Communication method, apparatus, and system
By updating communication keys during connection transitions, the method addresses the security gap in integrated communication systems, enhancing security and reducing system overhead.
Patent Information
- Application Number
- JP2024513466
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-08-30
- Filing Date
- 2022-08-25
- Publication Date
- 2025-08-04
- Estimated Expiration
- 2042-08-25
AI Technical Summary
Conventional communication standards lack a secure and effective method for integrating different communication systems, such as wireless short-range and 5G cellular networks, leading to inadequate security in these integrated scenarios.
A communication method where nodes release a connection using a preset key and establish a new connection with an updated key, enabling secure switching between different communication systems.
This approach enhances communication security by ensuring secure key updates and reduces system overhead, thereby improving the reliability of integrated communication systems.
Smart Images

Figure 0007717965000001 
Figure 0007717965000002 
Figure 0007717965000003
Abstract
Description
Technical Field
[0001] [Related Application] This application claims priority to Chinese Patent Application No. 202111005514.2, filed with the China National Intellectual Property Administration on August 30, 2021, and entitled "COMMUNICATION METHOD, APPARATUS, AND SYSTEM", which is incorporated herein by reference in its entirety.
[0002] [Technical Field] Embodiments of the present application relate to the field of communication technologies, and in particular, to communication methods, devices, and systems.
Background Art
[0003] The rapid development of mobile communication has promoted the continuous emergence of multiple application scenarios, and communication systems based on different communication technologies will inevitably be integrated. For example, due to the mature development of 5G technology and the wide application of wireless short-range communication systems, the scenario of integrating wireless short-range communication and 5G cellular networks has become a new trend. At the same time, the new integration scenario also poses higher requirements for the security of communication transmission.
[0004] However, in the conventional standards, there is no secure and effective communication method for the integration scenario of different communication systems.
Summary of the Invention
[0005] Embodiments of the present application provide a communication method, device, and system that update communication authentication keys and improve communication security.
[0006] According to a first aspect, embodiments of the present application provide a communication method, which can be applied to a first node. The method includes Obtaining a second key used for communication authentication with a second node, wherein the second key is different from a preset first key; receiving, from the second node, a request to release a first communication connection, wherein the first key is used for communication authentication of the first communication connection; and sending a connection establishment request to the second node, wherein the connection establishment request is used to request establishment of a connection based on the second key.
[0007] According to the above method, an embodiment of the present application provides a technical solution in which a first node and a second node release a connection after determining an updated key and establish a connection using the new key. Thereby, switching between different communication connections is realized, update processing of the key used for communication authentication is realized, and communication security is effectively improved.
[0008] In a possible implementation, requesting establishment of a connection based on the second key using the connection establishment request includes: requesting to execute an authentication and security context negotiation procedure based on the second key using the connection establishment request.
[0009] In a possible implementation, the method further includes receiving, from the second node, authentication information based on the second key, wherein the authentication information is used to verify the identity of the second node.
[0010] In a possible implementation, verifying the identity of the second node using the authentication information includes verifying whether a second communication connection to the second node is established based on the second key using the authentication information.
[0011] In a possible implementation, the first key is a key derived (or negotiated) based on the first communication system, and / or the second key is a key derived (or negotiated) based on the second communication system, and the first communication system is different from the second communication system.
[0012] In a possible implementation, the first communication system may be a single communication system, and the second communication system may be a communication system obtained after integration of different communication systems.
[0013] According to the foregoing method, embodiments of the present application provide a communication method in a scenario where communications integrated with different communication systems are performed. Thereby, communication security is effectively improved.
[0014] In a possible implementation, an authentication response based on the second key is transmitted to the second node, and the authentication response is used to verify the identity of the first node.
[0015] In a possible implementation, the fact that the authentication response is used to verify the identity of the first node includes the following: the authentication response is used by the second node to verify whether to establish the second communication connection to the first node based on the second key.
[0016] According to the above method, the first node transmits the authentication response to the second node, and the second node can further determine whether authentication based on the second key is successful based on the authentication response.
[0017] In a possible implementation, the release request includes request cause information, and the request cause information indicates that a key used for communication authentication is updated.
[0018] According to the above method, since the release request includes a request cause, after receiving the release request from the second node, the first node can learn the request cause, so the first node can respond to the request more appropriately and has strong adaptability.
[0019] In a possible implementation, the second key is valid within the first period, and the first period is defined using a timer or a timestamp.
[0020] According to the above method, in the process of the first node and the second node performing communication transmission using the second key, it is further verified whether the second key is valid. Thereby, the time validity of the second key can be ensured, and the security of communication transmission can be further ensured.
[0021] In a possible implementation, the second key is valid within the first period starting from the first time point, and the first time point is the time point when the first communication connection is released or the time point when the connection establishment request is sent.
[0022] According to the above method, the present application provides a plurality of cases of the first time point. Therefore, a plurality of solutions for determining the validity of the second key are provided, and the flexibility is high.
[0023] In a possible implementation, within the valid period of the second key, the method uses a backhaul link between the second node and the third node to perform information transmission with the third node.
[0024] According to a second aspect, an embodiment of the present application provides a communication method, which can be applied to a second node. The method includes the following: Obtaining a second key used for communication authentication with a first node, where the second key is different from a preset first key; Sending a request to release a first communication connection to the first node, where the first key is used for communication authentication of the first communication connection; Receiving a connection establishment request sent by the first node, where the connection establishment request is used to request the establishment of a connection based on the second key.
[0025] According to the above method, embodiments of the present application provide a technical solution in which the first node and the second node release the connection after determining the updated key and establish a connection using the new key. Thereby, switching between different communication connections is realized, the update process of the key used for communication authentication is realized, and the communication security is effectively improved.
[0026] In a possible implementation, using the connection establishment request to request the establishment of a connection based on the second key includes: using the connection establishment request to request to execute an authentication and security context negotiation procedure based on the second key.
[0027] In a possible implementation, the method further includes a step of transmitting authentication information based on the second key to the first node, where the authentication information is used to verify the identity of the second node.
[0028] In a possible implementation, using the authentication information to verify the identity of the second node includes verifying, by the first node, whether a second communication connection to the second node is established based on the second key using the authentication information.
[0029] In a possible implementation, the first key is a key derived (or negotiated) based on the first communication system, and / or the second key is a key derived (or negotiated) based on the second communication system, and the first communication system is different from the second communication system.
[0030] In a possible implementation, the first communication system may be a single communication system, and the second communication system may be a communication system obtained after the integration of different communication systems.
[0031] According to the foregoing method, embodiments of the present application provide a communication method in a scenario where different communication systems perform integrated communication. Thereby, communication security is effectively improved.
[0032] In a possible implementation, the method further includes the step of receiving, from the first node, an authentication response based on the second key, where the authentication response is used to verify the identity of the first node.
[0033] In a possible implementation, the use of the authentication response to verify the identity of the first node includes the following: the authentication response is used by the second node to verify whether to establish the second communication connection to the first node based on the second key. According to the above method, the first node transmits the authentication response to the second node, and the second node can further determine whether the authentication based on the second key is successful based on the authentication response.
[0034] In a possible embodiment, the release request includes request cause information, and the request cause information indicates that the key used for communication authentication is updated.
[0035] According to the above method, since the release request includes a request cause, after receiving the release request from the second node, the first node can learn the request cause, so the first node can respond to the request more appropriately and has strong adaptability.
[0036] In a possible implementation, the second key is valid within the first period, and the first period may be defined using a timer or a timestamp.
[0037] According to the above method, in the process of the first node and the second node performing communication transmission using the second key, it is further verified whether the second key is valid. Thereby, the temporal validity of the second key can be ensured, and the security of communication transmission can be further ensured.
[0038] In a possible implementation, the second key is valid within the first period starting from the first point in time, where the first point in time is the time when the first communication connection is released or the time when the second node receives the connection establishment request.
[0039] According to the above method, the present application provides multiple cases of the first point in time. Therefore, multiple solutions for determining the validity of the second key are provided, which is highly flexible.
[0040] In a possible implementation, the method further includes, within the valid period of the second key, transmitting transmission information from the first node to the third node using a backhaul link between the second node and the third node.
[0041] In a possible implementation, the backhaul link is stopped after the first communication connection to the first node is released.
[0042] According to the foregoing method, after the first communication connection is released, the second node stops the backhaul link. Thereby, the system overhead can be effectively reduced and resources can be saved.
[0043] In a possible implementation, the method further includes, after determining that the establishment of the second communication connection to the first node has been successful, starting the backhaul link, where communication authentication is performed on the second communication connection based on the second key.
[0044] According to the foregoing method, after determining that the second communication connection to the first node has been successfully established, the previously stopped backhaul link is started and the backhaul link is continuously used for communication transmission. Thereby, the system overhead can be effectively reduced and resources can be saved.
[0045] According to a third aspect, embodiments of the present application provide a communication method that can be applied to a first node. The method includes the following steps: obtaining a second key used for communication authentication with a second node, where the second key is different from a preset first key; releasing a first communication connection to the second node, where the first key is used for communication authentication of the first communication connection; sending a connection establishment request to the second node, where the connection establishment request is used to request the establishment of a connection based on the second key.
[0046] According to the above method, embodiments of the present application provide a technical solution in which a first node and a second node release a connection after determining an updated key and establish a connection using the new key. This realizes the switching between different communication connections, realizes the update process of the key used for communication authentication, and effectively improves communication security.
[0047] In a possible implementation, requesting the establishment of a connection based on the second key using the connection establishment request includes: requesting to execute an authentication and security context negotiation procedure based on the second key using the connection establishment request.
[0048] In a possible implementation, the method further includes receiving, from the second node, authentication information based on the second key, where the authentication information is used to verify the identity of the second node.
[0049] In a possible implementation, verifying the identity of the second node using the authentication information includes verifying whether a second communication connection to the second node is established based on the second key using the authentication information.
[0050] In a possible implementation, the first key is a key derived (or negotiated) based on the first communication system, and / or the second key is a key derived (or negotiated) based on the second communication system, and the first communication system is different from the second communication system.
[0051] In a possible implementation, the first communication system may be a single communication system, and the second communication system may be a communication system obtained after integration of different communication systems.
[0052] According to the foregoing method, an embodiment of the present application provides a communication method in a scenario where communications integrated by different communication systems are performed. Thereby, communication security is effectively improved.
[0053] In a possible implementation, the method further includes a step of transmitting an authentication response based on the second key to the second node, where the authentication response is used to verify the identity of the first node.
[0054] In a possible implementation, the use of the authentication response to verify the identity of the first node includes the following: the authentication response is used by the second node to verify whether to establish the second communication connection to the first node based on the second key.
[0055] According to the above method, the first node transmits the authentication response to the second node, and the second node can further determine whether the authentication based on the second key is successful based on the authentication response.
[0056] In a possible embodiment, the release request includes request cause information, and the request cause information indicates that the key used for communication authentication is updated.
[0057] According to the above method, since the release request includes the cause of the request, after receiving the release request from the second node, the first node can learn the cause of the request. Therefore, the first node can respond to the request more appropriately and has strong adaptability.
[0058] In a possible implementation, the second key is valid within the first period, and the first period is defined using a timer or a timestamp.
[0059] According to the above method, in the process of the first node and the second node performing communication transmission using the second key, it is further verified whether the second key is valid. Thereby, the temporal validity of the second key can be ensured, and the security of communication transmission can be further ensured.
