Communication method, device, and system

The method improves communication security by updating authentication keys during connection transitions between integrated communication systems, addressing the lack of secure integration methods in existing standards.

JP2025170241APending Publication Date: 2025-11-18HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2025123077
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-08-30
Filing Date
2025-07-23
Publication Date
2025-11-18

Smart Images

  • Figure 2025170241000001_ABST
    Figure 2025170241000001_ABST
Patent Text Reader

Abstract

To disclose a communication method, a device, and a system, and relate to a field of a communication technique.SOLUTION: A method includes steps of: obtaining a second key used for communication authentication with a second node, in which the second key is different from a preset first key; receiving a release request of a first communication connection from the second node, in which the first key is used for the communication authentication of the first communication connection; and sending a connection establishment request to the second node, in which the connection establishment request is used to request establishment of a connection based on the second key. The method provides a technical solution in which a first node and a second node release a connection after determining an updated key, and establish the connection using a new key, to implement an authentication procedure in an integrated scenario of a multi-communication scenario.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] [Related Applications] This application claims priority to Chinese Patent Application No. 202111005514.2, filed with the State Intellectual Property Office of China on August 30, 2021, entitled "COMMUNICATION METHOD, APPARATUS, AND SYSTEM," which is incorporated herein by reference in its entirety.

[0002] [Technical field] TECHNICAL FIELD Embodiments of the present application relate to the field of communication technologies, and in particular to communication methods, devices, and systems. [Background technology]

[0003] The rapid development of mobile communications has led to the continuous emergence of multiple application scenarios, and communication systems based on different communication technologies are inevitably integrated. For example, with the mature development of 5G technology and the widespread application of wireless short-range communication systems, the integration of wireless short-range communication and 5G cellular networks has become a new trend. At the same time, the new integration scenario also imposes higher requirements on communication transmission security.

[0004] However, existing standards lack a secure and effective communication method for the integration scenario of different communication systems. Summary of the Invention

[0005] SUMMARY OF THE INVENTION Embodiments of the present application provide a communication method, device, and system for updating a communication authentication key and improving communication security.

[0006] According to a first aspect, an embodiment of the present application provides a communication method, which can be applied to a first node, the method comprising: The method includes the steps of: obtaining a second key used for communication authentication with a second node, the second key being different from a pre-set first key; receiving a request to release a first communication connection from the second node, the first key being used for communication authentication of the first communication connection; and sending a connection establishment request to the second node, the connection establishment request being used to request the establishment of a connection based on the second key.

[0007] According to the above method, the embodiment of the present application provides a technical solution in which the first node and the second node release the connection after determining an updated key, and then establish a connection using a new key, thereby realizing switching between different communication connections and realizing the update process of the key used for communication authentication, and effectively improving communication security.

[0008] In a possible implementation, using the connection establishment request to request establishment of a connection based on the second key includes: using the connection establishment request to request performing authentication and security context negotiation procedures based on the second key.

[0009] In a possible implementation, the method further includes a step of receiving authentication information based on the second key from the second node, the authentication information being used to verify the identity of the second node.

[0010] In a possible implementation, verifying the identity of the second node using the authentication information includes using the authentication information to verify whether a second communication connection to the second node is established based on the second key.

[0011] In a possible implementation, the first key is a key derived (or negotiated) based on the first communication system, and / or the second key is a key derived (or negotiated) based on the second communication system, and the first communication system is different from the second communication system.

[0012] In a possible implementation, the first communication system may be a single communication system and the second communication system may be a communication system obtained after integration of different communication systems.

[0013] According to the above method, the embodiment of the present application provides a communication method in a scenario where different communication systems perform integrated communication, which effectively improves communication security.

[0014] In a possible implementation, an authentication response based on the second key is sent to the second node, and the authentication response is used to verify the identity of the first node.

[0015] In a possible implementation, the authentication response being used to verify the identity of the first node includes: the authentication response being used by the second node to verify whether to establish the second communication connection to the first node based on the second key.

[0016] According to the above method, the first node sends the authentication response to the second node, and the second node can further determine whether the authentication based on the second key was successful based on the authentication response.

[0017] In a possible implementation, the release request includes request cause information, which indicates that a key used for communication authentication is to be updated.

[0018] According to the above method, the release request includes the cause of the request, so that after receiving the release request from the second node, the first node can learn the cause of the request, so that the first node can respond to the request more appropriately and with stronger adaptability.

[0019] In a possible implementation, the second key is valid for the first period of time, the first period of time being defined using a timer or a timestamp.

[0020] According to the above method, in the process of the first node and the second node performing communication transmission using the second key, whether the second key is valid or not is further verified, thereby ensuring the time validity of the second key and further ensuring the security of communication transmission.

[0021] In a possible implementation, the second key is valid within the first period starting from a first point in time, the first point in time being the point in time when the first communication connection is released or the point in time when the connection establishment request is sent.

[0022] According to the above method, the present application provides multiple cases at the first point in time, thus providing multiple solutions for determining the validity of the second key, and providing high flexibility.

[0023] In a possible implementation, the method includes transmitting information to the third node using a backhaul link between the second node and the third node during the validity period of the second key.

[0024] According to a second aspect, an embodiment of the present application provides a communication method, which can be applied to a second node, the method including: obtaining a second key used for authenticating communication with the first node, the second key being different from the pre-defined first key; sending a request to the first node to release the first communication connection, wherein the first key is used for communication authentication of the first communication connection; receiving a connection establishment request sent by the first node, the connection establishment request being used to request establishment of a connection based on the second key.

[0025] According to the above method, the embodiment of the present application provides a technical solution in which the first node and the second node release the connection after determining an updated key, and then establish a connection using a new key, thereby realizing switching between different communication connections and realizing the update process of the key used for communication authentication, and effectively improving communication security.

[0026] In a possible implementation, using the connection establishment request to request establishment of a connection based on the second key includes: using the connection establishment request to request performing authentication and security context negotiation procedures based on the second key.

[0027] In a possible implementation, the method further includes a step of sending authentication information based on the second key to the first node, the authentication information being used to verify the identity of the second node.

[0028] In a possible implementation, verifying the identity of the second node using the authentication information includes verifying, by the first node, using the authentication information whether a second communication connection to the second node has been established based on the second key.

[0029] In a possible implementation, the first key is a key derived (or negotiated) based on the first communication system, and / or the second key is a key derived (or negotiated) based on the second communication system, and the first communication system is different from the second communication system.

[0030] In a possible implementation, the first communication system may be a single communication system and the second communication system may be a communication system obtained after integration of different communication systems.

[0031] According to the above method, the embodiment of the present application provides a communication method in a scenario where different communication systems perform integrated communication, which effectively improves communication security.

[0032] In a possible implementation, the method further includes a step of receiving an authentication response based on the second key from the first node, the authentication response being used to verify the identity of the first node.

[0033] In a possible implementation, the authentication response being used to verify the identity of the first node includes: the authentication response being used by the second node to verify whether to establish the second communication connection to the first node based on the second key. According to the above method, the first node sends the authentication response to the second node, and the second node can further determine whether authentication based on the second key is successful based on the authentication response.

[0034] In a possible embodiment, said release request comprises request cause information, said request cause information indicating that a key used for communication authentication is to be updated.

[0035] According to the above method, the release request includes the cause of the request, so that after receiving the release request from the second node, the first node can learn the cause of the request, so that the first node can respond to the request more appropriately and with stronger adaptability.

[0036] In a possible implementation, the second key is valid for the first period of time, which may be defined using a timer or a timestamp.

[0037] According to the above method, in the process of the first node and the second node performing communication transmission using the second key, whether the second key is valid or not is further verified, thereby ensuring the time validity of the second key and further ensuring the security of communication transmission.

[0038] In a possible implementation, the second key is valid for the first period starting from a first point in time, the first point in time being the point in time when the first communication connection is released or the point in time when the second node receives the connection establishment request.

[0039] According to the above method, the present application provides multiple cases at the first point in time, thus providing multiple solutions for determining the validity of the second key, and providing high flexibility.

[0040] In a possible implementation, the method further includes a step of transmitting transmission information from the first node to the third node using a backhaul link between the second node and the third node within the validity period of the second key.

[0041] In a possible implementation, the backhaul link is stopped after the first communication connection to the first node is released.

[0042] According to the method, after the first communication connection is released, the second node stops the backhaul link, which can effectively reduce system overhead and save resources.

[0043] In a possible implementation, the method comprises: The method further includes a step of activating the backhaul link after determining that the second communication connection to the first node has been successfully established, wherein communication authentication is performed for the second communication connection based on the second key.

[0044] According to the method, after determining that the second communication connection to the first node has been successfully established, the method activates a previously deactivated backhaul link and continues to use the backhaul link for communication transmission, thereby effectively reducing system overhead and saving resources.

[0045] According to a third aspect, an embodiment of the present application provides a communication method, which can be applied to a first node, the method comprising: obtaining a second key used for authenticating communication with a second node, the second key being different from the pre-defined first key; Releasing a first communication connection to the second node, wherein the first key is used for communication authentication of the first communication connection; sending a connection establishment request to the second node, the connection establishment request being used to request establishment of a connection based on the second key.

[0046] According to the above method, the embodiment of the present application provides a technical solution in which the first node and the second node release the connection after determining an updated key, and then establish a connection using a new key, thereby realizing switching between different communication connections and realizing the update process of the key used for communication authentication, and effectively improving communication security.

[0047] In a possible implementation, using the connection establishment request to request establishment of a connection based on the second key includes: using the connection establishment request to request performing authentication and security context negotiation procedures based on the second key.

[0048] In a possible implementation, the method further includes a step of receiving authentication information based on the second key from the second node, the authentication information being used to verify the identity of the second node.

[0049] In a possible implementation, verifying the identity of the second node using the authentication information includes using the authentication information to verify whether a second communication connection to the second node is established based on the second key.

[0050] In a possible implementation, the first key is a key derived (or negotiated) based on the first communication system, and / or the second key is a key derived (or negotiated) based on the second communication system, and the first communication system is different from the second communication system.

[0051] In a possible implementation, the first communication system may be a single communication system and the second communication system may be a communication system obtained after integration of different communication systems.

[0052] According to the above method, the embodiment of the present application provides a communication method in a scenario where different communication systems perform integrated communication, which effectively improves communication security.

[0053] In a possible implementation, the method further includes a step of sending an authentication response based on the second key to the second node, the authentication response being used to verify the identity of the first node.

[0054] In a possible implementation, the authentication response being used to verify the identity of the first node includes: the authentication response being used by the second node to verify whether to establish the second communication connection to the first node based on the second key.

[0055] According to the above method, the first node sends the authentication response to the second node, and the second node can further determine whether the authentication based on the second key was successful based on the authentication response.

[0056] In a possible embodiment, said release request comprises request cause information, said request cause information indicating that a key used for communication authentication is to be updated.

[0057] According to the above method, the release request includes the cause of the request, so that after receiving the release request from the second node, the first node can learn the cause of the request, so that the first node can respond to the request more appropriately and with stronger adaptability.

[0058] In a possible implementation, the second key is valid for the first period of time, the first period of time being defined using a timer or a timestamp.

