second aspect, or the third aspect, and any possible implementation of the first aspect, the second aspect, or the third aspect. The communication interface in the chip may be an input / output interface, a pin, or a circuit, etc.
[0103] In the seventeenth aspect, an embodiment of the present application provides a computer program product comprising a computer program, which, when the computer program is run on a computer, enables the computer to execute the method in the first aspect, the second aspect or the third aspect and any possible implementation of the first aspect, the second aspect or the third aspect.
[0104] In one possible implementation, the chip or chip system described above in this application further includes at least one memory, in which instructions are stored. The memory may be a storage unit within the chip, such as a register, a cache, etc., or a storage unit of the chip (e.g., a read-only memory, a random access memory, etc.).
[0105] It should be understood that the fourth, seventh and thirteenth aspects of the present application correspond to the technical solution of the first aspect of the present application, the fifth, eighth and fourteenth aspects of the present application correspond to the technical solution of the second aspect of the present application, the sixth, ninth and fourteenth aspects of the present application correspond to the technical solution of the third aspect of the present application, the tenth, eleventh, twelfth and fifteenth to seventeenth aspects of the present application correspond to the technical solutions of the first, second or third aspects of the present application, and the beneficial effects achieved by each aspect and the corresponding feasible implementation methods are similar and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0106] FIG1 is a schematic diagram of the architecture of a communication system 100 used in an embodiment of the present application;
[0107] FIG2 is a signaling interaction diagram exemplarily illustrating an LTM switching process;
[0108] FIG3 is an exemplary diagram illustrating a CU and DU architecture;
[0109] FIG4 is a signaling interaction diagram exemplarily illustrating a traditional key update method;
[0110] FIG5 is a signaling interaction diagram of a communication method provided by an embodiment of the present application, shown from the perspective of device interaction;
[0111] FIG6 is a schematic flow chart exemplarily illustrating a key updating method;
[0112] FIG7 is a signaling interaction diagram of another communication method provided by an embodiment of the present application, shown from the perspective of device interaction;
[0113] FIG8 is a signaling interaction diagram of another communication method provided by an embodiment of the present application, shown from the perspective of device interaction;
[0114] FIG9 is a schematic block diagram of a device for processing candidate cell configuration information provided in an embodiment of the present application;
[0115] FIG10 is a schematic diagram of a possible structure of a terminal device provided in an embodiment of the present application;
[0116] FIG11 is a schematic diagram of a possible structure of a primary cell network device provided in an embodiment of the present application, for example, a schematic diagram of the structure of a base station. DETAILED DESCRIPTION
[0117] The technical solution of this application will be described below with reference to the accompanying drawings.
[0118] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: Long Term Evolution (LTE) system, LTE Frequency Division Duplex (FDD) system, LTE Time Division Duplex (TDD) system, Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication system, future fifth generation (5G) communication system or new radio access technology (NR), vehicle-to-other devices (V2X), where V2X may include vehicle-to-network (V2N), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), vehicle-to-pedestrian (V2P), etc., Long Term Evolution-Vehicle (LTE-V), Internet of Vehicles, machine type communication (MTC), etc. communication (MTC), Internet of Things (IoT), Long Term Evolution-Machine (LTE-M), Machine to Machine (M2M), etc.
[0119] In order to facilitate understanding of the embodiments of the present application, a communication system applicable to the embodiments of the present application is first described in detail in conjunction with Figure 1. Figure 1 shows a schematic diagram of a communication system applicable to the communication method and communication device of the embodiments of the present application. The communication device can be a terminal device, an original network element or a target network element. As shown in Figure 1, the communication system 100 may include at least two network elements, such as the network element 110 and the network element 120 shown in Figure 1, and the communication system 100 may also include at least one terminal device, such as the terminal device 130 shown in Figure 1. The terminal device may be mobile or fixed. Network element 110 and network element 120 are both devices or units that can communicate with the terminal device 130 via a wireless link, such as a base station, a base station controller, a centralized unit (CU), etc. Each network element can provide communication coverage for a specific geographical area, and can communicate with terminal devices located in the coverage area (cell).
[0120] FIG1 exemplarily shows two network elements and one terminal device. Optionally, the communication system 100 may include at least one network element and each network element may include other number of devices within its coverage area, which is not limited in the embodiments of the present application.
[0121] Each of the aforementioned communication devices, such as network element 110, network element 120, or terminal device 130 in Figure 1, may be configured with multiple antennas. The multiple antennas may include at least one transmit antenna for sending signals and at least one receive antenna for receiving signals. In addition, each communication device also includes a transmitter chain and a receiver chain. Those skilled in the art will appreciate that they may include multiple components related to signal transmission and reception (e.g., processors, modulators, multiplexers, demodulators, demultiplexers, or antennas, etc.). Therefore, network elements and terminal devices can communicate using multi-antenna technology.
[0122] Optionally, the wireless communication system 100 may further include other network entities such as a network controller and a mobility management entity, but the embodiments of the present application are not limited thereto.
[0123] In the embodiment of the present application, the network element, which may also be referred to as a network device, may be any device with wireless transceiver capabilities. The device includes but is not limited to: an evolved Node B (eNB), a Radio Network Controller (RNC), a Node B (NB), a Base Station Controller (BSC), a Base Transceiver Station (BTS), a home base station (e.g., Home evolved NodeB, or Home Node B, HNB), a baseband unit (BBU), an access point (AP) in a Wireless Fidelity (WIFI) system, a wireless relay node, a wireless backhaul node, a transmission point (TP) or a transmission and reception point (TRP), etc. It can also be a gNB (the next generation Node B) in a 5G, such as NR, system, or a transmission point (TRP or TP), one or a group of antenna panels (including multiple antenna panels) of a base station in a 5G system, or a network node constituting a gNB or a transmission point, such as a baseband unit (BBU), or a centralized unit (Centralized Unit). Unit (CU), distributed unit (DU), etc.
[0124] In some deployments, a gNB may include a CU and a DU. The gNB may also include an active antenna unit (AAU). The CU implements some gNB functions, while the DU implements some gNB functions. For example, the CU is responsible for processing non-real-time protocols and services, and implementing radio resource control (RRC) and packet data convergence protocol (PDCP) layer functions. The DU is responsible for processing physical layer protocols and real-time services, and implementing radio link control (RLC), media access control (MAC), and physical (PHY) layer functions. The AAU implements some physical layer processing functions, RF processing, and active antenna-related functions. Because RRC layer information ultimately becomes PHY layer information, or is converted from PHY layer information, in this architecture, higher-layer signaling, such as RRC signaling, can also be considered to be sent by the DU, or by both the DU and the AAU. It is understood that a network element can be a device that includes one or more of a CU node, a DU node, or an AAU node. In addition, the CU may be divided into a network element in an access network (radio access network, RAN), or may be divided into a network element in a core network (core network, CN), which is not limited in this application.
[0125] The network element provides services for the cell, and the terminal device communicates with the cell through the transmission resources (for example, frequency domain resources, or spectrum resources) allocated by the network element. The cell can belong to a macro base station (for example, macro eNB or macro gNB, etc.) or a base station corresponding to a small cell. The small cells here can include: metro cells, micro cells, pico cells, femto cells, etc. These small cells have the characteristics of small coverage and low transmission power, and are suitable for providing high-speed data transmission services.
[0126] In the embodiments of the present application, a terminal device may also be referred to as user equipment (UE), access terminal, subscriber unit, subscriber station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user apparatus. The terminal device in the embodiments of the present application may include a handheld device, a vehicle-mounted device, etc. For example, some terminal devices are: mobile phones, tablet computers, PDAs, laptop computers, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication capabilities, computing devices or other processing devices connected to wireless modems, vehicle-mounted devices, wearable devices, terminal devices in 5G networks or future evolved public land mobile communication networks (PLMNs). The terminal equipment in the network (PLMN), etc., is not limited to this in the embodiments of the present application.
[0127] As an example and not a limitation, in the embodiment of the present application, the terminal device may also be a wearable device. Wearable devices may also be called wearable smart devices, which are a general term for wearable devices that are intelligently designed and developed using wearable technology for daily wear, such as glasses, gloves, watches, clothing, and shoes. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothes or accessories. Wearable devices are not only hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are fully functional, large in size, and can achieve complete or partial functions without relying on smartphones, such as smart watches or smart glasses, as well as those that only focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.
[0128] In addition, in the embodiment of the present application, the terminal device can also be a terminal device in the Internet of Things (IoT) system. IoT is an important part of the future development of information technology. Its main technical feature is to connect objects to the network through communication technology, thereby realizing an intelligent network of human-machine interconnection and object-to-object interconnection.
[0129] The terminal device in the embodiments of the present application may also be referred to as: terminal device, user equipment (UE), mobile station (MS), mobile terminal (MT), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication equipment, user agent or user device, etc.
[0130] In the embodiments of the present application, the terminal device or each network element includes a hardware layer, an operating system layer running on the hardware layer, and an application layer running on the operating system layer. The hardware layer includes hardware such as a central processing unit (CPU), a memory management unit (MMU), and memory (also known as main memory). The operating system can be any one or more computer operating systems that implement service processing through processes, such as a Linux operating system, a Unix operating system, an Android operating system, an iOS operating system, or a Windows operating system. The application layer includes applications such as browsers, address books, word processing software, and instant messaging software.
[0131] This application does not limit the specific form of the terminal device.
[0132] To facilitate a clear description of the technical solutions of the embodiments of the present application, some of the terms and technologies involved in the embodiments of the present application are briefly introduced below:
[0133] 1. Cell: A cell is described at a high level from the perspective of resource management, mobility management, or service unit. The coverage area of each network element can be divided into one or more cells, and each cell can correspond to one or more frequency points. In other words, each cell can be considered an area formed by the coverage area of one or more frequency points.
[0134] It should be noted that a cell can be an area within the coverage range of a wireless network of a network element. In an embodiment of the present application, different cells can correspond to the same or different network elements. For example, the network element to which cell #1 belongs and the network element to which cell #2 belongs can be different network elements, such as a base station. That is, cell #1 and cell #2 can be managed by different base stations. Or, for another example, the network element that manages cell #1 and the network element that manages cell #2 can also be different radio frequency processing units of the same base station, such as a radio remote unit (RRU). That is, cell #1 and cell #2 can be managed by the same base station, have the same baseband processing unit and intermediate frequency processing unit, but have different radio frequency processing units. Or, for another example, the network element to which cell #1 belongs and the network element to which cell #2 belongs can be the same network element, such as a base station. That is, cell #1 and cell #2 can be managed by the same base station. In this case, it can be said that cell #1 and cell #2 are co-located. This application does not specifically limit this.