[0060] In a possible implementation, the second key is valid within the first period starting from the first time point, and the first time point is the time when the first communication connection is released or the time when the connection establishment request is sent.
[0061] According to the above method, the present application provides a plurality of cases of the first time point. Therefore, a plurality of solutions for determining the validity of the second key are provided, and the flexibility is high.
[0062] In a possible implementation, within the valid period of the second key, the method uses a backhaul link between the second node and the third node to perform information transmission with the third node.
[0063] According to a fourth aspect, an embodiment of the present application provides a communication method, which can be applied to a second node. The method includes the following: Obtaining a second key used for communication authentication with a first node, where the second key is different from a preset first key; Releasing a first communication connection to the first node, where the first key is used for communication authentication of the first communication connection; Receiving a connection establishment request sent by the first node, wherein the connection establishment request is used to request establishment of a connection based on the second key, and the step, including.
[0064] According to the above method, an embodiment of the present application provides a technical solution in which a first node and a second node release a connection after determining an updated key and establish a connection using the new key. Thereby, switching between different communication connections is realized, the update process of the key used for communication authentication is realized, and communication security is effectively improved.
[0065] In a possible implementation, using the connection establishment request to request establishment of a connection based on the second key includes: using the connection establishment request to request executing authentication and security context negotiation procedures based on the second key.
[0066] In a possible implementation, the method further includes the step of sending authentication information based on the second key to the first node, wherein the authentication information is used to verify the identity of the second node.
[0067] In a possible implementation, using the authentication information to verify the identity of the second node includes the first node using the authentication information to verify whether a second communication connection to the second node is established based on the second key.
[0068] In a possible implementation, the first key is a key derived (or negotiated) based on the first communication system, and / or the second key is a key derived (or negotiated) based on the second communication system, and the first communication system is different from the second communication system.
[0069] In a possible implementation, the first communication system may be a single communication system, and the second communication system may be a communication system obtained after integration of different communication systems.
[0070] According to the foregoing method, embodiments of the present application provide a communication method in a scenario where communication is performed with different communication systems integrated. Thereby, communication security is effectively improved.
[0071] In a possible implementation, the method further includes the step of receiving an authentication response returned by the first node, where the authentication response is used to verify the identity of the first node.
[0072] In a possible implementation, the use of the authentication response to verify the identity of the first node includes: the authentication response is used by the second node to verify whether to establish the second communication connection to the first node based on the second key.
[0073] According to the above method, the first node transmits the authentication response to the second node, and the second node can further determine whether the authentication based on the second key is successful based on the authentication response.
[0074] In a possible embodiment, the release request includes request cause information, and the request cause information indicates that the key used for communication authentication is updated.
[0075] According to the above method, since the release request includes a request cause, after receiving the release request from the second node, the first node can learn the request cause, so that the first node can respond to the request more appropriately and has strong adaptability.
[0076] In a possible implementation, the second key is valid within the first period, and the first period may be defined using a timer or a timestamp.
[0077] According to the above method, in the process of the first node and the second node performing communication transmission using the second key, it is further verified whether the second key is valid. Thereby, the time validity of the second key can be ensured, and the security of communication transmission can be further ensured.
[0078] In a possible implementation, the second key is valid within the first period starting from the first time point, and the first time point is the time point when the first communication connection is released or the time point when the second node receives the connection establishment request.
[0079] According to the above method, the present application provides a plurality of cases of the first time point. Therefore, a plurality of solutions for determining the validity of the second key are provided, and the flexibility is high.
[0080] In a possible implementation, the method further includes a step of transmitting transmission information from the first node to the third node using a backhaul link between the second node and the third node within the valid period of the second key.
[0081] In a possible implementation, the backhaul link is stopped after the first communication connection to the first node is released.
[0082] According to the foregoing method, after the first communication connection is released, the second node stops the backhaul link. Thereby, the overhead of the system can be effectively reduced, and resources can be saved.
[0083] In a possible implementation, the method After determining that the establishment of the second communication connection to the first node is successful, a step of starting the backhaul link, wherein communication authentication is performed on the second communication connection based on the second key.
[0084] According to the foregoing method, after determining that the second communication connection to the first node has been successfully established, the previously stopped backhaul link is activated and continued to be used for communication transmission. Thereby, the overhead of the system can be effectively reduced and resources can be saved.
[0085] According to a fifth aspect, an embodiment of the present application provides a communication device. The device is configured to implement the method of the first aspect or any of the methods of the first aspect, and includes corresponding functional modules or units separately configured to implement the steps of the method of the first aspect. The functions may be implemented by hardware or may be implemented by hardware by executing corresponding software. The hardware or software includes one or more modules or units corresponding to the functions. Alternatively, the device is configured to implement the method of the third aspect or any of the methods of the third aspect, and includes corresponding functional modules or units separately configured to implement the steps of the method of the third aspect. The functions may be implemented by hardware or may be implemented by hardware by executing corresponding software. The hardware or software includes one or more modules or units corresponding to the functions.
[0086] According to a sixth aspect, an embodiment of the present application provides a communication device. The device is configured to implement the method of the second aspect or any of the methods of the second aspect, and includes corresponding functional modules or units separately configured to implement the steps of the method of the second aspect. The functions may be implemented by hardware or may be implemented by hardware by executing corresponding software. The hardware or software includes one or more modules or units corresponding to the functions. Alternatively, The machine is configured to implement the method according to the fourth aspect or any of the methods of the fourth aspect, and includes corresponding functional modules or units separately configured to implement the steps of the method of the fourth aspect. The function may be implemented by hardware or may be implemented by hardware by executing corresponding software. The hardware or software includes one or more modules or units corresponding to the function.
[0087] According to a seventh aspect, a communication device including a processor and a memory is provided. The memory is configured to store a computing program or instructions, and the processor is coupled to the memory. When the processor executes the computer program or the instructions, the device executes the method according to the first aspect or any method in the first aspect, and the device executes the method according to the third aspect or any method in the third aspect. The communication device may be the first device, or may be a device capable of assisting the first device in realizing the functions required by the method provided in the first aspect, or may be a device capable of assisting the first device in realizing the functions required by the method provided in the third aspect. For example, the communication device may be a terminal device or some components (such as chips) within the terminal device. The terminal device may be, for example, an intelligent mobile terminal, a smart home device, a smart car, or an intelligent wearable device. The intelligent mobile terminal may be, for example, a mobile phone, a tablet computer, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA). Smart home devices include smart refrigerators, smart washing machines, smart TVs, speakers, etc. The wearable devices of smart cars are, for example, smart headsets, smart glasses, smart clothes, or shoes.
[0088] According to the eighth aspect, a communication device including a processor and a memory is provided. The memory is configured to store a computing program or instructions, and the processor is coupled to the memory. When the processor executes the computer program or the instructions, the device executes the second aspect or any method in the second aspect, and the device executes the fourth aspect or any method in the fourth aspect. The communication device may be a second device, or a device that can assist the second device in realizing the functions required by the method provided in the second aspect, or a device that can assist the second device in realizing the functions required by the method provided in the fourth aspect. For example, the communication device may be a terminal device or some components (such as chips) within the terminal device. The terminal device may be, for example, an intelligent mobile terminal, a smart home device, a smart car, or an intelligent wearable device. The intelligent mobile terminal may be, for example, a mobile phone, a tablet computer, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA). Smart home devices include, for example, smart refrigerators, smart washing machines, smart TVs, speakers, etc. The wearable devices of smart cars are, for example, smart headsets, smart glasses, smart clothes, or shoes.
[0089] According to the ninth aspect, a terminal is provided. The terminal may include a device according to the fifth aspect or the seventh aspect and a device according to the sixth aspect or the eighth aspect. Optionally, the device may be, for example, a smart home device, an intelligent manufacturing device, an intelligent transportation device, etc., such as a vehicle, a drone, an unmanned transportation vehicle, an automobile and a vehicle, a robot, etc. Alternatively, the device may be a mouse, a keyboard, a wearable device, a TWS headset, etc.
[0090] According to the 10th aspect, the present application provides a chip, the chip is coupled to a memory, and is configured to read and execute a computer program or instructions stored in the memory, and implement any one of the methods of the 1st aspect or a possible implementation of the 1st aspect, or implement any one of the methods of the 2nd aspect or a possible implementation of the 2nd aspect, or implement any one of the methods of the 3rd aspect or a possible implementation of the 3rd aspect, or implement any one of the methods of the 4th aspect or a possible implementation of the 4th aspect.
[0091] According to the 11th aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program or instructions. When the computer program or the instructions are executed by a device, the device can execute any one of the methods of the 1st aspect or a possible implementation of the 1st aspect, or the device can execute any one of the methods of the 3rd aspect or a possible implementation of the 3rd aspect.
[0092] According to the 12th aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program or instructions. When the computer program or the instructions are executed by a device, the device can execute any one of the methods of the 2nd aspect or a possible implementation of the 2nd aspect, or the device can execute any one of the methods of the 4th aspect or a possible implementation of the 4th aspect.
[0093] According to the 13th aspect, a computer program product provided in the present application is provided. The computer program product includes a computer program or instructions. When the computer program or the instructions are executed by a device, the device can execute any one of the methods of the 1st aspect or a possible implementation of the 1st aspect, or the device can execute any one of the methods of the 3rd aspect or a possible implementation of the 3rd aspect.
[0094] According to the 14th aspect, a computer program product provided in the present application is provided. The computer program product includes a computer program or instructions. When the computer program or the instructions are executed by a device, the device can execute the method according to any one of the 2nd aspect or the possible implementations of the 2nd aspect, or the device can execute the method according to any one of the 3rd aspect or the possible implementations of the 3rd aspect.
[0095] Note that the technical solution provided in the present application can be applied to the integration scenarios of different communication systems and the communication methods in the scenarios where different communication systems perform integrated communication. Thereby, the communication security is effectively improved. Also, by setting the validity of the key used for communication authentication, the time validity of the key used for communication authentication can be ensured. Thereby, the communication transmission security can be made more reliable.
Brief Description of Drawings
[0096]
Figure 1
[0097]
Figure 2
[0098]
Figure 3
[0099]
Figure 4A
Figure 4B
[0100]
Figure 5A
Figure 5B
[0101]
Figure 6A
Figure 6B
[0102]
Figure 7A
Figure 7B
[0103]
Figure 8A
Figure 8B
[0104]
Figure 9A
Figure 9B
Figure 9C
[0105]
Figure 10
[0106]
Figure 11
[0107]
Figure 12
Best Mode for Carrying Out the Invention
[0108] Embodiments of the present application provide a communication method and device for implementing an authentication procedure for the integration of a wireless short - range and a 5G cellular network. To clarify the objectives, technical solutions, and advantages of the embodiments of the present application, the following will describe the embodiments of the present application in detail with reference to the accompanying drawings.
[0109] The communication method provided by the embodiments of the present application may be applicable to a fifth - generation (5G) communication system, such as 5G new radio (NR), or may also be applicable to various future communication systems, such as a sixth - generation (6G) communication system. This is not limited herein.
[0110] As shown in FIG. 1, embodiments of the present application provide an architecture of a communication system to which this communication method is applicable. The communication system may include a first node 100, a second node 110, and a third node 120. Optionally, in the communication system, the first node may be connected to the second node, and the second node may be connected to the third node.
