A data transmission method, device, readable storage medium and system

By pre-configuring the first CG-SDT resources and authentication parameters for the terminal device, the transmission problem of the CG-SDT scheme during cell reselection is solved, realizing low-latency, high-reliability small data transmission, avoiding signaling overhead and resource failure, and meeting the data transmission needs of practical application scenarios.

CN122179854APending Publication Date: 2026-06-09HONOR DEVICE CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HONOR DEVICE CO LTD
Filing Date
2026-04-27
Publication Date
2026-06-09

AI Technical Summary

Technical Problem

The current CG-SDT scheme does not support cell reselection, which means that after cell handover, terminal devices may need to fall back from the RRC_INACTIVE state to the RRC_IDLE state, increasing signaling overhead and transmission delay. Furthermore, the pre-configured SDT resources become invalid after cell handover, which cannot meet the data transmission requirements of actual application scenarios.

Method used

Before cell reselection, the anchor gNB configures the first CG-SDT resource and authentication parameters for the terminal device. After handover, the terminal device sends uplink data to the serving gNB through the first CG-SDT resource. The serving gNB uses the root key for local authentication, avoiding the need to obtain context information from the anchor gNB and supporting cell reselection.

Benefits of technology

It enables low-latency, high-reliability small data transmission without the need to obtain context information after cell handover, improving the efficiency and sustainability of SDT, reducing signaling overhead and collision probability, and meeting the data transmission needs of practical application scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122179854A_ABST
    Figure CN122179854A_ABST
Patent Text Reader

Abstract

This application provides a data transmission method, apparatus, readable storage medium, and system. In this method, cell reselection is performed in the RRC inactive state. When the SDT process is triggered, uplink data, including SDT data and authentication parameters, is sent to a first network device in the currently camped cell on the first CG-SDT resource. The authentication parameters are used by the first network device for legitimacy authentication based on the root key. The first CG-SDT resource and authentication parameters are configured by a second network device. The first CG-SDT resource includes a set of resource blocks in the CG-SDT resource pool configured for the RNA, which includes both the first and second network devices. This allows the first network device to perform small-data processing of the SDT process without needing to obtain the terminal device's context information from the second network device, thereby enabling CG-SDT to support cell reselection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a data transmission method, apparatus, readable storage medium, and system. Background Technology

[0002] Small data transmission (SDT) is a mechanism that allows terminal devices to transmit small data packets directly in the RRC_INACTIVE (inactive) state, without requiring the terminal device to transition to the RRC connected state, thus reducing power consumption and signaling overhead during the state transition process.

[0003] SDT can be initiated via a random access channel (RACH) or through type 1 configured channel resources. The CG-SDT scheme allows network devices to configure uplink resources for terminal devices in the RRC_INACTIVE state. When a terminal device needs to upload small amounts of data, it can directly use these pre-configured uplink resources to send the data. However, the current standard's CG-SDT scheme does not support cell reselection. Summary of the Invention

[0004] This application provides a data transmission method, apparatus, readable storage medium, and system that enable the CG-SDT process to support cell reselection.

[0005] Firstly, a data transmission method is provided. This method can be executed by a terminal device, or by a component (such as a circuit, chip, or chip system) configured in the terminal device, or by a logic module or software capable of implementing all or part of the functions of the terminal device. This application does not limit this approach. The following description uses a terminal device as an example.

[0006] The method includes: performing cell reselection in the RRC inactive state; when the SDT process is triggered, sending uplink data to the first network device currently camped in the cell on the first CG-SDT resource, the uplink data including SDT data and authentication parameters, the authentication parameters being used by the first network device for legitimacy authentication based on the root key; the first CG-SDT resource and authentication parameters are configured for the terminal device by the second network device camped in the cell before cell reselection, both the first and second network devices holding the root key; the first CG-SDT resource includes a set of resource blocks in the CG-SDT resource pool configured for the RNA, the RNA including the coverage areas of the first and second network devices. Since the coverage area of ​​the first network device providing services to the terminal device after handover is also within the RNA, the CG-SDT resource pool is known to the first network device, so the first network device can receive the uplink data sent by the terminal device on the first CG-SDT resource. The first network device can achieve local authentication based on the authentication parameters in the uplink data.

[0007] Thus, after cell handover, the first network device can perform small data processing of the SDT process without needing to obtain the context information of the terminal device from the second network device, thereby enabling CG-SDT to support cell reselection.

[0008] Secondly, a data transmission method is provided. This method can be executed by a first network device, or by a component (such as a circuit, chip, or chip system) configured in the first network device, or by a logic module or software capable of implementing all or part of the functions of the first network device. This application does not limit this method. The following description uses a first network device as an example.

[0009] The method includes: receiving uplink data sent by a terminal device on a first CG-SDT resource, the uplink data including SDT data and authentication parameters, wherein the first CG-SDT resource and authentication parameters are configured for the terminal device by a second network device in the cell where the terminal device camps before cell reselection; the first CG-SDT resource includes a set of resource blocks in a CG-SDT resource pool configured for RNA, wherein RNA includes the coverage area of ​​the first network device and the coverage area of ​​the second network device; performing legitimacy authentication based on the root key and authentication parameters, wherein both the first network device and the second network device hold the root key; and, if authentication is successful, sending the SDT data to the target network element.

[0010] The second aspect is the implementation on the network device side, which corresponds to the first aspect. The explanations, supplements, and descriptions of the beneficial effects of the first aspect also apply to the second aspect, and will not be repeated here.

[0011] Thirdly, a data transmission method is provided. This method can be executed by a second network device, or by a component (such as a circuit, chip, or chip system) configured in the second network device, or by a logic module or software capable of implementing all or part of the functions of the second network device. This application does not limit this approach. The following description uses a second network device as an example.

[0012] The method includes: configuring a first CG-SDT resource and authentication parameters for the terminal device before the terminal device enters the RRC inactive state. The authentication parameters are used by the first network device to perform legitimacy authentication based on the root key. Both the first network device and the second network device hold the root key. The first CG-SDT resource includes a set of resource blocks in the CG-SDT resource pool configured for RNA. The RNA includes the coverage area of ​​the first network device and the coverage area of ​​the second network device.

[0013] The third aspect is the implementation on the network device side, which corresponds to the first aspect. The explanations, supplements, and descriptions of the beneficial effects of the first aspect also apply to the third aspect, and will not be repeated here.

[0014] Fourthly, a communication device is provided, comprising a processing module and a transceiver module. The processing module is used to perform cell reselection in an RRC inactive state; the transceiver module is used to send uplink data to a first network device in the currently camped cell on a first CG-SDT resource when an SDT process is triggered. The uplink data includes SDT data and authentication parameters, and the authentication parameters are used by the first network device to perform legitimacy authentication based on the root key.

[0015] Fifthly, a communication device is provided, comprising a transceiver module. The transceiver module is used to receive uplink data sent by a terminal device on a first CG-SDT resource, the uplink data including SDT data and authentication parameters; the processing module is used to perform legitimacy authentication based on the root key and authentication parameters, wherein both the first network device and the second network device hold the root key; and if authentication is successful, the transceiver module sends the SDT data to a target network element.

[0016] Sixthly, a communication device is provided, comprising a transceiver module. The transceiver module and processing module are used to configure first CG-SDT resources and authentication parameters for a terminal device before the terminal device enters an RRC inactive state. The authentication parameters are used by a first network device to perform legitimacy authentication based on a root key.

[0017] The fourth, fifth, and sixth aspects are the implementations on the device side corresponding to the first, second, and third aspects. The explanations, supplements, and descriptions of the beneficial effects of the first, second, and third aspects also apply to the third, fourth, and sixth aspects, and will not be repeated here.

[0018] A seventh aspect provides a communication device including a processor. The processor is coupled to a memory and can be used to execute instructions or data in the memory to implement the method in any possible implementation of the first aspect. Optionally, the communication device further includes a memory. Optionally, the communication device further includes a communication interface, and the processor is coupled to the communication interface.

[0019] In one implementation, the communication interface may be a transceiver, or an input / output interface.

[0020] In another implementation, the communication device is a chip configured in a terminal device. When the communication device is a chip configured in a terminal device, the communication interface can be an input / output interface.

[0021] Eighthly, a communication device is provided, including a processor. The processor is coupled to a memory and can be used to execute instructions or data in the memory to implement the methods in any possible implementation of the second or third aspect described above. Optionally, the communication device further includes a memory. Optionally, the communication device further includes a communication interface, and the processor is coupled to the communication interface.

[0022] In one implementation, the communication interface may be a transceiver, or an input / output interface.

[0023] In another implementation, the communication device is a chip configured in a network device. When the communication device is a chip configured in a network device, the communication interface can be an input / output interface.

[0024] A ninth aspect provides a processor, comprising: an input circuit, an output circuit, and a processing circuit. The processing circuit is configured to receive signals through the input circuit and transmit signals through the output circuit, causing the processor to execute a method in any possible implementation of any aspect.

[0025] In specific implementation, the processor can be one or more chips, the input circuit can be input pins, the output circuit can be output pins, and the processing circuit can be transistors, gate circuits, flip-flops, and various logic circuits. The input signal received by the input circuit can be received and input by, for example, but not limited to, a receiver, and the signal output by the output circuit can be, for example, but not limited to, output to and transmitted by a transmitter. Furthermore, the input circuit and the output circuit can be the same circuit, which is used as both the input circuit and the output circuit at different times. This application does not limit the specific implementation of the processor and various circuits.

[0026] In a tenth aspect, a communication device is provided, including a processor and a memory. The processor is configured to read instructions stored in the memory, receive signals via a receiver, and transmit signals via a transmitter to execute the method in any possible implementation of any of the preceding aspects.

[0027] Optionally, the processor may be one or more, and the memory may be one or more.

[0028] Eleventhly, a computer program product is provided, the computer program product comprising: a computer program (also referred to as code or instructions), which, when the computer program is run, causes a computer to perform a method in any possible implementation of any of the preceding aspects.

[0029] In a twelfth aspect, a computer-readable storage medium is provided that stores a computer program (also referred to as code or instructions) that, when run on a computer, causes the computer to perform the methods in any possible implementation of any of the above aspects.