[0059] According to the above method, in the process of the first node and the second node performing communication transmission using the second key, whether the second key is valid or not is further verified, thereby ensuring the time validity of the second key and further ensuring the security of communication transmission.

[0060] In a possible implementation, the second key is valid within the first period starting from a first point in time, the first point in time being the point in time when the first communication connection is released or the point in time when the connection establishment request is sent.

[0061] According to the above method, the present application provides multiple cases at the first point in time, thus providing multiple solutions for determining the validity of the second key, and providing high flexibility.

[0062] In a possible implementation, the method includes transmitting information to the third node using a backhaul link between the second node and the third node during the validity period of the second key.

[0063] According to a fourth aspect, an embodiment of the present application provides a communication method, which can be applied to a second node, the method comprising: obtaining a second key used for authenticating communication with the first node, the second key being different from the pre-defined first key; Releasing a first communication connection to the first node, wherein the first key is used for communication authentication of the first communication connection; receiving a connection establishment request sent by the first node, the connection establishment request being used to request establishment of a connection based on the second key.

[0064] According to the above method, the embodiment of the present application provides a technical solution in which the first node and the second node release the connection after determining an updated key, and then establish a connection using a new key, thereby realizing switching between different communication connections and realizing the update process of the key used for communication authentication, and effectively improving communication security.

[0065] In a possible implementation, using the connection establishment request to request establishment of a connection based on the second key includes: using the connection establishment request to request performing authentication and security context negotiation procedures based on the second key.

[0066] In a possible implementation, the method further includes a step of sending authentication information based on the second key to the first node, the authentication information being used to verify the identity of the second node.

[0067] In a possible implementation, verifying the identity of the second node using the authentication information includes verifying, by the first node, using the authentication information whether a second communication connection to the second node has been established based on the second key.

[0068] In a possible implementation, the first key is a key derived (or negotiated) based on the first communication system, and / or the second key is a key derived (or negotiated) based on the second communication system, and the first communication system is different from the second communication system.

[0069] In a possible implementation, the first communication system may be a single communication system and the second communication system may be a communication system obtained after integration of different communication systems.

[0070] According to the above method, the embodiment of the present application provides a communication method in a scenario where different communication systems perform integrated communication, which effectively improves communication security.

[0071] In a possible implementation, the method further includes receiving an authentication response returned by the first node, the authentication response being used to verify the identity of the first node.

[0072] In a possible implementation, the authentication response being used to verify the identity of the first node includes: the authentication response being used by the second node to verify whether to establish the second communication connection to the first node based on the second key.

[0073] According to the above method, the first node sends the authentication response to the second node, and the second node can further determine whether the authentication based on the second key was successful based on the authentication response.

[0074] In a possible embodiment, said release request comprises request cause information, said request cause information indicating that a key used for communication authentication is to be updated.

[0075] According to the above method, the release request includes the cause of the request, so that after receiving the release request from the second node, the first node can learn the cause of the request, so that the first node can respond to the request more appropriately and with stronger adaptability.

[0076] In a possible implementation, the second key is valid for the first period of time, which may be defined using a timer or a timestamp.

[0077] According to the above method, in the process of the first node and the second node performing communication transmission using the second key, whether the second key is valid or not is further verified, thereby ensuring the time validity of the second key and further ensuring the security of communication transmission.

[0078] In a possible implementation, the second key is valid for the first period starting from a first point in time, the first point in time being the point in time when the first communication connection is released or the point in time when the second node receives the connection establishment request.

[0079] According to the above method, the present application provides multiple cases at the first point in time, thus providing multiple solutions for determining the validity of the second key, and providing high flexibility.

[0080] In a possible implementation, the method further includes a step of transmitting transmission information from the first node to the third node using a backhaul link between the second node and the third node within the validity period of the second key.

[0081] In a possible implementation, the backhaul link is stopped after the first communication connection to the first node is released.

[0082] According to the method, after the first communication connection is released, the second node stops the backhaul link, which can effectively reduce system overhead and save resources.

[0083] In a possible implementation, the method comprises: The method further includes a step of activating the backhaul link after determining that the second communication connection to the first node has been successfully established, wherein communication authentication is performed for the second communication connection based on the second key.

[0084] According to the method, after determining that the second communication connection to the first node has been successfully established, the method activates a previously deactivated backhaul link and continues to use the backhaul link for communication transmission, thereby effectively reducing system overhead and saving resources.

[0085] According to a fifth aspect, an embodiment of the present application provides a communications device, the device being configured to perform the first aspect or any of the methods of the first aspect, and including corresponding functional modules or units separately configured to perform the steps of the method of the first aspect. The functions may be implemented by hardware, or may be implemented by hardware by executing corresponding software. The hardware or software may include one or more modules or units corresponding to the functions. Alternatively, The device is configured to perform the method of the third aspect or any of the methods of the third aspect, and includes corresponding functional modules or units separately configured to perform the steps of the method of the third aspect. The functions may be implemented by hardware or by executing corresponding software. The hardware or software includes one or more modules or units corresponding to the functions.

[0086] According to a sixth aspect, an embodiment of the present application provides a communications device, the device being configured to perform the method of the second aspect or any of the second aspects, and including corresponding functional modules or units separately configured to perform the steps of the method of the second aspect. The functions may be implemented by hardware, or may be implemented by hardware by executing corresponding software. The hardware or software may include one or more modules or units corresponding to the functions. Alternatively, The device is configured to perform the method of the fourth aspect or any of the methods of the fourth aspect, and includes corresponding functional modules or units separately configured to perform the steps of the method of the fourth aspect. The functions may be implemented by hardware or by executing corresponding software. The hardware or software includes one or more modules or units corresponding to the functions.

[0087] According to a seventh aspect, there is provided a communication device including a processor and a memory. The memory is configured to store a computing program or instructions, and the processor is coupled to the memory. When the processor executes the computer program or the instructions, the device performs the first aspect or any of the methods in the first aspect, or the third aspect or any of the methods in the third aspect. The communication device may be a first device, a device capable of assisting the first device in implementing a function required by the method provided in the first aspect, or a device capable of assisting the first device in implementing a function required by the method provided in the third aspect. For example, the communication device may be a terminal device or some components (e.g., chips) within a terminal device. The terminal device may be, for example, an intelligent mobile terminal, a smart home device, a smart car, or an intelligent wearable device. The intelligent mobile terminal may be, for example, a mobile phone, a tablet computer, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA). The smart home devices include smart refrigerators, smart washing machines, smart TVs, speakers, etc. The wearable devices in smart cars are, for example, smart headsets, smart glasses, smart clothes, or shoes.

[0088] According to an eighth aspect, there is provided a communication device including a processor and a memory. The memory is configured to store a computing program or instructions, and the processor is coupled to the memory. When the processor executes the computer program or the instructions, the device performs the second aspect or any of the methods in the second aspect, or the fourth aspect or any of the methods in the fourth aspect. The communication device may be a second device, a device capable of assisting the second device in implementing a function required by the method provided in the second aspect, or a device capable of assisting the second device in implementing a function required by the method provided in the fourth aspect. For example, the communication device may be a terminal device or some components (e.g., chips) within a terminal device. The terminal device may be, for example, an intelligent mobile terminal, a smart home device, a smart car, or an intelligent wearable device. The intelligent mobile terminal may be, for example, a mobile phone, a tablet computer, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA). Smart home devices include smart refrigerators, smart washing machines, smart TVs, speakers, etc. Smart car wearable devices are, for example, smart headsets, smart glasses, smart clothes, or shoes.

[0089] According to a ninth aspect, there is provided a terminal. The terminal may include a device according to the fifth or seventh aspect and a device according to the sixth or eighth aspect. Optionally, the device may be a smart home device, an intelligent manufacturing device, an intelligent transportation device, etc., such as a vehicle, an unmanned aerial vehicle, an unmanned transport vehicle, an automobile and a vehicle, a robot, etc. Alternatively, the device may be a mouse, a keyboard, a wearable device, a TWS headset, etc.

[0090] According to a tenth aspect, the present application provides a chip, coupled to a memory and configured to read and execute computer programs or instructions stored in the memory, to perform the method of the first aspect or any one of its possible implementations, or to perform the method of the second aspect or any one of its possible implementations, or to perform the method of the third aspect or any one of its possible implementations, or to perform the method of the fourth aspect or any one of its possible implementations.

[0091] According to an eleventh aspect, there is provided a computer-readable storage medium, the computer-readable storage medium storing a computer program or instructions, which, when executed by an apparatus, enable the apparatus to perform the method of the first aspect or any one of its possible implementations, or enable the apparatus to perform the method of the third aspect or any one of its possible implementations.

[0092] According to a twelfth aspect, there is provided a computer-readable storage medium, the computer-readable storage medium storing a computer program or instructions which, when executed by an apparatus, enable the apparatus to perform the method of the second aspect or any one of its possible implementations, or enable the apparatus to perform the method of the fourth aspect or any one of its possible implementations.

[0093] According to a thirteenth aspect, there is provided herein a computer program product, the computer program product comprising a computer program or instructions, which, when executed by an apparatus, enable the apparatus to perform the method of the first aspect or any one of the possible implementations of the first aspect, or enable the apparatus to perform the method of the third aspect or any one of the possible implementations of the third aspect.

[0094] According to a fourteenth aspect, there is provided herein a computer program product, the computer program product comprising a computer program or instructions, which, when executed by an apparatus, enable the apparatus to perform the method of the second aspect or any one of the possible implementations of the second aspect, or enable the apparatus to perform the method of the third aspect or any one of the possible implementations of the third aspect.

[0095] Furthermore, the technical solution provided in this application can be applied to a scenario in which different communication systems are integrated and a communication method in a scenario in which different communication systems perform integrated communication, thereby effectively improving communication security. In addition, by setting the validity of the key used for communication authentication, the time validity of the key used for communication authentication can be ensured, thereby further ensuring communication transmission security. [Brief explanation of the drawings]

[0096] [Figure 1] 1 is a schematic diagram of a first communication system according to an embodiment of the present application;

[0097] [Figure 2] FIG. 2 is a schematic diagram of a second communication system according to an embodiment of the present application;

[0098] [Figure 3] 2 is a schematic flowchart of a first communication method according to an embodiment of the present application;

[0099] [Figure 4A] 4 is a schematic flowchart of a second communication method according to an embodiment of the present application; [Figure 4B] 4 is a schematic flowchart of a second communication method according to an embodiment of the present application;

[0100] [Figure 5A] 4 is a schematic flowchart of a third communication method according to an embodiment of the present application; [Figure 5B] 4 is a schematic flowchart of a third communication method according to an embodiment of the present application;

[0101] [Figure 6A] 10 is a schematic flowchart of a fourth communication method according to an embodiment of the present application; [Figure 6B] 10 is a schematic flowchart of a fourth communication method according to an embodiment of the present application;

[0102] [Figure 7A] 10 is a schematic flowchart of a fifth communication method according to an embodiment of the present application; [Figure 7B] 10 is a schematic flowchart of a fifth communication method according to an embodiment of the present application;

[0103] [Figure 8A] 10 is a schematic flowchart of a sixth communication method according to an embodiment of the present application. [Figure 8B] 10 is a schematic flowchart of a sixth communication method according to an embodiment of the present application.