[0111] The communication system in the present application may be a communication system obtained after different communication systems are integrated. For example, it may be a communication system obtained after a wireless short - range communication system is integrated into a 5G cellular network communication system. This is not limited herein. Also, the integrated communication system may sometimes be called a tight interworking communication system or an interworking communication system.
[0112] For example, in the present application, a communication system obtained after integrating a wireless short - range communication system and a 5G cellular network communication system is used as an example to describe the integrated communication system.
[0113] In an integrated communication system, a terminal node that supports wireless short-distance communication can access a 5G network using a control node or a gateway node, and further use the services provided by the 5G network. Also, the 5G network can further configure and manage the data transmission policy of the terminal node based on the subscription information and link state information of the terminal node, and provide sophisticated services to the terminal node. That is, in the integrated communication system, the wireless short-distance communication system and the 5G cellular network communication system can interact with each other and operate in a complementary manner.
[0114] Optionally, the wireless short-distance communication system described in this application may be any possible short-distance communication system, for example, current and future possible short-distance communication systems such as Bluetooth, Wi-Fi, vehicle-mounted general short-distance communication systems, and SparkLink.
[0115] The first node may be a terminal device or a communication device that can support the terminal device when realizing the functions required by this method, or the first node may be a network device or a communication device that can support the network device when realizing the functions required by this method, or, of course, it may be other communication devices such as a chip system. The second node may be a network device or a communication device that can support the network device when realizing the functions required by this method, or the second node may be a terminal device or a communication device that can support the terminal device when realizing the functions required by this method, or, of course, it may be other communication devices such as a chip system. The third node may be a network device or a communication device that can support the network device when realizing the functions required by this method, or the third node may be a terminal device or a communication device that can support the terminal device when realizing the functions required by this method, or, of course, it may be other communication devices such as a chip system.
[0116] Optionally, the terminal device in the embodiments of the present application may be a device configured to implement a wireless communication function, for example, a terminal device or a chip that can be used in a terminal device. For example, the terminal device may include a handheld device having a wireless connection function, or a processing device connected to a wireless modem. The terminal device can communicate with a core network via a radio access network (RAN) and exchange voice and / or data with the RAN. The terminal device may also be referred to as a user equipment (UE), a wireless terminal device, a mobile terminal device, a subscriber unit, a subscriber station, a mobile station, a mobile console, a remote station, an access point (AP), a remote terminal device, an access terminal device, a user terminal device, a user agent, a user device, etc. For example, the terminal device may include a mobile phone (or a so-called "cellular" phone), a computer equipped with a mobile terminal device, or a portable, pocket-sized, handheld, or computer-integrated, or in-vehicle mobile device, or a smart wearable device. For example, the terminal device may be a device such as a Personal Communication Service (PCS) phone, a cordless phone set, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, or a Personal Digital Assistant (PDA). Alternatively, the terminal device may include a limited device, for example, a device with relatively low power consumption, a device with limited storage capacity, or a device with limited computing ability.For example, the terminal device includes an information sensing device such as a barcode, radio frequency identification (RFID), sensor, global positioning system (GPS), or laser scanner.
[0117] By way of example and not limitation, in an embodiment of the present application, the terminal device may alternatively be a wearable device. The wearable device may be referred to as a wearable intelligent device, which is, for example, a general term for wearable devices that are intelligently designed and developed for daily wear using wearable technologies such as glasses, gloves, watches, clothes, shoes, etc. The wearable device is a portable device that can be directly worn on the body or integrated into the user's clothes or accessories. The wearable device not only implements a hardware device but also implements powerful functions through software support, data exchange, and cloud interaction. In a broad sense, the wearable intelligent device includes full-featured large devices that can implement all or part of the functions without relying on a smartphone, such as a smartwatch or smart glasses, and devices that are dedicated to one type of application function and need to operate in cooperation with other devices such as a smartphone, for example, various smart bands, smart helmets, or smart jewelry, etc., including devices for monitoring physical signs.
[0118] Also, the network device in the present embodiment of the present application may include an access network (AN) device, a radio access network (RAN) device, an access network device such as a base station (e.g., an access point). The wireless terminal device can refer to a device that communicates with the wireless terminal device via a wireless interface using one or more cells in the access network. The base station may be configured to convert between the received radio frame and an Internet protocol (IP) packet and serve as a router between the terminal device and the rest of the access network. The rest of the access network can include an IP network. The network-side device may further adjust the attribute management of the wireless interface. For example, the network device can include an evolved NodeB (NodeB, eNB or e-NodeB, evolved NodeB) in a long term evolution (LTE) system or a long term evolution-advanced (LTE-A) system, and can include a next generation NodeB (gNB), a next generation evolved NodeB (ng-eNB) or an enhanced next generation NodeB en-gNB (enhanced next generation NodeB, gNB) in a 5th generation (5G) mobile communication technology new radio (NR) system, and can include a centralized unit (CU) and a distributed unit (DU) in a cloud radio access network (Cloud RAN) system. This is not limited in the embodiments of the present application.
[0119] Furthermore, the present application further provides another communication system. As shown in FIG. 2, the communication system may further include functional entities such as a session management function (SMF), an access and mobility management function (AMF), a user plane function (UPF), and a DN.
[0120] The functions may be connected via interfaces. In the embodiments of the present application, the sequence number or the name of the interface is not limited. Interfaces defined in the 3GPP-related standard protocols of the 5G system may be used, or interfaces in future communication systems may be used. For example, the terminal device communicates with the AMF via the interface of the next generation network (N) 1 (abbreviated as N1), the network device communicates with the AMF via the N2 interface (abbreviated as N2), and the network device communicates with the local UPF via the N3 interface (abbreviated as N3). The UPF communicates with the DN through the N6 interface (abbreviated as N6). The AMF communicates with the SMF via the N11 interface (abbreviated as N11), and the SMF communicates with the UPF via the N4 interface (abbreviated as N4).
[0121] The functions included in a communication system may also be referred to by function entities, network elements, or other names. For example, the SMF may be referred to as the SMF entity. Optionally, the functions in the embodiments of the present application may be implemented by one device, jointly implemented by multiple devices, or implemented by one or more function modules within one device. This is not specifically limited in the embodiments of the present application. It should be understood that each function in the embodiments of the present application may be a network element within a hardware device, a software function executed on dedicated hardware, a combination of hardware and software, or a virtualized function (e.g., a cloud platform) instantiated on a platform.
[0122] Note that the distribution form of each function is not limited in the embodiments of the present application. Optionally, each function may include another function entity formed after combining any multiple functions, for example, a function entity having two functions of session management and policy control, a function entity having three functions of session management, access and mobility management, and policy control, or a function entity having two functions of network exposure and application function.
[0123] It should be noted that the communication systems shown in FIGS. 1 and 2 do not constitute the limitations of the communication systems applicable to the embodiments of the present application. Of course, the number of terminal devices in FIG. 2 is merely an example. In actual applications, a network device can provide services to multiple terminal devices. All or part of the network device and multiple terminal devices can each determine scheduling limitations according to the methods provided in the embodiments of the present application. The communication system architecture shown in FIGS. 1 and / or 2 may be a non-roaming 5G system architecture. Optionally, the methods in the embodiments of the present application are further applicable to roaming 5G system architectures and various future communication networks.
[0124] Each function or device in the embodiments of the present application may also be referred to as a communication device and may be a general-purpose device or a dedicated device. This is not specifically limited in the embodiments of the present application.
[0125] The foregoing content briefly describes the application architecture in the embodiments of the present application. The following describes the technical features in the embodiments of the present application.
[0126] Currently, there is no secure and effective communication method for the integration scenarios of different communication systems. Therefore, the embodiments of the present application provide a technical solution in which a first node and a second node release a connection after determining an updated key and establish a connection using a new key, and provide a communication method in a scenario where different communication systems perform integrated communication. Thereby, communication security is effectively improved. The method and the device are based on the same technical concept. Since the problem-solving principles of the method and the device of the present invention are similar, for the implementation of the device and the method of the present invention, reference is made to each other, and the overlapping parts will not be described again.
[0127] The embodiments of the present application provide a first communication method. FIG. 3 is a flowchart of the method.
[0128] S300: The first node obtains a second key used for communication authentication with the second node.
[0129] The second key in the embodiments of the present application is different from the preset first key.
[0130] Optionally, in this embodiment of the present application, the first node is configured to perform communication authentication on a first communication connection, and the second node is configured to perform communication authentication on a second communication connection.
[0131] In any optional aspect of the present application, the first key is a key derived (or negotiated) based on a first communication system, and / or the second key is a key derived (or negotiated) based on a second communication system, and the first communication system is different from the second communication system.
[0132] In the present application, the first communication system may be a single communication system, for example, a wireless short-distance communication system, a 5G cellular network communication system, an ultra-high-reliability low-latency communication system, an extended mobile broadband communication system, or a massive machine-type communication system. In the present application, the second communication system may be a communication system obtained after different communication systems are integrated. For example, it may be a communication system obtained after a wireless short-distance communication system is integrated into a 5G cellular network communication system, or a communication system obtained after a 5G cellular network communication system is integrated into an ultra-high-reliability low-latency communication system.
[0133] Specifically, the first key may be a key used for authentication in the initial connection phase between the first node and the second node. The first key may be preset before the first node and the second node initially connect to each other. Alternatively, the first key may be determined by the second node and indicated to the first node by signaling. Alternatively, the first key may be determined by the first node and indicated to the second node by signaling. This is not limited in the present application.
[0134] Specifically, after the first node establishes the first communication connection to the second node, the second key may be determined by the first node and indicated to the second node by signaling. Alternatively, after the first node establishes the first communication connection to the second node, the second key may be determined by the second node and indicated to the first node by signaling. Alternatively, after the first node establishes the first communication connection to the second node, the second key may be negotiated jointly by the first node and the second node. This is not limited in the present application.
[0135] Furthermore, to more securely ensure the security of the communication system, the second key obtained by the first node and used for communication authentication with the second node has a specific time validity. When the second key is valid, it is understood that the second key may be used for authentication in the second communication connection. Alternatively, when the second key is invalid, the second key cannot be used for authentication in the second communication connection. Also, when the second key is invalid, the key may be updated.
[0136] Before S300 is implemented, the following step 1 may further be included: The first node and the second node are connected in an integration method (i.e., the initial authentication procedure in the integration scenario of different communication systems is implemented).
[0137] The specific implementation process of step 1 may be as follows: The first node and the second node perform authentication in the initial connection based on the first key. After the first node and the second node determine that the authentication in the initial connection based on the first key is successful, the first node and the second node establish a first communication connection for performing communication authentication based on the first key.
[0138] S301: The second node obtains a second key for use in communication authentication with the first node.
[0139] Specifically, the second key may be determined by the first node after the first node establishes a first communication connection to the second node and is indicated to the second node by signaling. Alternatively, the second key may be determined by the second node after the first node establishes a first communication connection to the second node and is indicated to the first node by signaling. Or, the second key may be jointly negotiated by the first node and the second node after the first node establishes a first communication connection to the second node. This is not limited in the present application.
[0140] S302: The second node sends a release request for the first communication connection to the first node.
[0141] The release request can include one or more of the following information 1 to information 4.
[0142] Information 1: Request cause information, where the request cause information indicates that the key used for communication authentication is updated.