[0030] In a thirteenth aspect, embodiments of this application provide a chip system including one or more processors for calling and executing instructions stored in memory, causing the methods in any of the above aspects or any possible implementations of the above aspects to be executed. The chip system may be composed of chips or may include chips and other discrete devices.

[0031] The chip system may include input circuits or interfaces for transmitting information or data, and output circuits or interfaces for receiving information or data.

[0032] In a fourteenth aspect, a communication system is provided, including the aforementioned terminal device, first network device, and second network device. Optionally, the communication system may further include other devices that communicate with the terminal device and / or the network device. Attached Figure Description

[0033] Figure 1 This is a schematic diagram of the architecture of a communication system according to an exemplary embodiment; Figure 2 This is a flowchart illustrating a data transmission method according to an exemplary embodiment; Figure 3 This is a schematic diagram illustrating a process for configuring CG-SDT resources for a cell according to an exemplary embodiment; Figure 4 This is a schematic diagram illustrating an operation process performed by a terminal device according to an exemplary embodiment; Figure 5This is a schematic flowchart illustrating a method performed by a serving base station according to an exemplary embodiment; Figure 6 This is a flowchart illustrating a data transmission method according to another exemplary embodiment; Figure 7 This is a schematic diagram illustrating a root key allocation process according to an exemplary embodiment; Figure 8 This is a schematic block diagram illustrating a communication device according to an exemplary embodiment; Figure 9 This is another schematic block diagram of a communication device according to an exemplary embodiment. Detailed Implementation

[0034] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0035] The technical solutions provided in this application can be applied to various communication systems, such as: Global System for Mobile Communications (GSM) systems, General Packet Radio Service (GPRS), Wireless Local Area Network (WLAN), Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, sidelink communication systems, Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication systems, non-terrestrial network (NTN) communication systems, 5th generation (5G) mobile communication systems, 6th generation (6G) mobile communication systems, or new radio access technology (NR). The technical solutions provided in this application can also be applied to future communication systems. This application does not limit the scope of these applications.

[0036] Figure 1This is a schematic diagram of the architecture of a communication system applied in an embodiment of this application. The communication system may include access network device 110, terminal device 120, and core network 130.

[0037] It should be noted that, Figure 1 Two access network devices and one terminal device are illustrated as an example. Optionally, the communication system may also include more access network devices and / or multiple terminal devices.

[0038] Access network equipment, sometimes also called access nodes, has wireless transceiver capabilities for communicating with terminal devices. Access network equipment includes, but is not limited to, base stations, evolved NodeBs (eNodeBs), transmission reception points (TRPs) in the aforementioned communication systems, next-generation NodeBs (gNBs) in 5G mobile communication systems, access network equipment or modules in open RAN (ORAN) systems, satellites in NTN communication systems, base stations in future mobile communication systems, or access nodes in WiFi systems. Access network equipment can also be modules or units capable of implementing some of the functions of a base station. Access network equipment can be macro base stations, micro base stations, indoor stations, relay nodes, donor nodes, or wireless controllers in cloud radio access network (CRAN) scenarios. Optionally, access network equipment can also be servers, wearable devices, or vehicle-mounted equipment. For example, in vehicle-to-everything (V2X) technology, the access network equipment can be a roadside unit (RSU). Multiple access network devices in a communication system can be base stations of the same type or different types. Base stations can communicate with terminal devices, or they can communicate with terminal devices through relay stations. Terminal devices can communicate with multiple base stations using different access technologies. The embodiments of this application do not limit the specific technology or device form used in the access network devices. In the embodiments of this application, the access network device is referred to as a network device, and the following will use a gNB as an example for illustration.

[0039] A gNB can cover one or more cells. The cell that has established a wireless connection with the terminal device is called the serving cell of that terminal device. The gNB corresponding to the serving cell can be called the serving gNB.

[0040] In this application embodiment, the device for implementing the function of the network device can be the network device itself, or it can be any device capable of supporting the network device in implementing that function, such as a processor, circuit, chip, or chip system. This device can be installed in the network device or connected to and used with the network device. In the technical solution provided in this application, the example of a network device being used to implement the function of the network device is used to describe the technical solution provided in this application.

[0041] The terminal device in this application embodiment can be a wireless terminal device capable of receiving network device scheduling and instruction information. The wireless terminal device can be a device providing voice and / or data connectivity to a user, a handheld device with wireless connectivity, or other processing devices connected to a wireless modem. For example, the terminal device can communicate with one or more core networks or the Internet via a radio access network (RAN). The terminal device can also be called a terminal, UE, mobile station, mobile terminal, etc. Terminal devices can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), Internet of Things (IoT), ultra-reliable low-latency communication (URLLC), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, smart cities, or satellite communication, etc. The terminal device can be a mobile phone, tablet computer, computer with wireless transceiver capabilities, wearable device, vehicle, aircraft (such as drone, helicopter, airplane), hot air balloon, ship, robot, robotic arm, or smart home device, etc. The embodiments of this application do not limit the form of the terminal device.

[0042] In the embodiments of this application, the device for implementing the functions of the terminal device can be the terminal device itself, or any device capable of supporting the terminal device in implementing the functions, such as a processor, circuit, chip, or chip system. This device can be installed in the terminal device or connected to and used with the terminal device. In the technical solutions provided in this application, the terminal device is used as an example to illustrate the technical solutions provided in this application.

[0043] In one example, the terminal device includes a modem, which comprises a NAS (Non-Access Stratum) layer, an RRC (Radio Resource Control) layer, a Packet Data Convergence Protocol (PDCP) layer, a Radio Link Control (RLC) layer, a Medium Access Control (MAC) layer, and a Physical (PHY) layer. Each of these layers can be a software module. The modem interacts with network devices via an antenna.

[0044] Network devices and / or terminal devices can be fixed or mobile. They can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; on water; or in the air on aircraft, balloons, and satellites. This application does not limit the application scenarios of the network devices and terminal devices. They can be deployed in the same or different scenarios; for example, both network devices and terminal devices can be deployed on land simultaneously; or, network devices can be deployed on land and terminal devices on water, etc., and so on.

[0045] Communication between network devices and terminal devices, between network devices, and between terminal devices can be conducted using licensed spectrum, unlicensed spectrum, or both simultaneously. Communication can be conducted using spectrum below 6 GHz, spectrum above 6 GHz, or both simultaneously. The embodiments of this application do not limit the spectrum resources used for wireless communication.

[0046] The core network's main functions include providing user connections, managing users, and carrying out service delivery, serving as the bearer network and providing an interface to external networks. User connection establishment includes functions such as mobility management (MM), call management (CM), and switching / routing.

[0047] For example, the core network of a 4G network is an evolved packet core (EPC) network. The EPC network possesses traditional mobile network capabilities such as user subscription data storage, mobility management, and data exchange, and can provide users with an ultra-high-speed internet experience. For example, the core network of a 5G network is a 5G Core (or 5GC for short). 5GC uses general-purpose network function virtualization devices to replace the dedicated communication equipment of 4G networks. The 6G core network further adopts a native artificial intelligence (AI) architecture. The core network is no longer just a passive forwarding and storage node, but has built-in distributed AI training / inference units. This means that the 6G core network itself is a giant distributed intelligent agent, capable of automatically learning, predicting, and optimizing its own behavior, and even providing computing power and AI model services to external applications.

[0048] As an example, the core network in this network architecture may include access and mobility management function (AMF) network elements, mobility management entity (MME), authentication server function (AUSF) network elements, user plane function (UPF) network elements, unified data management (UDM) network elements, and base station key management center (BKMC), etc.

[0049] The AMF network element is responsible for access authentication of terminal devices, ensuring that only legitimate users can access the network. It works in conjunction with UDM and AUSF to complete the two-way identity authentication and key negotiation authentication process, guaranteeing the security and legitimacy of user identities.

[0050] The core function of the MME is to manage the mobility of terminal devices. For example, it can locate terminal devices through the logical area of ​​the tracking area (TA). When a terminal device is not transmitting data, the MME only records its TA list. When downlink data arrives, the MME triggers paging and searches for the terminal device among all base stations in the TA list. When a terminal device moves during a call or data transmission, the MME is responsible for coordinating the handover process between base stations to ensure uninterrupted service. When a terminal device enters a new area, it reports its location, and the MME is also responsible for updating the records.

[0051] UPF network elements are primarily responsible for processing and forwarding user plane data. For example, they receive user data from base stations, perform necessary processing and forwarding, and ultimately deliver the user data to the target network or application server.

[0052] BKMC is primarily responsible for the entire process management of keys, including generation, storage, distribution, updating, recovery, backup, and destruction.

[0053] Each network element in the core network can also be called a functional entity. It can be a network element implemented on dedicated hardware, a software instance running on dedicated hardware, or an instance of virtualized function on an appropriate platform.

[0054] It should be understood that all network element names in this application are merely examples. In future communications, such as 6G, they may be referred to by other names, or in future communications, such as 6G, the network elements involved in this application may be replaced by other entities or devices with the same function, etc., and this application does not limit them in any way. This is a unified explanation here and will not be repeated hereafter. Optionally, the various network elements in the embodiments of this application may be communication devices, or chips or chip systems that can be used in the communication devices, etc., and this application does not limit them in any way.

[0055] Understandable Figure 1 The core network in the network architecture shown may also include other devices, network elements, network entities, or network subsystems, such as serving gateway (SGW) network elements, policy control function (PCF) network elements, session management function (SMF) network elements, etc. This application embodiment does not limit this. It should be noted that this application embodiment does not limit the distribution method of each network element in the core network; the specific distribution method can be found in relevant technical documents, and will not be elaborated upon here.

[0056] For ease of understanding, the terminology used in the embodiments of this application will be briefly explained below. Optionally, the explanation of some terms may also refer to the explanation in the 3rd Generation Partnership Project (3GPP) standard protocol.

[0057] 1. Anchor point gNB This refers to the last gNB that provides services to the terminal device before it enters the RRC_INACTIVE state. The anchor gNB is responsible for storing the terminal device's context information, including security keys, capability information, SDT configuration, and inactive radio network temporary identifier (I-RNTI).