[0104] [Figure 9A] 10 is a schematic flowchart of a sixth communication method according to an embodiment of the present application. [Figure 9B] 10 is a schematic flowchart of a sixth communication method according to an embodiment of the present application. [Figure 9C] 10 is a schematic flowchart of a sixth communication method according to an embodiment of the present application.

[0105] [Figure 10] 1 is a schematic diagram of the structure of a first communication device according to an embodiment of the present application;

[0106] [Figure 11] FIG. 2 is a schematic diagram of the structure of a second communication device according to an embodiment of the present application;

[0107] [Figure 12] 1 is a schematic diagram of the structure of a terminal according to an embodiment of the present application; DETAILED DESCRIPTION OF THE INVENTION

[0108] The embodiments of the present application provide a communication method and device for implementing an authentication procedure for the integration of wireless short-range and 5G cellular networks. In order to clarify the objectives, technical solutions and advantages of the embodiments of the present application, the following describes the embodiments of the present application in detail with reference to the accompanying drawings.

[0109] The communication method provided in the embodiments of the present application may be applied to a fifth generation (5G) communication system, such as a 5G new radio (NR), and may also be applied to various future communication systems, such as a sixth generation (6G) communication system, which is not limited herein.

[0110] As shown in Figure 1, an embodiment of the present application provides a communication system architecture to which the present communication method can be applied. The communication system may include a first node 100, a second node 110, and a third node 120. Optionally, in the communication system, the first node may be connected to the second node, and the second node may be connected to the third node.

[0111] The communication system in this application may be a communication system obtained after different communication systems are integrated, for example, a communication system obtained after a wireless short-range communication system is integrated into a 5G cellular network communication system, but this is not limited thereto. In addition, the integrated communication system may also be called a tight interworking communication system or an interworking communication system.

[0112] For example, in this application, the communication system obtained after integrating a wireless short-range communication system and a 5G cellular network communication system is used as an example to describe the integrated communication system.

[0113] In the unified communication system, a terminal node supporting wireless short-range communication can use a control node or a gateway node to access a 5G network and further use services provided by the 5G network. The 5G network can further configure and manage the data transmission policy of the terminal node based on the subscription information and link state information of the terminal node, and provide sophisticated services to the terminal node. That is, in the unified communication system, the wireless short-range communication system and the 5G cellular network communication system can interact with each other and operate to complement each other.

[0114] Optionally, the wireless short-range communication system described herein may be any possible short-range communication system, such as Bluetooth, Wi-Fi, in-vehicle universal short-range communication system, and SparkLink, among other current and future short-range communication systems.

[0115] The first node may be a terminal device or a communication device capable of supporting the terminal device in implementing the functions required by the method, or the first node may be a network device or a communication device capable of supporting the network device in implementing the functions required by the method, or of course other communication devices such as a chip system. The second node may be a network device or a communication device capable of supporting the network device in implementing the functions required by the method, or the second node may be a terminal device or a communication device capable of supporting the terminal device in implementing the functions required by the method, or of course other communication devices such as a chip system. The third node may be a network device or a communication device capable of supporting the network device in implementing the functions required by the method, or the third node may be a terminal device or a communication device capable of supporting the terminal device in implementing the functions required by the method, or of course other communication devices such as a chip system.

[0116] Optionally, the terminal device in the embodiments of the present application may be a device configured to implement wireless communication functions, such as a terminal device or a chip that can be used in a terminal device. For example, the terminal device may include a handheld device with wireless connectivity or a processing device connected to a wireless modem. The terminal device may communicate with a core network via a radio access network (RAN) and exchange voice and / or data with the RAN. The terminal device may also be called user equipment (UE), wireless terminal device, mobile terminal device, subscriber unit, subscriber station, mobile station, mobile console, remote station, access point (AP), remote terminal, access terminal, user terminal, user agent, user device, etc. For example, a terminal device may include a mobile telephone (also called a "cellular" phone), a computer with a mobile terminal device, or a portable, pocket-sized, handheld, computer-based, or vehicle-mounted mobile device, or a smart wearable device. For example, a terminal device may be a device such as a Personal Communication Service (PCS) phone, a cordless telephone set, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, or a Personal Digital Assistant (PDA). Alternatively, a terminal device may include a limited device, such as a relatively low-power device, a device with limited storage capabilities, or a device with limited computing capabilities.For example, the terminal device may include an information sensing device such as a barcode, a radio frequency identification (RFID), a sensor, a global positioning system (GPS), or a laser scanner.

[0117] By way of example and not limitation, in embodiments of the present application, the terminal device may instead be a wearable device. A wearable device may be referred to as a wearable intelligent device, which is a general term for wearable devices intelligently designed and developed for everyday wear using wearable technology, such as glasses, gloves, watches, clothing, and shoes. A wearable device is a portable device that can be worn directly on the body or integrated into a user's clothing or accessories. A wearable device is not just a hardware device, but also implements powerful functions through software support, data exchange, and cloud interaction. In a broad sense, a wearable intelligent device includes a full-featured, large device that can implement all or part of its functions without relying on a smartphone, such as a smart watch or smart glasses, as well as a device that is dedicated to a single application function and needs to work in conjunction with another device, such as a smartphone, to monitor physical signs, such as various smart bands, smart helmets, or smart jewelry.

[0118] Furthermore, the network device in this embodiment of the present application may include an access network device such as an access network (AN) device, a radio access network (RAN) device, or a base station (e.g., an access point). A wireless terminal device may refer to a device that communicates with a wireless terminal device over a radio interface using one or more cells in an access network. The base station may be configured to convert received radio frames to and from Internet Protocol (IP) packets and serve as a router between the terminal device and the rest of the access network. The rest of the access network may include an IP network. The network side device may further coordinate attribute management of the radio interface. For example, the network device may include an evolved NodeB (NodeB, eNB or e-NodeB, evolved NodeB) or a long term evolution-advanced (LTE-A) system in a long term evolution (LTE) system, a next generation NodeB (gNB), a next generation evolved NodeB (ng-eNB), or an enhanced next generation NodeB (en-gNB) in a fifth generation (5G) mobile communication technology new radio (NR) system, and a centralized unit (CU) and a distributed unit (DU) in a cloud radio access network (Cloud RAN) system. This is not limited to the embodiments of the present application.

[0119] Furthermore, the present application also provides another communication system, which may further include functional entities such as a session management function (SMF), an access and mobility management function (AMF), a user plane function (UPF), and a DN, as shown in Figure 2.

[0120] Functions may be connected via interfaces. In the embodiment of the present application, the sequence numbers or names of the interfaces are not limited. An interface defined in a 3GPP-related standard protocol for a 5G system may be used, or an interface in a future communication system may be used. For example, a terminal device communicates with an AMF via a next generation network (N) 1 interface (abbreviated as N1), a network device communicates with the AMF via an N2 interface (abbreviated as N2), and a network device communicates with a local UPF via an N3 interface (abbreviated as N3). The UPF communicates with a DN via an N6 interface (abbreviated as N6). The AMF communicates with an SMF via an N11 interface (abbreviated as N11), and the SMF communicates with a UPF via an N4 interface (abbreviated as N4).

[0121] A function included in a communication system may be referred to as a functional entity, a network element, or another name. For example, an SMF may be referred to as an SMF entity. Optionally, a function in an embodiment of the present application may be implemented by one device, jointly implemented by multiple devices, or implemented by one or more functional modules in one device. This is not specifically limited in the embodiments of the present application. It should be understood that each function in the embodiments of the present application may be a network element in a hardware device, a software function running on dedicated hardware, a combination of hardware and software, or a virtualization function instantiated on a platform (e.g., a cloud platform).

[0122] It should be noted that the distribution form of each function is not limited in the embodiments of the present application. Optionally, each function may include another functional entity formed after combining any multiple functions, such as a functional entity having two functions of session management and policy control, a functional entity having three functions of session management, access and mobility management, and policy control, or a functional entity having two functions of network publication and application function.

[0123] It should be noted that the communication systems shown in Figures 1 and 2 do not constitute limitations on communication systems to which the embodiments of the present application can be applied. Of course, the number of terminal devices in Figure 2 is merely an example. In a practical application, a network device may provide services to multiple terminal devices. All or some of the network device and the multiple terminal devices may each determine scheduling restrictions according to the methods provided in the embodiments of the present application. The communication system architecture shown in Figure 1 and / or Figure 2 may be a non-roaming 5G system architecture. Optionally, the methods in the embodiments of the present application may also be applicable to roaming 5G system architectures and various future communication networks.

[0124] Each function or device in the embodiment of the present application is also called a communication device, and may be a general-purpose device or a dedicated device, which is not specifically limited in the embodiment of the present application.

[0125] The above briefly describes the application architecture of the embodiment of the present application. The following describes the technical features of the embodiment of the present application.

[0126] Currently, there is no secure and effective communication method for the integration scenario of different communication systems. Therefore, the embodiments of the present application provide a technical solution in which the first node and the second node release the connection after determining an updated key and then establish a connection using a new key, providing a communication method for the integration scenario of different communication systems. This effectively improves communication security. The method and the apparatus are based on the same technical concept. Because the problem-solving principles of the method and the apparatus of the present invention are similar, the implementations of the apparatus and the method of the present invention will refer to each other, and the overlapping parts will not be described again.

[0127] An embodiment of the present application provides a first communication method, and Figure 3 is a flowchart of the method.

[0128] S300: The first node acquires a second key used for authenticating communication with the second node.

[0129] The second key in the present embodiment is different from the preset first key.

[0130] Optionally, in this embodiment of the present application, the first node is configured to perform communication authentication on the first communication connection, and the second node is configured to perform communication authentication on the second communication connection.

[0131] In an optional aspect of the present application, the first key is a key derived (or negotiated) based on a first communication system, and / or the second key is a key derived (or negotiated) based on a second communication system, the first communication system being different from the second communication system.

[0132] In this application, the first communication system may be a single communication system, such as a wireless short-range communication system, a 5G cellular network communication system, an ultra-reliable low-latency communication system, an enhanced mobile broadband communication system, or a large-scale machine-connected communication system. In this application, the second communication system may be a communication system obtained after different communication systems are integrated, such as a communication system obtained after a wireless short-range communication system is integrated into a 5G cellular network communication system, or a communication system obtained after a 5G cellular network communication system is integrated into an ultra-reliable low-latency communication system.

[0133] Specifically, the first key may be a key used for authentication in an initial connection phase between the first node and the second node. The first key may be set in advance before the first node and the second node make an initial connection with each other. Alternatively, the first key may be determined by the second node and indicated to the first node by signaling. Alternatively, the first key may be determined by the first node and indicated to the second node by signaling. This is not a limitation in the present application.

[0134] Specifically, the second key may be determined by the first node and indicated to the second node by signaling after the first node establishes a first communication connection to the second node. Alternatively, the second key may be determined by the second node and indicated to the first node by signaling after the first node establishes a first communication connection to the second node. Alternatively, the second key may be jointly negotiated by the first node and the second node after the first node establishes a first communication connection to the second node. This is not a limitation in this application.

[0135] Furthermore, to further ensure the security of the communication system, the second key obtained by the first node and used for authenticating communication with the second node has a specific time validity. It is understood that if the second key is valid, the second key may be used for authentication in the second communication connection. Alternatively, if the second key is invalid, the second key cannot be used for authentication in the second communication connection. Also, if the second key is invalid, the key may be updated.