[0135] As mentioned above, in some possible deployments, a gNB may include both a CU and a UD. In this deployment, cell #1 and cell #2 may be managed by the same CU and the same UD, i.e., they share both the CU and the DU; cell #1 and cell #2 may be managed by the same CU and different DUs, i.e., they share the CU but not the DU; or cell #1 and cell #2 may be managed by different CUs and different DUs, i.e., they do not share either the CU or the DU.
[0136] 2. Switching: In a wireless communication system, when a terminal device moves from one cell to / approaches another cell, switching is required to keep the communication of the terminal device uninterrupted. In an embodiment of the present application, the original cell / source cell represents the cell that provides services to the terminal device before the switch, and the target cell represents the cell that provides services to the terminal device after the switch. Relevant information of the target cell (such as the physical cell identification of the target cell, frequency information, random access resource information required for switching to the target cell, etc.) can be indicated by a switching message, which is sent by the network element to which the source cell belongs (i.e., the source network element) to the terminal device.
[0137] A handover may be an intra-site handover or an inter-site handover. An intra-site handover may refer to a situation where the source cell and the target cell belong to the same network element (such as a base station or CU), where the source cell and the target cell may be the same cell or different cells; an inter-site handover may refer to a situation where the source cell and the target cell belong to different network elements (such as a base station or CU). This application does not limit this.
[0138] It should be understood that a cell is a coverage area of a network element, an original cell corresponds to an original network element (eg, an original base station / original CU), and a target cell corresponds to a target network element (eg, a target base station / target CU).
[0139] In the traditional handover process, the mobility management of the terminal device is controlled by the network element. That is, the network element can instruct the terminal device to which cell to switch to and how to switch through a handover message. For example, the original network element sends a handover message to the terminal device to control the terminal device to switch from the original cell to the target cell. The handover message can be an RRC message. For example, in the LTE system, the RRC message can be an RRC connection reconfiguration message carrying a mobility control information element (mobility control info); in the NR system, the RRC message can be an RRC reconfiguration message carrying a synchronization reconfiguration element (reconfiguration with sync).
[0140] 3. LTM (Layer triggered mobility) handover: In the LTM handover process, the source cell can pre-configure candidate cells.
[0141] Figure 2 is a signaling interaction diagram for the LTM handover process. In step 201, the terminal device may perform layer (L) measurement reporting based on the configured candidate cell. This layer measurement reporting may include any layer measurement reporting, such as layer 1 measurement reporting, layer 2 measurement reporting, or layer 3 measurement reporting. This application uses layer 3 measurement reporting for illustration, but in practice, the method for performing layer measurement reporting is not particularly limited.
[0142] The candidate cell may refer to all neighboring cells that the terminal device can access. When the original network element receives the L3 measurement report sent by the terminal device, it decides to perform the LTM cell change. In step 202, during the execution of LTM, the original cell may send an LTM switching request to the target cell and potential target cell in the candidate cell. The target cell and the potential target cell may respond to the LTM switching request of the original cell. The original cell receives the LTM switching request response. In step 203, the original cell may also send the configuration information of the target cell and the potential target cell to the terminal device through the RRC reconfiguration message. In step 204, after receiving the configuration information of the candidate cell, the terminal device may respectively perform downlink synchronization and uplink synchronization for each candidate cell. In step 205, the original cell determines the target cell based on the L3 measurement report of the original cell and the candidate cell and sends the LTM switching command to the UE in step 206. The LTM switching command may be carried in the MAC CE signaling. The MAC CE may include at least the following information: timing advance (TA), transmission configuration indication state (TCI state) identity document (ID), CFRA resource information, and candidate cell configuration information identifier. In step 207, the terminal device receives the MAC CE and may disconnect from the original cell, perform a random access procedure, connect to the target cell, and perform data transmission through the target cell. Then, step 208 determines that the LTM cell handover is complete.
[0143] It should also be understood that the network element of the original cell and the network element of the target cell can be the same network element, or the original cell and the target cell can be co-located. In this case, for a certain terminal device, the key corresponding to the target cell and the key corresponding to the original cell can be the same.
[0144] It should also be understood that the handover message and the RRC message indicating the handover are described from different perspectives. The handover message is described from a functional perspective, intended to express that the message is used to instruct the terminal device to perform a handover. The RRC message is described from the perspective of message type, intended to express that the message is high-layer signaling. The RRC reconfiguration message is an enumeration of RRC messages. In other words, the handover message is sent to the terminal device via high-layer signaling.
[0145] It should also be understood that different RRC messages are listed above, such as the RRC connection reconfiguration message in LTE and the RRC reconfiguration message in NR. These messages are examples for ease of understanding only and should not constitute any limitation to this application. This application does not limit the specific name of the handover message used to instruct the terminal device to send a handover procedure.
[0146] 3. CU-DU Architecture: In the 5G Radio Access Network (RAN) architecture, the baseband unit (BBU) is divided into two functional units: the CU and the DU. The CU is responsible for functions such as the PDCP layer and the RRC layer, while the DU is responsible for the physical layer, MAC layer, and RLC layer.
[0147] Based on the configuration of protocol stack functions, CU-DU architectures can be categorized into two types: CU-DU separation and CU-DU convergence. In the CU-DU separation architecture, NR protocol stack functions can be dynamically configured and split, with some functions implemented in the CU and the remaining functions in the DU. In the CU-DU convergence architecture, the logical functions of the CU and DU are integrated into the same gNB, implementing the full functionality of the protocol stack.
[0148] For ease of understanding, an example diagram of a CU and DU architecture is shown in Figure 3. Referring to Figure 3, a CU can be connected to multiple DUs, and each DU can support multiple cells.
[0149] It should be understood that a CU can support multiple cells, and terminal devices within the coverage area of a cell can access the cell.
[0150] 4. Security: When a terminal device communicates with the target cell, the key used by the terminal device and the network must remain consistent. This ensures communication security and secure key sharing between the terminal device and the network device during data transmission.
[0151] Figure 4 is a signaling interaction diagram of a traditional key update method. Referring to Figure 4, traditional key synchronization is generally performed after the terminal device and the network device complete authentication. In step 401, both the network device and the terminal device can obtain the anchor key K through security authentication. SEAF , and respectively through the anchor bond K SEAF Further derive the key K AMF The network device can be a base station or a CU. After that, the process of establishing a security context will be started. Further, in step 402, the original base station can obtain the security capabilities of the terminal from the Access and Mobility Management Function (AMF). In step 403, the original base station can determine the security algorithm of the terminal based on the security capabilities of the terminal. In step 404, the UE and the AMF can establish a security context through the anchor key K SEAF Derive the key K of gNB or next generation base station (Next Generation eNodeB, ng-eNB) NG-RANand the next hop parameter NH, including the key K derived from the gNB gNV The next hop link counter NCC is associated with each key K NG-RAN Associated with the next hop parameter NH. NG-RAN The keys correspond to two types of access networks, one is gNB as the access network, and the other is ng-eNB as the access network; the former indicates that the 5G base station accesses the 5G core network, and the latter indicates that the LTE base station accesses the 5G core network.
[0152] When performing key derivation, the UE and the original base station can further derive K NR-RAN Specifically, the initial parameters, namely K NG-RAN and NCC value is 0, and establish K NG-RAN In step 405, the original base station may send a handover signaling to the terminal device, and the handover signaling may instruct the terminal device to perform a cell handover. Specifically, in step 406, the terminal device may access the target base station through random access.
[0153] After the handover is completed, in step 407, the UE and the target base station can use the current K NG-RAN and NH parameters to derive K NG-RAN * The original base station uses the K derived from the UE and the target base station. NG-RAN * The target key can include the RRC signaling encryption key and the integrity protection key (K RRC-enc ,K RRC-int ) and the encryption key and integrity key (K UP-enc ,and K UP-int ).
[0154] It should be understood that the derivation of the above key is completed by the original base station. When the target cell of the handover is still the original base station, although the cell handover occurs, the keys of the terminal device and the network device can still remain consistent because the base station has not changed.
[0155] It should also be understood that, as mentioned above, a CU or gNB can simultaneously support multiple cells. When a terminal device performs a cell handover, if the original and target cells belong to the same CU or gNB, the terminal device, despite the cell handover, does not actually change the network equipment it accesses. In this case, the terminal device and network equipment can still use the original key. However, if the original and target cells belong to different CUs or gNBs, the keys of the network equipment and terminal device corresponding to the target cell must remain consistent to ensure communication security between the network equipment and the terminal device after the cell handover.
[0156] Based on this, the present application provides a communication method, so that after the terminal device performs a service cell change, even if the network element of the changed target cell changes, the key consistency between the network element and the terminal device can be guaranteed.
[0157] Accordingly, in the technical solution of this application, when the original cell determines to perform an inter-network element cell handover, it sends instruction information to the target network element and terminal device respectively. This instruction information can instruct the target network element and terminal device to synchronously perform a key update. This ensures that when performing an inter-network element cell handover, the keys of the target network element and terminal device are updated in a timely manner, improving the security of key use during the communication process. This ensures that the key of the target network element and the key of the terminal device remain consistent. After the cell handover, the network device and terminal device use their respective keys to transmit data or information, improving the security of the communication process.
[0158] In order to facilitate understanding of the embodiments of the present application, the following explanations are made before introducing the embodiments of the present application.
[0159] First, in the embodiment of the present application, "used for indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated. For example, including but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information. There is an association relationship between the other information and the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, it is also possible to use a pre-agreement (such as a protocol provision) on whether a certain information element exists to implement the indication of the information to be indicated, thereby reducing the indication overhead to a certain extent.
[0160] Second, in the embodiments of this application, terms such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. For example, the terms "first chip" and "second chip" are used solely to distinguish between different chips and do not define their order. Those skilled in the art will understand that terms such as "first" and "second" do not define the quantity or execution order, and do not necessarily imply differences.
[0161] In the embodiments shown below, the first, second, and various numbers are only used for the convenience of description and are not intended to limit the scope of the embodiments of the present application, for example, to distinguish different indication information, different time intervals, etc.
[0162] Third, "predefinition" or "preconfiguration" can be achieved by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device (for example, including terminal devices and network elements). This application does not limit its specific implementation method.