[0058] Similarly, the anchor cell refers to the last cell that provides service to the terminal device before it enters the RRC_INACTIVE state. The anchor cell is a logical partition within the coverage area of ​​the anchor gNB.

[0059] 2. Service gNB This refers to the gNB corresponding to the cell where the terminal device currently resides after cell reselection. If the terminal device has not moved, the serving gNB is the anchor gNB; once the terminal device reselects to another gNB, the serving gNB becomes the new gNB, but the anchor gNB remains the original gNB.

[0060] Similarly, the serving cell refers to the cell where the device is currently camped through cell reselection; in other words, the serving cell is the cell currently providing network connectivity services to the terminal device. The serving cell is a logical partition within the coverage area of ​​the serving gNB.

[0061] 3. Xn interface It is the communication interface between base stations, used to perform critical context acquisition and path forwarding functions.

[0062] 4. Three connection states of terminal devices The three connection states of the terminal device include: radio resource control (RRC) inactive state (RRC_INACTIVE), RRC connected state (RRC_CONNECTED), and RRC idle state (RRC_IDLE).

[0063] In the RRC_CONNECTED state, the terminal device has established an RRC connection with the network and is in an active communication state. Both the network and the terminal device store complete context information, including radio resource configuration, security parameters, etc., supporting bidirectional data transmission. The RRC_CONNECTED state is suitable for scenarios that require continuous data transmission.

[0064] In the RRC_INACTIVE state, the terminal device maintains a partial connection with the network and is in a low-power standby state. Both the network and the terminal device store some context information. The terminal device typically needs to quickly enter the RRC_CONNECTED state through the RRC recovery process to enable normal transmission and reception of user data. The RRC_INACTIVE state is suitable for scenarios requiring intermittent data transmission.

[0065] In the RRC_IDLE state, the terminal device has not established an RRC connection with the network and is in a completely idle state. Neither the network nor the terminal device stores context information. The terminal device cannot send or receive user data, and typically cannot receive paging messages from the network. There is almost no signaling interaction between the terminal device and the network; it only initiates a random access procedure when a connection needs to be established. The RRC_IDLE state is suitable for scenarios where data transmission is not required for extended periods.

[0066] The connection state of a terminal device transitions between the three states described above. For example, when a terminal device needs to send or receive data, it initiates a random access procedure to the network, establishes an RRC connection, and enters the RRC_CONNECTED state. When the terminal device has no data transmission needs for a period of time, the network can initiate an RRC connection release procedure, transferring the terminal device to the RRC_INACTIVE state. When the terminal device has data transmission needs or receives a paging message from the network, it initiates an RRC connection recovery procedure, re-establishes the RRC connection, and enters the RRC_CONNECTED state. If the terminal device has no data transmission needs for an extended period in the RRC_INACTIVE state, the network can initiate an RRC connection release procedure, transferring the terminal device to the RRC_IDLE state.

[0067] From the perspective of connection establishment delay and signaling overhead, RRC_INACTIVE is more efficient than RRC_IDLE. From the perspective of saving points, RRC_INACTIVE is more efficient than RRC_CONNECTED. Therefore, RRC_INACTIVE may become a more commonly used state in future communication systems.

[0068] 5. I-RNTI The I-RNTI is a temporary radio network identifier used to uniquely identify terminal devices in the RRC_INACTIVE state, and can be assigned by the anchor gNB. In the RRC_INACTIVE state, both the network and the terminal device use the I-RNTI to uniquely identify and address the terminal device. The I-RNTI consists of two parts: the device identifier of the anchor gNB and the unique device identifier of the terminal device under the anchor gNB. In the RRC_INACTIVE state, if the terminal device performs cell reselection, and the Xn interface between the serving gNB and the anchor gNB is reachable, the serving gNB can request the complete uplink and downlink information of the terminal device from the anchor gNB based on the I-RNTI, and implement path forwarding functionality.

[0069] 6. Radio Access Network-based notification area (RNA) An RNA (RNAi) is a geographical region planned by the network (such as the AMF element on the core network side) and can be used to manage terminal devices in the RRC_INACTIVE state. When a terminal device moves within an RNA, it does not need to notify the network and can freely perform cell reselection; when a terminal device moves out of an RNA, it needs to initiate an RNA update procedure to notify the network to update its location. An RNA can contain one or more cells.

[0070] 7. Configure Grant (CG) - SDT Resource Pool The CG-SDT resource pool includes all CG-SDT resource blocks (referred to as resource blocks) within the RNA. As an example of this application, the network can pre-divide a sub-resource pool for each cell within the RNA, and a sub-resource pool includes at least one resource block. The CG-SDT resource pool includes sub-resource pools for all cells within the RNA. The CG-SDT resource pool has a fixed frequency and repeats periodically over time.

[0071] 8. Root Key (K) It is the long-term key for RNA-internal access network devices (such as gNBs). The root key can be distributed by the BKMC. The root key is not transmitted over the air interface.

[0072] 9. Authentication Code (MAC) This is used for authenticating the CG-SDT resources configured by the anchor gNB for the terminal device, and for authenticating the terminal device itself. The authentication code can be generated based on the root key, sequence number, and random number, such as... .in The function generates the network authentication code. SQN is a time-related sequence number generated by the network (such as the anchor gNB) to ensure that each authentication request from the network to the terminal device is fresh and unique, thus effectively resisting replay attacks; RAND is a random number generated by the network (such as the anchor gNB).

[0073] 10. Encryption Key (CK) Used to encrypt user data, it can be generated based on a root key and a random number, such as .in This is a cryptographic key generation function defined in the standard.

[0074] 11. Integrity Protection Key (IK) Used for integrity protection of user data, it can also be generated based on the root key and random numbers, such as... .in This is an integrity key generation function defined in the standard.

[0075] 12. Schedule in advance Timing advance (TA), also known as time lead, is used to indicate how much advance time a terminal device needs to send uplink data to compensate for signal transmission delays in space and ensure that uplink signals from different terminal devices arrive simultaneously and in alignment on the network device side. In some communication systems (such as 6G), the TA of the cell to be switched can be obtained in advance before the terminal device officially switches over.

[0076] It should be understood that the technical terms used in the embodiments of this application are merely examples and not limitations. For example, as technology evolves, technical terms may also change, and other technical terms with the same technical meaning should also apply to this application.

[0077] In New Radio (NR), SDT (Small Data Transmission) was introduced in Rel-17. As mentioned earlier, SDT allows terminal devices to transmit small amounts of data while maintaining the RRC_INACTIVE state. SDT is a fundamental function for data transmission in the RRC_INACTIVE state. SDT can be initiated via RACH transmission or via Type 1 configured channel resources; the former is called RA-SDT, and the latter is called CG-SDT. The RA-SDT scheme allows terminal devices to carry user data in the first few steps of the random access procedure while in the RRC inactive state, such as carrying small data packets in MsgA (the first message) and Msg3 (the third message). The CG-SDT scheme allows network devices to configure dedicated uplink resources for terminal devices in the RRC_INACTIVE state. When a terminal device needs to upload a small amount of data, it can directly use these pre-configured uplink resources to send data without going through the cumbersome random access and connection recovery process, thereby reducing transmission latency and device power consumption.

[0078] This application primarily focuses on the CG-SDT scheme, which currently does not support mobility. Although some proposals suggest that after cell reselection within the RNA, the serving gNB obtains the terminal device's context information from the anchor gNB via the Xn interface, enabling mobility support in the SDT process, issues such as lack of inter-vendor equipment connectivity, unsupported deployment scenarios, or link failures can render the Xn interface between the serving gNB and the anchor gNB unavailable. This prevents the serving gNB from successfully obtaining the terminal device's context information from the anchor gNB. Consequently, the serving gNB cannot verify the terminal device's identity or obtain the security key. Furthermore, the serving gNB cannot understand the SDT resources configured by the anchor gNB for the terminal device, including CG resource allocation and radio bearer configuration. The serving gNB also cannot handle downlink data arrival events and subsequent uplink data forwarding. In such cases, the terminal device may be forced to transition to the RRC_IDLE state and establish a complete connection from scratch, which contradicts the original intention of SDT—reducing signaling overhead and rapidly transmitting small data.

[0079] In addition, the current CG-SDT solution also has the following problems: 1. The current SDT procedure is restricted to the initial bandwidth portion (initial BWP), but the initial BWP has a narrow bandwidth, allowing the SDT procedure to support only a very small amount of data transmission, which is insufficient to meet the needs of real-world applications. In some cases, the amount of data to be transmitted may not be completed in a single SDT procedure, resulting in frequent switching between active and released RRC states. Furthermore, since both the SDT procedure and the Random Access Response (RACH) procedure are executed on the initial BWP, sharing the same bandwidth resource significantly increases the probability of collisions in the RACH procedure.

[0080] 2. In some configurations, the maximum duration of the SDT process is limited to 4 seconds. This short time window results in low transmission efficiency. Taking chat applications as an example, although such applications themselves do not need to transmit large amounts of data, once a session begins, text message sending is often continuous and will not end naturally within 4 seconds. However, due to the 4-second termination mechanism of SDT, the system needs to repeatedly send RRCresumRequest and RRCrease messages, resulting in significant signaling overhead.

[0081] 3. Pre-configured SDT resources are dedicated resources assigned to terminal devices by the anchor gNB. When a terminal device switches to a new cell, it still believes it is using "dedicated" resources, while the new serving gNB treats these resources as part of a public resource pool. This difference in perception causes the dedicated attribute of the originally pre-configured SDT resources to immediately become invalid. The new serving gNB may force the terminal device to fall back from the RRC_INACTIVE state to the RRC_IDLE state and establish a complete connection from scratch, a process that violates the original design intent of SDT.

[0082] In view of this, embodiments of this application provide a data transmission method in which an anchor gNB pre-generates an independently verifiable authentication vector and configures it for the terminal device along with a first CG-SDT resource. The first CG-SDT resource is a sub-resource pool of the CG-SDT resource pool allocated by the network to all cells within the RNA. When the terminal device needs to transmit small amounts of data, it transmits uplink data carrying the authentication vector on the first CG-SDT resource. This allows the serving gNB to receive the uplink data on the first CG-SDT resource and process the data through local verification, avoiding the need to obtain context information from the anchor gNB. This achieves low-latency, high-reliability small data transmission.