[0143] Information 2: Request time, where the request time indicates the time when the second node sends the release request. Optionally, the request time can be represented using a timestamp.
[0144] Information 3: Release time, where the release time indicates the time when the first node releases the first communication connection.
[0145] For example, the release time can indicate a specific time. For example, the specific time is 1 minute after the first node receives the release request. In this case, the first node releases the first communication connection based on the release time included in the release request 1 minute after receiving the release request. Alternatively, the release time can indicate a specific time period. For example, the specific time period is within 5 minutes after the first node receives the release request. In this case, the first node releases the first communication connection based on the release time included in the release request within 5 minutes after receiving the release request.
[0146] Information 4: Information indicating to stop the radio resources.
[0147] Also, the release request may further indicate to suspend the radio resources. For example, the release request may include information indicating to suspend the radio resources corresponding to the first communication connection.
[0148] After the first node and the second node determine that the first key used for communication authentication is updated to the second key, if the first communication connection is released and the establishment of the second communication connection fails, the radio resources corresponding to the first communication connection are stopped and not released. Thereby, the rapid recovery of the communication link can be effectively achieved.
[0149] Note that the contents of Information 1 to Information 4 included in the release request are examples of the information included in the release request and do not limit the information included in the release request.
[0150] In addition, the first node receiving a release request from the second node may include, but is not limited to, the following:
[0151] The release request may be based on an improvement in signaling transmission between the first node and the second node. Alternatively, the release request may be made in the signaling transmission between the first node and the second node. For example, in an actual application, the release request may be made in signaling indicating a second key transmitted from the first node to the second node, or the release request may be a new signaling between the first node and the second node.
[0152] Furthermore, the second node releases the first communication connection to the first node.
[0153] Note that in any aspect of the present application, the second node may determine that the key has been updated after receiving the second key. Accordingly, the second node may trigger the release of the first communication connection to the first node and establish a second communication connection for which communication authentication is performed based on the second key.
[0154] Furthermore, when the second node transmits a release request for the first communication connection to the first node, the second node may further receive a release request response from the first node, which is used to notify the release state of the first communication connection of the first node.
[0155] Furthermore, the second node may release the first communication connection to the first node before executing S302. That is, the second node releases the first communication connection to the first node after obtaining the second key. Alternatively, the second node may release the first communication connection to the first node after executing S302. That is, the second node releases the first communication connection to the first node after sending a release request for the first communication connection to the first node. Alternatively, after receiving a release request response from the first node and determining that the first node has completed the release of the first communication connection, the second node may further release the first communication connection to the first node.
[0156] S303: The first node receives a release request for the first communication connection from the second node.
[0157] Furthermore, the first node releases the first communication connection to the second node.
[0158] Note that in any aspect of this application, after receiving a release request for the first communication connection from the second node, the first node may trigger the release of the first communication connection to the second node.
[0159] Furthermore, the first node may send a response based on the release request to the second node to notify the second node of the release status of the first communication connection of the first node.
[0160] S304: The first node sends a connection establishment request to the second node. The connection establishment request is used to request the establishment of a connection based on the second key.
[0161] Optionally, the connection establishment request sent by the first node to the second node may include, but is not limited to, the following:
[0162] The connection establishment request may be an improvement based on signaling transmission between the first node and the second node. Alternatively, the connection establishment request may be made in signaling transmission between the first node and the second node. Alternatively, the connection establishment request may be a new signaling between the first node and the second node.
[0163] The connection establishment request can include one or more of the following information 1 to information 4.
[0164] Information 1: Request cause information, where the request cause information indicates that the key used for communication authentication is updated.
[0165] Information 2: Request time, which indicates the time when the first node sends the connection establishment request. Optionally, the request time can be represented using a timestamp.
[0166] Information 3: Connection establishment time, which indicates the time when the first node authenticates the second communication connection to the second node.
[0167] For example, the connection establishment time can indicate a specific time. For example, the specific time is 1 minute after the second node receives the connection establishment request. In this case, after receiving the connection establishment request, the second node establishes a second communication connection to the first node based on the connection establishment time included in the connection establishment request 1 minute later. Alternatively, the connection establishment time can indicate a specific time period. For example, the specific time period is within 5 minutes after the second node receives the connection establishment request. In this case, after receiving the connection establishment request, the second node establishes a second communication connection to the first node within 5 minutes after receiving the connection establishment request based on the connection establishment time included in the connection establishment request.
[0168] Information 4: Information indicating connection recovery.
[0169] It can be understood that the connection establishment request may be a request to restore the connection between the first node and the second node. That is, after the first communication connection between the first node and the second node is released, the first node and the second node need to establish a second communication connection for communication authentication based on the second key. In this case, the first node may send a connection recovery request to the second node, and after receiving the connection recovery request, the second node may establish a communication connection to the first node.
[0170] Note that the content of Information 1 to Information 4 included in the connection establishment request is an example of the information included in the connection establishment request, and does not limit the information included in the connection establishment request.
[0171] S305: The second node receives the connection establishment request sent by the first node.
[0172] Furthermore, requesting the establishment of a connection based on the second key using the connection establishment request may include the following: requesting to execute an authentication and security context negotiation procedure based on the second key using the connection establishment request.
[0173] Optionally, the authentication and security context negotiation procedure may also include an identity authentication process for the first node and the second node (for example, the interaction between authentication information and authentication responses).
[0174] The content of the identity authentication process for the first node and the second node can be described as follows:
[0175] First, after the second node receives the connection establishment request sent by the first node, the second node sends authentication information based on the second key to the first node, and the authentication information is used to verify the identity of the second node. The authentication information is used to verify the identity of the second node. It is understood that the first node can use the authentication information to verify whether the first node can establish a second communication connection to the second node based on the second key.
[0176] Optionally, the authentication information may include an authentication vector derived by the second node using the second key.
[0177] Next, after the first node receives the authentication information from the second node based on the second key and determines that the authentication at the second node is successful, the first node sends an authentication response to the second node for the authentication information, and the authentication response is used to verify the identity of the first node. The authentication response is used to verify the identity of the first node. It is understood that the second node can use the authentication response to verify whether the second node can establish a second communication connection to the first node based on the second key.
[0178] Optionally, the first node may determine whether the authentication at the second node is successful based on the authentication vector derived by the second node using the second key included in the received authentication information.
[0179] For example, after receiving the authentication information, the first node obtains the first authentication vector included in the authentication information and derived by the second node based on the second key. The first node derives a second authentication vector based on the second key and compares the first authentication vector with the second authentication vector. When the first authentication vector and the second authentication vector meet the authentication requirements, for example, the authentication requirement may be that the first authentication vector and the second authentication vector are the same, or the sum of the first authentication vector and the second authentication vector is zero, the first node determines that the authentication at the second node is successful. If the first authentication vector and the second authentication vector do not meet the authentication requirements, the first node determines that the authentication at the second node fails.
[0180] Finally, the second node receives the authentication response sent by the first node and performs identity authentication at the first node based on the authentication response.
[0181] According to the above method, after determining the updated key, the first node and the second node release the connection, and then establish a connection using the new key. Thereby, the switching between different communication connections is realized, and the update process of the key used for communication authentication is realized. Thereby, the communication security is effectively improved.
[0182] To describe the communication method provided by this application in more detail, based on the content shown in FIG. 3, the following two scenarios will be described in further detail. Some steps in the following scenarios are optional, and the step sequence does not represent the actual execution sequence. Therefore, this application is not limited to executing the following steps and sequences.
[0183] Scenario 1: After obtaining the second key, the first node actively releases the first communication connection.
[0184] Refer to FIGS. 4A and 4B. The following steps may be executed in the method corresponding to Scenario 1.
[0185] S400: The first node establishes a first communication connection to the second node based on the first key.
[0186] S401: The first node obtains a second key for use in communication authentication with the second node.
[0187] S402: The second node obtains a second key for use in communication authentication with the first node.
[0188] S403: The second node releases the first communication connection to the first node.
[0189] S404: The first node releases the first communication connection to the second node.
[0190] S405: The first node sends a connection establishment request to the second node. The connection establishment request is used to request the establishment of a connection based on the second key.
[0191] S406: The second node receives the connection establishment request sent by the first node.
[0192] S407: The second node sends authentication information based on the second key to the first node, and the authentication information is used to verify the identity of the second node.
[0193] S408: The first node receives authentication information based on the second key from the second node.
[0194] S409: The first node determines whether the authentication at the second node is successful. If the authentication at the second node is successful, it executes S410. If the authentication at the second node fails, it executes S411.
[0195] S410: The first node sends an authentication response for the authentication information to the second node, verifies the identity of the first node using the authentication response, and continues with S412.
[0196] Optionally, the authentication response includes authentication information generated based on the second key.
[0197] The authentication information can include one or more of the following Information 1 and Information 2.
[0198] Information 1: An authentication vector obtained by the first node based on the second key, for example, the second authentication vector in the content example of step S305.
[0199] Information 2: The result of the authentication performed by the first node on the second node.
[0200] Note that the content of Information 1 and Information 2 included in the authentication information is an example of the information included in the authentication information and does not limit the information included in the authentication information.
[0201] S411: After determining that the authentication performed by the second node using the second communication connection based on the second key has failed, the first node terminates the communication transmission.
[0202] In any aspect of the present application, after the first node determines that the authentication at the second node has failed, the second node may resume the communication authentication based on the second key and terminate the communication transmission when the number of authentication failures reaches the threshold number of failures.
[0203] For example, let the threshold number of failures be 2. After the first node determines that the communication authentication based on the second key at the second node has failed, the first node may send an authentication failure message to the second node. After receiving the authentication failure message, the second node may resend the authentication information based on the second key to the first node for re - authentication.
[0204] The first node receives the authentication information based on the second key from the second node again and performs communication authentication. If the first node determines in the second authentication that the communication authentication performed by the second node based on the second key has failed, the first node determines that the number of authentication failures has reached the threshold value of 2 and ends the communication transmission.
[0205] Similarly, if the second node receives two consecutive messages indicating that the communication authentication based on the second key has failed, the second node may end the communication transmission. Alternatively, after determining to end the communication transmission, the first node may send a message to end the communication transmission to the second node, and after receiving the message to end the communication transmission from the first node, the second node may end the communication transmission.
[0206] S412: The second node receives the authentication response sent by the first node.
[0207] Optionally, the second node that receives the authentication response may determine whether the authentication at the first node is successful based on the authentication information included in the authentication response generated based on the second key. For the specific determination method, please refer to the determination method of the first node described above. For the sake of brevity, the details will not be described again here.
[0208] S413: The second node determines whether the authentication at the first node is successful. If the authentication at the first node is successful, it executes S414. If the authentication at the first node fails, it executes S415.
[0209] S414: After determining that the authentication at the second node has been successful, the second node establishes a second communication connection with the first node and then proceeds to S416.
[0210] S415: After determining that the authentication performed by the first node over the second communication connection based on the second key has failed, the second node terminates the communication transmission.
[0211] In any aspect of the present application, after determining to terminate the communication transmission, the second node transmits a communication transmission termination message to the first node. After the first node receives the communication transmission termination message from the second node, the first node terminates the communication transmission.
[0212] S416: After the establishment of the second communication connection with the second node is completed, the first node notifies the second node that the establishment of the second communication connection has been completed.