[0163] Fourth, the "protocol" involved in the embodiments of the present application may refer to a standard protocol in the field of communications, for example, it may include an LTE protocol, an NR protocol, and related protocols used in future communication systems, which is not limited in this application.
[0164] Fifth, "at least one item" refers to one or more items, and "multiple items" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b and c can mean: a, or b, or c, or a and b, or a and c, or b and c, or a, b and c. Where a, b and c can be single or multiple, respectively.
[0165] Sixth, in the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "if" all mean that the device (such as a terminal device or a network element) will make corresponding processing under certain objective circumstances. It does not limit the time, and does not require the device (such as a terminal device or a network element) to have a judgment action when implementing it, nor does it mean that there are other limitations.
[0166] Seventh, to facilitate description of the embodiments of this application, unless otherwise specified, all message names mentioned are those in NR. However, it should be understood that these message names are examples for ease of understanding only and should not constitute any limitation on this application. This application does not exclude the possibility of defining other message names in future protocols to replace the message names listed in this application to achieve the same or similar functions.
[0167] Eighth, the following describes several embodiments in detail with reference to various flowcharts. However, it should be understood that these flowcharts and the descriptions of their corresponding embodiments are provided for ease of understanding only and should not constitute any limitation on this application. Not every step in each flowchart is necessarily required; for example, some steps can be skipped. Furthermore, the order in which the steps are executed is not fixed and is not limited to that shown in the figures. The order in which the steps are executed should be determined by their functions and inherent logic.
[0168] It should be noted that in the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0169] The method provided in the embodiments of the present application is described in detail below with reference to the accompanying drawings.
[0170] It should be understood that the following description is only for ease of understanding and explanation, and the method provided in the embodiment of the present application is described in detail using the interaction between a terminal device and a network element as an example. However, this does not constitute any limitation on the execution subject of the method provided in the present application. For example, the terminal device shown in the embodiment below can be replaced by a component (such as a chip or circuit) configured in the terminal device. The network element shown in the embodiment below can also be replaced by a component (such as a chip or circuit) configured in the network element.
[0171] The embodiments shown below do not particularly limit the specific structure of the execution subject of the method provided in the embodiments of the present application. As long as it is possible to communicate according to the method provided in the embodiments of the present application by running a program that records the code of the method provided in the embodiments of the present application, for example, the execution subject of the method provided in the embodiments of the present application can be a terminal device or a network element, or a functional module in the terminal device or network element that can call and execute the program.
[0172] Figure 5 is a signaling interaction diagram of a communication method 500 provided by an embodiment of the present application, illustrating the communication method 500 from the perspective of device interaction. As shown in Figure 5 , the method 500 may include steps 510 to 590. Each step in the method 500 is described in detail below.
[0173] In step 510, the original network element sends first indication information to the target network element and the terminal device respectively when performing inter-network element cell handover. Accordingly, the target network element can receive the first indication information. The terminal device can also receive the first indication information.
[0174] The first indication information may be used to instruct the terminal device to synchronously perform key update with the target network element. Cross-network element cell handover may refer to a situation where the original network element where the terminal device performs cell handover and the target network element where the target cell is located are different.
[0175] As mentioned above, a network element can refer to a device in a network that has a certain transmission function. A network element can include a base station or a CU. Therefore, in this application, the source network element can be the source base station or the source CU, and the target network element can be the target base station or the target CU. In addition, the network element can also be a device with other hardware structures or combinations. This application does not limit the specific device type or device composition of the network element.
[0176] In one embodiment of the present application, the device types of the original network element and the target network element may be the same. For example, when the original network element is the original base station, the target network element may be the target base station. When the original network element is the original CU, the target network element may be the target CU. However, the device types of the original network element and the target network element may be different. For example, when the original network element is the original base station, the target network element may be the target CU. When the original network element is the original CU, the target network element may be the target base station, or when the original network element is the original base station, the target network element may be the target CU.
[0177] It should be understood that when the original network element performs inter-network element cell handover, before sending the first indication information to the target network element and the terminal device respectively, the original network element may first trigger the inter-network element cell handover. The original network element may trigger the inter-network element cell handover by receiving a cell handover command or the L3 measurement result reported by the UE meeting the cell handover condition. The cell handover command may be sent by the UE to the original network element. The UE may decide whether to trigger the cell handover as needed. For example, whether to trigger the cell handover may be decided based on the triggering cell handover condition.
[0178] The L3 measurement result reported by the UE determines that the cell switching condition is met, which may specifically include at least one of the following situations:
[0179] 1. The communication quality of the original network element is lower than the preset communication quality. 2. The communication quality of the original network element is lower than the communication quality of the candidate cell. 3. The distance between the original network element and the terminal device is greater than the distance between the candidate cell and the terminal device. The above-mentioned specific implementation methods for satisfying the cell handover conditions are merely exemplary and should not constitute specific limitations on triggering cell handover. This application does not impose any restrictions on this.
[0180] In the present application, the handover scenario of the cross-network element cell handover can be any cell handover scenario, for example, it can be an LTM cell handover, that is, performing a cross-network element LTM cell handover. When performing the cross-network element LTM cell handover, the original network element sends first indication information to the target network element and the terminal device respectively. The first indication information can instruct the terminal device and the target network element to synchronously perform a key update.
[0181] It should be understood that the cell switching methods under the LTM mechanism listed above are only examples and should not constitute any limitation to this application. This application does not limit the specific method for the network device to perform cell switching.
[0182] In this embodiment, the original network element sending the first indication information to the target network element and the terminal device UE may include: the original network element sending the first indication information to the target network element, and the original network element sending the first indication information to the UE. Specifically, the original network element may send the first indication information to the target network element at a first moment, and the original network element may send the indication information to the UE at a second moment. The first moment and the second moment may be the same or different. The first moment may be before the second moment, or the first moment may be after the second moment.
[0183] It should be understood that the original network element can send the first indication information to the target network element through the beam corresponding to the target network element. The original network element can also send the first indication information to the UE through the beam corresponding to the terminal device. The embodiment of the beam in the NR protocol can be a spatial filter (spatial filter), or a spatial filter (spatial filter) or a spatial parameter (spatial parameters). The beam used to send signals can be called a transmission beam (Tx beam), which can be called a spatial domain transmit filter or a spatial domain transmit parameter; the beam used to receive signals can be called a reception beam (Rx beam), which can be called a spatial receive filter or a spatial receive parameter.
[0184] Based on different transmission directions, beams can be divided into transmit beams and receive beams. A transmit beam refers to the distribution of signal strength in different directions in space after a signal is transmitted by an antenna, while a receive beam refers to the distribution of signal strength in different directions in space after a wireless signal is received by an antenna.
[0185] It should be understood that the embodiment of beamforming in the NR protocol listed above is only an example and should not constitute any limitation to this application. This application does not exclude the possibility of defining other terms in future protocols to express the same or similar meanings.
[0186] In this embodiment, after the terminal device and the target network element respectively receive the first indication information, in step 520, the terminal device and the target network element may synchronously perform key update.
[0187] It should be understood that the synchronization in the synchronous execution of key update by the terminal device and the target terminal may include the time when the terminal device and the target network element apply the updated key being the same; or, it may include the time when the terminal device executes the key update being the same as the time when the target network element executes the key update; or, it may include the time when the terminal device and the target network element each execute the key update being different but the time when both apply the updated key being the same.
[0188] For example, the terminal device may perform a key update at a third time, and the target network element may perform a key update at a fourth time. There may be a first time interval between the third time and the fourth time, and the first time interval may include one or more time slots.
[0189] Therefore, in order to synchronize the application time of the terminal device and the target network element, after the terminal device switches to the target cell of the target network element, the terminal device can send a communication status to the target network element. The communication status can indicate that the target network element starts applying the updated key. After the terminal device sends the communication status to the target network element, it can determine to use the updated key.
[0190] It should be understood that cross-network element cell handover may refer to a situation where the original network element where the terminal device performs cell handover and the target network element where the target cell are located are different. The different original network element and target network element may refer to the original network element and the target network element being different devices. Taking the network element as a CU as an example, cross-network element cell handover may refer to cell handover between CUs. That is, handover from the original cell of the original CU to the target cell of the target CU.
[0191] In this embodiment, when performing cell switching across network elements, the first indication information can instruct the terminal device and the target network element to perform key updates respectively. If both perform key updates at the same time, the keys of the terminal device and the target network element can remain consistent, thereby ensuring the security of communication between the terminal device and the target network element.
[0192] Optionally, the original network element sending the first indication information to the target network element and the terminal device respectively may include: the original network element sending MAC CE signaling to the terminal device and the target network element respectively, and the MAC CE signaling may carry the first indication information; or the original network element sending dedicated signaling to the terminal device and the target network element respectively, and the dedicated signaling may carry the first indication information. Accordingly, the terminal device may receive the MAC CE signaling and read the first indication information from the MAC CE signaling. The target network element may receive the MAC CE signaling and read the first indication information from the MAC CE signaling.
[0193] As described above, the first indication information can be carried in MAC CE signaling or proprietary signaling. Transmitting the first indication information through the original MAC CE signaling can save communication resources. Among them, proprietary signaling can refer to signaling set up for transmitting indication information. Setting up proprietary signaling to carry the first indication information can enrich the information interaction between the UE and the network element, allowing the original cell to quickly indicate the first indication information of the target network element and terminal device.
[0194] The first indication information may explicitly instruct the terminal device and the target network element to perform a key update, respectively. For example, the indication may be provided by a predefined field in the MAC CE signaling. In this case, the first indication information may be a predefined field in the MAC CE signaling. The predefined field may be an existing field in the MAC CE signaling or a newly defined field, and this application does not impose any additional restrictions on this.
[0195] The first indication information may also implicitly instruct the terminal device and the target network element to perform key updates, respectively. For example, the MAC CE signaling may include parameters for key updates, such as the next hop link counter NCC, algorithm indication information, and other parameters. When the terminal device receives the MAC CE signaling, it may determine whether to initiate a key update based on the parameters included in the MAC CE signaling.
[0196] Optionally, MAC CE signaling may be transmitted between the terminal device and the network element via a physical uplink shared channel (Physical Uplink Shared Channel, PUSCH) or a physical downlink shared channel (Physical Downlink Shared Channel, PDSCH).
[0197] As mentioned above, the terminal device and the target network element need to perform key update respectively, and the key update process involves many parameters. In this embodiment, the first indication information may include at least one of the following: a next hop link counter NCC, and algorithm indication information.