[0083] Furthermore, the first CG-SDT resource can be dedicated to transmitting uplink data, with unlimited bandwidth, supporting more small data transmissions. It also avoids the problem of increased collision probability in the RACH process caused by the SDT process needing to share bandwidth resources with the RACH process.

[0084] Furthermore, the first CG-SDT resource is periodic and has no maximum duration limit, which improves SDT efficiency and extends the duration of SDT.

[0085] In addition, since the first CG-SDT resource is allocated based on the CG-SDT resource pool within the RNA, the anchor gNB and the service gNB within the RNA have the same understanding of the first CG-SDT resource, thus avoiding misalignment between the anchor gNB and the service gNB regarding the CG-SDT resources allocated to the terminal device.

[0086] The data transmission method provided in this application can be applied to, but is not limited to, the following typical application scenarios: (1) Application layer keep-alive and push mechanism This type of traffic mainly includes heartbeat packets or keep-alive messages sent periodically by instant messaging, email clients and other web applications to maintain long-term connections. In addition, push notification services of various applications (such as social, news, system notifications, etc.) also rely on frequent small data packet interactions to ensure real-time message delivery.

[0087] (2) Periodic reporting of Internet of Things and smart devices This type of traffic comes from a wide range of sources, such as wearable devices periodically uploading location information and health monitoring data, industrial sensor networks transmitting sensor readings of temperature, pressure, vibration, etc. in a periodic or event-triggered manner, and smart meters and smart meter networks periodically reporting metering readings of electricity, water, gas, etc.

[0088] (3) Generative AI (GenAI) interactive traffic In generative AI applications, especially in text-based interaction scenarios with generative pre-trained transformers (GPTs), the data packet size involved in a single query and response is typically small, such as about 0.5 KB. Queries and responses are generally generated and transmitted within the same cycle, and this type of query / response cycle occurs infrequently, primarily driven by the user's proactive query behavior.

[0089] The data transmission scheme provided in this application will be described in detail below with reference to the corresponding flowcharts. It is understood that the illustrative flowcharts provided in this application mainly use different devices (e.g., terminal devices, network devices) as examples of the execution subjects of this interactive illustration to illustrate the method, but this application does not limit the execution subjects of the interactive illustrations. For example, the devices (e.g., terminal devices, network devices) in the illustrative flowcharts can also be chips, chip systems, or processors that support the implementation of this method on the device, or logic modules or software that can implement all or part of the functions of the device.

[0090] As a general statement, the message or signaling interactions involved in the interaction process of this application embodiment can be standard messages or signaling or newly introduced messages or signaling. This application embodiment does not make specific limitations on this.

[0091] Figure 2 This is a flowchart illustrating a data transmission method provided in an embodiment of this application. Figure 2 The terminal device in the middle can be Figure 1 The term "terminal device" can also refer to a component within the terminal device (such as a processor, chip, or chip system). Both the first and second network devices can be... Figure 1 The term "access network equipment" can also refer to devices within the access network equipment (such as processors, chips, or chip systems). The first network device and the second network device are not the same. For example, the first network device might be the serving gNB, and the second network device might be the anchor gNB. That is, the first network device is the network device that camps on the cell after cell reselection, while the second network device is the network device that camps on the cell before cell reselection. Figure 2 As shown, this data transmission method includes some or all of the following: In step S210, the terminal device performs cell reselection while the RRC is inactive.

[0092] In one example, the second network device triggers the terminal device to enter the RRC inactive state. For instance, when the second network device decides to release the RRC connection but wants the terminal device to remain in the RRC inactive state, it sends an RRCrelease message to the terminal device, triggering the terminal device to enter the RRC inactive state.

[0093] As an example of this application, before entering the RRC inactive state, the terminal device receives a first message sent by the second network device. Optionally, the first message can be an RRC release message. The first message includes first configuration information and an authentication vector. The first configuration information is used to indicate a first CG-SDT resource, which is used by the terminal device to transmit small data in the RRC inactive state. The authentication vector includes authentication parameters, which are used by the first network device to perform legitimacy authentication based on the root key.

[0094] As an example, the first CG-SDT resource is a sub-resource pool within the CG-SDT resource pool of the RNA, where the RNA includes the coverage areas of the first network device and the second network device. As mentioned earlier, the CG-SDT resource pool within the RNA can be pre-configured for cells within the RNA by the network (e.g., the core network). The CG-SDT resource pool has a fixed frequency and repeats periodically over time. A CG-SDT resource pool within a cycle includes multiple resource blocks, and the network can allocate a sub-resource pool to each cell within the RNA from this CG-SDT resource pool. A cell's sub-resource pool includes one or more resource blocks. See also... Figure 3 The process of allocating a sub-resource pool to each cell within the RNA network can include the following implementation steps A1-A4: A1: Assign CG-SDT resource pools to cells within RNA.

[0095] The configuration parameters for the CG-SDT resource pool include the CG-SDT resource cycle and the CG-SDT resource frequency.

[0096] A2: Number the resource blocks within a cycle of the CG-SDT resource pool.

[0097] The network can number the resource blocks of the CG-SDT resource pool within a period according to a preset numbering rule. For example, if the CG-SDT resource pool includes M resource blocks in a period, these resource blocks can be numbered from 0 to M-1, or from 1 to M. For instance, if M is 30, then the 30 resource blocks included in the CG-SDT resource pool in a period can be numbered sequentially as 0, 1, 2, 3, 4, ..., 29.

[0098] A3: Assign sub-resource pools to each cell within the RNA within the CG-SDT resource pool.

[0099] The network can allocate sub-resource pools within the CG-SDT resource pool to each cell in the RNA based on the number of cells and the total number of resource blocks. A sub-resource pool includes one or more resource blocks, and the total number of resource blocks is the total number of resource blocks contained in the CG-SDT resource pool within one cycle. For example, if the total number of cells in the RNA is n, then the number of resource blocks included in the sub-resource pool allocated to each cell in the CG-SDT resource pool is M / n, meaning the number of resource blocks included in each cell's sub-resource pool is the quotient of the total number of resource blocks and the number of cells. For instance, when n is 5, each cell's sub-resource pool includes 6 resource blocks.

[0100] It should be noted that the embodiments of this application are illustrated by taking the average allocation of resource blocks to each cell as an example. In another example, sub-resource pools can also be allocated to each cell according to other strategies. That is, the number of resource blocks included in the sub-resource pools of each cell may be different. The embodiments of this application do not limit this.

[0101] A4: Determine the starting position of each cell's sub-resource pool within the CG-SDT resource pool.

[0102] As an example, for any cell within the RNA, the starting position of the sub-resource pool allocated to that cell can be determined based on the cell identifier, prime number, and total number of resource blocks. For instance, the starting position can be calculated as (cell identifier × prime number) modulo the total number of resource blocks N, where mod is the modulo operation. The prime number can be configured by the network or specified by the protocol, and it is necessary to ensure that the starting positions of the sub-resource pools for each cell are different. For example, the prime number can be greater than a certain value, which is the product of the total number of cells within the RNA and the number of resource blocks contained in the sub-resource pool of each cell.

[0103] For example, if a cell has a cell identifier of 2, a prime number of 13, and a total number of resource blocks of 30, then the starting position of the sub-resource pool of the cell is (2×13) mod 30, that is, the starting position is 26.

[0104] Knowing the starting position of each cell's sub-resource pool within the CG-SDT resource pool and the number of resource blocks included in each sub-resource pool, it is possible to determine which resource blocks are included in each cell's sub-resource pool. For example, if the CG-SDT resource pool contains 30 resource blocks numbered 0, 1, 2, 3, 4, ..., 29 within a given period, and a cell's starting position is 26, and its sub-resource pool contains 6 resource blocks, then the resource block numbers included in that cell's sub-resource pool can be determined to be 26, 27, 28, 29, 0, and 1.

[0105] When the second network device decides to release the RRC connection but wants the terminal device to remain in the RRC inactive state, if the terminal device is determined to be a CG-SDT candidate based on its service characteristics, such as the terminal device's service being frequent, having small data volume, and low latency, then the second network device configures the first CG-SDT resource for the terminal device in the first sub-resource pool of the anchor cell and determines the first configuration information used to indicate the first CG-SDT resource.

[0106] The first configuration information includes the CG-SDT resource period, CG-SDT resource frequency, and CG-SDT indication information. The CG-SDT indication information indicates the set of resource blocks configured for the terminal device in the first sub-resource pool. The first sub-resource pool includes resource blocks allocated for the anchor cell within one period of the CG-SDT resource pool. The anchor cell is the cell in which the terminal device camps before cell reselection.

[0107] The first sub-resource pool can be determined based on its starting position and the number of resource blocks it contains. As mentioned earlier, the starting position of the first sub-resource pool can be determined by the cell identifier, prime number, and total number of resource blocks of the anchor cell. The method for determining the first resource pool of the anchor cell is described above. The number of resource blocks contained in the first sub-resource pool is determined based on the total number of resource blocks and the total number of cells within the RNA; the specific implementation can also be found above. For example, if the cell identifier of the anchor cell is 2, then according to the above process, the resource block numbers contained in the first sub-resource pool can be determined to be 26, 27, 28, 29, 0, and 1, respectively.

[0108] The set of resource blocks configured for the terminal device in the first sub-resource pool can be determined based on the device identifier of the terminal device and the number of resource blocks contained in the first sub-resource pool. As an example, the resource block offset can be determined based on the device identifier of the terminal device and the number of resource blocks contained in the first sub-resource pool, thereby determining the set of resource blocks configured for the terminal device in the first sub-resource pool. The resource block offset indicates the offset of the set of resource blocks allocated to the terminal device relative to the initial position of the first sub-resource pool. For example, the resource block offset is the modulo operation result between the device identifier of the terminal device and the number of resource blocks contained in the first sub-resource pool. For instance, if the device identifier of the terminal device is 45 and the number of resource blocks contained in the first sub-resource pool is 6, then the resource block offset is 45 mod 6, which is 3.