[0213] S417: The first node performs information transmission with the third node using the backhaul link between the second node and the third node.
[0214] Note that in the method procedures shown in FIGS. 4A and 4B, the sequence numbers of the steps do not imply an execution sequence. The execution order of the processes should be determined based on the functions and internal logics of the processes and should not be considered as a limitation to the implementation processes of the embodiments of the present invention. For example, S402 may be prioritized over S401. Also, in the method procedures shown in FIGS. 4A and 4B, the above steps are not limited, and the addition, deletion, or modification of the above steps shall be included in the protection scope of the present application.
[0215] Scenario 2: After receiving the release request for the first communication connection transmitted from the second node, the first node releases the first communication connection.
[0216] Refer to FIGS. 5A and 5B. The following steps may be executed in a manner corresponding to Scenario 2.
[0217] S500: The first node establishes a first communication connection to the second node based on the first key.
[0218] S501: The first node obtains a second key for communication authentication with the second node.
[0219] S502: The second node obtains a second key for communication authentication with the first node.
[0220] S503: The second node releases the first communication connection to the first node.
[0221] S504: The second node sends a release request for the first communication connection to the first node.
[0222] S505: The first node receives a release request for the first communication connection from the second node.
[0223] S506: The first node releases the first communication connection to the second node.
[0224] S507: The first node sends a connection establishment request to the second node. The connection establishment request is used to request the establishment of a connection based on the second key.
[0225] S508: The second node receives the connection establishment request sent by the first node.
[0226] S509: The second node sends authentication information based on the second key to the first node, and the authentication information is used to verify the identity of the second node.
[0227] S510: The first node receives the authentication information based on the second key from the second node.
[0228] S511: The first node determines whether the authentication at the second node is successful. If the authentication at the second node is successful, S512 is executed; if the authentication at the second node fails, S513 is executed.
[0229] S512: After determining that the authentication at the second node has succeeded, the first node sends an authentication response for the authentication information to the second node, verifies the identity of the first node using the authentication response, and then executes S514.
[0230] S513: After determining that the authentication performed by the second node in the second communication connection based on the second key has failed, the first node terminates the communication transmission.
[0231] S514: The second node receives the authentication response sent by the first node.
[0232] In this application, optionally, the second node that has received the authentication response may determine whether the authentication at the first node has succeeded based on the authentication information included in the authentication response generated based on the second key. For the specific determination method, please refer to the determination method of the first node described above. For the sake of brevity, the details will not be described again here.
[0233] S515: The second node determines whether the authentication at the first node has succeeded. If the authentication at the first node has succeeded, it executes S516. If the authentication at the first node has failed, it executes S517.
[0234] S516: After determining that the authentication at the second node has succeeded, the second node establishes a second communication connection with the first node and then executes S518.
[0235] S517: After determining that the authentication performed by the first node in the second communication connection based on the second key has failed, the second node terminates the communication transmission.
[0236] S518: After the establishment of the second communication connection with the second node is completed, the first node notifies the second node that the establishment of the second communication connection has been completed.
[0237] S519: The first node performs information transmission with the third node using the backhaul link between the second node and the third node.
[0238] Note that in the method procedures shown in FIGS. 5A and 5B, the sequence numbers of the steps do not mean the execution sequence. The execution order of the processing should be determined based on the functions and internal logics of the processing, and should not be considered as a limitation to the implementation processing of the embodiments of the present invention. For example, S502 may be prioritized over S501. Also, in the method procedures shown in FIGS. 5A and 5B, the above steps are not limited, and the addition, deletion, or modification of the above steps shall be included in the protection scope of the present application.
[0239] Furthermore, in the present application, in order to effectively reduce the system overhead, after releasing the first communication connection to the first node, the second node may further stop the backhaul link. And after determining that it has successfully established the second communication connection to the first node, the second node may start the backhaul link.
[0240] Referring to Scenario 2 above, the operation details of stopping and starting the backhaul link in the communication process will be described. Refer to FIGS. 6A and 6B. The corresponding method procedures are as follows:
[0241] S600: The first node establishes a first communication connection to the second node based on the first key.
[0242] S601: The first node obtains a second key for communication authentication with the second node.
[0243] S602: The second node obtains a second key for communication authentication with the first node.
[0244] S603: The second node releases the first communication connection to the first node.
[0245] S604: The second node stops the backhaul link between the second node and the third node.
[0246] S605: The second node sends a release request for the first communication connection to the first node.
[0247] S606: The first node receives a release request for the first communication connection from the second node.
[0248] S607: The first node releases the first communication connection to the second node.
[0249] S608: The first node sends a connection establishment request to the second node. The connection establishment request is used to request the establishment of a connection based on the second key.
[0250] S609: The second node receives the connection establishment request sent by the first node.
[0251] S610: After determining that the authentication at the second node is successful, the first node sends an authentication response for the authentication information to the second node and uses the authentication response to verify the identity of the first node.
[0252] S611: The first node receives the authentication information based on the second key from the second node.
[0253] S612: After determining that the authentication at the second node is successful, the first node sends an authentication response for the authentication information to the second node and uses the authentication response to verify the identity of the first node.
[0254] S613: The second node receives the authentication response sent by the first node.
[0255] S614: After determining that the authentication at the second node is successful, the second node establishes a second communication connection to the first node.
[0256] S615: After the establishment of the second communication connection to the second node is completed, the first node notifies the second node that the establishment of the second communication connection has been completed.
[0257] S616: After determining that the establishment of the second communication connection to the first node has been successful, the second node activates the backhaul link.
[0258] S617: The first node performs information transmission with the third node using the backhaul link between the second node and the third node.
[0259] Note that in the method procedures shown in FIGS. 6A and 6B, the sequence numbers of the steps do not mean the execution sequence. The execution order of the processing should be determined based on the functions and internal logics of the processing, and should not be considered as a limitation to the implementation processing of the embodiments of the present invention. For example, S605 may be prioritized over S604. Also, in the method procedures shown in FIGS. 6A and 6B, the above steps are not limited, and the addition, deletion, or change of the above steps shall be included in the protection scope of the present application.
[0260] In the present application, the backhaul link is stopped after the connection is released, and the backhaul link is activated after the connection is established. Thereby, the power consumption of the system can be effectively reduced, and resources can be saved.
[0261] Regarding the above case of Scenario 1, the content of the stop and activation of the backhaul link in the communication process is the same as the content of FIGS. 6A and 6B. For simplicity, refer to the content of FIGS. 6A and 6B and the above case of Scenario 1. To obtain the content of the stop and activation of the backhaul link in the communication process with reference to the above case of Scenario 1, steps S605 and S606 in FIG. 6A are deleted. Details are not described again here.
[0262] In the present application, in order to more reliably ensure the temporal validity of the second key and improve the security of communication transmission, in the process of the first node and the second node performing communication transmission using the second key, whether the second key is valid may be further verified.
[0263] In addition, in the present application, the first node may determine whether the second key is valid and notify the second node of the determination result of the second key. Alternatively, the second node may determine whether the second key is valid and notify the first node of the determination result of the second key. Alternatively, both the first node and the second node may determine the validity of the second key.
[0264] In an optional aspect of the present application, the second key is valid within a first period, and the first period may be defined using a timer or a timestamp. The first period may start timing from a first point in time. The first point in time may be the time when the first communication connection is released, or the time when the second node receives a connection establishment request and / or the time when the first node sends a connection establishment request. This is not specifically limited.
[0265] In the following, when referring to the above Scenario 2 and when both the first node and the second node are selected to determine the validity of the second key, an explanation will be given. In the present application, a plurality of verification methods are provided, but are not particularly limited to the following several methods.
[0266] Method 1: The first node and the second node individually determine whether the second key is valid based on their respective timers.
[0267] Referring to FIGS. 7A and 7B. The method procedure corresponding to Method 1 is as follows.
[0268] S700: The first node establishes a first communication connection to the second node based on the first key.
[0269] S701: The first node obtains the second key used for communication authentication with the second node.
[0270] S702: The second node acquires a second key used for communication authentication with the first node.
[0271] S703: The second node releases the first communication connection to the first node.
[0272] S704: The second node starts a corresponding second timer used to determine the validity of the second key.
[0273] The normal operation period of the second timer is the first period.
[0274] S705: The second node sends a release request for the first communication connection to the first node.
[0275] S706: The first node receives a release request for the first communication connection from the second node.
[0276] S707: The first node releases the first communication connection to the second node.
[0277] S708: The first node starts a corresponding first timer used to determine the validity of the second key.
[0278] The normal operation period of the first timer is the first period.
[0279] S709: The first node sends a connection establishment request to the second node. The connection establishment request is used to request the establishment of a connection based on the second key.
[0280] S710: The second node receives the connection establishment request sent by the first node.
[0281] S711: The second node sends authentication information based on the second key to the first node, and the authentication information is used to verify the identity of the second node.
[0282] S712: The first node receives the authentication information based on the second key from the second node.
[0283] S713: After determining that the authentication at the second node has succeeded, the first node sends an authentication response to the second node for the authentication information and verifies the identity of the first node using the authentication response.
[0284] S714: The second node receives the authentication response sent by the first node.
[0285] S715: After determining that the authentication at the second node has succeeded, the second node establishes a second communication connection to the first node.
[0286] S716: After the establishment of the second communication connection to the second node is completed, the first node notifies the second node that the establishment of the second communication connection has been completed.
[0287] S717: The first node stops the corresponding first timer.
[0288] S718: The first node determines whether the first timer has expired. If the first timer has expired, it executes S719; if the first timer has not expired, it executes S720.
[0289] S719: The first node determines that the second key is invalid and terminates the communication transmission.
[0290] S720: The first node performs information transmission with the third node using the backhaul link between the second node and the third node.
[0291] S721: After receiving the notification indicating that the establishment of the second communication connection from the first node is completed, the second node stops the corresponding second timer.
[0292] S722: The second node determines whether the second timer has expired. If the second timer has expired, it executes S723; if the second timer has not expired, it executes S724.
[0293] S723: The second node determines that the second key is invalid and terminates the communication transmission.
[0294] S724: The second node transmits the transmission information from the first node to the third node using the backhaul link between the second node and the third node.
[0295] In the present application, in the method procedures shown in FIGS. 7A and 7B, the point in time when the first node starts the corresponding first timer is not limited to the point in time after step S707 is executed. For example, the point in time when the first node starts the corresponding first timer may alternatively be after step S709 is executed. Similarly, the point in time when the second node starts the corresponding second timer is not limited to the point in time after step S704 is executed. For example, the point in time when the second node starts the corresponding second timer may alternatively be after step S710 is executed.
[0296] Note that in the method procedures shown in FIGS. 7A and 7B, the sequence numbers of the steps do not mean the execution sequence. The execution order of the processes should be determined based on the functions and internal logics of the processes and should not be considered as a limitation to the implementation processes of the embodiments of the present invention. For example, S702 may be prioritized over S701. Also, in the method procedures shown in FIGS. 7A and 7B, the above steps are not limited, and the addition, deletion, or modification of the above steps shall be included in the protection scope of the present application.
[0297] Referring to the case of Scenario 1, the content for determining the validity of the second key in Method 1 is the same as the content in FIGS. 7A and 7B. For simplicity, referring to the content in FIGS. 7A and 7B and the case of Scenario 1, steps S705 and S706 in FIG. 7A are deleted, and it becomes the content for determining the validity of the second key in Method 1 with reference to the case of Scenario 1. Details will not be described again here.