[0198] The next hop chaining counter (NCC) is a parameter used for key derivation. The security algorithm may refer to an algorithm used for key derivation. For example, it may include a KDF (Key derivation function) algorithm. In addition, the first indication information may also include other parameters, for example, it may include a key KgNB, so that the terminal device and the target network element use the same key.
[0199] It should be understood that the first indication information may include at least one of the NCC and algorithm indication information. When the first indication information explicitly indicates that the terminal device and the target device need to perform a key update, the first indication information may indicate the need to perform a key update through a partial field, and may also carry the NCC and algorithm indication information through another partial field. When the first indication information implicitly indicates that the terminal device and the target device need to perform a key update, the fields of the first indication information may be the NCC and the algorithm indication information. The application of the NCC and algorithm indication information in the key update process can refer to the embodiment shown in Figure 6.
[0200] For ease of understanding, Figure 6 shows a schematic flowchart of a key update method provided by an embodiment of the present disclosure. As shown in Figure 6, the disclosed key update method can be configured on a terminal device and a target network element. Method 600 may include steps 601 to 602. Each step in method 600 is described in detail below.
[0201] Step 601: Based on the current K NG-RAN and NCC, derive the updated key K NG-RAN *.
[0202] Step 602: Update the key K according to the security algorithm NG-RAN *, derive the target key, which can include KRRC-enc (RRC signaling encryption key), KRRC-int (RRC signaling integrity protection key), KUP-enc (encryption key for UP (upload) data packets), and KUP-int (integrity protection key for UP data packets).
[0203] Optionally, the security algorithm may include an integrity protection algorithm and an encryption algorithm.
[0204] Specifically, step 602 may include: according to the integrity protection algorithm and the update key K NG-RAN *, derive KRRC-int, KUP-int. According to the encryption algorithm and the updated key K NG-RAN *, derive KRRC-enc, KUP-enc.
[0205] The current K involved in step 601 NG-RAN It can refer to the initial key before the terminal device or target network element performs a key update, or it can refer to the latest key stored in the terminal device or target network element, which needs to be updated. The terminal device and target network element can store their latest K NG-RAN After the key is updated, the terminal device and the target network element can delete the original key.
[0206] In the initial stage of key derivation, the NH parameter can be set to 0. The NH parameter can beNG-RAN Related to NCC. The NH parameter is a key derived from ME and AMF, which can be used to provide forward security and initialize the key K NG-RAN and NCC.
[0207] It should be understood that the algorithm indication information can be used to determine the security algorithm involved in the key update process. Both the terminal device and the target network element can determine the security algorithm used in the key update process through the algorithm indication information.
[0208] In one possible design, the algorithm indication information may be at least one of the following: indication information on whether to use the original security algorithm; whether to execute the integrity protection algorithm and / or encryption algorithm; and the index of the algorithm.
[0209] The original security algorithm refers to the security algorithm configured on the terminal device. Each security algorithm can be associated with at least one candidate cell. The network element corresponding to the candidate cell associated with a security algorithm can use the security algorithm to perform key update.
[0210] Security algorithms may include integrity protection algorithms and / or encryption algorithms. Integrity protection algorithms may be used to derive KRRC-int and KUP-int. Encryption algorithms may be used to derive KRRC-enc and KUP-enc.
[0211] An algorithm index is an identifier used to query security algorithms. For example, security algorithms can be stored in a table, and each security algorithm can be associated with an index. The corresponding security algorithm can be queried using the index.
[0212] The communication method provided in this embodiment can provide first indication information to the terminal device and the target network element via MAC CE signaling. The first indication information can include the NCC and algorithm indication information used during the key update process. This synchronizes the parameters involved in the key update process and ensures that the updated keys of the terminal device and the target network element remain consistent. During this process, no key transmission is required, which prevents attackers from obtaining the new key during transmission and enhances network security.
[0213] In the following, the algorithm indication information including several different combinations will be used to illustrate how to perform key update through the first indication information.
[0214] 1. Algorithm indication information includes: indication information on whether to use the original security algorithm.
[0215] It should be understood that a predefined field in the algorithm indication information may carry information indicating whether a security algorithm is used. For example, the predefined field may be a first numerical value or a second numerical value. The first numerical value or the second numerical value may be other information such as predefined numbers, letters, or symbols, and this application does not limit this.
[0216] The first value may be information indicating the use of the original security algorithm, and the second value may be information indicating the use of the security algorithm. Alternatively, the second value may be information indicating the use of the security algorithm, and the first value may be information indicating the use of the security algorithm. This application is not limited to this.
[0217] Exemplarily, if the value of the predefined field in the algorithm indication information is 1, it indicates that the security algorithm is used; if the value of the predefined field is 0, it indicates that the security algorithm is not used.
[0218] In addition, the algorithm indication information can also implicitly indicate whether to use a security algorithm. For example, the algorithm indication information can include information such as the algorithm name, algorithm identifier, and algorithm index, which can be used to indicate the use of a security algorithm. However, if the algorithm indication information is not the algorithm name, algorithm identifier, or algorithm index, but is information unrelated to the original security algorithm, such as NULL or algorithm information of a new security algorithm, it can indicate that the original security algorithm is not to be used.
[0219] It should be understood that if the algorithm indication information indicates the use of the original security algorithm, the key can be updated according to the original security algorithm. If the algorithm indication information indicates the use of the original security algorithm, the key can be updated according to the default security algorithm. The default security algorithm may refer to a security algorithm pre-set by both the terminal device and the target network element. The default security algorithm of the terminal device and the default security algorithm of the target network element are the same.
[0220] The original security algorithm may refer to a security algorithm configured in the terminal device, for example, a security algorithm of a configured candidate cell.
[0221] 2. Algorithm indication information includes: whether to execute integrity protection algorithm and / or encryption algorithm.
[0222] It should be understood that the algorithm indication information can use another predefined field to indicate whether an integrity protection algorithm and / or an encryption algorithm are executed. This predefined field can have multiple values, such as 1, 2, 3, or 4. For example, a value of 1 can indicate execution of the integrity protection algorithm. A value of 2 can indicate execution of the encryption algorithm. A value of 3 can indicate execution of both the integrity protection algorithm and the encryption algorithm. A value of 4 can indicate neither the integrity protection algorithm nor the encryption algorithm are executed. The character length of the predefined field can be set based on usage requirements. For example, it can be set to 2 characters, with a value of 1 being 01, a value of 2 being 10, a value of 3 being 11, and a value of 4 being 00. Of course, the above approach is merely exemplary and is not intended to be limiting in this application. It should be understood that if the algorithm indication information indicates execution of the integrity protection algorithm and the encryption algorithm, the integrity protection algorithm and the encryption algorithm are determined to participate in the key update. If the algorithm indication information indicates execution of the integrity protection algorithm, the integrity protection algorithm is determined to participate in the key update. If the algorithm indication information indicates execution of the encryption algorithm, the encryption algorithm is determined to participate in the key update.
[0223] 3. Algorithm indication information includes: algorithm index.
[0224] It should be understood that if the algorithm indication information includes an algorithm index, the algorithm corresponding to the index can be directly determined as the security algorithm participating in the key update. The algorithm indication information can carry the algorithm index through a predefined field, for example, the value of the field is the algorithm index.
[0225] 4. Algorithm indication information includes: indication information on whether to use the original security algorithm and whether to execute the integrity protection algorithm and / or encryption algorithm.
[0226] It should be understood that if the algorithm indication information indicates the use of the original security algorithm, the algorithm ultimately participating in the key update can be determined in combination with whether the integrity protection algorithm and / or the encryption algorithm are executed. In other words, if the algorithm indication information includes the indication information for using the original security algorithm and also indicates the execution of the integrity protection algorithm, the integrity protection algorithm can be determined as the algorithm participating in the key update. If the algorithm indication information includes the indication information for using the original security algorithm and also indicates the execution of the encryption algorithm, the encryption algorithm can be determined as the algorithm participating in the key update. If the algorithm indication information includes the indication information for using the original security algorithm and also indicates the execution of the integrity protection algorithm and the encryption algorithm, it can be determined that both the integrity protection algorithm and the encryption algorithm participate in the key update.
[0227] In addition, if the algorithm indication information includes indication information for not using the original security algorithm, the algorithm that ultimately participates in the key update can be further determined based on whether the integrity protection algorithm and / or the encryption algorithm are executed. That is, if the algorithm indication information indicates the execution of the integrity protection algorithm and / or the encryption algorithm, the integrity protection algorithm and / or the default encryption algorithm are determined to participate in the key update.
[0228] 5. Algorithm indication information includes: whether to use the original security algorithm and the algorithm index.
[0229] It should be understood that if the algorithm indication information includes indication information for using the original security algorithm and the index of the algorithm, it is possible to first determine whether the original security algorithm is the same as the algorithm corresponding to the index. If they are the same, the original security algorithm is used directly; if they are different, the original security algorithm can be selected to perform key update, or the algorithm corresponding to the algorithm index can be used to perform key update.
[0230] It should also be understood that if the algorithm indication information includes not using the original security algorithm and the algorithm index, the key update can be performed directly using the algorithm corresponding to the algorithm index.
[0231] 6. Algorithm indication information includes whether to use the original security algorithm, whether to execute the integrity protection algorithm and / or encryption algorithm and the algorithm index.
[0232] It should be understood that when the algorithm indication information includes information indicating whether to use the original security algorithm, whether to execute the integrity protection algorithm and / or encryption algorithm, and the algorithm index, priority can be set for the above information. For example, the priority of the indication of whether to use the original security algorithm is higher than the priority of whether to execute the integrity protection algorithm and / or encryption algorithm, and the priority of whether to execute the integrity protection algorithm and / or encryption algorithm is higher than the priority of the algorithm index. Of course, the setting of the above priorities is merely exemplary and should not constitute a specific limitation.
[0233] It should be understood that if the algorithm indication information includes indication information for using the original security algorithm, executing the integrity protection algorithm and / or encryption algorithm, and the algorithm index, the original security algorithm, the executed integrity protection algorithm and / or encryption algorithm, and the algorithm corresponding to the algorithm index can be determined first to participate in the key update. If there are duplicate algorithms participating in the key update, one can be randomly selected or the latest algorithm can be selected.