[0109] In one example, the CG-SDT indication information includes the index information of the first CG-SDT resource. For instance, if the resource block number included in the first CG-SDT resource is 29, then the index information included in the CG-SDT indication information is 29, meaning the index information includes the resource block number.

[0110] In another example, the CG-SDT indication information includes the starting position and resource block offset of the first sub-resource pool. For instance, if the starting position of the first sub-resource pool is 26 and the resource block offset is 3, then the first CG-SDT resource can be determined to include the fourth resource block in the first sub-resource pool, which is numbered 29.

[0111] It should be noted that the content included in the above CG-SDT indication information is only exemplary. In another example, the CG-SDT indication information may also include other parameters that can indicate the set of resource blocks configured for the terminal device in the first sub-resource pool, such as the total number of resource blocks, the total number of cells in the RNA, the prime number, and I-RNTI, so that the terminal device can determine the first CG-SDT resource based on these parameters.

[0112] It should be noted that the embodiments in this application are illustrated using the example of a first CG-SDT resource comprising one resource block. In another example, the first CG-SDT resource may also comprise multiple resource blocks. In this case, when the CG-SDT indication information includes index information, the index information includes multiple numbers; or when the CG-SDT indication information includes the starting position of the first sub-resource pool and the resource block offset, it also includes the number of resource blocks in the first CG-SDT resource.

[0113] In addition, the second network device generates an authentication vector. The authentication vector includes authentication parameters related to the root key. For example, the authentication parameters include the authentication code MAC, the sequence number SQN, and the random number RAND. Optionally, the authentication vector also includes a first encryption key CK and a first integrity protection key IK. The first encryption key CK is used by the terminal device to encrypt user data, and the first integrity protection key IK is used by the terminal device to protect the integrity of user data.

[0114] For example, the second network device generates a random number RAND and a time-related sequence number SQN. Based on the random number RAND, the sequence number SQN, and the stored root key, it generates a first authentication code MAC for the terminal device, MAC = f1(K, SQN, RAND), and uses the random number RAND, the sequence number SQN, and the first authentication code MAC as authentication parameters. Optionally, the second network device can also generate a first encryption key CK for the terminal device based on the random number and the root key, CK = f3(K, RAND), and a first integrity protection key IK for the terminal device based on the random number and the root key, IK = f4(K, RAND).

[0115] The second network device stores a root key. As mentioned earlier, the root key is a long-term key within the RNA, meaning all network devices within the RNA hold the same root key. The root key can be generated by BKMC for each network device within the RNA and bound to the RNA's region identifier. It is stored in the network device's hardware encryption device. For details on the distribution process of the root key for RNA regions, please refer to [link to relevant documentation]. Figure 7 The example shown.

[0116] It should be noted that the embodiments of this application are illustrated using the example of authentication parameters including random number RAND, serial number SQN and first authentication code MAC. In another example, the authentication parameters may also include other parameters related to legitimacy authentication, which are not specifically limited in this embodiment of the application.

[0117] Subsequently, the second network device sends the authentication vector and the first configuration information of the first CG-SDT resource to the terminal device. For example, the authentication vector may include MAC, RAND, SQN, CK, and IK. As an example, the second network device may carry configuredGrantConfig and the authentication vector in the RRCrelease message, where configuredGrantConfig contains the first configuration information.

[0118] As an example of this application, the first message is an encrypted RRC release message, i.e., the first message is an encrypted RRCrelease message. The second network device sends the first message to the terminal device through an encrypted channel. After receiving the encrypted RRCrelease message, the terminal device decrypts it, then enters the RRC inactive state, carrying the first configuration information and authentication vector as it moves. When moving to a new cell, the terminal device performs cell reselection, switching from the anchor cell to the new cell, hereinafter referred to as the serving cell. As an example, after cell reselection, the network device to which the terminal device camps (i.e., the serving cell) belongs is the first network device, which is different from the second network device.

[0119] It is worth mentioning that the second network device sends the authentication vector and the first configuration information to the terminal device through an encrypted channel, which can ensure the security of the authentication vector transmission, thereby ensuring the effectiveness and reliability of subsequent authentication.

[0120] It should be noted that this application embodiment is illustrated using the RRCrelease message as the first message. In another example, the first message may be other messages, such as a message sent before sending the RRCrelease message. This application embodiment does not limit this.

[0121] In addition, the RRCrelease message also contains the suspendConfig configuration, which includes I-RNTI, etc.

[0122] Step S220: When the SDT procedure is triggered, uplink data is sent to the first network device of the currently camped cell on the first CG-SDT resource. The uplink data includes SDT data and authentication parameters. Correspondingly, the first network device receives the uplink data sent by the terminal device on the first CG-SDT resource.

[0123] For example, the uplink data is a Medium Access Control Protocol Data Unit (MAC PDU). The plaintext of the MAC PDU includes authentication parameters RAND, SQN, and MAC. As an example, the MAC PDU also includes encrypted and integrity-protected user data; that is, the SDT data can be encrypted data, where the encrypted data is obtained by encrypting and protecting the user data according to a first encryption key CK and a first integrity protection key IK, respectively.

[0124] In one example, see Figure 4 The specific implementation of step S220 may include the following implementation steps B1 to B8: B1: The upper layer of the terminal device generates user data to be transmitted.

[0125] For example, the NAS layer or application layer of a terminal device generates user data to be transmitted. For instance, when sensor data reaches a certain threshold, the NAS layer generates user data to be transmitted; or, when a user sends an email through an email application, the application layer generates user data, which includes email data such as the email body.

[0126] B2: Determine whether the amount of data for this user is less than the first threshold.

[0127] The first threshold can be configured by the first network device, or it can be specified by the protocol. For example, the first threshold is represented as sdt-DataVolumeThreshold.

[0128] If the amount of user data is less than the first threshold, it means that the user data meets the SDT data volume transmission condition, i.e., the user data is small data. In this case, the terminal device enters operation B3 as follows. Otherwise, if the amount of user data is greater than or equal to the first threshold, it means that the user data does not meet the SDT data volume transmission condition, i.e., the user data is not small data. In this case, the terminal device enters operation B7 as follows.

[0129] B3: Determine whether the signal strength of the serving cell is greater than the second threshold.

[0130] The second threshold can be configured by the first network device, or it can be specified by the protocol. For example, the second threshold is represented as sdt-RSRP-Threshold.

[0131] Because SDT transmission is prone to failure under weak signal conditions, once it fails, the terminal device has to revert to the normal RRC connection establishment process. After data transmission, the terminal device may return to the RRC inactive state. This repeated state switching by the terminal device negates the energy-saving advantages of SDT. Therefore, to ensure uplink quality and system stability, and to prevent signaling storms and resource waste caused by small data transmissions under weak signal conditions, the SDT process must also meet the condition that the signal strength of the serving cell is greater than the second threshold.

[0132] In one example, the terminal device can measure the reference signal received power (RSRP) of the serving cell. If the RSRP of the serving cell is greater than or equal to a second threshold, it indicates that the signal strength of the serving cell is strong and the coverage is good. In this case, the terminal device proceeds to operation B4 below. Otherwise, if the RSRP of the serving cell is less than the second threshold, it indicates that the signal strength of the serving cell is weak and the coverage is poor. In this case, the terminal device proceeds to operation B7 below.

[0133] B4: If the first CG-SDT resource is configured for the terminal device, then determine whether the TA value is valid.

[0134] Before cell handover, the terminal device can obtain the TA values ​​of multiple nearby cells, including the serving cell, through measurement and other methods. After the terminal device performs cell reselection, it may have moved tens or even hundreds of meters. At this time, the TA value of the serving cell may have become invalid. If uplink data is sent with an invalid TA value, it is easy to cause inter-slot interference between the uplink data sent by the terminal device and the uplink data sent by other terminal devices on the first network device side, affecting the user experience. Therefore, when the terminal device is configured with the first CG-SDT resource, before transmitting uplink data on the first CG-SDT resource, the terminal device can also determine whether the TA value of the serving cell is valid. If the TA value is valid, proceed to operation B5 below; otherwise, if the TA value of the serving cell is invalid, proceed to operation B8 below.

[0135] In one example, the TA value corresponds to a time alignment timer (TAT). The terminal device can determine whether the TA is invalid based on the TAT. For example, if the TAT times out, the terminal device determines that the TA is invalid; otherwise, if the TAT does not time out, the terminal device determines that the TA is not invalid.

[0136] It should be noted that step B4 is an optional operation. In another example, it is not necessary to determine whether the TA value is valid. For example, if the second network device has configured the first CG-SDT resource for the terminal device, the operation in step B5 can be directly entered. This application embodiment does not limit this.

[0137] B5: The terminal device uses the first encryption key CK and the first integrity protection key IK to encrypt and protect the integrity of the user data to be transmitted, and obtains encrypted data.

[0138] It should be noted that B5 is an optional step. For example, in an optional embodiment, the user data may not be encrypted and protected for integrity. In this case, the SDT data is the user data itself. This application does not limit this.

[0139] B6: The terminal device sends a MAC PDU to the first network device of the serving cell on the first CG-SDT resource.

[0140] Both the first and second network devices are located within the RNA, and both hold the same root key.

[0141] The plaintext of the MAC PDU carries RAND, SQN, and MAC, followed by encrypted and protected user data.

[0142] In one example, in addition to SDT data and authentication parameters, the MAC PDU may also include I-RNTI, which can be used by the first network device to identify the terminal device.

[0143] B7: The terminal device sends an RRRCResumeRequest message to the first network device.

[0144] If the amount of user data is greater than or equal to the first threshold, or if the RSRP of the serving cell measured by the terminal device is less than or equal to the second threshold, it indicates that the transmission conditions of SDT are not met. In this case, the terminal device sends an RRCResumeRequest message to the first network device to request the establishment of an RRC connection.

[0145] B8: The terminal device initiates the RA-SDT process.