[0298] Method 2: The first node and the second node hold the same timer and determine whether the second key is valid.
[0299] Refer to FIGS. 8A and 8B. The method procedure corresponding to Method 2 is as follows.
[0300] S800: The first node establishes a first communication connection to the second node based on the first key.
[0301] S801: The first node obtains a second key for use in communication authentication with the second node.
[0302] S802: The second node obtains a second key for use in communication authentication with the first node.
[0303] S803: The second node releases the first communication connection to the first node.
[0304] S804: The second node starts a timer used to determine the validity of the second key.
[0305] S805: The second node sends a release request for the first communication connection to the first node.
[0306] S806: The first node receives a release request for the first communication connection from the second node.
[0307] S807: The first node releases the first communication connection to the second node.
[0308] S808: The first node sends a connection establishment request to the second node. The connection establishment request is used to request the establishment of a connection based on the second key.
[0309] S809: The second node receives the connection establishment request sent by the first node.
[0310] S810: The second node sends authentication information based on the second key to the first node, and the authentication information is used to verify the identity of the second node.
[0311] S811: The first node receives authentication information based on the second key from the second node.
[0312] S812: After determining that authentication at the second node has succeeded, the first node sends an authentication response for the authentication information to the second node and verifies the identity of the first node using the authentication response.
[0313] S813: The second node receives the authentication response sent by the first node.
[0314] S814: After determining that authentication at the second node has succeeded, the second node establishes a second communication connection with the first node.
[0315] S815: After the establishment of the second communication connection with the second node is completed, the first node notifies the second node that the establishment of the second communication connection has been completed.
[0316] S816: The first node stops the timer.
[0317] S817: The first node determines whether the timer has expired. If the timer has expired, it executes S818; if the timer has not expired, it executes S819.
[0318] S818: The first node determines that the second key is invalid and ends the communication transmission.
[0319] In the present application, optionally, further, the first node may further notify the second node of the result that the second key is invalid.
[0320] S819: The first node performs information transmission with the third node using the backhaul link between the second node and the third node.
[0321] In the method procedures shown in FIGS. 8A and 8B, alternatively, the first node may start a timer and the second node may stop the timer. For example, after executing S807, the first node starts a timer, and the second node stops the timer after receiving a notification transmitted by the first node indicating that the establishment of the second communication connection is completed in S815. Similarly, the second node may determine whether the timer has expired and determine whether the second key is valid.
[0322] Note that in the method procedures shown in FIGS. 8A and 8B, the sequence numbers of the steps do not mean the execution sequence. The execution order of the processes should be determined based on the functions and internal logics of the processes and should not be considered as a limitation to the implementation processes of the embodiments of the present invention. For example, S802 may be given priority over S801. Also, in the method procedures shown in FIGS. 8A and 8B, the above steps are not limited, and the addition, deletion, or modification of the above steps shall be included in the protection scope of the present application.
[0323] Referring to the case of Scenario 1, the content for determining the validity of the second key in Method 2 is the same as the content in FIGS. 8A and 8B. For the sake of simplicity, referring to the content in FIGS. 8A and 8B and the case of Scenario 1, steps S805 and S806 in FIG. 8A are deleted, and it becomes the content for determining the validity of the second key in Method 2 with reference to the case of Scenario 1. Details are not described again here.
[0324] Method 3: The first node and the second node determine whether the second key is valid based on a time stamp transmitted by signaling.
[0325] Referring to FIGS. 9A to 9C. The method procedure corresponding to Method 3 is as follows.
[0326] S900: The first node establishes a first communication connection to the second node based on the first key.
[0327] S901: The first node obtains a second key for use in communication authentication with the second node.
[0328] S902: The second node acquires a second key used for communication authentication with the first node.
[0329] S903: The second node releases the first communication connection to the first node.
[0330] S904: The second node sends a release request for the first communication connection to the first node. The release request conveys a first timestamp.
[0331] The first timestamp may be the time when the second node sent the release request to the first node.
[0332] Optionally in the present application, after sending the release request to the first node, the second node records the first timestamp.
[0333] S905: The first node receives the release request for the first communication connection from the second node and acquires the first timestamp.
[0334] S906: The first node releases the first communication connection to the second node.
[0335] S907: The first node sends a connection establishment request to the second node. The connection establishment request is used to request the establishment of a connection based on the second key.
[0336] S908: The second node receives the connection establishment request sent by the first node.
[0337] S909: The second node sends authentication information based on the second key to the first node. The authentication information is used to verify the identity of the second node.
[0338] S910: The first node receives the authentication information based on the second key from the second node.
[0339] After determining that the authentication at the second node has succeeded, the first node sends an authentication response to the second node for the authentication information and verifies the identity of the first node using the authentication response.
[0340] S912: The second node receives the authentication response sent by the first node.
[0341] S913: After determining that the authentication at the second node has succeeded, the second node establishes a second communication connection with the first node.
[0342] S914: After the establishment of the second communication connection to the second node is completed, the first node sends an establishment completion message to the second node, and the establishment completion message conveys a second timestamp.
[0343] The establishment completion message is used to notify the second node that the first node has completed the establishment of the second communication connection.
[0344] The second timestamp may be the time when the first node sends the establishment completion message to the second node. Alternatively, the second timestamp may be the time when the first node completes the establishment of the second communication connection.
[0345] In this application, the first node optionally records the second timestamp.
[0346] S915: The first node determines whether the time difference between the second timestamp and the first timestamp exceeds a first period. If the time difference between the second timestamp and the first timestamp does not exceed the first period, it executes S916. If the time difference between the second timestamp and the first timestamp exceeds the first period, it executes S917.
[0347] S916: The first node performs information transmission with the third node using the backhaul link between the second node and the third node.
[0348] S917: The first node determines that the second key is invalid and terminates the communication transmission.
[0349] S918: After receiving the establishment completion message, the second node obtains a second timestamp.
[0350] S919: The second node determines whether the time difference between the second timestamp and the first timestamp exceeds the first period. If the time difference between the second timestamp and the first timestamp does not exceed the first period, S920 is executed. If the time difference between the second timestamp and the first timestamp exceeds the first period, S921 is executed.
[0351] S920: The second node uses the backhaul link between the second node and the third node to transmit the transmission information from the first node to the third node.
[0352] S921: The second node determines that the second key is invalid and terminates the communication transmission.
[0353] Note that the method procedures shown in FIGS. 9A to 9C are only an example in which the first node and the second node determine whether the second key is valid using timestamps, and do not limit the method of determining whether the second key is valid using timestamps, nor do they limit the above steps. The addition, deletion, or modification of the above steps is included in the protection scope of this application.
[0354] Referring to the case of Scenario 1, the content of determining the validity of the second key in Method 3 is the same as the content of FIGS. 9A to 9C. For simplicity, referring to the content of FIGS. 9A to 9C and the case of Scenario 1, steps S904 and S905 in FIG. 9A are deleted, and the content of determining the validity of the second key in Method 3 referring to the case of Scenario 1 is obtained. Details will not be described again here.
[0355] In this application, in the process of communication transmission between the first node and the second node using the second key, it is further verified whether the second key is valid. Thereby, the temporal validity of the second key can be ensured, and the security of communication transmission can be further ensured.
[0356] As described above, with reference to FIGS. 3 to 9C, the communication system and the implemented communication method in this application have been described in detail. In this communication solution, this application provides a communication method in a scenario where communication is performed by integrating different communication systems. Thereby, the communication security is effectively improved.
[0357] Furthermore, the content of FIGS. 3 to 9C does not limit the communication method provided in this application. Any deformation of the content of FIGS. 3 to 9C is included in the protection scope of this application. For example, by combining the content of FIGS. 4A and 4B, FIGS. 6A and 6B, and FIGS. 7A and 7B, in Scenario 1 of this application, a communication solution can be obtained in which the backhaul link is stopped and started, and the validity of the second key is verified. Thereby, the system overhead can be further reduced, and the communication security can be improved.
[0358] The method and device are devised based on the same or similar technical concepts. The method and device have the same principle for solving problems. Therefore, for the implementation of the device and the method, reference may be made to each other. Details of repetitive parts are not described. The terms "system" and "network" may be used synonymously in the embodiments of the present application. In the description of the embodiments of the present application, the term "and / or" describes the association relationship between associated objects and indicates that three relationships may exist. For example, A and / or B may indicate the following three cases: only A exists, both A and B exist, and only B exists. The character " / " usually indicates an "or" relationship between associated objects. In the present application, "at least one" means one or more, and "a plurality of" means two or more. Furthermore, it should be understood that in the description of the present application, terms such as "first", "second", and "third" are only used for distinction and description and should not be understood as an indication or suggestion of relative importance, nor as an indication or suggestion of order. References to "embodiments", "some embodiments", etc. described in this specification mean that one or more embodiments of the present application include the specific features, structures, or characteristics described with reference to the embodiments. Therefore, in this specification, descriptions such as "in an embodiment", "in some embodiments", "in some other embodiments", and "in other embodiments" appearing in different places do not necessarily refer to the same embodiment. Instead, unless specified otherwise in other ways, the description means "one or more but not all of the embodiments". The terms "include", "have" (include, have), and their variants all mean "include but not limited to" unless otherwise specified in other ways.
[0359] The device provided in the embodiments of the present application will be described in detail below with reference to FIGS. 10 and 11. It should be understood that the description of the device embodiments corresponds to the description of the method embodiments. Therefore, for the content not described in detail, reference may be made to each other.
[0360] FIG. 10 is a schematic block diagram of a device 1000 according to an embodiment of the present application. The device 1000 is configured to implement the functions of the first device or the second device in the embodiment of the foregoing method. For example, the device may be a software module or a chip system. The chip may include the chip, or may include the chip and another individual component. The device 1000 includes a processing unit 1001 and a communication unit 1002. The communication unit 1002 is configured to communicate with another device and is also referred to as a communication interface, a transceiver unit, an input / output interface, etc.
[0361] In some embodiments, the device 1000 may be configured to implement the functions of the first device in the foregoing method. The device 1000 may be the first device, or may be a chip, a circuit, etc. configured as the first device. The processing unit 1001 may be configured to execute operations related to the processing of the first device in the embodiment of the foregoing method, and the communication unit 1002 may be configured to instruct operations related to the reception and transmission of the first device in the embodiment of the foregoing method.
[0362] For example, the processing unit 1001 is configured to obtain a second key used for communication authentication with the second node, and the second key is different from a pre-configured first key. The communication unit 1002 is configured to receive a release request for the first communication connection from the second node, and the first key is used for communication authentication in the first communication connection. The communication unit 1002 is further configured to transmit a connection establishment request to the second node. The connection establishment request is used to request to establish a connection based on the second key.
[0363] Optionally, using the connection establishment request to request the establishment of a connection based on the second key includes: using the connection establishment request to request to execute authentication and security context negotiation procedures based on the second key.
[0364] Optionally, the communication unit 1002 is further configured to receive authentication information based on a second key from a second node, and the authentication information is used to verify the identity of the second node.
[0365] Optionally, verifying the identity of the second node using the authentication information includes verifying whether a second communication connection to the second node is established based on the second key using the authentication information.