[0234] In the embodiments of the present application, security algorithms are involved in the process of synchronously executing key updates by the terminal device and the target network element. In actual applications, security algorithms may include multiple types, such as but not limited to AS integrity protection algorithm, AS encryption algorithm, etc., and the specific types or categories of security algorithms are not overly limited in this embodiment. In the face of many security algorithms, in order to improve the adaptability of the terminal device and the security algorithm, so that the security algorithm can operate normally in the terminal device, a security algorithm can be selected for the terminal device based on the security information of the terminal device. In addition, in order to enable the terminal device and the target network element to use the same security algorithm to ensure the consistency of the key, the target network element can execute the selection of the security algorithm of the terminal device, and then configure the security algorithm selected for the terminal device to the terminal device.
[0235] Before performing an inter-network element cell handover, method 500 further includes: Step 530: In the LTM mechanism, the terminal device may perform a Layer 3 measurement report to the original network element. Accordingly, the original network element may receive the Layer 3 measurement report result reported by the terminal device and trigger a change in the UE's serving cell based on the Layer 3 measurement report result. The original network element may initiate the inter-network element cell handover.
[0236] It should be understood that the original network element can use preset handover conditions to determine whether to initiate a cross-network element cell handover. This handover condition may, for example, include that the communication quality of a candidate cell meets a preset quality threshold. The candidate cell can be used as a target cell, and the original network element initiates a cell handover request to the target cell and / or a potential target cell initiates a cell handover request. Furthermore, the original network element may also determine to initiate a cross-network element cell handover request when the target cell is located in a different target network element than the original network element.
[0237] Optionally, the original network element may sort the candidate cells based on their communication quality or select the cells based on a quality threshold to obtain the top N candidate cells with the highest communication quality, where N is a positive integer greater than or equal to 1. The top N candidate cells with the highest communication quality may include target cells and potential target cells. For example, the candidate cell with the highest communication quality may be selected as the target cell, and the remaining N-1 candidate cells may be selected as potential target cells.
[0238] After the original network element initiates inter-network element cell handover, it may send a cell handover request to a candidate network element in step 540. Accordingly, the candidate network element may receive the cell handover request. Candidate network elements may include target network elements and potential target network elements. That is, the target network element may receive the cell handover request. Potential target network elements may also receive the cell handover request. Of course, candidate network elements may also include other network elements, and this embodiment does not impose any particular limitations on this.
[0239] After receiving the cell handover request, if the target network element determines that the terminal device can access the covered cell, it can send a response message of the cell handover request to the original network element. After receiving the cell handover request, if the potential target network element determines that the terminal device can access the covered cell, it can also send a response message of the cell handover request to the original network element.
[0240] It should be understood that the cell handover request may include various parameters required for performing cell handover, for example, information of the target cell (such as the physical cell identifier (PCI) of the target cell), frequency information corresponding to the target cell, etc.
[0241] Optionally, after receiving the cell switching request sent by the original network element, the candidate network element may obtain security information of the terminal device in step 550 .
[0242] As described above, the candidate network element may trigger the acquisition of the security information of the terminal device based on the cell handover request. Further, the candidate network element may respond to the cell handover request and acquire the security information in the cell handover request.
[0243] In a possible design, the cell handover request may also carry security information of the terminal device, and transmit the security information of the terminal device to the target network element and the potential target network element through the cell handover request.
[0244] Optionally, the target network element or potential target network element may obtain security information of the terminal device and determine a security algorithm for the terminal device based on the security information of the terminal device. A mapping relationship between the security information of the terminal device and the security algorithm of the terminal device is established so that the security algorithm used by the terminal device and the security algorithm used by the target network element or potential target network element are the same, thereby ensuring that the key update process of the terminal device and the target network element or potential target network element is consistent and obtain the same key.
[0245] In another possible design, the security information of the terminal device may also be provided by the core network element to the candidate network element. After receiving the cell handover request, the candidate network element may send an acquisition request to the core network element. The acquisition request may instruct the core network element to send the terminal security information to the candidate network element. The core network element may be, for example, an AMF, a Session Management Function (SMF), or a User Plane Function (UPF).
[0246] Optionally, the security information of the terminal device may include at least one of the following:
[0247] The security capabilities of the terminal device, the security level of the terminal device, and the security attributes of the terminal device.
[0248] It should be understood that the security capabilities of a terminal device may include the terminal device's hardware security capabilities and software security capabilities. Specifically, the terminal device's hardware security capabilities may refer to the ability of the terminal device's hardware to resist network risks. The terminal device's software security capabilities may refer to the ability of the terminal device's software to resist risks.
[0249] It should be understood that the security level of a terminal device may refer to a security level set according to the security of the terminal device. For example, the security level of a terminal device may include two categories: basic level and enhanced level. For another example, the security level of a terminal device may include multiple levels such as first security level, second security level, and third security level. Each level represents different security performance or security capabilities.
[0250] For example, the security levels of the first security level, the second security level, and the third security level may be arranged in descending order or in descending order. Of course, in this embodiment, the division of the security levels of the terminal device is merely exemplary and does not constitute a detailed limitation. In the embodiments of this application, there are no excessive restrictions on the number and order of the security levels.
[0251] It should be understood that the security attributes of a terminal device may refer to characteristics designed to protect the security of the terminal device. For example, these may include attributes such as confidentiality, integrity, availability, and trustworthiness. The higher the strength of the terminal device's security attributes and the richer the security attributes, the stronger the terminal device's security capabilities. Conversely, the lower the strength of the terminal device's security attributes and the fewer the security attributes, the weaker the terminal device's security capabilities. Of course, the security attributes of a terminal device may also include other characteristics, and the specific content of the terminal device's security attributes is not excessively limited in this embodiment.
[0252] In the embodiments of the present application, at least one of the terminal device's security capability, the terminal device's security level, and the terminal device's security attributes is used as the terminal device's security information, thereby enriching the specific meaning of the terminal device's security information. Thus, a more accurate terminal device security algorithm can be obtained by utilizing the terminal device's security information.
[0253] In order to determine the security algorithm of the terminal device, in step 560, the candidate network element may determine the security algorithm of the terminal device based on the security information.
[0254] It should be understood that a mapping relationship or mapping table may be pre-set between security information and security algorithms. The candidate network element may determine the security algorithm of the terminal device based on the security information of the terminal device. Specifically, the candidate network element may determine, through the mapping relationship or mapping table, a security algorithm that has a mapping relationship with the security information of the terminal device, and then use the security algorithm as the security algorithm of the terminal device.
[0255] It should be understood that the pre-set mapping relationship between security information and security algorithms may refer to an algorithmic solution model or formula corresponding to the security information and the security algorithm. This algorithmic solution model or formula can be used to solve the security algorithm corresponding to the security information. For example, the input of this mapping formula may be the characteristics of the security information, and the output may be the determined security algorithm. The security algorithm solution model may be, for example, an artificial intelligence model. The formula may be a mapping formula for a local mapping calculation function. This formula can be used to solve the security algorithm corresponding to the security information. Of course, the above mapping relationship is merely exemplary and does not constitute a specific limitation.
[0256] It should be understood that the pre-set mapping table of security information and security algorithms may refer to a table formed by the corresponding relationship between security information and security algorithms. A row in the table may be a security information and the security algorithm corresponding to the security information, or a set of security information and the set of corresponding security algorithms.
[0257] In the embodiment of the present application, the pre-set mapping relationship or mapping table between security information and security algorithms may include at least one of the following:
[0258] Each piece of security information and the corresponding security algorithm; each piece of security information and the corresponding algorithm set, the algorithm set may include multiple security algorithms, specifically may include algorithm indexes corresponding to multiple security algorithms; a security information set and the corresponding security algorithm; a security information set and the corresponding algorithm set, the security information set includes multiple security information, specifically may include information identifiers or information names corresponding to multiple security information, the algorithm set may include multiple security algorithms, specifically may include algorithm indexes corresponding to multiple security algorithms.
[0259] As described above, each network element can correspond to one or more cells. A network element can associate each of its cells or cell groups with the terminal device's security algorithm, allowing the terminal device's security algorithm to be associated with the cell for use. This allows the terminal device to obtain the security algorithm corresponding to the target cell during a cell handover. Therefore, in step 570, the candidate network element can send the security algorithm determined for the terminal device to the original network element. Correspondingly, the original network element can receive the terminal device's security algorithm sent by the candidate network element.
[0260] It should be understood that the candidate network element sending the terminal device's security algorithm to the original network element may include: sending the terminal device's security algorithm to the original network element via a handover request response message. That is, when the candidate network element sends the terminal device's security algorithm to the original network element, the handover request response message may carry the terminal device's security algorithm.
[0261] The handover request response message may include parameters required to determine the cell handover of the terminal device. For example, it may include information about the target cell, the response result, and the time. Furthermore, the handover request response message may also include other parameters, such as the security algorithm determined by the candidate network element for the terminal device.
[0262] It should be understood that the original network element may receive a terminal device security algorithm sent by one or more candidate network elements. Candidate network elements may include a target network element and a potential target network element. The original network element may also be configured to determine configuration information based on the terminal device security algorithm sent by at least one candidate network element. Specifically, the terminal device security algorithm sent by at least one candidate network element may be combined to obtain the configuration information.
[0263] In order to synchronize the correspondence between each cell and the corresponding security algorithm with the terminal device, the original network element may send configuration information to the terminal device in step 580. The configuration information may be used to configure the correspondence between the candidate cells and the security algorithms of the terminal device.
[0264] Specifically, the correspondence between the covered candidate cells and the security algorithms determined by the candidate network elements for the terminal device, or, each candidate cell is configured with a security algorithm set, and each algorithm in the set is identified by an algorithm index, and / or, the configuration information is used to indicate the correspondence between the terminal device configuration cell set covered by the candidate network element and the security algorithm determined by the candidate network element for the terminal device, and the security algorithm of the terminal device is determined based on the security information of the terminal device.
[0265] In actual applications, when the original network element sends configuration information to the terminal device, the configuration information can be carried through various messages or signaling specified in the protocol. For example, the configuration information can be carried in an RRC reconfiguration message, or in a Media Access Control - Control Element MAC CE signaling or proprietary signaling.
[0266] In one implementation, the original network element may send an RRC reconfiguration message to the terminal device, and the RRC reconfiguration message may carry the configuration information. Specifically, the original network element may send the RRC reconfiguration message to the terminal device when the original network element is in an RRC connection with the terminal device.
[0267] Accordingly, after receiving the RRC reconfiguration message, the terminal device can configure the security algorithm of the terminal device according to the configuration information carried in the RRC reconfiguration message.