[0146] If the TA value of the serving cell is invalid, the terminal device needs to reacquire the TA value of the serving cell to ensure that user data can be successfully transmitted and will not interfere with the user data of other terminal devices. For this purpose, the terminal device needs to initiate the RA-SDT procedure so that the first network device can calculate a new and accurate TA value based on the preamble sent by the terminal device and configure it to the terminal device.

[0147] For the first network device, it can detect uplink data in the CG-SDT resource pool, for example, by periodically detecting it according to the CG-SDT resource cycle. Since the first CG-SDT resource is a resource in the CG-SDT resource pool, the first network device can receive uplink data sent by the terminal device on the first CG-SDT resource. After receiving the uplink data, the first network device decodes the uplink data, performs legitimacy authentication based on the authentication parameters obtained from the decoding, and, if the authentication is successful, decodes the encrypted data and then sends the decrypted user data to the target network element, such as the UPF network element. See [example example] for further details. Figure 5 The specific operation of the first network device may include the following implementation steps C1 to C8: C1: The first network device detects and decodes uplink data on the first CG-SDT resource.

[0148] As described above, since the first CG-SDT resource is a sub-resource pool within the CG-SDT resource pool, when the terminal device sends uplink data on the first CG-SDT resource, the first network device can receive the uplink data on the first CG-SDT resource. After receiving the uplink data, the first network device can decode the uplink data to obtain the authentication parameters and encrypted data.

[0149] C2: Did the first network device successfully decode? If decoding failed, proceed to step C3. If decoding was successful, proceed to step C4.

[0150] In the hybrid automatic repeat reQuest (HARQ) mechanism, after the first network device successfully decodes the data, it can send an ACK code to the terminal device to notify the terminal device that decoding was successful and no retransmission is needed. The first network device then proceeds to operation C4. Otherwise, if decoding fails, the first network device sends a NACK code to the terminal device to notify the terminal device of decoding failure and proceeds to operation C3.

[0151] C3: Revert to the RA-SDT process.

[0152] C4: The first network device determines the second authentication code based on the random number and sequence number in the authentication parameters, as well as the stored root key.

[0153] For example, the second authentication code XMAC = f1(K, SQN, RAND).

[0154] C5: The first network device determines whether the first authentication code and the second authentication code are the same, and whether the freshness verification of the SQN is successful.

[0155] Since the second authentication code is generated based on the random number RAND, the sequence number SQN, and the root key, and the random number RAND and sequence number are generated by the first network device, if the second authentication code is the same as the first authentication code reported by the terminal device, it means that the root key held by the first network device is the same as the root key held by the second network device. This confirms that the first CG-SDT resource was allocated by the second network device, thus achieving authentication of the legitimacy of the resource allocation. Furthermore, if the first authentication code is the same as the second authentication code, and the freshness verification of the SQN passes, it indicates that the uplink data is fresh and not replayed, meaning it was not obtained and replayed by an attacker. The authentication parameters reported by the terminal device are the authentication parameters sent by the second network device. Since the authentication parameters and the first CG-SDT resource are sent to the terminal device by the second network device, for example, through an encrypted channel, an unauthorized terminal device typically cannot obtain the first CG-SDT resource and authentication parameters allocated by the second network device. Therefore, this indirectly verifies the legitimacy of the terminal device, and the first network device confirms that the legitimacy authentication of the terminal device has passed.

[0156] In one example, the first network device can match the Sequence Number (SQN) in the authentication parameters with a known time window. If the SQN reported by the terminal device falls within the time window, it indicates that the uplink data is fresh, thus confirming that the freshness verification of the reported SQN has passed. Otherwise, if the SQN reported by the terminal device does not fall within the time window, it is determined that the freshness verification of the reported SQN has failed.

[0157] If the validity verification passes, proceed to operation C6; otherwise, discard the upstream data and proceed to operation C3.

[0158] C6: The first network device determines the second encryption key and the second integrity protection key based on the random number and the root key.

[0159] The root key is stored in the first network device. The root key allocation process can be found in the following example. Figure 7The illustrated embodiment. Thus, after receiving uplink data sent by the terminal device, the first network device can generate a second encryption key based on the root key and the random number carried in the uplink data, and generate a second integrity protection key based on the root key and the random number carried in the uplink data, such as the second encryption key XCK = f3(K, RAND) and the second integrity protection key XIK = f4(K, RAND).

[0160] C7: The first network device performs integrity verification and decryption processing on the encrypted data based on the second integrity protection key and the second encryption key, respectively, to obtain the user data.

[0161] The first network device uses the second integrity key to verify the integrity of the encrypted data. If the verification is successful, the first network device uses the second encryption key to decrypt the encrypted data, thereby obtaining the user data.

[0162] C8: The first network device sends user data to the UPF network element.

[0163] After successful decryption and integrity verification, the first network device directly sends the user data to the UPF network element, for example, by sending the user data to the UPF network element through the NG-U interface. In this way, the first network device achieves data forwarding without any signaling interaction with the second network device.

[0164] It should be noted that the embodiments of this application are illustrated by taking the example of the first network device sending user data to the UPF network element. In another example, the first network device may also send user data to other nodes, such as the AMF network element. The embodiments of this application do not limit this.

[0165] In this embodiment, before the terminal device enters the RRC inactive state, the second network device configures independently authenticable authentication parameters for the terminal device and configures a first CG-SDT resource for the terminal device from the pre-configured CG-SDT resource pool of the RNA. The terminal device moves carrying the authentication parameters. After handover to a new cell, when small data needs to be transmitted, the terminal device can directly send uplink data on the first CG-SDT resource, and the uplink data includes the authentication parameters. Since the coverage area of ​​the first network device providing services to the terminal device after handover is also within the RNA range, and the CG-SDT resource pool is known to the first network device, the first network device can receive the uplink data sent by the terminal device on the first CG-SDT resource. The first network device can achieve local authentication based on the authentication parameters in the uplink data. In this way, small data processing of the SDT process is realized without obtaining the context information of the terminal device from the second network device, thereby enabling CG-SDT to support cell reselection.

[0166] It should be noted that the authentication parameters in this embodiment differ from resumeMAC-I in related technologies. resumeMAC-I is generated from the key KRRCint, the PCI of the current serving cell, and C-RNTI. KRRCint is closely related to the terminal device and is a private key shared between the terminal device and the base station. When the terminal device sends an RRC connection recovery request (RRCResumeRequest) message, it needs to use the KRRCint key to perform calculations on the inputs (such as PCI and C-RNTI) to generate a "signature" that only a legitimate terminal device can generate. The base station uses its own KRRCint to verify this signature, thereby confirming the true identity of the terminal device. However, different base stations have different KRRCints. In a cell handover scenario, the new serving base station does not hold the anchor base station's KRRCint, so it cannot generate resumeMAC-I locally. This means that the serving base station needs to forward the RRRCResumeRequest message sent by the terminal device to the anchor base station for authentication via the Xn interface. If the Xn interface is unreachable, authentication cannot be achieved. Therefore, the method provided in this embodiment differs from related technologies.

[0167] To facilitate understanding, the communication method provided in the embodiments of this application will be described below with specific examples. See also Figure 6 , Figure 6 This is a flowchart illustrating a communication method according to an exemplary embodiment, which can be implemented through interaction between an anchor gNB, a serving gNB, and a terminal device. The method may include some or all of the following: S601: Anchor point gNB determines that the terminal device is a candidate for CG-SDT.

[0168] When the anchor gNB decides to release the RRC connection of the terminal device but wants the terminal device to remain in an RRC inactive state, the terminal device is determined to be a candidate for CG-SDT based on the service characteristics of the terminal device.

[0169] S602: The anchor gNB allocates the first CG-SDT resource to the terminal device in the CG-SDT resource pool.

[0170] For example, the CG-SDT resource pool includes 30 resource blocks, numbered 0, 1, 2, 3, 4, ..., 29. The RNA containing the anchor gNB includes 5 cells, and each cell's sub-resource pool includes 6 resource blocks. If the cell identifier of the anchor gNB is 2, then the starting position of the anchor gNB's sub-resource pool is 26. Therefore, the resource block numbers included in the first sub-resource pool of the anchor gNB are 26, 27, 28, 29, 0, and 1, respectively. If the device identifier of the terminal device is 45, then by performing a modulo operation between this device identifier and the number of resource blocks included in the sub-resource pool of a single cell, the offset of the first CG-SDT resource allocated to the terminal device relative to the starting position of the first sub-resource pool is determined to be 3. Therefore, the resource block number included in the first CG-SDT resource allocated to the terminal device is 29.

[0171] For a detailed implementation of the above process, please refer to [link / reference]. Figure 2 Step S210 in the embodiment.

[0172] S603: Anchor point gNB generates random numbers RAND and time-dependent SQN.

[0173] S604: Anchor gNB generates the first authentication code based on RAND and the stored root key K.

[0174] S605: Anchor point gNB generates the first encryption key based on RAND and K.

[0175] S606: Anchor gNB generates the first integrity protection key based on RAND and K.

[0176] S607: The anchor gNB sends an RRCRelease message to the terminal device. The RRCRelease message contains: suspendConfig configuration, configuredGrantConfig configuration and authentication vector. The configuredGrantConfig configuration contains first configuration information for indicating the first CG-SDT resource. The authentication vector contains MAC, RAND, SQN, CK and IK.

[0177] The anchor gNB sends the RRCRelease message to the terminal device through an encrypted channel, meaning the RRCRelease message is encrypted.

[0178] S608: The terminal device has entered the RRC inactive state.

[0179] After receiving the encrypted RRCRelease message, the terminal device decrypts the RRCRelease message to obtain the suspendConfig configuration, configuredGrantConfig configuration, and authentication vector carried in it, and stores the obtained data.

[0180] S609: In the RRC inactive state, the terminal device performs cell reselection.

[0181] S610: When the upper layer of the terminal device generates user data to be transmitted, if the amount of user data is less than the first threshold and the RSRP of the serving gNB is greater than the second threshold, the terminal device uses the first encryption key and the first integrity protection key to encrypt and protect the integrity of the user data respectively.

[0182] If the amount of user data is less than the first threshold and the RSRP of the serving gNB is greater than the second threshold, it means that the SDT process is currently met. The terminal device encrypts and protects the integrity of the user data to obtain encrypted data.