[0366] Optionally, the communication unit 1002 is further configured to send an authentication response to the second node based on the second key, and the authentication response is used to verify the identity of the first node.
[0367] Optionally, the authentication response being used by the second node as an option to verify the identity of the first node includes: the authentication response is used by the second node to verify whether to establish a second communication connection to the first node based on the second key.
[0368] Optionally, the release request includes request cause information, and the request cause information indicates that the key used for communication authentication is updated.
[0369] Optionally, the second key is valid within a first period, and the first period is defined using a timer or a timestamp.
[0370] Optionally, the second key is valid within a first period starting from a first point in time, and the first point in time is the time when the first communication connection is released or the time when a connection establishment request is sent.
[0371] Optionally, the processing unit 1001 is further configured to perform information transmission with a third node using a backhaul link between the second node and the third node within the valid period of the second key.
[0372] Optionally, the first key is a key derived (or negotiated) based on the first communication system, and / or the second key is a key derived (or negotiated) based on the second communication system, where the first communication system is different from the second communication system.
[0373] In some other embodiments, device 1000 may be configured to implement the functions of the second device in the above-described method embodiments. Device 1000 may be the second device, or may be a chip, a circuit, etc. configured for the second device. The processing unit 1001 may be configured to perform operations related to the processing of the second device in the above-described method embodiments, and the communication unit 1002 may be configured to perform operations related to the reception and transmission of the second device in the above-described method embodiments.
[0374] For example, the processing unit 1001 is configured to obtain a second key used for communication authentication with the first node, where the second key is different from a pre-configured first key. The communication unit 1002 is configured to send a request to release the first communication connection to the first node, where the first key is used for communication authentication in the first communication connection. The communication unit 1002 is further configured to receive a connection establishment request sent by the first node. The connection establishment request is used to request the establishment of a connection based on the second key.
[0375] Optionally, using the connection establishment request to request the establishment of a connection based on the second key includes: using the connection establishment request to request the execution of authentication and security context negotiation procedures based on the second key.
[0376] Optionally, the communication unit 1002 is further configured to send authentication information based on the second key to the first node, where the authentication information is used to verify the identity of the second node.
[0377] Optionally, verifying the identity of the second node using the authentication information includes verifying by the first node whether a second communication connection to the second node is established based on the second key using the authentication information.
[0378] Optionally, the first key is a key derived (or negotiated) based on a first communication system, and / or the second key is a key derived (or negotiated) based on a second communication system, and the first communication system is different from the second communication system.
[0379] Optionally, the communication unit 1002 is further configured to receive an authentication response based on the second key from the first node, and the authentication response is used to verify the identity of the first node.
[0380] Optionally, the authentication response being used as an option to verify the identity of the first node includes: the authentication response is used by the second node to verify whether to establish a second communication connection to the first node based on the second key.
[0381] Optionally, the release request includes request cause information, and the request cause information indicates that the key used for communication authentication is updated.
[0382] Optionally, the second key is valid within a first period, and the first period may be defined using a timer or a timestamp.
[0383] Optionally, the second key is valid within a first period starting from a first point in time, and the first point in time is the time when the first communication connection is released or the time when the second node receives a connection establishment request.
[0384] Optionally, the processing unit 1001 is further configured to transmit transmission information from the first node to the third node using a backhaul link between the second node and the third node within the valid period of the second key.
[0385] Optionally, after releasing the first communication connection to the first node, the processing unit 1001 is further configured to stop the backhaul link.
[0386] Optionally, after determining that the establishment of the second communication connection to the first node has succeeded, the processing unit 1001 is further configured to start the backhaul link, and communication authentication is performed on the second communication connection based on the second key.
[0387] In the present embodiment of the present application, the division into units is an example and is merely a logical function division. In an actual implementation, another division method may be used. Further, the functional units in the present embodiment of the present application may be integrated into one processor, or each of the units may physically exist alone, or two or more units may be integrated into one unit. The integrated unit may be implemented in the form of hardware or in the form of a software functional unit.
[0388] FIG. 11 is a schematic diagram of a device 1100 according to an embodiment of the present application. The device 1100 may be a node or a component within a node, such as a chip or an integrated circuit. The device 1100 may include at least one processor 1102 and a communication interface 1104. Further, optionally, the device may further include at least one memory 1101. Further, optionally, the device may further include a bus 1103. The memory 1101, the processor 1102, and the communication interface 1104 are communicatively connected to each other through the bus 1103.
[0389] Memory 1101 is configured to provide a storage space, and the storage space can store data such as an operating system and computer programs. It should be understood that the memory 1101 referred to in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include a volatile memory and a non-volatile memory. The non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM) used as an external cache. By way of example, and not limitation, many forms of RAM may be used, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).
[0390] Note that the memories described in this specification are intended to include, without limitation, these memories and any other suitable types of memories. The processor 1102 is a module for performing arithmetic and / or logical operations, and specifically, it may be one or a combination of a plurality of processing modules such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor unit (MPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), a coprocessor (which assists the central processing unit in completing corresponding processes and applications), and a microcontroller unit (MCU).
[0391] Note that if the processor is a general-purpose processor, an ASIC, an FPGA, or other programmable logic element, an individual gate, or a transistor logic device, or an individual hardware component, the memory (storage module) may be integrated with the processor.
[0392] The communication interface 1104 may be configured to provide information input or output for at least one processor. Alternatively, the communication interface may be configured to receive data transmitted from the outside and / or transmit data to the outside, and may be a wired link interface including an Ethernet cable or the like, or may be a wireless link (Wi-Fi, Bluetooth, Universal Wireless Transmission, Vehicle Proximity Communication Technology, etc.) interface. Optionally, the communication interface 1104 may further include a transmitter (such as a radio frequency transmitter or an antenna) coupled to the interface, a receiver, and the like.
[0393] In some embodiments, the device 1100 may be the first device in the embodiments of the foregoing method, or a component in the first device, such as a chip or an integrated circuit. The processor 1102 in the device 1100 is configured to read a computer program stored in the memory 1101 and control the first device to perform the following operations. Obtain a second key used for communication authentication with the second node, the second key being different from a preset first key, receive a release request for the first communication connection from the second node, the first key being used for communication authentication of the first communication connection, and transmit a connection establishment request to the second node, the connection establishment request being used to request establishment of a connection based on the second key.
[0394] Optionally, the processor 1102 in the first device reads a program in the memory 1101 and executes the method steps executed by the first node in S300 to S305 shown in FIG. 3, or executes the method steps executed by the first node in S400 to S417 shown in FIGS. 4A and 4B, or executes the method steps executed by the first node in S500 to S519 shown in FIGS. 5A and 5B, or executes the method steps executed by the first node in S600 to S617 shown in FIGS. 6A and 6B, or executes the method steps executed by the first node in S700 to S724 shown in FIGS. 7A and 7B, or executes the method steps executed by the first node in S800 to S819 shown in FIGS. 8A and 8B, or may be further configured to execute the method steps executed by the first node in S900 to S921 shown in FIGS. 9A and 9C.
[0395] For specific details, refer to the description in the embodiments of the foregoing method. The details are not described again here.
[0396] In some other embodiments, the device 1100 may be the second device in the embodiments of the foregoing method, or a component in the second device, such as a chip or an integrated circuit. The processor 1102 in the device 1100 is configured to read a computer program stored in the memory 1101 and control the second device to perform the following operations. Obtain a second key used for communication authentication with the first node. The second key is different from the preset first key. Send a request to release the first communication connection to the first node. The first key is used for communication authentication of the first communication connection. Receive a connection establishment request sent by the first node. The connection establishment request is used to request the establishment of a connection based on the second key.
[0397] Optionally, the processor 1102 in the second device reads the program in the memory 1101 and executes the method steps executed by the second node in S300 to S305 shown in FIG. 3, or executes the method steps executed by the second node in S400 to S417 shown in FIGS. 4A and 4B, or executes the method steps executed by the second node in S500 to S519 shown in FIGS. 5A and 5B, or executes the method steps executed by the second node in S600 to S617 shown in FIGS. 6A and 6B, or executes the method steps executed by the second node in S700 to S724 shown in FIGS. 7A and 7B, or executes the method steps executed by the second node in S800 to S819 shown in FIGS. 8A and 8B, or executes the method steps executed by the second node in S900 to S921 shown in FIGS. 9A and 9C, and may be further configured.
[0398] For specific details, refer to the description in the foregoing embodiments of the method. The details are not described again here.
[0399] Embodiments of the present application further provide a terminal. The terminal may be an intelligent terminal such as a smartphone, a notebook computer, a tablet computer, etc. having a short-range communication function, a mouse, a keyboard, a headset, a speaker, an in-vehicle playback device, etc. The terminal includes the first device and / or the second device. The first device and the second device may be the first node and the second node in the embodiment shown in FIG. 3, respectively. The types of the first device and the second device may be the same or different.
[0400] FIG. 12 is a schematic diagram of a simplified structure of a terminal device. In FIG. 12, for ease of explanation, an example in which the terminal device is a mobile phone is used. As shown in FIG. 12, the terminal device includes a processor, a memory, a radio frequency circuit, an antenna, and an input / output device. The processor is mainly configured to process communication protocols and communication data, control the terminal device, execute software programs, and process data of software programs. The memory is mainly configured to store software programs and data. The radio frequency circuit is mainly configured to perform conversion between a baseband signal and a radio frequency signal and process the radio frequency signal. The antenna is mainly configured to transmit and receive radio frequency signals in the form of electromagnetic waves. An input / output device such as a touch screen, a display, or a keyboard is mainly configured to receive data input by a user and output data to the user. It should be noted that some types of terminal devices may not have an input / output device.
[0401] When data needs to be transmitted, the processor performs baseband processing on the data to be transmitted and then outputs the baseband signal to the radio frequency circuit. The radio frequency circuit performs radio frequency processing on the baseband signal and transmits the radio frequency signal to the outside in the form of electromagnetic waves via the antenna. When data is transmitted to the terminal device, the radio frequency circuit receives the radio frequency signal via the antenna, converts the radio frequency signal into a baseband signal, and outputs the baseband signal to the processor. The processor converts the baseband signal into data and processes the data. For ease of explanation, FIG. 12 shows only one memory and one processor. An actual terminal device product may have one or more processors and one or more memories. The memory may also be referred to as a storage medium, a storage device, etc. The memory may be arranged independently of the processor or integrated with the processor. This is not limited in the embodiments of the present application.
[0402] In the present embodiment of the present application, the antenna and the radio frequency circuit having functions of a transceiver may be considered as a transceiver unit of a terminal device, and the processor having processing functions may be considered as a processing unit of the terminal device. As shown in FIG. 12, the terminal device includes a transceiver unit 1210 and a processing unit 1220. The transceiver unit may also be referred to as a transceiver, a transceiver machine, a transceiver device, etc. The processing unit may also be referred to as a processor, a processing board, a processing module, a processing device, etc. Optionally, a component that is within the transceiver unit 1210 and is configured to implement a receiving function may be considered as a receiving unit, and a component that is within the transceiver unit 1210 and is configured to implement a transmitting function may be considered as a transmitting unit. In other words, the transceiver unit 1210 includes a receiving unit and a transmitting unit. The transceiver unit may sometimes also be referred to as a transceiver machine, a transceiver, a transceiver circuit, etc. The receiving unit may sometimes also be referred to as a receiving machine, a receiver, a receiving circuit, etc. The transmitting unit may sometimes also be referred to as a transmitting machine, a transmitter, a transmitting circuit, etc.