[0136] Before S300 is implemented, the following step 1 may be further included: the first node and the second node are connected in an integrated manner (i.e., an initial authentication procedure in an integrated scenario of different communication systems is implemented).

[0137] A specific implementation process of step 1 may be as follows: the first node and the second node perform authentication for an initial connection based on a first key; after the first node and the second node determine that the authentication for the initial connection based on the first key is successful, the first node and the second node establish a first communication connection that performs communication authentication based on the first key.

[0138] S301: The second node acquires a second key used for authenticating communication with the first node.

[0139] Specifically, the second key may be determined by the first node and indicated to the second node by signaling after the first node establishes a first communication connection to the second node. Alternatively, the second key may be determined by the second node and indicated to the first node by signaling after the first node establishes a first communication connection to the second node. Alternatively, the second key may be jointly negotiated by the first node and the second node after the first node establishes a first communication connection to the second node. This is not a limitation in this application.

[0140] S302: The second node sends a release request for the first communication connection to the first node.

[0141] The release request may include one or more of the following information 1 to information 4.

[0142] Information 1: Request cause information, which indicates that a key used for communication authentication is to be updated.

[0143] Information 2: Request time, which indicates the time when the second node sends the release request. Optionally, the request time can be represented using a timestamp.

[0144] Information 3: Release time, which indicates the time when the first node releases the first communication connection.

[0145] For example, the release time may indicate a specific time. For example, the specific time may be one minute after the first node receives the release request. In this case, the first node releases the first communication connection one minute after receiving the release request based on the release time included in the release request. Alternatively, the release time may indicate a specific time period. For example, the specific time period may be within five minutes after the first node receives the release request. In this case, the first node releases the first communication connection within five minutes after receiving the release request based on the release time included in the release request.

[0146] Information 4: Information indicating that radio resources are to be deactivated.

[0147] The release request may further indicate that the radio resources are to be suspended. For example, the release request may include information indicating that the radio resources corresponding to the first communication connection are to be suspended.

[0148] After determining that the first key used for communication authentication has been updated to the second key, the first node and the second node stop and do not release the radio resources corresponding to the first communication connection if the first communication connection is released and the second communication connection is not successfully established, thereby effectively achieving a rapid recovery of the communication link.

[0149] The contents of information 1 to information 4 included in the release request are examples of information included in the release request, and do not limit the information included in the release request.

[0150] Also, the first node receiving the release request from the second node may include, but is not limited to:

[0151] The release request may be based on an improvement in signaling transmission between the first node and the second node. Alternatively, the release request may be made in signaling transmission between the first node and the second node. For example, in practical applications, the release request may be conveyed in signaling indicating the second key sent from the first node to the second node, or the release request may be new signaling between the first node and the second node.

[0152] Additionally, the second node releases the first communication connection to the first node.

[0153] In any aspect of the present application, the second node may determine that the key has been updated after receiving the second key, and may therefore trigger the release of the first communication connection to the first node and establish a second communication connection in which communication authentication is performed based on the second key.

[0154] Furthermore, the second node may further receive a release request response from the first node, which is used to notify the first node of a release status of the first communication connection based on when the second node sent the release request for the first communication connection to the first node.

[0155] Furthermore, the second node may release the first communication connection to the first node before executing S302. That is, the second node releases the first communication connection to the first node after obtaining the second key. Alternatively, the second node may release the first communication connection to the first node after executing S302. That is, the second node releases the first communication connection to the first node after sending a release request for the first communication connection to the first node. Alternatively, the second node may further release the first communication connection to the first node after receiving a release request response from the first node and determining that the first node has completed the release of the first communication connection.

[0156] S303: The first node receives a release request for the first communication connection from the second node.

[0157] Additionally, the first node releases the first communication connection to the second node.

[0158] It should be noted that in any aspect of the present application, after receiving a request to release the first communication connection from the second node, the first node may trigger the release of the first communication connection to the second node.

[0159] Additionally, the first node may transmit a response based on the release request to the second node to notify the second node of the release status of the first communication connection of the first node.

[0160] S304: The first node sends a connection establishment request to the second node. The connection establishment request is used to request to establish a connection based on the second key.

[0161] Optionally, the connection establishment request sent by the first node to the second node may include, but is not limited to:

[0162] The connection establishment request may be an improvement based on signaling transmission between the first node and the second node. Alternatively, the connection establishment request may be made in signaling transmission between the first node and the second node. Alternatively, the connection establishment request may be new signaling between the first node and the second node.

[0163] The connection establishment request may include one or more of the following information 1 to information 4.

[0164] Information 1: Request cause information, which indicates that a key used for communication authentication is to be updated.

[0165] Information 2: Request time, which indicates the time when the first node sends the connection establishment request. Optionally, the request time can be represented using a timestamp.

[0166] Information 3: Connection establishment time, which indicates the time when the first node establishes a second communication connection to the second node.

[0167] For example, the connection establishment time may indicate a specific time. For example, the specific time may be one minute after the second node receives the connection establishment request. In this case, the second node establishes the second communication connection to the first node one minute after receiving the connection establishment request based on the connection establishment time included in the connection establishment request. Alternatively, the connection establishment time may indicate a specific time period. For example, the specific time period may be within five minutes after the second node receives the connection establishment request. In this case, the second node establishes the second communication connection to the first node within five minutes after receiving the connection establishment request based on the connection establishment time included in the connection establishment request.

[0168] Information 4: Information indicating connection recovery.

[0169] It can be understood that the connection establishment request may be a request to restore a connection between a first node and a second node. That is, after a first communication connection between the first node and the second node is released, the first node and the second node need to establish a second communication connection that performs communication authentication based on a second key. In this case, the first node may send a connection restoration request to the second node, and after receiving the connection restoration request, the second node may establish a communication connection with the first node.

[0170] The contents of information 1 to information 4 included in the connection establishment request are examples of information included in the connection establishment request, and do not limit the information included in the connection establishment request.

[0171] S305: The second node receives the connection establishment request sent by the first node.

[0172] Further, using the connection establishment request to request establishment of a connection based on the second key may include: using the connection establishment request to request performing authentication and security context negotiation procedures based on the second key.

[0173] Optionally, the authentication and security context negotiation procedure may also include an identity authentication process of the first node and the second node (eg, interaction of authentication information and authentication response).

[0174] The identity authentication process of the first node and the second node can be described as follows:

[0175] First, after the second node receives the connection establishment request sent by the first node, the second node sends authentication information based on the second key to the first node, and the authentication information is used to verify the identity of the second node. It is understood that the first node can use the authentication information to verify whether the first node can establish a second communication connection to the second node based on the second key.

[0176] Optionally, the authentication information may include an authentication vector derived by the second node using the second key.

[0177] The first node then receives authentication information from the second node based on the second key, and after determining that authentication with the second node is successful, the first node sends an authentication response to the authentication information to the second node, where the authentication response is used to verify the identity of the first node. It will be understood that the second node can use the authentication response to verify whether the second node can establish a second communication connection to the first node based on the second key.

[0178] Optionally, the first node may determine whether authentication with the second node was successful based on an authentication vector included in the received authentication information and derived by the second node using the second key.

[0179] For example, after receiving the authentication information, the first node obtains the first authentication vector included in the authentication information and derived by the second node based on the second key. The first node derives a second authentication vector based on the second key and compares the first authentication vector with the second authentication vector. If the first authentication vector and the second authentication vector satisfy the authentication requirement, for example, the authentication requirement may be that the first authentication vector and the second authentication vector are identical or that the sum of the first authentication vector and the second authentication vector is zero, the first node determines that the authentication at the second node has been successful. If the first authentication vector and the second authentication vector do not satisfy the authentication requirement, the first node determines that the authentication at the second node has failed.

[0180] Finally, the second node receives the authentication response sent by the first node and performs identity authentication with the first node based on the authentication response.

[0181] According to the above method, after determining the updated key, the first node and the second node release the connection and then establish a connection using the new key, thereby realizing switching between different communication connections and realizing the process of updating the key used for communication authentication, thereby effectively improving communication security.

[0182] To explain the communication method provided by the present application in more detail, the following two scenarios will be described in more detail based on the contents shown in Fig. 3. Some steps in the following scenarios are optional, and the step sequence does not represent an actual execution sequence. Therefore, the present application is not limited to performing the following steps and sequences.

[0183] Scenario 1: After obtaining the second key, the first node actively releases the first communication connection.

[0184] 4A and 4B, the following steps may be performed in a manner corresponding to Scenario 1.

[0185] S400: A first node establishes a first communication connection to a second node based on a first key.

[0186] S401: The first node acquires a second key used for authenticating communication with the second node.

[0187] S402: The second node acquires a second key used for authenticating communication with the first node.

[0188] S403: The second node releases the first communication connection to the first node.

[0189] S404: The first node releases the first communication connection to the second node.

[0190] S405: The first node sends a connection establishment request to the second node. The connection establishment request is used to request to establish a connection based on the second key.

[0191] S406: The second node receives the connection establishment request sent by the first node.

[0192] S407: The second node sends authentication information based on the second key to the first node, where the authentication information is used to verify the identity of the second node.

[0193] S408: The first node receives authentication information based on the second key from the second node.

[0194] S409: The first node determines whether authentication at the second node is successful, and if authentication at the second node is successful, executes S410, and if authentication at the second node is unsuccessful, executes S411.

[0195] S410: The first node sends an authentication response to the authentication information to the second node, verifies the identity of the first node using the authentication response, and continues with S412.

[0196] Optionally, the authentication response includes authentication information generated based on a second key.

[0197] The authentication information may include one or more of the following information 1 and information 2.

[0198] Information 1: An authentication vector obtained by the first node based on the second key, for example, the second authentication vector in the example content of step S305.

[0199] Info 2: The result of the authentication performed by the first node against the second node.

[0200] The contents of information 1 and information 2 included in the authentication information are examples of information included in the authentication information, and do not limit the information included in the authentication information.

[0201] S411: After determining that the authentication performed by the second node on the second communication connection based on the second key has failed, the first node terminates the communication transmission.

[0202] In any aspect of the present application, after the first node determines that authentication with the second node has failed, the second node may further resume communication authentication based on the second key and terminate the communication transmission when the number of authentication failures reaches a threshold number of failures.

[0203] For example, the threshold failure number is set to 2. After the first node determines that communication authentication based on the second key with the second node has failed, the first node may send an authentication failure message to the second node. After receiving the authentication failure message, the second node may resend authentication information based on the second key to the first node to perform authentication again.

[0204] The first node receives authentication information based on the second key from the second node again and performs communication authentication. If the first node determines in the second authentication that the communication authentication performed by the second node based on the second key has failed, the first node determines that the number of authentication failures has reached the threshold amount 2 and terminates the communication transmission.

[0205] Similarly, if the second node receives two consecutive messages indicating that communication authentication based on the second key has failed, the second node may terminate the communication transmission. Alternatively, after deciding to terminate the communication transmission, the first node may send a message to terminate the communication transmission to the second node, and the second node may terminate the communication transmission after receiving the message to terminate the communication transmission from the first node.

[0206] S412: The second node receives the authentication response sent by the first node.