[0183] Optionally, if the amount of user data is less than the first threshold and the RSRP of the serving gNB is greater than the second threshold, the terminal device can query whether the current TA value is valid before processing the user data. If valid, encryption and integrity protection operations are performed; otherwise, the RA-SDT process is initiated. See the previous text for details.

[0184] S611: The terminal device sends a MAC PDU on the first CG-SDT resource indicated by the first configuration information. The MAC PDU includes RAND, SQN and MAC, and also includes encrypted and protected user data.

[0185] S612: The service gNB receives the MAC PDU on the first CG-SDT resource.

[0186] S613: The service gNB reads the RAND, SQN, and MAC from the MAC PDU.

[0187] S614: The service gNB determines the second authentication code based on the SQN and RAND.

[0188] S615: The service gNB compares the first authentication code with the second authentication code.

[0189] S616: If the first authentication code is the same as the second authentication code, then the service gNB verifies the freshness of the SQN.

[0190] S617: When the freshness verification of SQN passes, the service gNB generates a second encryption key and a second integrity protection key based on RAND and the stored root key K, respectively.

[0191] When the freshness verification of the SQN passes, the legitimacy verification is confirmed to pass, and the service gNB generates a second encryption key and a second integrity protection key. For example, the second encryption key XCK = f3(K, RAND), and the second integrity protection key XIK = f4(K, RAND).

[0192] S618: The service gNB performs integrity verification on the encrypted data in the MAC PDU based on the second integrity key.

[0193] S619: After the integrity verification is passed, the service gNB decrypts the encrypted data in the MAC PDU based on the second encryption key to obtain the user data.

[0194] Afterwards, the serving gNB can send the obtained user data to target network elements such as the UPF.

[0195] It should be noted that the embodiments of this application are illustrated by the example of the terminal device performing cell reselection in the RRC inactive state. If the terminal device does not perform cell reselection in the RRC inactive state, or the selected cell is covered by the anchor gNB, then when there is small data to be transmitted, the terminal device continues to interact with the anchor gNB according to the process specified in the current protocol. The embodiments of this application will not elaborate on this.

[0196] In this embodiment, before the terminal device enters the RRC inactive state, the anchor gNB configures independently authenticable authentication parameters for the terminal device and configures a first CG-SDT resource for the terminal device from the pre-configured CG-SDT resource pool of the RNA. The terminal device moves carrying the authentication parameters. After handover to a new cell, when small data needs to be transmitted, the terminal device can directly send uplink data on the first CG-SDT resource, and the uplink data includes the authentication parameters. Since the coverage area of ​​the serving gNB providing services to the terminal device after handover is also within the RNA's range, and the CG-SDT resource pool is known to the serving gNB, the serving gNB can receive the uplink data sent by the terminal device on the first CG-SDT resource. The serving gNB can achieve local authentication based on the authentication parameters in the uplink data. Thus, small data processing of the SDT process is realized without obtaining the context information of the terminal device from the anchor gNB, thereby enabling CG-SDT to support cell reselection.

[0197] See Figure 7 , Figure 7 This is a flowchart illustrating a root key distribution method according to an exemplary embodiment. The method is implemented through interaction between a base station, a BKMC, and an AMF network element. The base station can be any network device within the RNA, such as a first network device or a second network device. The method may include some or all of the following: S710: After the base station is powered on, it obtains the region identifier of the RNA where it is currently located.

[0198] In one example, the base station can obtain the region identifier of the RNA it is currently in through pre-configuration, or the base station can obtain the region identifier of the RNA it is currently in from neighboring base stations. This application embodiment does not limit this.

[0199] The base station comes pre-installed with a device certificate at the factory. It also comes pre-installed with a corresponding private key, which is stored in the base station's hardware security module (HSM) and cannot be exported.

[0200] S720: The base station sends a key request message to the AMF network element. The key request message contains the base station identifier and the RNA area identifier.

[0201] S730: AMF network element verifies the legitimacy of the base station.

[0202] For example, the AMF network element can query whether the base station has been registered in the network management system based on the base station identifier. If it has been registered in the network management system, the legitimacy verification of the base station is determined to be successful; otherwise, the legitimacy verification of the base station is determined to be unsuccessful.

[0203] S740: After successful verification, the AMF network element forwards the key request message to the BKMC.

[0204] If the legitimacy verification of the base station is successful, the AMF network element will forward the key request message from the base station to the BKMC. Of course, if the legitimacy verification of the base station fails, the key request message can be ignored, such as not responding to the base station.

[0205] S750: BKMC performs two-way authentication with the base station based on certificates.

[0206] Both BKMC and the base station hold root digital certificate authority (CA) certificates, which can be used to verify device certificates. In implementation, the base station can send its own device certificate to BKMC. BKMC uses its stored root CA to verify the signature and validity of the base station's device certificate. If the verification passes, BKMC sends its own device certificate to the base station; BKMC has its own device certificate pre-installed. The base station uses the same root CA certificate to verify the signature and validity of BKMC's device certificate, thus achieving two-way certificate authentication.

[0207] S760: After successful two-way authentication, an encrypted secure channel is established between BKMC and the base station.

[0208] For example, the secure channel established between BKMC and the base station is an IPsec tunnel.

[0209] In addition, after successful two-way authentication, BKMC can bind the RNA's region identifier to the assigned root key, so that when the RNA's root key needs to be queried later, it can be queried based on the RNA's region identifier and this binding relationship.

[0210] S770: BKMC sends a key response message to the base station through a secure channel. The key response message includes the root key.

[0211] Optionally, the key response message may also include a key validity period.

[0212] S780: The base station parses the root key from the key response message and stores it.

[0213] For any base station within the RNA, the root key bound to the RNA can be obtained in this way. That is, all base stations within the RNA have the same root key, so that they can perform mutual authentication based on the root key.

[0214] In this embodiment, by assigning the same root key to each network device within the RNA, during the SDT process, any network device can indirectly verify the legitimacy of the terminal device based on the authentication vector generated by another network device using the root key, thus avoiding the need to obtain the context information of the terminal device through the Xn interface.

[0215] It should be understood that Figures 1 to 7 The flowcharts or scene diagrams shown are for illustrative purposes only and are not intended to limit the embodiments of this application to the examples illustrated. In fact, those skilled in the art can interpret the embodiments based on... Figures 1 to 7 The examples in the document can be transformed into equivalent ways to obtain more implementations.

[0216] The above text combined Figures 1 to 7 This document describes in detail the communication method provided in the embodiments of this application. The following will combine... Figures 8 to 9 The device embodiments of this application are described in detail below. It should be understood that the communication device of this application embodiment can execute the various communication methods of the foregoing embodiments of this application, that is, the specific working processes of the various products below can be referred to the corresponding processes in the foregoing method embodiments.

[0217] In the embodiments described above, the terminal device may execute some or all of the steps in each embodiment; the network device may execute some or all of the steps in each embodiment. These steps or operations are merely examples, and the embodiments of this application may also perform other operations or variations thereof. Furthermore, the steps may be executed in different orders as presented in the embodiments, and it is not necessary to execute all the operations in the embodiments of this application. Moreover, the sequence number of each step does not imply the order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0218] Figure 8 This is a schematic block diagram of a communication device provided in an embodiment of this application. Figure 8 As shown, the communication device 800 may include a communication module 820. The communication module 820 can implement corresponding communication functions, which can be internal communication functions of the communication device 800 or communication functions between the communication device 800 and other devices. Optionally, the communication module 820 may also be referred to as a communication interface or transceiver module. Optionally, the communication device 800 also includes a processing module 810. The processing module 810 can implement corresponding processing functions.

[0219] Optionally, the communication device 800 further includes a storage module, which can be used to store instructions and / or data; the processing module 810 can read the instructions and / or data in the storage module so that the communication device 800 can implement the aforementioned method embodiments.

[0220] In one possible design, the communication device 800 may correspond to the terminal device in the above method embodiments, or a component (such as a circuit, chip, or chip system) configured in the terminal device. The communication device 800 can be used to execute the steps or processes performed by the terminal device in any of the above method embodiments.

[0221] For example, the processing module 810 is used to perform cell reselection in the RRC inactive state; the communication module 820 is used to send uplink data to the first network device in the currently camped cell on the first CG-SDT resource when the SDT process is triggered. The uplink data includes SDT data and authentication parameters. The authentication parameters are used by the first network device to perform legitimacy authentication based on the root key.

[0222] The above are merely examples; for detailed steps or procedures, please refer to the descriptions in the foregoing embodiments.

[0223] In one possible design, the communication device 800 may correspond to the network device in the above method embodiments, or to a component (such as a circuit, chip, or chip system) configured in the network device. The communication device 800 can be used to perform the steps or processes performed by the network device in any of the above method embodiments.

[0224] In one example, the communication module 820 receives uplink data sent by the terminal device on the first CG-SDT resource. The uplink data includes SDT data and authentication parameters. The first CG-SDT resource and authentication parameters are configured for the terminal device by the second network device in the cell where the terminal device camps before cell reselection. The first CG-SDT resource includes a set of resource blocks in a CG-SDT resource pool configured based on RNA. The RNA includes the coverage areas of the first network device and the second network device. The processing module 810 performs legitimacy authentication based on the root key and authentication parameters. Both the first and second network devices hold the root key. If authentication is successful, the SDT data is sent to the target network element through the communication module 820.

[0225] In another example, the communication module 820 also configures the first CG-SDT resources and authentication parameters for the terminal device before the terminal device enters the RRC inactive state.

[0226] The above are merely examples; for detailed steps or procedures, please refer to the descriptions in the foregoing embodiments.

[0227] Figure 9 This is another schematic block diagram of the communication device 900 provided in the embodiments of this application. The communication device 900 may be a chip, chip system, or processor, etc., in a terminal device or network device that implements the above-described methods. The communication device 900 can be used to implement the methods described in the above-described method embodiments; for details, please refer to the descriptions in the above-described method embodiments.

