Method for establishing a secure transmission channel, method for determining a key, and communication device
Patent Information
- Application Number
- KR1020247007194
- Authority / Receiving Office
- KR · KR
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-07-31
- Filing Date
- 2022-07-28
- Publication Date
- 2026-09-21
- Estimated Expiration
- 2042-07-28
Smart Images

Figure 112024023886603-PCT00059_ABST
Abstract
Description
Technology Field
[0001] delete
[0002] This application relates to an integrated access and backhaul network, in particular, a method for establishing a secure transmission channel, a key determination method, and a communication device. Background Technology
[0003] To meet the ultra-high-capacity requirements of 5th generation (5G) mobile communication systems, high-frequency small cell networking is becoming mainstream. Since high-frequency carriers have poor propagation characteristics, severe attenuation due to blocking, and narrow coverage, a large number of small cells need to be deployed densely. Integrated access and backhaul (IAB) technology provides a concept to address the aforementioned problems. Wireless transmission solutions are utilized on both the access link and the backhaul link within the IAB network to avoid optical-fiber deployment.
[0004] As illustrated in FIGS. 3 and 4, an F1 interface needs to be established between the IAB node and the donor node. To protect the security of the F1 interface, an internet protocol (IP) security (IPsec) connection may be established between the IAB node and the IAB donor.
[0005] In the case of an architecture with separation between the control plane and the user plane of an IAB donor central unit, how to establish IPsec secure connections between the distributed units of the IAB nodes and the user plane entities of the IAB donor central unit is becoming an urgent problem that needs to be solved.
[0006] This application provides a method for establishing a secure transmission channel between a user plane entity of a donor node central unit (donor centralized unit user plane, donor-CU-UP) and a distributed unit of an IAB node (IAB-distributed unit, IAB-DU).
[0007] According to a first aspect, a method for establishing a secure transmission channel is provided. The method applies to a donor-CU-UP, and the method comprises the steps of: receiving a first message from a control plane entity of a donor node central unit (donor centralized unit control plane, donor-CU-CP)—the first message includes a first key, the first key is different from a root key, the root key is a key obtained by the donor-CU-CP from the network in a procedure in which an IAB node registers with the network—; and establishing a user plane secure transmission channel between the donor-CU-UP and the IAB-DU based on the first key.
[0008] For example, in the procedure for establishing a user plane secure transmission channel by the donor-CU-UP and IAB-DU, the first key is an authentication credential used by the donor-CU-UP and IAB-DU.
[0009] For example, the first key is K IAB And, the root key is K gNB am.
[0010] Based on the above-described technical solution, in order to help Donor-CU-UP establish a user plane secure transmission channel between Donor-CU-UP and IAB-DU based on a first key, and to help avoid the problem of authentication errors generated when Donor-CU-UP and IAB-DU establish the user plane secure transmission channel, a first message received by Donor-CU-UP from Donor-CU-CP includes a first key.
[0011] For example, the first message is a bearer context setup request message. For example, in a procedure where a terminal device accesses a network through an IAB-DU, the donor-CU-CP sends a bearer context setup request message to the donor-CU-UP, wherein the bearer context setup request message includes a first key.
[0012] As another example, the first message is a bearer context modification request message. For example, in a procedure where a terminal device accesses a network via IAB-DU, Donor-CU-CP sends a bearer context modification request message to Donor-CU-UP, where the bearer context modification request message includes a first key.
[0013] Referring to the first aspect, in some embodiment of the first aspect, the first message further includes a first IP address of a donor-CU-UP, and the method further includes the step of determining to establish a user plane secure transmission channel by using the first IP address of a donor-CU-UP; and the step of determining a first key based on the first IP address.
[0014] Optionally, the first message further includes the IP address of the IAB-DU.