[0268] It should be understood that the configuration information can be carried in a predefined field in the RRC message. The configuration information can be set in a predefined field in the RRC signaling. In addition to carrying the configuration information, the RRC message may also include the parameters required by the target network element for the terminal device to access the target cell. For example, it may include information about the target cell (such as the physical cell identifier (PCI) of the target cell), the frequency information corresponding to the target cell, the resource information allocated by the target network element to the terminal device (such as dedicated random access channel (RACH) resources and / or public RACH resources), etc.
[0269] Optionally, after the terminal device configures the security algorithm of the terminal device according to the configuration information carried by the RRC reconfiguration message, it can also send an RRC reconfiguration completion message to the original network element based on the above parameters. The RRC reconfiguration completion message can prompt the original network element that it has completed the resource configuration of the target cell. It should be noted that in some embodiments of the present application, it is described that the terminal device can feedback the RRC reconfiguration completion message to the network element, but this feedback step may be unnecessary. For example, the first network element can start the sending of the first indication information without receiving the RRC reconfiguration completion message. For another example, the first network element can start a predefined timer after sending the RRC message, and when the timer expires, it can start the sending of the first indication information. The type and duration of the timer are not limited.
[0270] In this embodiment, the configuration information is sent to the terminal device via an RRC message. Using existing signaling transmission can avoid unnecessary channel overhead, save communication resources, and achieve flexible and efficient information transmission while improving service performance.
[0271] In another implementation, the original network element may send a Media Access Control (MAC) Element (CE) signaling to the terminal device, which carries the configuration information. Accordingly, the terminal device may receive the MAC CE and configure the security algorithm according to the configuration information carried in the MAC CE signaling.
[0272] In this embodiment, the configuration information is sent to the terminal device via MAC CE signaling, which can reduce the number of signaling transmissions. The cell switching command and the configuration information related to the cell switching are transmitted to the terminal device at the same time, which can improve transmission efficiency and achieve more flexible cell adjustment.
[0273] It should be understood that MAC CE signaling can carry configuration information through predefined fields.
[0274] In another implementation, the original network element may send proprietary signaling to the terminal device. The proprietary signaling may carry configuration information. Accordingly, the terminal device may receive the proprietary signaling and configure the security algorithm according to the configuration information carried in the proprietary signaling.
[0275] It should be understood that the proprietary signaling may be pre-configured signaling used to transmit information between the terminal device and the original network element. In this embodiment, the specific signaling structure of the proprietary signaling is not excessively limited.
[0276] In this embodiment, since proprietary signaling has higher transmission efficiency and greater flexibility, transmitting configuration information to the terminal device through proprietary signaling can improve the transmission efficiency and transmission security of the configuration information.
[0277] The communication method provided in this embodiment can configure the security algorithm determined by each candidate network element for the terminal device to the terminal device through configuration information, so that the security algorithm in the terminal device and each candidate network element is the same. Therefore, when both the terminal device and the target network element perform a key update, the same security algorithm is used, ensuring that the key update process of the terminal device and the target network element is consistent, so that the updated keys of the terminal device and the target network element are consistent, and the communication security between the terminal device and the target network element is effectively guaranteed.
[0278] As mentioned above, the configuration information can configure the corresponding relationship between the candidate cell and the security algorithm of the terminal device. The following lists several possible structures of the configuration information.
[0279] 1. A security algorithm configured for each candidate cell and terminal device.
[0280] It should be understood that the candidate cells and the security algorithms of the terminal device may be in a corresponding relationship. That is, each candidate cell may have a mapping relationship with a security algorithm of the terminal device, and the mapping relationship may reflect the association relationship among the candidate cell, the terminal device, and the security algorithm.
[0281] 2. Each candidate cell and terminal device is configured with a corresponding security algorithm set, which includes multiple security algorithms.
[0282] It should be understood that each candidate cell may have a corresponding relationship with a security algorithm set of the terminal device. That is, each candidate cell may have a mapping relationship with a security algorithm set of the terminal device, and the mapping relationship may reflect the association relationship between the candidate cell, the terminal device, and the security algorithm set.
[0283] Optionally, the security algorithm set may include algorithm indexes corresponding to multiple security algorithms. A security algorithm may consist of one or more algorithms, and a combination of one or more algorithms may be referred to as a security algorithm. For example, the combination of an integrity protection algorithm and an encryption algorithm may be referred to as a security algorithm, while the integrity protection algorithm alone may also be referred to as a security algorithm, and the encryption algorithm alone may also be referred to as a security algorithm.
[0284] 3. Each candidate cell set / group and terminal device is configured with a corresponding security algorithm.
[0285] It should be understood that each candidate cell set / group may include one or more candidate cells, and specifically may include information about one or more candidate cells, such as at least one of the following: the candidate cell's physical cell identifier, cell identifier, cell name, etc. Each candidate cell set / group may be mapped to a security algorithm of a terminal device. That is, any candidate cell in each candidate cell set / group uses a security algorithm of the terminal device.
[0286] 4. Each candidate cell set / group and terminal device is configured with a security algorithm set, which includes multiple security algorithms.
[0287] It should be understood that any candidate cell in each candidate cell set / group may use a security algorithm set correspondingly configured by the terminal device. That is, the candidate cell may use any security algorithm in the security algorithm set to perform key update.
[0288] Furthermore, the candidate cell and the terminal device can each use the same algorithm selection strategy to select a target security algorithm from the algorithm security set, so that both the candidate cell and the terminal device can perform key updates using the target security algorithm. The algorithm selection strategy can be pre-set, for example, based on parameters such as the computational complexity and computation time of the security algorithm.
[0289] In the above embodiment, in step 520, after the target base station and the terminal device can respectively perform key updates under the instruction of the first indication information, the method can also include: step 590, the terminal device initiates a random access process to the target network element.
[0290] In this embodiment, the random access process between the terminal device and the target cell can refer to the existing technology and will not be described here for the sake of brevity.
[0291] Below, the technical solution of the present disclosure will be described in detail using the LTM mechanism as a switching mechanism during cell switching, combined with two methods for obtaining security information involved in the cell switching process.
[0292] This application provides two ways for a candidate network element to obtain the security of a terminal device. In order to better understand the embodiment of this application, the application scenario of the communication method disclosed in this disclosure will be further described below with reference to FIG7 and FIG8.
[0293] Scenario 1: The target network element obtains the security information of the terminal device from the LTM cell handover request.
[0294] FIG7 is a signaling interaction diagram of a communication method provided by an embodiment of the present application. The process shown in FIG7 includes steps 701 to 710.
[0295] In step 701, the terminal device performs L3 measurement reporting, for example, reporting the measurement results of each candidate cell to the original network element. Accordingly, the original network element receives the measurement results and determines to perform inter-network element cell handover based on the measurement results of the terminal device. The original network element may include the original base station / CU.
[0296] Optionally, the measurement result may include an L3 measurement result.
[0297] In step 702, if the original network element determines to perform an inter-network element cell handover, it sends an LTM cell handover request to the target network element. The LTM cell handover request may carry security information of the terminal device. The target network element may include a target base station / CU and a potential target base station / CU.
[0298] Accordingly, the target network element, such as the target base station and the potential target base station, may receive the LTM cell handover request.
[0299] It should be understood that the LTM cell handover request carries the security information of the terminal device. The specific options of the security information can be referred to the description of the above embodiment and will not be repeated here.
[0300] In step 703, the target network element may determine the security algorithm of the terminal device according to the security information of the terminal device carried in the LTM cell handover request.
[0301] In step 704, the target network element sends an LTM switching request response message to the original network element. The LTM switching request response message may carry the security algorithm of the terminal device.
[0302] In step 705, the original network element sends an RRC message to the terminal device. The RRC message may carry configuration information. The configuration information may include at least one of the following:
[0303] A security algorithm configured for each candidate cell and terminal device;
[0304] Each candidate cell and terminal device is configured with a corresponding security algorithm set, which includes multiple security algorithms;
[0305] Each candidate cell set / group and terminal device is configured with a corresponding security algorithm;
[0306] Each candidate cell set / group and terminal device is configured with a corresponding security algorithm set, and the security algorithm set includes multiple security algorithms.
[0307] In step 706, the terminal device saves the configuration information.
[0308] In step 707, the terminal device sends an RRC reconfiguration completion message to the original network element. The RRC reconfiguration completion message can prompt the original network element that the resource configuration of the target cell has been completed.
[0309] In step 708, the original network element sends a MAC CE signaling to the terminal device, and the MAC CE signaling may carry first indication information. The original network element sends the first indication information to the target network element. The first indication information may be used to instruct the terminal device and the target network element to synchronously perform a key update.
[0310] The first indication information may include at least one of the following: a next hop link counter NCC and algorithm indication information.
[0311] In step 709, the target network element and the terminal device may synchronously perform key update under the instruction of the first indication information.
[0312] In step 710, a random access process may be initiated between the target network element and the terminal device.
[0313] Scenario 2: The target network element obtains the security information of the terminal device from the core network element. The core network element may include the AMF.
[0314] FIG8 is a specific flow chart of a communication method provided by an embodiment of the present application. The flow shown in FIG8 includes steps 801 to 803.
[0315] In step 801, the terminal device performs L3 measurement reporting, for example, reporting the measurement results to the original network element. Accordingly, the original network element receives the measurement results and determines to perform inter-network element cell handover based on the measurement results of the terminal device. The original network element may include the original base station / CU.
[0316] Optionally, the measurement result may include an L3 measurement result.
[0317] In step 802, the original network element sends an LTM cell handover request to the target network element when determining that an inter-network element cell handover is triggered. The LTM cell handover request may not carry security information of the terminal device. The target network element may include a target base station and / or a potential target base station.
[0318] Accordingly, the target network element, such as the target base station and the potential target base station, may receive the LTM cell handover request.
[0319] It should be understood that not carrying the security information of the terminal device in the LTM cell switching request can reduce overhead.
[0320] In step 803, the target network element may send a security acquisition request to the core network element AMF, where the security acquisition request is used to instruct the core network element AMF to feedback the security information of the terminal device. Accordingly, the target network element may receive the security information of the terminal device sent by the core network element.
[0321] In step 804, the target network element may determine the security algorithm of the terminal device according to the security information of the terminal device.
[0322] In step 805, the target network element sends an LTM switching request response message to the original network element. The LTM switching request response message may carry the security algorithm of the terminal device.
[0323] In step 806, the original network element sends an RRC message to the terminal device. The RRC message may carry configuration information. The configuration information may include at least one of the following:
[0324] A security algorithm configured for each candidate cell and terminal device;
[0325] Each candidate cell and terminal device is configured with a corresponding security algorithm set, which includes multiple security algorithms;
[0326] Each candidate cell set / group and terminal device is configured with a corresponding security algorithm;
[0327] Each candidate cell set / group and terminal device is configured with a corresponding security algorithm set, and the security algorithm set includes multiple security algorithms.