[0207] Optionally, the second node that receives the authentication response may determine whether the authentication at the first node is successful based on the authentication information included in the authentication response, which is generated based on the second key. For specific determination methods, please refer to the determination method of the first node described above. For brevity, the details will not be described again here.

[0208] S413: The second node determines whether authentication with the first node is successful, and if authentication with the first node is successful, executes S414, and if authentication with the first node is unsuccessful, executes S415.

[0209] S414: After the second node determines that the authentication at the second node is successful, it establishes a second communication connection to the first node, and then executes S416.

[0210] S415: After determining that the authentication performed by the first node on the second communication connection based on the second key has failed, the second node terminates the communication transmission.

[0211] In any aspect of the present application, after the second node decides to end the communication transmission, the second node sends a communication transmission end message to the first node, and after the first node receives the communication transmission end message from the second node, the first node ends the communication transmission.

[0212] S416: After the first node completes the establishment of the second communication connection to the second node, the first node notifies the second node that the establishment of the second communication connection has been completed.

[0213] S417: The first node transmits information to and from the third node using the backhaul link between the second node and the third node.

[0214] In the method procedures shown in Figures 4A and 4B, the sequence numbers of the steps do not indicate the execution sequence. The execution order of the processes should be determined based on the function and internal logic of the processes, and should not be considered as a limitation on the implementation process of the embodiment of the present invention. For example, S402 may take precedence over S401. In addition, in the method procedures shown in Figures 4A and 4B, the above steps are not limited, and addition, deletion, or modification of the above steps is within the scope of protection of the present application.

[0215] Scenario 2: The first node receives a request to release the first communication connection sent from the second node, and then releases the first communication connection.

[0216] 5A and 5B, the following steps may be performed in a manner corresponding to Scenario 2.

[0217] S500: A first node establishes a first communication connection to a second node based on a first key.

[0218] S501: The first node acquires a second key used for authenticating communication with the second node.

[0219] S502: The second node acquires a second key used for authenticating communication with the first node.

[0220] S503: The second node releases the first communication connection to the first node.

[0221] S504: The second node sends a release request for the first communication connection to the first node.

[0222] S505: The first node receives a release request for the first communication connection from the second node.

[0223] S506: The first node releases the first communication connection to the second node.

[0224] S507: The first node sends a connection establishment request to the second node. The connection establishment request is used to request to establish a connection based on the second key.

[0225] S508: The second node receives the connection establishment request sent by the first node.

[0226] S509: The second node sends authentication information based on the second key to the first node, where the authentication information is used to verify the identity of the second node.

[0227] S510: The first node receives authentication information based on the second key from the second node.

[0228] S511: The first node determines whether authentication at the second node is successful, and if authentication at the second node is successful, executes S512, and if authentication at the second node is unsuccessful, executes S513.

[0229] S512: After determining that the authentication with the second node is successful, the first node sends an authentication response to the authentication information to the second node, verifies the identity of the first node using the authentication response, and then executes S514.

[0230] S513: After determining that the authentication performed by the second node on the second communication connection based on the second key has failed, the first node terminates the communication transmission.

[0231] S514: The second node receives the authentication response sent by the first node.

[0232] In this application, optionally, the second node that receives the authentication response may determine whether the authentication at the first node is successful based on the authentication information generated based on the second key and included in the authentication response. For a specific determination method, please refer to the determination method of the first node described above. For brevity, the details will not be described again here.

[0233] S515: The second node determines whether authentication with the first node is successful, and if authentication with the first node is successful, executes S516, and if authentication with the first node is unsuccessful, executes S517.

[0234] S516: After the second node determines that the authentication at the second node is successful, it establishes a second communication connection to the first node, and then executes S518.

[0235] S517: After determining that the authentication performed by the first node on the second communication connection based on the second key has failed, the second node terminates the communication transmission.

[0236] S518: After the first node completes the establishment of the second communication connection to the second node, the first node notifies the second node that the establishment of the second communication connection has been completed.

[0237] S519: The first node transmits information to and from the third node using the backhaul link between the second node and the third node.

[0238] Note that in the method procedures shown in Figures 5A and 5B, the sequence numbers of the steps do not indicate the execution sequence. The execution order of the processes should be determined based on the function and internal logic of the processes, and should not be considered as a limitation on the implementation process of the embodiment of the present invention. For example, S502 may take precedence over S501. Furthermore, in the method procedures shown in Figures 5A and 5B, the above steps are not limited, and addition, deletion, or modification of the above steps is within the scope of protection of the present application.

[0239] Furthermore, in the present application, to effectively reduce system overhead, the second node may further deactivate the backhaul link after releasing the first communication connection to the first node, and may activate the backhaul link after determining that the second communication connection to the first node has been successfully established.

[0240] Referring to the above Scenario 2, the operation content of stopping and starting the backhaul link in the communication process will be described. Please refer to Figure 6A and Figure 6B. The corresponding method steps are as follows:

[0241] S600: A first node establishes a first communication connection to a second node based on a first key.

[0242] S601: The first node acquires a second key used for authenticating communication with the second node.

[0243] S602: The second node acquires a second key used for authenticating communication with the first node.

[0244] S603: The second node releases the first communication connection to the first node.

[0245] S604: The second node stops the backhaul link between the second node and the third node.

[0246] S605: The second node sends a release request for the first communication connection to the first node.

[0247] S606: The first node receives a release request for the first communication connection from the second node.

[0248] S607: The first node releases the first communication connection to the second node.

[0249] S608: The first node sends a connection establishment request to the second node. The connection establishment request is used to request to establish a connection based on the second key.

[0250] S609: The second node receives the connection establishment request sent by the first node.

[0251] S610: The second node sends authentication information based on the second key to the first node, where the authentication information is used to verify the identity of the second node.

[0252] S611: The first node receives authentication information based on the second key from the second node.

[0253] S612: After determining that the authentication with the second node is successful, the first node sends an authentication response to the authentication information to the second node and verifies the identity of the first node using the authentication response.

[0254] S613: The second node receives the authentication response sent by the first node.

[0255] S614: The second node establishes a second communication connection to the first node after determining that the authentication at the second node is successful.

[0256] S615: After the first node completes the establishment of the second communication connection to the second node, the first node notifies the second node that the establishment of the second communication connection has been completed.

[0257] S616: After the second node determines that the second communication connection to the first node has been successfully established, it activates the backhaul link.

[0258] S617: The first node transmits information to and from the third node using the backhaul link between the second node and the third node.

[0259] Note that in the method procedures shown in Figures 6A and 6B, the sequence numbers of the steps do not indicate the execution sequence. The execution order of the processes should be determined based on the function and internal logic of the processes, and should not be considered as a limitation on the implementation process of the embodiment of the present invention. For example, S605 may take precedence over S604. Furthermore, in the method procedures shown in Figures 6A and 6B, the above steps are not limited, and addition, deletion, or modification of the above steps is within the scope of protection of the present application.

[0260] In this application, the backhaul link is stopped after the connection is released, and is started after the connection is established, which can effectively reduce the power consumption of the system and save resources.

[0261] In the case of the above scenario 1, the contents of stopping and starting the backhaul link in the communication process are the same as those in Figures 6A and 6B. For simplification, the contents of Figures 6A and 6B and the case of the above scenario 1 are referred to. In order to obtain the contents of stopping and starting the backhaul link in the communication process by referring to the case of the above scenario 1, steps S605 and S606 in Figure 6A are deleted. The details will not be described again here.

[0262] In the present application, in order to further ensure the time validity of the second key and improve the security of communication transmission, whether the second key is valid may be further verified during the process in which the first node and the second node perform communication transmission using the second key.

[0263] In the present application, the first node may determine whether the second key is valid and notify the second node of the determination result of the second key. Alternatively, the second node may determine whether the second key is valid and notify the first node of the determination result of the second key. Alternatively, both the first node and the second node may determine the validity of the second key.

[0264] In an optional aspect of the present application, the second key is valid for a first period of time, which may be defined using a timer or a timestamp. The first period of time may be timed starting from a first point in time. The first point in time may be when the first communication connection is released, or when the second node receives a connection establishment request and / or when the first node sends a connection establishment request. This is not particularly limited.

[0265] The following describes the case where the above Scenario 2 is referred to, and the case where both the first node and the second node are selected to determine the validity of the second key. In this application, several verification methods are provided, but are not limited to the following methods:

[0266] Method 1: The first node and the second node each independently determine whether the second key is valid based on their corresponding timers.

[0267] 7A and 7B, the method steps corresponding to Method 1 are as follows.

[0268] S700: A first node establishes a first communication connection to a second node based on a first key.

[0269] S701: The first node acquires a second key used for authenticating communication with the second node.

[0270] S702: The second node acquires a second key used for authenticating communication with the first node.

[0271] S703: The second node releases the first communication connection to the first node.

[0272] S704: The second node starts a corresponding second timer used to determine the validity of the second key.

[0273] The normal operation period of the second timer is the first period.

[0274] S705: The second node sends a release request for the first communication connection to the first node.

[0275] S706: The first node receives a release request for the first communication connection from the second node.

[0276] S707: The first node releases the first communication connection to the second node.

[0277] S708: The first node starts a corresponding first timer used to determine the validity of the second key.

[0278] The normal operation period of the first timer is the first period.

[0279] S709: The first node sends a connection establishment request to the second node. The connection establishment request is used to request to establish a connection based on the second key.

[0280] S710: The second node receives the connection establishment request sent by the first node.

[0281] S711: The second node sends authentication information based on the second key to the first node, where the authentication information is used to verify the identity of the second node.

[0282] S712: The first node receives authentication information based on the second key from the second node.

[0283] S713: After determining that the authentication with the second node is successful, the first node sends an authentication response to the authentication information to the second node and verifies the identity of the first node using the authentication response.

[0284] S714: The second node receives the authentication response sent by the first node.

[0285] S715: The second node establishes a second communication connection to the first node after determining that the authentication at the second node is successful.

[0286] S716: After the first node completes the establishment of the second communication connection to the second node, the first node notifies the second node that the establishment of the second communication connection has been completed.

[0287] S717: The first node stops the corresponding first timer.

[0288] S718: The first node determines whether the first timer has expired, and executes S719 if the first timer has expired, or executes S720 if the first timer has not expired.

[0289] S719: The first node determines that the second key is invalid and terminates the communication transmission.

[0290] S720: The first node transmits information to and from the third node using the backhaul link between the second node and the third node.

[0291] S721: After receiving a notification from the first node indicating that the establishment of the second communication connection has been completed, the second node stops the corresponding second timer.

[0292] S722: The second node determines whether the second timer has expired, and executes S723 if the second timer has expired, or executes S724 if the second timer has not expired.

[0293] S723: The second node determines that the second key is invalid and terminates the communication transmission.

[0294] S724: The second node sends the transmission information from the first node to the third node using the backhaul link between the second node and the third node.

[0295] In the present application, in the method steps shown in Figures 7A and 7B, the time when the first node starts the corresponding first timer is not limited to the time after step S707. For example, the time when the first node starts the corresponding first timer may alternatively be after step S709. Similarly, the time when the second node starts the corresponding second timer is not limited to the time after step S704. For example, the time when the second node starts the corresponding second timer may alternatively be after step S710.