[0403] Note that, in the embodiment of the method shown in FIG. 3, the transceiver unit 1210 is configured to perform a transmitting operation and a receiving operation on the first node side, and the processing unit 1220 is configured to perform another operation other than the transmitting operation and the receiving operation on the first node side in the embodiment of the method shown in FIG. 3.
[0404] For example, in implementation, in the embodiment shown in FIG. 3, the transceiver unit 1210 is configured to perform a transmitting operation and a receiving operation, such as S303 and S305, on the terminal device side, and / or is configured to support other processes of the technology described in this specification. The processing unit 1220 is configured to perform an operation other than the transmitting operation and the receiving operation, such as S300, on the terminal device side in the embodiment shown in FIG. 3, and / or is configured to support other processes of the technology described in this specification.
[0405] Alternatively, in the embodiment of the method shown in FIGS. 4A and 4B, the transceiver unit 1210 is configured to perform a transmission operation and a reception operation on the terminal device side, and in the embodiment of the method shown in FIGS. 4A and 4B, the processing unit 1220 is configured to perform operations other than the transmission operation and the reception operation on the terminal device side.
[0406] For example, in implementation, in the embodiment shown in FIGS. 4A and 4B, the transceiver unit 1210 is configured to perform a transmission step and a reception step, for example, and S406 on the terminal device side, and / or is configured to support other processes of the technology described in this specification. The processing unit 1220 is configured to perform operations other than the transmission operation and the reception operation, for example, S409 on the terminal device side in the embodiment shown in FIGS. 4A and 4B, and / or is configured to support other processes of the technology described in this specification.
[0407] Alternatively, in the embodiment of the method shown in FIGS. 5A and 5B, the transceiver unit 1210 is configured to perform a transmission operation and a reception operation on the terminal device side, and in the embodiment of the method shown in FIGS. 5A and 5B, the processing unit 1220 is configured to perform operations other than the transmission operation and the reception operation on the terminal device side.
[0408] For example, in implementation, in the embodiment shown in FIGS. 5A and 5B, the transceiver unit 1210 is configured to perform a transmission step and a reception step, for example, and S508 on the terminal device side, and / or is configured to support other processes of the technology described in this specification. The processing unit 1220 is configured to perform operations other than the transmission operation and the reception operation, for example, S511 on the terminal device side in the embodiment shown in FIGS. 5A and 5B, and / or is configured to support other processes of the technology described in this specification.
[0409] Alternatively, in the embodiment of the method shown in FIGS. 6A and 6B, the transceiver unit 1210 is configured to perform transmission and reception operations on the terminal device side, and the processing unit 1220 is configured to perform operations other than transmission and reception operations on the terminal device side in the embodiment of the method shown in FIGS. 6A and 6B.
[0410] For example, in implementation, the transceiver unit 1210 is configured to perform transmission steps and reception steps, such as and S606, on the terminal device side in the embodiments shown in FIGS. 6A and 6B, and / or configured to support other processes of the technology described in this specification. The processing unit 1220 is configured to perform operations other than transmission and reception operations, such as S604, on the terminal device side in the embodiments shown in FIGS. 6A and 6B, and / or configured to support other processes of the technology described in this specification.
[0411] Alternatively, in the embodiment of the method shown in FIGS. 7A and 7B, the transceiver unit 1210 is configured to perform transmission and reception operations on the terminal device side, and the processing unit 1220 is configured to perform operations other than transmission and reception operations on the terminal device side in the embodiment of the method shown in FIGS. 7A and 7B.
[0412] For example, in implementation, the transceiver unit 1210 is configured to perform transmission steps and reception steps, such as and S706, on the terminal device side in the embodiments shown in FIGS. 7A and 7B, and / or configured to support other processes of the technology described in this specification. The processing unit 1220 is configured to perform operations other than transmission and reception operations, such as S704, on the terminal device side in the embodiments shown in FIGS. 7A and 7B, and / or configured to support other processes of the technology described in this specification.
[0413] Alternatively, in the embodiment of the method shown in FIGS. 8A and 8B, the transceiver unit 1210 is configured to perform transmission and reception operations on the terminal device side, and in the embodiment of the method shown in FIGS. 8A and 8B, the processing unit 1220 is configured to perform operations other than transmission and reception operations on the terminal device side.
[0414] For example, in the implementation, in the embodiment shown in FIGS. 8A and 8B, the transceiver unit 1210 is configured to perform transmission and reception steps, for example, and S806, on the terminal device side, and / or configured to support other processes of the technology described herein. The processing unit 1220 is configured to perform operations other than transmission and reception operations, for example, S804, on the terminal device side in the embodiment shown in FIGS. 8A and 8B, and / or configured to support other processes of the technology described herein.
[0415] Alternatively, in the embodiment of the method shown in FIGS. 9A to 9C, the transceiver unit 1210 is configured to perform transmission and reception operations on the terminal device side, and in the embodiment of the method shown in FIGS. 9A to 9C, the processing unit 1220 is configured to perform operations other than transmission and reception operations on the terminal device side.
[0416] For example, in the implementation, in the embodiment shown in FIGS. 9A to 9C, the transceiver unit 1210 is configured to perform transmission and reception steps, for example, and S905, on the terminal device side, and / or configured to support other processes of the technology described herein. The processing unit 1220 is configured to perform operations other than transmission and reception operations, for example, S915, on the terminal device side in the embodiment shown in FIGS. 9A to 9C, and / or configured to support other processes of the technology described herein.
[0417] When the communication device is a chip, the chip includes a transceiver unit and a processing unit. The transceiver unit may be an input / output circuit or a communication interface. The processing unit is a processor, a microprocessor, or an integrated circuit integrated in the chip.
[0418] Embodiments of the present application further provide a computer-readable storage medium including instructions. When the instructions are executed by a computer, the computer executes the method described in the foregoing aspect.
[0419] Embodiments of the present application further provide a chip system. The chip system includes at least one processor and an interface circuit. Further optionally, the chip system may further include a memory or an external memory. The processor is configured to execute instruction and / or data interaction through the interface circuit to implement the method in the embodiments of the foregoing method. The chip system may include a chip, or may include a chip and another individual component.
[0420] Embodiments of the present application further provide a computer program product including instructions. When the instructions are executed by a computer, the computer executes the method described in the foregoing aspect.
[0421] In embodiments of the present application, the processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or another programmable logic element, an individual gate or transistor logic element, an individual hardware component, or a coprocessor, and may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed with respect to the embodiments of the present application may be directly executed by a hardware processor, or may be executed using a combination of hardware and software modules in the processor.
[0422] In an embodiment of the present application, the memory may be a non-volatile memory, a hard disk drive (HDD) or a solid-state drive (SSD), or may be a volatile memory, such as a random-access memory (RAM). The memory can transmit or store the expected program code in the form of instructions or data structures, and can be any other medium accessible by a computer, but is not limited thereto. The memory of the embodiment of the present application may alternatively be a circuit or any other device capable of implementing a storage function and configured to store program instructions and / or data.
[0423] All or part of the method in the embodiments of the present application can be implemented using software, hardware, firmware, or any combination thereof. When software is used to implement the embodiments, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the procedures or functions according to the embodiments of the present application are all or partially generated. The computer may be a general-purpose computer, a dedicated computer, a computer network, a network device, a user device, or another programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted in a wired (e.g., coaxial cable, optical fiber, or digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, or microwave) manner from a website, computer, server, or data center to another website, computer, server, or data center. The computer-readable storage medium may be any usable medium accessible by a computer, or a data storage device such as a server or data center that integrates one or more usable media. The usable media may be a magnetic medium (e.g., floppy disk, hard disk, or magnetic tape), an optical medium (e.g., digital video disc (DVD)), a semiconductor medium (e.g., SSD), etc.
[0424] Those skilled in the art can recognize that, in combination with the examples described in the embodiments disclosed herein, the units and algorithms can be implemented by electronic hardware or a combination of computer software and electronic hardware. Whether a function is executed by hardware or software depends on the specific application of the technical solution and design constraints. Those skilled in the art may use different methods to implement the described functions for each specific application, but the implementation should not be considered to exceed the scope of this application.
[0425] For the sake of convenience and concise description, for the detailed operation processes of the aforementioned systems, devices, and units, it can be clearly understood by those skilled in the art to refer to the corresponding processes in the embodiments of the aforementioned methods. The details will not be described again here.
[0426] The units described as separate parts may or may not be physically separated. The parts shown as units may or may not be physical units, may be placed in one location, or may be distributed among multiple network units. Some or all of the units may be selected based on actual requirements to achieve the objectives of the solution of the embodiment.
[0427] When the function is implemented in the form of a software functional unit and sold or used as an independent product, the function may be stored in a computer-readable storage medium. Based on such an understanding, basically, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution, may be implemented in the form of a software product. The software product is stored in a storage medium and includes several instructions for instructing a computer device (which may be a personal computer, a server, or a network device) to execute all or part of the steps of the method described in the embodiments of the present application. The aforementioned storage medium includes any medium such as a USB flash drive, a removable hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk that can store program code.
[0428] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. The present application intends to cover these changes and modifications of the present application if they are included within the protection scope defined by the following claims and the scope of their equivalent technologies.
Claims
1. A communication method, the method comprising: obtaining a second key used for communication authentication with a second node, the second key being different from a preset first key; receiving a release request for a first communication connection from the second node, the first key being used for communication authentication of the first communication connection; sending a connection establishment request to the second node, the connection establishment request being used to request establishment of a connection based on the second key; wherein the release request includes request cause information; the request cause information indicates that the key used for communication authentication is updated.
2. The fact that the connection establishment request is used to request establishment of a connection based on the second key includes that the connection establishment request is used to request performing authentication and security context negotiation procedures based on the second key. The method according to claim 1.
3. The method further includes: receiving authentication information based on the second key from the second node, the authentication information being used to verify the identity of the second node. The method according to claim 1.
4. The method further includes: sending an authentication response based on the second key to the second node, the authentication response being used to verify the identity of a first node. The method according to claim 3.
5. The second key is valid within a first period, the first period being defined by a timer or a timestamp. The method according to claim 1.
6. The second key is valid within the first period starting from a first point in time, the first point in time being the time when the first communication connection is released or the time when the connection establishment request is sent. The method according to claim 5.
7. The method further includes: during the valid period of the second key, performing information transmission with a third node using a backhaul link between the second node and the third node. The method according to claim 1.
8. A communication device including at least one processor and an interface circuit, the interface circuit providing a program or instructions for the at least one processor, the at least one processor enabling the device in which the communication device is disposed to execute any one of claims 1 to 7, the communication device.
9. A computer-readable storage medium including computer instructions, which, when executed on a computer, enable the computer to execute the method according to any one of claims 1 to 7, the computer-readable storage medium.
10. A terminal including a first node that executes the method according to any one of claims 1 to 7, the terminal.
Citation Information
Patent Citations
Key update method, device, and storage medium
EP3793317A1
Method and Apparatus for Securing Initial User Identity in Initial Signaling Messages
JP2009542091A
Key management method and key management apparatus
JP2010004379A
Cited By
Communication methods, devices and systems
KR1020240049384A
Communication methods, devices, and systems
KR103000827B1