[0328] In step 807, the terminal device saves the configuration information.
[0329] In step 808, the terminal device sends an RRC reconfiguration completion message to the original network element. The RRC reconfiguration completion message can prompt the original network element that the resource configuration of the target cell has been completed.
[0330] In step 809, the original network element sends MAC CE signaling to the terminal device. The MAC CE signaling may carry first indication information. The original network element sends the first indication information to the target network element. The first indication information may be used to instruct the terminal device and the target network element to synchronously perform a key update. The first indication information may include at least one of the following: a next hop link counter (NCC) and algorithm indication information.
[0331] In step 810, the target network element and the terminal device may synchronously perform key update under the instruction of the first indication information.
[0332] In step 811, a random access process may be initiated between the target network element and the terminal device.
[0333] The communication method provided in the embodiment of the present application is described in detail above in conjunction with Figures 5 to 8 , and the device provided in the embodiment of the present application is described in detail below in conjunction with Figure 9 .
[0334] FIG9 is a schematic block diagram of a communication device 90 according to an embodiment of the present application. As shown in FIG9 , the communication device 90 may include a processing unit 91 and a transceiver unit 92 .
[0335] In one possible design, the communication device 90 can implement the operations of the corresponding terminal device in the above method embodiment. For example, the communication device can be a terminal device, or a component configured in the terminal device, such as a chip or circuit.
[0336] The communication device can implement the corresponding operations of the terminal device in the method embodiments shown in Figures 5 to 8. For example, the transceiver unit 91 can execute steps 510, 530, 540, 550, 570, or 580 in method 500, and the processing unit 91 can execute steps 520, 560, etc. in method 50. The various units in the communication device 90 and the other operations and / or functions described above are respectively for implementing the corresponding processes in the method embodiment shown in Figure 5.
[0337] Specifically, when the communication device 90 is used to execute the communication method shown in Figure 5, the transceiver unit 92 can be used to: receive a first indication message, the first indication message is used to indicate that a key update is performed synchronously with the target network element, and the first indication message is sent when performing an inter-network element cell handover. The inter-network element cell handover refers to switching from the original cell corresponding to the original network element to the target cell corresponding to the target network element. The original network element and the target network element are different.
[0338] Specifically, before receiving the first indication information, the method further includes: receiving configuration information, the configuration information being used to configure a security algorithm determined by a candidate network element for the terminal device according to security information of the terminal device, the candidate network element including a target network element and a potential target network element.
[0339] In another possible design, the communication device 90 can implement the operations of the corresponding original network element in the above method embodiment. For example, the communication device can be the original network element, or a component configured in the original network element, such as a chip or circuit.
[0340] Specifically, when the communication device 90 executes the communication method shown in Figure 5, the transceiver unit 92 can be used to: when performing cross-network element cell switching, send first indication information to the target network element and the terminal device respectively, and the first indication information is used to instruct the target network element and the terminal device to synchronously perform key updates. Cross-network element cell switching means that the original network element where the original cell where the terminal device performs cell switching is located and the target network element where the target cell is located are different.
[0341] Specifically, the transceiver unit 92 is further used to: send configuration information to the terminal device, where the configuration information is used to configure a security algorithm determined by a candidate network element for the terminal device according to security information of the terminal device, and the candidate network element includes a target network element.
[0342] Specifically, the transceiver unit 92 is also used to: send a cell switching request to a candidate network element, the cell switching request is used to instruct the candidate network element to obtain security information of the terminal device, the security information is used to determine the security algorithm of the terminal device, and the candidate network element includes the target network element.
[0343] In another possible design, the communication device 90 may implement the operations corresponding to the candidate network element in the above method embodiment, and the candidate network element may include the target network element. For example, the communication device may be a candidate network element, or a component configured in the candidate network element, such as a chip or circuit.
[0344] Specifically, when the communication device 90 executes the communication method shown in Figure 5, the transceiver unit 92 can be used to: receive a first indication message, the first indication message is used to indicate that a key update is performed synchronously with the terminal device, and the first indication message is sent when performing an inter-network element cell handover. The inter-network element cell handover refers to switching from an original cell corresponding to an original network element to a target cell corresponding to a target network element. The original network element and the target network element are different.
[0345] Specifically, the transceiver unit 92 is further configured to receive a cell handover request, where the cell handover request is used to instruct the target network element to obtain security information of the terminal device. The processing unit 91 may be configured to determine a security algorithm of the terminal device based on the security information.
[0346] It should be understood that the specific process of each unit executing the above corresponding steps has been described in detail in the above method embodiment, and for the sake of brevity, it will not be repeated here.
[0347] It should also be understood that the division of modules in the embodiments of the present application is illustrative and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the various embodiments of the present application may be integrated into a single processor, or may exist physically separately, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or software functional modules.
[0348] It should be understood that the communication device 90 may correspond to the terminal device 130 or the network elements 110-120 in the communication system 100 shown in Figure 1. Specifically, the processing unit 91 in the communication device 90 may correspond to the processor in the terminal device 130 or the network elements 110-120, and the instructions stored in the memory may be called by the processor in the terminal device 130 or the network elements 110-120 to implement the above-mentioned functions, such as network coding and obtaining original packets. The transceiver unit 92 may correspond to the interface in the terminal device 130 or the network elements 110-120, and may respond to the instructions of the processor to implement the above-mentioned functions of receiving and / or sending data.
[0349] It should also be understood that the transceiver unit 92 in the communication device 90 can be implemented by a transceiver or a communication interface, for example, it can correspond to the transceiver 2020 in the terminal device 2000 shown in Figure 10 and the transceiver 3100 in the network device 3000 shown in Figure 11. The processing unit 91 in the communication device 90 can be implemented by at least one processor, for example, it can correspond to the processor 2010 in the terminal device 2000 shown in Figure 10 and the processor 3200 in the network device 3000 shown in Figure 11.
[0350] Figure 10 is a schematic diagram of the structure of a terminal device 2000 provided in an embodiment of the present application. The terminal device 2000 can be applied to the system shown in Figure 1 to perform the functions of the terminal device in the above method embodiment. As shown in the figure, the terminal device 2000 includes a processor 2010 and a transceiver 2020. Optionally, the terminal device 2000 also includes a memory 2030. The processor 2010, the transceiver 2020, and the memory 2030 can communicate with each other through an internal connection path to transmit control and / or data signals. The memory 2030 is used to store computer programs, and the processor 2010 is used to call and run the computer program from the memory 2030 to control the transceiver 2020 to send and receive signals. Optionally, the terminal device 2000 may also include an antenna 2040 for transmitting uplink data or uplink control signaling output by the transceiver 2020 via wireless signals.
[0351] The processor 2010 and the memory 2030 may be combined into a processing device, and the processor 2010 is configured to execute program codes stored in the memory 2030 to implement the aforementioned functions. In a specific implementation, the memory 2030 may also be integrated into the processor 2010 or independent of the processor 2010. The processor 2010 may correspond to the processing unit 11 in FIG. 11 .
[0352] The transceiver 2020 may correspond to the transceiver unit 92 in FIG9 . The transceiver 2020 may include a receiver (or receiver, receiving circuit) and a transmitter (or transmitter, transmitting circuit). The receiver is used to receive signals, and the transmitter is used to transmit signals.
[0353] It should be understood that the terminal device 2000 shown in FIG10 is capable of implementing the various processes involved in the terminal device in the method embodiments shown in FIG5 through FIG8. The operations and / or functions of the various modules in the terminal device 2000 are respectively for implementing the corresponding processes in the above method embodiments. For details, please refer to the description of the above method embodiments; to avoid repetition, detailed descriptions are omitted here.
[0354] The processor 2010 can be used to execute the actions implemented within the terminal device described in the previous method embodiments, while the transceiver 2020 can be used to execute the actions of the terminal device sending to or receiving from the network device described in the previous method embodiments. For details, please refer to the description of the previous method embodiments and will not be repeated here.
[0355] Optionally, the terminal device 2000 may further include a power supply 2050 for providing power to various devices or circuits in the terminal device.
[0356] In addition, in order to make the functions of the terminal device more complete, the terminal device 2000 can also include one or more of an input unit 2060, a display unit 2070, an audio circuit 2080, a camera 2090 and a sensor 2100, and the audio circuit can also include a speaker 2082, a microphone 2084, etc.
[0357] Figure 11 is a schematic diagram of the structure of a network element provided in an embodiment of the present application, for example, a schematic diagram of the structure of a base station. The base station 3000 can be used in the system shown in Figure 1 to perform the functions of the network device in the above-mentioned method embodiment. As shown in the figure, the base station 3000 may include one or more radio frequency units, such as a remote radio unit (RRU) 3100 and one or more baseband units (BBU) (also known as distributed units (DU)) 3300. The RRU 3100 may be referred to as a transceiver unit, corresponding to the transceiver unit 92 in Figure 9. Optionally, the transceiver unit 3100 may also be referred to as a transceiver, a transceiver circuit, or a transceiver, etc., and may include at least one antenna 3101 and a radio frequency unit 3102. Optionally, the transceiver unit 3100 may include a receiving unit and a transmitting unit. The receiving unit may correspond to a receiver (or a receiver, a receiving circuit), and the transmitting unit may correspond to a transmitter (or a transmitter, a transmitting circuit). The RRU 3100 is mainly used for transmitting and receiving radio frequency signals and converting radio frequency signals into baseband signals, for example, for sending indication information to a terminal device. The BBU 3300 is mainly used for baseband processing, base station control, etc. The RRU 3100 and BBU 3300 can be physically located together or physically separated, i.e., a distributed base station.
[0358] BBU 3300 is the control center of the base station, also known as a processing unit, which may correspond to processing unit 91 in Figure 9 and is primarily responsible for performing baseband processing functions such as channel coding, multiplexing, modulation, and spread spectrum. For example, the BBU (processing unit) may be used to control the base station to execute the network device operation procedures in the above-mentioned method embodiments, such as generating the above-mentioned indication information.