[0296] Note that in the method procedures shown in Figures 7A and 7B, the sequence numbers of the steps do not indicate the execution sequence. The execution order of the processes should be determined based on the function and internal logic of the processes, and should not be considered as a limitation on the implementation process of the embodiment of the present invention. For example, S702 may take precedence over S701. Furthermore, in the method procedures shown in Figures 7A and 7B, the above steps are not limited, and addition, deletion, or modification of the above steps is within the scope of protection of the present application.

[0297] When referring to the case of scenario 1, the content of determining the validity of the second key in method 1 is similar to the content of Figures 7A and 7B. For simplicity, when referring to the content of Figures 7A and 7B and the case of scenario 1, steps S705 and S706 in Figure 7A are deleted, and the content of determining the validity of the second key in method 1 referring to the case of scenario 1 is obtained. The details will not be described again here.

[0298] Method 2: The first node and the second node maintain the same timer to determine whether the second key is valid.

[0299] 8A and 8B, the method steps corresponding to Method 2 are as follows.

[0300] S800: A first node establishes a first communication connection to a second node based on a first key.

[0301] S801: The first node acquires a second key used for authenticating communication with the second node.

[0302] S802: The second node acquires a second key used for authenticating communication with the first node.

[0303] S803: The second node releases the first communication connection to the first node.

[0304] S804: The second node starts a timer used to determine the validity of the second key.

[0305] S805: The second node sends a release request for the first communication connection to the first node.

[0306] S806: The first node receives a release request for the first communication connection from the second node.

[0307] S807: The first node releases the first communication connection to the second node.

[0308] S808: The first node sends a connection establishment request to the second node. The connection establishment request is used to request to establish a connection based on the second key.

[0309] S809: The second node receives the connection establishment request sent by the first node.

[0310] S810: The second node sends authentication information based on the second key to the first node, where the authentication information is used to verify the identity of the second node.

[0311] S811: The first node receives authentication information based on the second key from the second node.

[0312] S812: After determining that the authentication with the second node is successful, the first node sends an authentication response to the authentication information to the second node and verifies the identity of the first node using the authentication response.

[0313] S813: The second node receives the authentication response sent by the first node.

[0314] S814: The second node establishes a second communication connection to the first node after determining that the authentication at the second node is successful.

[0315] S815: After the first node completes the establishment of the second communication connection to the second node, the first node notifies the second node that the establishment of the second communication connection has been completed.

[0316] S816: The first node stops the timer.

[0317] S817: The first node determines whether the timer has expired, and if the timer has expired, executes S818, and if the timer has not expired, executes S819.

[0318] S818: The first node determines that the second key is invalid and terminates the communication transmission.

[0319] In the present application, optionally, the first node may further notify the second node of the result that the second key is invalid.

[0320] S819: The first node transmits information to and from the third node using the backhaul link between the second node and the third node.

[0321] 8A and 8B, the first node may alternatively start the timer and the second node may stop the timer. For example, after performing S807, the first node may start the timer, and the second node may stop the timer after receiving a notification sent by the first node indicating that the establishment of the second communication connection has been completed in S815. Similarly, the second node may determine whether the timer has expired and then determine whether the second key is valid.

[0322] Note that in the method procedures shown in Figures 8A and 8B, the sequence numbers of the steps do not indicate the execution sequence. The execution order of the processes should be determined based on the function and internal logic of the processes, and should not be considered as a limitation on the implementation process of the embodiment of the present invention. For example, S802 may take precedence over S801. Furthermore, in the method procedures shown in Figures 8A and 8B, the above steps are not limited, and addition, deletion, or modification of the above steps is within the scope of protection of the present application.

[0323] When referring to the case of scenario 1, the content of determining the validity of the second key in method 2 is similar to the content of Figures 8A and 8B. For simplicity, when referring to the content of Figures 8A and 8B and the case of scenario 1, steps S805 and S806 in Figure 8A are deleted, and the content of determining the validity of the second key in method 2 referring to the case of scenario 1 is obtained. The details will not be described again here.

[0324] Method 3: The first node and the second node determine whether the second key is valid based on a timestamp conveyed in the signaling.

[0325] 9A to 9C, the method steps corresponding to Method 3 are as follows.

[0326] S900: A first node establishes a first communication connection to a second node based on a first key.

[0327] S901: The first node acquires a second key used for authenticating communication with the second node.

[0328] S902: The second node acquires a second key used for authenticating communication with the first node.

[0329] S903: The second node releases the first communication connection to the first node.

[0330] S904: The second node sends a release request for the first communication connection to the first node, the release request carrying the first timestamp.

[0331] The first timestamp may be the time when the second node sent the release request to the first node.

[0332] In the present application, optionally, the second node records a first timestamp after sending the release request to the first node.

[0333] S905: The first node receives a release request for the first communication connection from the second node, and obtains a first timestamp.

[0334] S906: The first node releases the first communication connection to the second node.

[0335] S907: The first node sends a connection establishment request to the second node. The connection establishment request is used to request to establish a connection based on the second key.

[0336] S908: The second node receives the connection establishment request sent by the first node.

[0337] S909: The second node sends authentication information based on the second key to the first node, where the authentication information is used to verify the identity of the second node.

[0338] S910: The first node receives authentication information based on the second key from the second node.

[0339] S911: After determining that the authentication with the second node is successful, the first node sends an authentication response to the authentication information to the second node, and verifies the identity of the first node using the authentication response.

[0340] S912: The second node receives the authentication response sent by the first node.

[0341] S913: The second node establishes a second communication connection to the first node after determining that the authentication at the second node is successful.

[0342] S914: After the first node completes the establishment of the second communication connection to the second node, the first node sends an establishment completion message to the second node, where the establishment completion message carries a second timestamp.

[0343] The Establishment Complete message is used to notify the second node that the first node has completed the establishment of the second communication connection.

[0344] The second timestamp may be the time when the first node sends an establishment completion message to the second node, or the second timestamp may be the time when the first node completes establishment of the second communication connection.

[0345] In this application, the first node optionally records a second timestamp.

[0346] S915: The first node determines whether the time difference between the second timestamp and the first timestamp does not exceed the first period, and if the time difference between the second timestamp and the first timestamp does not exceed the first period, executes S916, and if the time difference between the second timestamp and the first timestamp exceeds the first period, executes S917.

[0347] S916: The first node transmits information to and from the third node using the backhaul link between the second node and the third node.

[0348] S917: The first node determines that the second key is invalid and terminates the communication transmission.

[0349] S918: After receiving the establishment completion message, the second node obtains a second timestamp.

[0350] S919: The second node determines whether the time difference between the second timestamp and the first timestamp does not exceed the first period, and executes S920 if the time difference between the second timestamp and the first timestamp does not exceed the first period, and executes S921 if the time difference between the second timestamp and the first timestamp exceeds the first period.

[0351] S920: The second node sends transmission information from the first node to the third node using a backhaul link between the second node and the third node.

[0352] S921: The second node determines that the second key is invalid and terminates the communication transmission.

[0353] 9A to 9C are merely examples of how the first node and the second node use a timestamp to determine whether the second key is valid, and do not limit the method of using a timestamp to determine whether the second key is valid, or the steps described above. Addition, deletion, or modification of the steps described above is within the scope of protection of the present application.

[0354] With reference to the case of scenario 1, the contents of determining the validity of the second key in method 3 are similar to those of Figures 9A to 9C. For simplicity, with reference to the contents of Figures 9A to 9C and the case of scenario 1, steps S904 and S905 of Figure 9A are deleted, and the contents of determining the validity of the second key in method 3 with reference to the case of scenario 1 are the same. The details will not be explained again here.

[0355] In the present application, in the process of the first node and the second node using the second key for communication transmission, the validity of the second key is further verified, thereby ensuring the time validity of the second key and further ensuring the security of the communication transmission.

[0356] The communication system and the implemented communication method in the present application have been described in detail above with reference to Figures 3 to 9C. In this communication solution, the present application provides a communication method in a scenario where different communication systems perform integrated communication, thereby effectively improving communication security.

[0357] Furthermore, the contents of Figures 3 to 9C do not limit the communication methods provided in the present application. Any modifications of the contents of Figures 3 to 9C are within the scope of protection of the present application. For example, by combining the contents of Figures 4A and 4B, Figures 6A and 6B, and Figures 7A and 7B, a communication solution can be obtained in Scenario 1 of the present application, in which the backhaul link is stopped and started and the validity of the second key is verified. This can further reduce system overhead and improve communication security.

[0358] The method and the device are devised based on the same or similar technical concept. The method and the device have the same problem-solving principle. Therefore, the implementation of the device and the method refer to each other. Detailed descriptions of repeated parts are not provided. The terms "system" and "network" may be used synonymously in the embodiments of the present application. In the description of the embodiments of the present application, the term "and / or" describes an association relationship between associated objects and indicates that three relationships may exist. For example, A and / or B may indicate the following three cases: only A exists, both A and B exist, and only B exists. The character " / " generally indicates an "or" relationship between associated objects. In the present application, "at least one" means one or more, and "multiple" means two or more. Furthermore, it should be understood that in the description of the present application, terms such as "first," "second," and "third" are used merely for distinction and explanation, and should not be understood as an indication or suggestion of relative importance or an indication or suggestion of order. References herein to "an embodiment," "some embodiments," etc. mean that one or more embodiments of the present application include the particular feature, structure, or characteristic described with reference to the embodiment. Thus, the appearance of phrases such as "in an embodiment," "in some embodiments," "in some other embodiments," and "in other embodiments" in different places herein do not necessarily mean to refer to the same embodiment. Instead, unless otherwise specified, the statement means "one or more, but not all, of the embodiments." The terms "include," "have," and variations of these terms all mean "including, but not limited to," unless otherwise specified.

[0359] The device provided in the embodiment of the present application will be described in detail below with reference to Figures 10 and 11. It should be understood that the description of the device embodiment corresponds to the description of the method embodiment, and therefore, for the contents not described in detail, cross-reference will be made.

[0360] 10 is a schematic block diagram of a device 1000 according to an embodiment of the present application, configured to implement the functions of the first device or the second device in the aforementioned method embodiments. For example, the device may be a software module or a chip system. The chip may include a chip, or may include a chip and other individual components. The device 1000 includes a processing unit 1001 and a communication unit 1002. The communication unit 1002 is configured to communicate with another device and may also be referred to as a communication interface, a transceiver unit, an input / output interface, etc.

[0361] In some embodiments, device 1000 may be configured to implement the functionality of a first device in the above-described method. Device 1000 may be the first device, or a chip, circuit, etc. configured in the first device. Processing unit 1001 may be configured to perform operations related to processing of the first device in the above-described method embodiments, and communication unit 1002 may be configured to direct operations related to receiving and transmitting of the first device in the above-described method embodiments.

[0362] For example, the processing unit 1001 is configured to obtain a second key used for communication authentication with a second node, where the second key is different from the pre-configured first key. The communication unit 1002 is configured to receive a request to release the first communication connection from the second node, where the first key is used for communication authentication in the first communication connection. The communication unit 1002 is further configured to send a connection establishment request to the second node. The connection establishment request is used to request establishing a connection based on the second key.

[0363] Optionally, using the connection establishment request to request establishment of a connection based on the second key includes: using the connection establishment request to request performing authentication and security context negotiation procedures based on the second key.