[0228] like Figure 9 As shown, the communication device 900 may include one or more processors 910, which may also be referred to as processing units or processing modules, and can implement certain control functions. The processor 910 may be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, while the central processing unit can be used to control the communication device 900 (e.g., a base station, baseband chip, user, user chip), execute software programs, and process data from the software programs.

[0229] In an alternative design, the processor 910 may also store instructions and / or data that can be executed by the processor 910 to cause the communication device 900 to perform the methods described in the above method embodiments.

[0230] In another alternative design, the communication device 900 may include a communication interface 920 for implementing receiving and transmitting functions. For example, the communication interface 920 may be a transceiver circuit, interface, interface circuit, or transceiver. The transceiver circuit, interface, interface circuit, or transceiver for implementing receiving and transmitting functions may be separate or integrated. The aforementioned transceiver circuit, interface, interface circuit, or transceiver may be used for reading and writing code / data, or it may be used for transmitting or relaying signals.

[0231] Optionally, the communication device 900 may include one or more memories 930, which may store instructions that can be executed on the processor 910, causing the communication device 900 to perform the methods described in the above method embodiments. Optionally, the memories 930 may also store data. Optionally, the processor 910 may also store instructions and / or data. The processor 910 and the memories 930 may be provided separately or integrated together.

[0232] It should be understood that, in one possible design, the steps in the method embodiments provided in this application can be implemented by integrated logic circuits in the processor's hardware or by instructions in software form. The steps of the methods disclosed in the embodiments of this application can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules in the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, detailed descriptions are not provided here.

[0233] In one implementation, the communication device 900 may correspond to the terminal device in the above method embodiments and may be used to execute the various steps and / or processes executed by the terminal device in the above method embodiments. The processor 910 may be used to execute instructions stored in the memory 930, and when the processor 910 executes the instructions stored in the memory, the processor 910 is used to execute the various steps and / or processes of the above method embodiments corresponding to the terminal device.

[0234] In another implementation, the communication device 900 may correspond to the network device in the above method embodiments and may be used to execute the various steps and / or processes executed by the network device in the above method embodiments. The processor 910 may be used to execute instructions stored in the memory 930, and when the processor 910 executes the instructions stored in the memory, the processor 910 is used to execute the various steps and / or processes of the above method embodiments corresponding to the network device.

[0235] It should be understood that the aforementioned processing device can be one or more chips. For example, the processing device can be a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), a system-on-chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chips.

[0236] It is understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0237] According to the method provided in the embodiments of this application, this application also provides a chip system, which includes one or more processors for calling and executing instructions stored in memory, thereby causing the method described in the embodiments of this application to be executed. The chip system may be composed of chips or may include chips and other discrete devices.

[0238] The chip system may include input circuits or interfaces for transmitting information or data, and output circuits or interfaces for receiving information or data.

[0239] According to the method provided in the embodiments of this application, this application also provides a communication system, which includes the aforementioned network device and terminal device.

[0240] According to the method provided in the embodiments of this application, this application also provides a computer program product, which includes: computer program code, which, when run on a computer, causes the computer to execute the various steps or processes executed by the network device or terminal device in any of the foregoing method embodiments.

[0241] According to the method provided in the embodiments of this application, this application also provides a computer-readable storage medium storing program code, which, when run on a computer, causes the computer to execute the various steps or processes executed by the network device or terminal device in any of the foregoing method embodiments.

[0242] The computer-readable storage medium may be the aforementioned volatile memory or non-volatile memory, or it may include both volatile memory and non-volatile memory.

[0243] In the embodiments of this application, the terms and English abbreviations are exemplary examples given for ease of description and should not be construed as limiting the application in any way. This application does not preclude the possibility of defining other terms that can achieve the same or similar functions in existing or future agreements.

[0244] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When these computer instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated.

[0245] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0246] It should be understood that in the various embodiments of this application, the sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0247] In summary, the above description is merely a preferred embodiment of the technical solution of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A data transmission method, characterized in that, Applied to a terminal device, the method includes: Cell reselection is performed while Radio Resource Control (RRC) is inactive. When the Small Data Transmission SDT process is triggered, uplink data is sent to the first network device of the currently camped cell on the first CG-SDT resource. The uplink data includes SDT data and authentication parameters. The authentication parameters are used by the first network device to perform legality authentication based on the root key. The first CG-SDT resource and the authentication parameters are configured for the terminal device by the second network device camped in the cell before cell reselection. Both the first network device and the second network device hold the root key. The first CG-SDT resource includes a set of resource blocks in the CG-SDT resource pool configured for the notification area RNA based on the radio access network. The RNA includes the coverage area of ​​the first network device and the coverage area of ​​the second network device.

2. The method as described in claim 1, characterized in that, The method further includes: Before entering the RRC inactive state, a first message is received from the second network device. The first message includes first configuration information and an authentication vector. The first configuration information is used to indicate the first CG-SDT resource, and the authentication vector includes the authentication parameters.

3. The method as described in claim 1 or 2, characterized in that, The authentication parameters include a first authentication code, a random number, and a serial number.

4. The method as described in claim 2, characterized in that, The first configuration information includes CG-SDT resource period, CG-SDT resource frequency and CG-SDT indication information. The CG-SDT indication information is used to indicate the set of resource blocks configured for the terminal device in the first sub-resource pool. The first sub-resource pool includes resource blocks allocated for anchor cells within one period of the CG-SDT resource pool. The anchor cell is the cell in which the terminal device camps before cell reselection.

5. The method as described in claim 4, characterized in that, The CG-SDT indication information includes index information of the first CG-SDT resource; or, the CG-SDT indication information includes the starting position and resource block offset of the first sub-resource pool, wherein the resource block offset is used to indicate the offset of the set of resource blocks allocated to the terminal device relative to the initial position of the first sub-resource pool.

6. The method as described in claim 5, characterized in that, The starting position of the first sub-resource pool is determined based on the cell identifier, prime number, and total number of resource blocks of the anchor cell, wherein the total number of resource blocks is the total number of resource blocks contained in the CG-SDT resource pool in one cycle; The resource block offset is determined based on the device identifier of the terminal device and the number of resource blocks contained in the first sub-resource pool. The number of resource blocks contained in the first sub-resource pool is determined based on the total number of resource blocks and the total number of cells in the RNA.

7. The method as described in claim 1 or 2, characterized in that, The SDT data is encrypted data, which is obtained by encrypting and protecting user data according to a first encryption key and a first integrity protection key. The first encryption key and the first integrity protection key are generated by the second network device according to the root key.

8. The method as described in claim 2, characterized in that, The first message is an encrypted RRC release message.

9. The method as described in claim 1 or 2, characterized in that, The uplink data also includes the inactive wireless network temporary identifier I-RNTI.

10. A data transmission method, characterized in that, Applied to a first network device, the method includes: The terminal device receives uplink data on a first CG-SDT resource. The uplink data includes SDT data and authentication parameters. The first CG-SDT resource and the authentication parameters are configured for the terminal device by a second network device in the cell where the terminal device camps before cell reselection. The first CG-SDT resource includes a set of resource blocks in a CG-SDT resource pool configured for a radio access network notification area (RNA). The RNA includes the coverage area of ​​the first network device and the coverage area of ​​the second network device. The legitimacy is verified based on the root key and the authentication parameters, and both the first network device and the second network device hold the root key. If authentication is successful, the SDT data is sent to the target network element.

11. The method as described in claim 10, characterized in that, The authentication parameters include a first authentication code, a random number, and a serial number.

12. The method as described in claim 11, characterized in that, The legitimacy authentication based on the root key and the authentication parameters includes: A second authentication code is generated based on the root key, the random number, and the sequence number; If the first authentication code is the same as the second authentication code, and the freshness verification of the serial number passes, then the legality authentication is confirmed to be successful.

13. The method as described in claim 11 or 12, characterized in that, The SDT data is encrypted data, which is obtained by encrypting and protecting the data according to the first encryption key and the first integrity protection key respectively. The first encryption key and the first integrity protection key are generated by the second network device according to the root key.

14. The method as described in claim 13, characterized in that, The step of sending the SDT data to the target network element upon successful authentication includes: A second encryption key is generated based on the root key and the random number; Based on the root key and the random number, a second integrity protection key is generated; Based on the second encryption key and the second integrity protection key, the encrypted data is decrypted and its integrity is verified, respectively. After successful decryption and integrity verification, the decrypted user data is sent to the target network element.

15. A data transmission method, characterized in that, Applied to a second network device, the method includes: Before the terminal device enters the RRC inactive state, the terminal device is configured with the first CG-SDT resource and authentication parameters. The authentication parameters are used by the first network device to perform legality authentication based on the root key. Both the first network device and the second network device hold the root key. The first CG-SDT resource includes a set of resource blocks in a CG-SDT resource pool configured for a radio access network-based notification area RNA, wherein the RNA includes the coverage area of ​​the first network device and the coverage area of ​​the second network device.

16. The method as described in claim 15, characterized in that, Before the terminal device enters the RRC inactive state, the first CG-SDT resource and authentication parameters are configured for the terminal device, including: Before the terminal device enters the RRC inactive state, a first message is sent to the terminal device. The first message includes first configuration information and an authentication vector. The first configuration information is used to indicate the first CG-SDT resource, and the authentication vector includes the authentication parameters.

17. The method as described in claim 16, characterized in that, The first message is an encrypted RRC release message.

18. A communication device, characterized in that, The device includes at least one processor coupled to a memory storing a program or instructions, the processor executing the program or instructions to cause the communication device to perform the method as claimed in any one of claims 1 to 9, or the method as claimed in any one of claims 10 to 14, or the method as claimed in any one of claims 15 to 17.

19. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, When the computer program or instructions are executed, they cause the computer to perform the method as described in any one of claims 1 to 9, or the method as described in any one of claims 10 to 14, or the method as described in any one of claims 15 to 17.

20. A communication system, characterized in that, Includes the communication device as described in claim 18.

21. A chip system, characterized in that, The chip system includes one or more processors, which are configured to retrieve and execute instructions stored in memory, such that the method of any one of claims 1 to 9 is performed, or the method of any one of claims 10 to 14 is performed, or the method of any one of claims 15 to 17 is performed.