[0359] In one example, the BBU 3300 can be composed of one or more single boards, and multiple single boards can jointly support a wireless access network with a single access standard (such as an LTE network), or can separately support wireless access networks with different access standards (such as an LTE network, a 5G network, or other networks). The BBU 3300 also includes a memory 3201 and a processor 3202. The memory 3201 is used to store necessary instructions and data. The processor 3202 is used to control the base station to perform necessary actions, such as controlling the base station to execute the operation process of the network device in the above method embodiment. The memory 3201 and the processor 3202 can serve one or more single boards. That is, a memory and a processor can be set separately on each single board. Alternatively, multiple single boards can share the same memory and processor. In addition, necessary circuits can also be set on each single board.
[0360] It should be understood that base station 3000 shown in Figure 11 is capable of implementing the various processes involving the target network device in the method embodiments shown in Figures 2 to 10. The operations and / or functions of the various modules in base station 3000 are respectively for implementing the corresponding processes in the above method embodiments. For details, please refer to the description of the above method embodiments; to avoid repetition, detailed descriptions are omitted here.
[0361] The BBU 3300 can be used to perform the actions implemented within the network device described in the previous method embodiments, while the RRU 3100 can be used to perform the actions described in the previous method embodiments, where the network device sends data to or receives data from a terminal device. For details, please refer to the description in the previous method embodiments and will not be repeated here.
[0362] It should be understood that the base station 3000 shown in Figure 11 is only one possible architecture of a network device and should not constitute any limitation to this application. The method provided in this application is applicable to network devices with other architectures. For example, network devices including CUs, DUs, and active antenna units (AAUs). This application does not limit the specific architecture of the network device.
[0363] An embodiment of the present application further provides a processing device, including a processor and an interface; the processor is used to execute the method in any of the above method embodiments.
[0364] It should be understood that the processing device may be one or more chips. For example, the processing device may be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chips.
[0365] During implementation, each step of the above method can be completed by an integrated logic circuit of the hardware in the processor or by instructions in the form of software. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor. The software module can be located in a storage medium mature in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in conjunction with its hardware. To avoid repetition, it will not be described in detail here.
[0366] It should be noted that the processor in the embodiments of the present application can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method embodiment can be completed by an integrated logic circuit of the hardware in the processor or by instructions in the form of software. The above processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The various methods, steps, and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
[0367] It is understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct RAM bus RAM (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0368] According to the method provided in the embodiments of the present application, the present application also provides a computer program product, which includes: computer program code, which, when running on a computer, enables the computer to execute the method of any one of the embodiments shown in Figures 2 to 10.
[0369] According to the method provided in the embodiments of the present application, the present application also provides a computer-readable medium, which stores program code. When the program code runs on a computer, the computer executes the method of any one of the embodiments shown in Figures 2 to 10.
[0370] According to the method provided in the embodiment of the present application, the present application also provides a system, which includes one or more terminal devices and one or more network devices as mentioned above.
[0371] The network devices in the above-mentioned various apparatus embodiments completely correspond to the network devices or terminal devices in the terminal devices and method embodiments, and the corresponding steps are performed by the corresponding modules or units. For example, the communication unit (transceiver) performs the receiving or sending steps in the method embodiments, and other steps except sending and receiving can be performed by the processing unit (processor). The functions of the specific units can be referred to the corresponding method embodiments. Among them, there can be one or more processors.
[0372] As used in this specification, the terms "component," "module," "system," and the like are used to represent computer-related entities, hardware, firmware, a combination of hardware and software, software, or software in execution. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an executable file, an execution thread, a program, and / or a computer. By way of illustration, both an application running on a computing device and a computing device can be a component. One or more components can reside in a process and / or an execution thread, and a component can be located on a computer and / or distributed between two or more computers. In addition, these components can be executed from various computer-readable media having various data structures stored thereon. Components can communicate, for example, via local and / or remote processes based on signals having one or more data packets (e.g., data from two components interacting with another component on a local system, a distributed system, and / or a network, such as the Internet interacting with other systems via signals).
[0373] Those skilled in the art will appreciate that the various illustrative logical blocks and steps described in conjunction with the embodiments disclosed herein can be implemented using electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0374] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0375] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0376] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0377] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0378] In the above embodiments, the functions of each functional unit can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions (programs). When the computer program instructions (program) are loaded and executed on a computer, the process or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrated therein. Available media may be magnetic media (eg, floppy disks, hard disks, tapes), optical media (eg, high-density digital video discs (DVDs)), or semiconductor media (eg, solid state disks (SSDs)).
[0379] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, and other media that can store program codes.
[0380] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A communication method, characterized in that: include: Receive first indication information, where the first indication information is used to indicate that a key update is performed synchronously with a target network element. The first indication information is sent when performing an inter-network element cell handover. The inter-network element cell handover refers to switching from an original cell corresponding to an original network element to a target cell corresponding to a target network element. The original network element and the target network element are different.
2. The method according to claim 1, characterized in that Before receiving the first indication information, the method further includes: Configuration information is received, where the configuration information is used to configure a security algorithm determined by a candidate network element for the terminal device based on security information of the terminal device, the candidate network element including the target network element.
3. The method according to claim 2, characterized in that The configuration information includes at least one of the following: A security algorithm configured corresponding to each candidate cell and the terminal device; Each candidate cell is configured with a security algorithm set corresponding to the terminal device, and the security algorithm set includes multiple security algorithms; Each candidate cell set / group is configured with a security algorithm corresponding to the terminal device; Each candidate cell set / group is configured with a security algorithm set corresponding to the terminal device, and the security algorithm set includes multiple security algorithms.
4. The method according to claim 2, characterized in that Also includes: The security information of the terminal device is carried in the cell handover request received by the candidate network element, and the cell handover request is provided by the original network element; The security information of the terminal device is provided to the candidate network element by the core network network element, and the core network network element includes the access mobility management network element AMF.
5. The method according to claim 2, characterized in that The security information includes at least one of the following: The security capabilities of the terminal device, the security level of the terminal device, and the security attributes of the terminal device.
6. The method according to claim 2, characterized in that The configuration information is carried in an RRC reconfiguration message, or in a media access control-control element MAC CE signaling.
7. The method according to any one of claims 1 to 6, characterized in that The first indication information includes at least one of the following: Next hop link counter NCC, algorithm indication information.
8. The method according to claim 7, characterized in that The algorithm indication information is at least one of the following: Indication of whether to use the original security algorithm; Whether to implement integrity protection algorithms and / or encryption algorithms; The index of the algorithm.
9. The method according to any one of claims 1 to 8, characterized in that The first indication information is carried in a media access control-control element MAC CE or dedicated signaling for handover.
10. A communication method, characterized in that: include: In the case of performing cross-network element cell switching, a first indication message is sent to the target network element and the terminal device respectively, wherein the first indication message is used to instruct the target network element and the terminal device to synchronously perform key update, and the cross-network element cell switching means that the original network element where the original cell where the terminal device performs cell switching is located and the target network element where the target cell is located are different.
11. The method according to claim 10, characterized in that Also includes: Configuration information is sent to the terminal device, where the configuration information is used to configure a security algorithm determined by a candidate network element for the terminal device based on the security information of the terminal device, and the candidate network element includes the target network element.
12. The method according to claim 11, characterized in that The configuration information includes at least one of the following: A security algorithm configured corresponding to each candidate cell and the terminal device; Each candidate cell is configured with a security algorithm set corresponding to the terminal device, and the security algorithm set includes multiple security algorithms; Each candidate cell set / group is configured with a security algorithm corresponding to the terminal device; Each candidate cell set / group is configured with a security algorithm set corresponding to the terminal device, and the security algorithm set includes multiple security algorithms.
13. The method according to claim 11, characterized in that Also includes: A cell switching request is sent to the candidate network element, where the cell switching request is used to instruct the candidate network element to obtain security information of the terminal device, where the security information is used to determine a security algorithm of the terminal device, and the candidate network element includes the target network element.
14. The method according to claim 13, wherein: Also include at least one of the following: The security information of the terminal device is carried in the cell handover request; The security information of the terminal device is provided to the candidate network element by the core network network element, and the core network network element includes the access mobility management network element AMF.
15. The method according to claim 11, characterized in that The security information includes at least one of the following: The security capabilities of the terminal device, the security level of the terminal device, and the security attributes of the terminal device.
16. The method according to claim 11, characterized in that The configuration information is carried in an RRC reconfiguration message or in a Media Access Control-Control Element MAC CE signaling.
17. The method according to any one of claims 10 to 16, characterized in that: The first indication information includes at least one of the following: Next hop link counter NCC, algorithm indication information.
18. The method according to claim 17, characterized in that The algorithm indication information is at least one of the following: Indication of whether to use the original security algorithm; Whether integrity protection and / or encryption algorithms are implemented; The index of the algorithm.
19. The method according to any one of claims 10 to 18, characterized in that: When the first indication information is sent to the terminal device, the first indication information is switching media access control-control element MAC CE.
20. A communication method, characterized in that: include: Receive first indication information, where the first indication information is used to indicate that a key update is performed synchronously with a terminal device. The first indication information is sent when performing an inter-network element cell switch. The inter-network element cell switch refers to switching from an original cell corresponding to an original network element to a target cell corresponding to a target network element. The original network element and the target network element are different.
21. The method according to claim 20, characterized in that Also includes: receiving a cell handover request, where the cell handover request is used to instruct the target network element to obtain security information of the terminal device; A security algorithm for the terminal device is determined based on the security information.
22. The method according to claim 21, characterized in that The method further comprises at least one of the following: The security information of the terminal device is carried in the cell handover request; The security information of the terminal device is provided by the core network network element, and the core network network element includes the access mobility management network element AMF.
23. The method according to claim 21, characterized in that The security information includes at least one of the following: The security capabilities of the terminal device, the security level of the terminal device, and the security attributes of the terminal device.
24. The method according to any one of claims 20 to 23, characterized in that The first indication information includes at least one of the following: Next hop link counter NCC, algorithm indication information.
25. A terminal device, characterized in that: including: processor and memory; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the terminal device executes the communication method according to any one of claims 1 to 9.
26. An original network element, characterized in that: include: processor and memory; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the network element executes the communication method according to any one of claims 10 to 19.
27. A target network element, characterized in that: include: processor and memory; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the network element performs the communication method according to any one of claims 20 to 24.
28. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 24 is implemented.
29. A chip system, characterized in that: The system comprises at least one processor and a communication interface, wherein the communication interface and the at least one processor are interconnected via a line, and the at least one processor is configured to run a computer program or instruction to execute the method according to any one of claims 1 to 24.
30. A computer program product, characterized in that The method comprises a computer program which, when being executed, causes a computer to execute the method according to any one of claims 1 to 24.