[0015] Referring to the first aspect, in some embodiment of the first aspect, the first message comprises a one-to-one correspondence between a plurality of internet protocol (IP) addresses of the donor-CU-UP and a plurality of keys, wherein the plurality of keys comprises a first key, and the first key corresponds to a first IP address; the method further comprises the step of determining to establish a user plane secure transmission channel by using the first IP address of the donor-CU-UP; and the step of determining a first key based on the first IP address.
[0016] Specifically, the donor-CU-UP is a first key that corresponds to a first IP address and determines a key within a plurality of keys included in the first message.
[0017] Based on the technical solution described above, when the donor-CU-UP has multiple IP addresses, the donor-CU-UP can receive keys corresponding to multiple IP addresses in order to help the donor-CU-UP establish different user plane secure transmission channels between the donor-CU-UP and the IAB-DU based on multiple keys and multiple IP addresses.
[0018] For example, the first message is a bearer context setup request message. For example, in a procedure where the mobile termination of an IAB node (IAB-mobile termination, IAB-MT) accesses the network through the distributed unit of a donor node (donor distributed unit, donor-DU), the donor-CU-CP sends a bearer context setup request message to the donor-CU-UP, wherein the bearer context setup request message includes a one-to-one correspondence between multiple IP addresses and multiple keys of the donor-CU-UP. It should be understood that the donor-DU, donor-CU-UP, and donor-CU-CP belong to the same donor node, and the IAB-DU and IAB-MT belong to the same IAB node.
[0019] Optionally, the first message further includes the IP address of IAB-DU, and multiple keys all correspond to the IP address of IAB-DU. In other words, each of the multiple keys corresponds to one IP address of Donor-CU-UP and the IP address of IAB-DU.
[0020] Referring to the first aspect, in some embodiment of the first aspect, the method further comprises the steps of: receiving first instruction information from a donor-CU-CP; and transmitting a plurality of IP addresses of a donor-CU-UP to a donor-CU-CP based on the first instruction information.
[0021] For example, the first instruction information indicates that IAB-DU belongs to the IAB node.
[0022] Referring to the first aspect, in some embodiment of the first aspect, the method further includes the step of storing a correspondence between a first key and an IP address of an IAB-DU.
[0023] For example, the donor-CU-UP stores the correspondence between the first key and the IP address of the IAB-DU within the context of the donor-CU-UP.
[0024] Referring to the first aspect, in some implementation of the first aspect, the first message further includes first instruction information, and the first instruction information indicates that IAB-DU belongs to an IAB node.
[0025] Based on the above-described technical solution, the donor-CU-UP determines that the IAB-DU belongs to the IAB node based on the first instruction information, and the first key included in the first message can be received and stored as required.
[0026] According to a second aspect, a method for establishing a secure transmission channel is provided, wherein the method is applied to an IAB-DU, and the method comprises the steps of: receiving a second message from a donor-CU-CP, wherein the second message includes a first IP address of a donor-CU-UP; transmitting a first request message to an IAB-MT, wherein the first request message requests a first key, wherein the first key is different from a root key, wherein the root key is a key generated by the IAB-MT in a network registration procedure, and the first request message includes a first IP address; receiving a first response message from the IAB-MT, wherein the first response message includes a first key; and establishing a user plane secure transmission channel between the IAB-DU and the donor-CU-UP based on the first key.
[0027] For example, in the procedure for establishing a user plane secure transmission channel by the donor-CU-UP and IAB-DU, the first key is an authentication credential used by the donor-CU-UP and IAB-DU.
[0028] For example, the first key is K IAB And, the root key is K gNB am.
[0029] Based on the technical solution described above, upon receiving the first IP address of the donor-CU-UP, the IAB-DU transmits the first IP address of the donor-CU-UP to the IAB-MT via a first request message, thereby enabling the IAB-MT to determine a first key based on the first IP address of the donor-CU-UP and transmit the first key to the IAB-DU. When the IAB-DU receives the first key, this helps the IAB-DU establish a user plane secure transmission channel between the IAB-DU and the donor-CU-UP based on the first key, and helps avoid the problem of authentication errors that occur when the donor-CU-UP and the IAB-DU establish a user plane secure transmission channel.