[0364] Optionally, the communication unit 1002 is further configured to receive authentication information based on the second key from the second node, the authentication information being used to verify the identity of the second node.

[0365] Optionally, verifying the identity of the second node using the authentication information includes using the authentication information to verify whether a second communication connection to the second node is established based on said second key.

[0366] Optionally, the communication unit 1002 is further configured to send an authentication response to the second node based on the second key, where the authentication response is used to verify the identity of the first node.

[0367] Optionally, the authentication response is used to optionally verify the identity of the first node, including: the authentication response is used by the second node to verify whether to establish a second communication connection to the first node based on the second key.

[0368] Optionally, the release request includes request cause information, which indicates that a key used for communication authentication is to be updated.

[0369] Optionally, the second key is valid for a first period of time, the first period being defined using a timer or timestamp.

[0370] Optionally, the second key is valid for a first time period starting from a first time point, the first time point being the time point when the first communication connection is released or when the connection establishment request is sent.

[0371] Optionally, the processing unit 1001 is further configured to perform information transmission with the third node using a backhaul link between the second node and the third node within the validity period of the second key.

[0372] Optionally, the first key is a key derived (or negotiated) based on a first communication system, and / or the second key is a key derived (or negotiated) based on a second communication system, the first communication system being different from the second communication system.

[0373] In some other embodiments, device 1000 may be configured to implement the functionality of the second device in the above-mentioned method embodiments. Device 1000 may be the second device, or a chip, circuit, etc. configured in the second device. Processing unit 1001 may be configured to perform the processing-related operations of the second device in the above-mentioned method embodiments, and communication unit 1002 is configured to perform the receiving and transmitting-related operations of the second device in the above-mentioned method embodiments.

[0374] For example, the processing unit 1001 is configured to obtain a second key used for communication authentication with the first node, where the second key is different from the pre-configured first key. The communication unit 1002 is configured to send a request to release the first communication connection to the first node, where the first key is used for communication authentication in the first communication connection. The communication unit 1002 is further configured to receive a connection establishment request sent by the first node. The connection establishment request is used to request establishing a connection based on the second key.

[0375] Optionally, using the connection establishment request to request establishment of a connection based on the second key includes: using the connection establishment request to request performing authentication and security context negotiation procedures based on the second key.

[0376] Optionally, the communication unit 1002 is further configured to send authentication information based on the second key to the first node, the authentication information being used to verify the identity of the second node.

[0377] Optionally, verifying the identity of the second node using the authentication information includes verifying, by the first node, using the authentication information whether a second communication connection to the second node is established based on said second key.

[0378] Optionally, the first key is a key derived (or negotiated) based on a first communication system, and / or the second key is a key derived (or negotiated) based on a second communication system, the first communication system being different from the second communication system.

[0379] Optionally, the communication unit 1002 is further configured to receive an authentication response based on the second key from the first node, wherein the authentication response is used to verify the identity of the first node.

[0380] Optionally, the authentication response is used to optionally verify the identity of the first node, including: the authentication response is used by the second node to verify whether to establish a second communication connection to the first node based on the second key.

[0381] Optionally, the release request includes request cause information, which indicates that a key used for communication authentication is to be updated.

[0382] Optionally, the second key is valid for a first period of time, which may be defined using a timer or timestamp.

[0383] Optionally, the second key is valid for a first time period starting from a first time point, the first time point being the time point when the first communication connection is released or the time point when the second node receives the connection establishment request.

[0384] Optionally, the processing unit 1001 is further configured to send the transmission information from the first node to the third node using a backhaul link between the second node and the third node within the validity period of the second key.

[0385] Optionally, the processing unit 1001 is further configured to deactivate the backhaul link after releasing the first communication connection to the first node.

[0386] Optionally, the processing unit 1001 is further configured to activate a backhaul link after determining that the second communication connection to the first node has been successfully established, and communication authentication is performed for the second communication connection based on the second key.

[0387] In this embodiment of the present application, the division into units is an example and is merely a logical division of functions. In actual implementation, other division methods may be used. Furthermore, the functional units in this embodiment of the present application may be integrated into one processor, or each unit may exist physically alone, or two or more units may be integrated into one unit. The integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0388] 11 is a schematic diagram of a device 1100 according to one embodiment of the present application. The device 1100 may be a node or a component within a node, for example, a chip or an integrated circuit. The device 1100 may include at least one processor 1102 and a communication interface 1104. Optionally, the device may further include at least one memory 1101. Optionally, the device may further include a bus 1103. The memory 1101, the processor 1102, and the communication interface 1104 are communicatively coupled to each other via the bus 1103.

[0389] The memory 1101 is configured to provide a storage space, and the storage space can store data such as an operating system and computer programs. It should be understood that the memory 1101 referred to in the embodiments of the present application may be a volatile memory or a nonvolatile memory, or may include a volatile memory and a nonvolatile memory. The nonvolatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM) used as an external cache. By way of example, and not limitation, many types of RAM may be used, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (Synchlink DRAM, SLDRAM), and direct Rambus random access memory (DR RAM).

[0390] It should be noted that memory, as described herein, is intended to include, without being limited to, these and any other suitable types of memory. The processor 1102 is a module for performing arithmetic and / or logical operations, and may be one or a combination of multiple processing modules, such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor unit (MPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), a coprocessor (which assists the central processing unit in completing corresponding processes and applications), and a microcontroller unit (MCU).

[0391] It should be noted that the memory (storage module) may be integrated into the processor if the processor is a general purpose processor, an ASIC, FPGA or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component.

[0392] The communication interface 1104 may be configured to provide information input or output for at least one processor. Alternatively, the communication interface may be configured to receive data transmitted from an external source and / or transmit data to an external source, and may be a wired link interface, such as an Ethernet cable, or a wireless link interface (such as Wi-Fi, Bluetooth, universal wireless transmission, in-vehicle short-range communication technology, etc.). Optionally, the communication interface 1104 may further include a transmitter (such as a radio frequency transmitter or antenna), a receiver, etc. coupled to the interface.

[0393] In some embodiments, the device 1100 may be a first device in the above-described method embodiments, or a component in the first device, such as a chip or integrated circuit. A processor 1102 in the device 1100 is configured to load a computer program stored in the memory 1101 and control the first device to perform the following operations: A second key is obtained that is used for communication authentication with a second node, the second key being different from a preset first key, a request to release the first communication connection is received from the second node, the first key is used for communication authentication of the first communication connection, and a connection establishment request is sent to the second node, the connection establishment request is used to request the establishment of a connection based on the second key.

[0394] Optionally, the processor 1102 in the first device may be further configured to read the program in the memory 1101 and perform the method steps performed by the first node at S300 to S305 shown in Figure 3, or to perform the method steps performed by the first node at S400 to S417 shown in Figures 4A and 4B, or to perform the method steps performed by the first node at S500 to S519 shown in Figures 5A and 5B, or to perform the method steps performed by the first node at S600 to S617 shown in Figures 6A and 6B, or to perform the method steps performed by the first node at S700 to S724 shown in Figures 7A and 7B, or to perform the method steps performed by the first node at S800 to S819 shown in Figures 8A and 8B, or to perform the method steps performed by the first node at S900 to S921 shown in Figures 9A and 9C.

[0395] For specific details, please refer to the description in the preceding method embodiment, and the details will not be described again here.

[0396] In some other embodiments, device 1100 may be the second device in the aforementioned method embodiments, or a component in the second device, such as a chip or integrated circuit. A processor 1102 in device 1100 is configured to load a computer program stored in memory 1101 and control the second device to perform the following operations: A second key is obtained that is used for communication authentication with the first node, the second key being different from the preset first key, and a request to release the first communication connection is sent to the first node; the first key is used for communication authentication of the first communication connection; a connection establishment request sent by the first node is received; and the connection establishment request is used to request the establishment of a connection based on the second key.

[0397] Optionally, the processor 1102 in the second device may be further configured to read the program in the memory 1101 and perform the method steps performed by the second node at S300 to S305 shown in Figure 3, or to perform the method steps performed by the second node at S400 to S417 shown in Figures 4A and 4B, or to perform the method steps performed by the second node at S500 to S519 shown in Figures 5A and 5B, or to perform the method steps performed by the second node at S600 to S617 shown in Figures 6A and 6B, or to perform the method steps performed by the second node at S700 to S724 shown in Figures 7A and 7B, or to perform the method steps performed by the second node at S800 to S819 shown in Figures 8A and 8B, or to perform the method steps performed by the second node at S900 to S921 shown in Figures 9A and 9C.

[0398] For specific details, please refer to the description in the preceding method embodiment, and the details will not be described again here.

[0399] An embodiment of the present application further provides a terminal. The terminal may be an intelligent terminal such as a smartphone, a notebook computer, a tablet computer, etc., with a short-range communication function, a mouse, a keyboard, a headset, a speaker, an in-car playback device, etc. The terminal includes a first device and / or a second device. The first device and the second device may be the first node and the second node, respectively, in the embodiment shown in FIG. 3. The first device and the second device may be the same type or different types.

[0400] FIG. 12 is a schematic diagram of a simplified structure of a terminal device. For ease of explanation, FIG. 12 uses an example in which the terminal device is a mobile phone. As shown in FIG. 12, the terminal device includes a processor, a memory, a radio frequency circuit, an antenna, and input / output devices. The processor is mainly configured to process communication protocols and communication data, control the terminal device, execute software programs, and process data of the software programs. The memory is mainly configured to store software programs and data. The radio frequency circuit is mainly configured to perform conversion between baseband signals and radio frequency signals and process radio frequency signals. The antenna is mainly configured to transmit and receive radio frequency signals in the form of electromagnetic waves. The input / output devices, such as a touch screen, a display, or a keyboard, are mainly configured to receive data input by a user and output data to a user. It should be noted that some types of terminal devices may not have input / output devices.

[0401] When data needs to be transmitted, the processor performs baseband processing on the data to be transmitted and then outputs the baseband signal to the radio frequency circuit. The radio frequency circuit performs radio frequency processing on the baseband signal and transmits the radio frequency signal to the outside in the form of electromagnetic waves via an antenna. When data is transmitted to the terminal device, the radio frequency circuit receives the radio frequency signal via the antenna, converts the radio frequency signal into a baseband signal, and outputs the baseband signal to the processor. The processor converts the baseband signal into data and processes the data. For ease of explanation, FIG. 12 shows only one memory and one processor. An actual terminal device product may have one or more processors and one or more memories. The memory may also be referred to as a storage medium, storage device, etc. The memory may be located independently of the processor or integrated into the processor. This is not limited to the embodiments of the present application.

[0402] In this embodiment of the present application, the antenna and radio frequency circuitry having transceiver functionality may be considered a transceiver unit of the terminal device, and the processor having processing functionality may be considered a processing unit of the terminal device. As shown in FIG. 12, the terminal device includes a transceiver unit 1210 and a processing unit 1220. The transceiver unit may also be referred to as a transceiver, transceiver machine, transceiver equipment, etc. The processing unit may also be referred to as a processor, processing board, processing module, processing equipment, etc. Optionally, components within the transceiver unit 1210 configured to implement receiving functionality may be considered a receiving unit, and components within the transceiver unit 1210 configured to implement transmitting functionality may be considered a transmitting unit. In other words, the transceiver unit 1210 includes a receiving unit and a transmitting unit. The transceiver unit may sometimes be referred to as a transceiver machine, transceiver, transceiver circuit, etc. The receiving unit may sometimes be referred to as a receiving machine, receiver, receiving circuit, etc. A transmitting unit may sometimes be referred to as a transmitting machine, a transmitter, a transmitting circuit, or the like.

[0403] It should be noted that the transceiver unit 1210 is configured to perform a transmitting operation and a receiving operation on the first node side in the embodiment of the method shown in FIG. 3, and the processing unit 1220 is configured to perform an operation other than the transmitting operation and the receiving operation on the first node side in the embodiment of the method shown in FIG. 3.

[0404] For example, in an implementation, the transceiver unit 1210 is configured to perform transmission and reception operations, e.g., S303 and S305, at the terminal device side in the embodiment shown in Figure 3, and / or to support other processing of the techniques described herein. The processing unit 1220 is configured to perform operations other than transmission and reception operations, e.g., S300, at the terminal device side in the embodiment shown in Figure 3, and / or to support other processing of the techniques described herein.

[0405] Alternatively, the transceiver unit 1210 is configured to perform transmitting and receiving operations on the terminal device side in the embodiment of the method shown in Figures 4A and 4B, and the processing unit 1220 is configured to perform operations other than transmitting and receiving operations on the terminal device side in the embodiment of the method shown in Figures 4A and 4B.

[0406] For example, in an implementation, the transceiver unit 1210 may be configured to perform transmitting and receiving steps, e.g., S406 and S406, at the terminal device side in the embodiment shown in Figures 4A and 4B, and / or to support other processing of the techniques described herein. The processing unit 1220 may be configured to perform operations other than transmitting and receiving operations, e.g., S409, at the terminal device side in the embodiment shown in Figures 4A and 4B, and / or to support other processing of the techniques described herein.

[0407] Alternatively, the transceiver unit 1210 is configured to perform transmission and reception operations on the terminal device side in the embodiment of the method shown in Figures 5A and 5B, and the processing unit 1220 is configured to perform operations other than transmission and reception operations on the terminal device side in the embodiment of the method shown in Figures 5A and 5B.

[0408] For example, in an implementation, the transceiver unit 1210 may be configured to perform transmitting and receiving steps, e.g., S508 and S508, at the terminal device side in the embodiment shown in Figures 5A and 5B, and / or to support other processing of the techniques described herein. The processing unit 1220 may be configured to perform operations other than transmitting and receiving operations, e.g., S511, at the terminal device side in the embodiment shown in Figures 5A and 5B, and / or to support other processing of the techniques described herein.

[0409] Alternatively, the transceiver unit 1210 is configured to perform transmission and reception operations on the terminal device side in the embodiment of the method shown in Figures 6A and 6B, and the processing unit 1220 is configured to perform operations other than transmission and reception operations on the terminal device side in the embodiment of the method shown in Figures 6A and 6B.

[0410] For example, in an implementation, the transceiver unit 1210 may be configured to perform transmitting and receiving steps, e.g., S606 and S606, at the terminal device side in the embodiment shown in Figures 6A and 6B, and / or to support other processing of the techniques described herein. The processing unit 1220 may be configured to perform operations other than transmitting and receiving operations, e.g., S604, at the terminal device side in the embodiment shown in Figures 6A and 6B, and / or to support other processing of the techniques described herein.

[0411] Alternatively, the transceiver unit 1210 is configured to perform transmission and reception operations on the terminal device side in the embodiment of the method shown in Figures 7A and 7B, and the processing unit 1220 is configured to perform operations other than transmission and reception operations on the terminal device side in the embodiment of the method shown in Figures 7A and 7B.

[0412] For example, in an implementation, the transceiver unit 1210 may be configured to perform transmitting and receiving steps, e.g., S706 and S706, at the terminal device side in the embodiment shown in Figures 7A and 7B, and / or to support other processing of the techniques described herein. The processing unit 1220 may be configured to perform operations other than transmitting and receiving operations, e.g., S704, at the terminal device side in the embodiment shown in Figures 7A and 7B, and / or to support other processing of the techniques described herein.

[0413] Alternatively, the transceiver unit 1210 is configured to perform transmission and reception operations on the terminal device side in the embodiment of the method shown in Figures 8A and 8B, and the processing unit 1220 is configured to perform operations other than transmission and reception operations on the terminal device side in the embodiment of the method shown in Figures 8A and 8B.

[0414] For example, in an implementation, the transceiver unit 1210 may be configured to perform transmitting and receiving steps, e.g., S806 and S806, at the terminal device side in the embodiment shown in Figures 8A and 8B, and / or to support other processing of the techniques described herein. The processing unit 1220 may be configured to perform operations other than transmitting and receiving operations, e.g., S804, at the terminal device side in the embodiment shown in Figures 8A and 8B, and / or to support other processing of the techniques described herein.

[0415] Alternatively, the transceiver unit 1210 is configured to perform transmission and reception operations on the terminal device side in the embodiment of the method shown in Figures 9A to 9C, and the processing unit 1220 is configured to perform operations other than transmission and reception operations on the terminal device side in the embodiment of the method shown in Figures 9A to 9C.

[0416] For example, in an implementation, transceiver unit 1210 may be configured to perform transmitting and receiving steps, e.g., S905 and S906, at the terminal device side in the embodiment shown in Figures 9A-9C, and / or to support other processing of the techniques described herein. Processing unit 1220 may be configured to perform operations other than transmitting and receiving operations, e.g., S915, at the terminal device side in the embodiment shown in Figures 9A-9C, and / or to support other processing of the techniques described herein.

[0417] When the communication device is a chip, the chip includes a transceiver unit and a processing unit. The transceiver unit may be an input / output circuit or a communication interface. The processing unit may be a processor, a microprocessor, or an integrated circuit integrated into the chip.

[0418] An embodiment of the present application further provides a computer-readable storage medium containing instructions that, when executed on a computer, cause the computer to perform the method described in the preceding aspect.

[0419] An embodiment of the present application further provides a chip system. The chip system includes at least one processor and an interface circuit. Optionally, the chip system may further include a memory or an external memory. The processor is configured to execute instructions and / or data interactions through the interface circuit to implement the method in the aforementioned method embodiment. The chip system may include a chip, or may include a chip and other individual components.

[0420] An embodiment of the present application further provides a computer program product comprising instructions that, when executed on a computer, cause the computer to perform the method described in the preceding aspect.

[0421] In the embodiments of the present application, the processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic element, a discrete gate or transistor logic element, a discrete hardware component, or a coprocessor, which may implement or perform the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of the present application may be performed directly by a hardware processor, or may be performed using a combination of hardware and software modules in the processor.

[0422] In embodiments of the present application, the memory may be a non-volatile memory, such as a hard disk drive (HDD) or solid-state drive (SSD), or a volatile memory, such as a random-access memory (RAM). The memory may be any other medium capable of transmitting or storing expected program code in the form of instructions or data structures and accessible by a computer, but is not limited to such. The memory in embodiments of the present application may alternatively be a circuit or any other device capable of implementing a storage function and configured to store program instructions and / or data.

[0423] All or part of the methods in the embodiments of the present application can be implemented using software, hardware, firmware, or any combination thereof. When software is used to implement the embodiments, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When loaded and executed on a computer, the computer program instructions generate all or part of the procedures or functions according to the embodiments of the present application. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, user equipment, or another programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from a website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, optical fiber, or digital subscriber line (DSL)) or wireless (e.g., infrared, radio, or microwave) transmission. The computer-readable storage medium may be any available medium accessible by a computer, or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, or a magnetic tape), an optical medium (e.g., a digital video disc (DVD)), a semiconductor medium (e.g., an SSD), etc.

[0424] In combination with the examples described in the embodiments disclosed herein, those skilled in the art may recognize that the units and algorithms can be implemented by electronic hardware or a combination of computer software and electronic hardware. Whether a function is performed by hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but the implementation should not be considered to go beyond the scope of the present application.

[0425] For the purpose of convenience and concise description, the detailed operating processes of the aforementioned systems, devices and units may be clearly understood by those skilled in the art by referring to the corresponding processes in the aforementioned method embodiments, and the details will not be described again here.

[0426] The units described as separate parts may or may not be physically separated. The parts shown as units may or may not be physical units, and may be located in one place or distributed among multiple network units. Some or all of the units may be selected based on actual requirements to achieve the purpose of the solution of the embodiment.

[0427] When a function is implemented in the form of a software functional unit and sold or used as an independent product, the function may be stored in a computer-readable storage medium. Based on this understanding, essentially, the technical solution of the present application, or a portion contributing to the prior art, or all or a portion of the technical solution may be implemented in the form of a software product. The software product is stored in a storage medium and includes some instructions for instructing a computer device (which may be a personal computer, a server, or a network device) to execute all or a portion of the steps of the method described in the embodiments of the present application. The aforementioned storage medium includes any medium capable of storing program code, such as a USB flash drive, a removable hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0428] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the scope of the present application, and the present application intends to cover these modifications and variations of the present application if they fall within the scope of protection defined by the following claims and their equivalent techniques.

Claims

1. 1. A method of communication, the method comprising: obtaining a second key used for authenticating communication with the first node, the second key being different from the pre-defined first key; sending a request to the first node to release the first communication connection, wherein the first key is used for communication authentication of the first communication connection; receiving a connection establishment request from the first node, the connection establishment request being used to request establishment of a connection based on the second key; A method comprising:

2. The connection establishment request is used to request establishment of a connection based on the second key, The method of claim 1 , wherein the connection establishment request is used to request performing authentication and security context negotiation procedures based on the second key.

3. The method comprises:

2. The method of claim 1, further comprising the step of: sending to the first node authentication information based on the second key, the authentication information being used to verify the identity of the second node.

4. The method comprises:

4. The method of claim 3, further comprising receiving an authentication response from the first node based on the second key, the authentication response being used to verify the identity of the first node.

5. the release request includes request cause information; The method of claim 1 , wherein the request cause information indicates that a key used to authenticate communications is to be updated.

6. The method of claim 1 , wherein the second key is valid for a first period of time, the first period being defined by a timer or a timestamp.

7. 7. The method of claim 6, wherein the second key is valid within the first time period starting from a first time point, the first time point being the time point when the first communication connection is released or the time point when the connection establishment request is received by the second node.

8. The method comprises:

2. The method of claim 1, further comprising: sending an information transmission to the third node using a backhaul link between the second node and a third node during a validity period of the second key.

9. 2. The method of claim 1, wherein the first key is a key derived based on a first communication system and / or the second key is a key derived based on a second communication system, the first communication system being different from the second communication system.

10. 10. A communications device comprising at least one processor and an interface circuit, said interface circuit providing programs or instructions for said at least one processor, said at least one processor using logic circuits or executing said programs or instructions to enable a device in which said communications device is located to perform any one of claims 1 to 9.

11. A computer readable storage medium containing computer instructions, which when executed on a computer, enable the computer to carry out the method of any one of claims 1 to 9.

12. A terminal, comprising a second node, which executes the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • The method and device for updating the key in the active state

    EP2197147A1

  • Key update method, device, and storage medium

    EP3793317A1