[0030] Referring to the second aspect, in some embodiment of the second aspect, before transmitting the first request message to the IAB-MT, the method further comprises the step of receiving a user plane data request message from a terminal device, wherein the user plane secure transmission channel is for transmitting user plane data of the terminal device.
[0031] Based on the above-described technical solution, IAB-DU can request a first key from IAB-MT as required based on a user flat data request message.
[0032] Referring to the second aspect, in some implementation of the second aspect, before transmitting the first request message to the IAB-MT, the method further includes the step of receiving an authentication request message from the donor-CU-UP, wherein the authentication request message is for establishing a user plane secure transmission channel.
[0033] Based on the above-described technical solution, IAB-DU can request a first key from IAB-MT as required based on an authentication request message.
[0034] Referring to the second aspect, in some embodiment of the second aspect, the method further includes the step of storing a correspondence between a first key and a first IP address of a donor-CU-UP.
[0035] For example, the IAB-DU stores the correspondence between the first key and the first IP address of the donor-CU-UP within the context of the IAB-DU.
[0036] According to a third aspect, a method for establishing a secure transmission channel is provided, wherein the method is applied to an IAB-DU, and the method comprises the steps of: receiving a second message from a donor-CU-CP, wherein the second message includes a first IP address of a donor-CU-UP; transmitting a second request message to an IAB-MT, wherein the second request message requests a root key, the root key is for generating a first key, the first key is different from the root key, and the root key is a key generated by the IAB-MT in a network registration procedure; receiving a second response message from the IAB-MT, wherein the second response message includes a root key; deriving a first key based on the root key, the IP address of the IAB-DU, and the first IP address; and establishing a user plane secure transmission channel between the IAB-DU and the donor-CU-UP based on the first key.
[0037] For example, IAB-DU derives the first key by using the root key as an input key and by using the IP address of IAB-DU and the first IP address as input parameters.
[0038] For example, in the procedure for establishing a user plane secure transmission channel by the donor-CU-UP and IAB-DU, the first key is an authentication credential used by the donor-CU-UP and IAB-DU.
[0039] For example, the first key is K IAB And, the root key is K gNB am.
[0040] Based on the technical solution described above, when receiving the first IP address of the donor-CU-UP, the IAB-DU obtains a root key for generating the first key from the IAB-MT, and can determine the first key based on the first IP address of the donor-CU-UP, the root key, and the IP address of the IAB-DU to help the IAB-DU establish a user plane secure transmission channel between the IAB-DU and the donor-CU-UP based on the first key, and to help avoid the problem of authentication errors generated when the donor-CU-UP and the IAB-DU establish the user plane secure transmission channel.
[0041] Referring to the third aspect, in some embodiment of the third aspect, before transmitting the second request message to the IAB-MT, the method further comprises the step of receiving a user plane data request message from a terminal device, wherein the user plane secure transmission channel is for transmitting user plane data of the terminal device.
[0042] Based on the above-described technical solution, IAB-DU can request the root key of the donor node from IAB-MT as required, based on user flat data request messages.
[0043] Referring to the third aspect, in some implementation of the third aspect, before transmitting the second request message to the IAB-MT, the method further includes the step of receiving an authentication request message from the donor-CU-UP, wherein the authentication request message is for establishing a user plane secure transmission channel.
[0044] Based on the above-described technical solution, IAB-DU can request the root key of the donor node from IAB-MT as required, based on the authentication request message.
[0045] Referring to the third aspect, in some embodiment of the third aspect, the method further includes the step of storing a correspondence between a first key and a first IP address of a donor-CU-UP.
[0046] For example, the IAB-DU stores the correspondence between the first key and the first IP address of the donor-CU-UP within the context of the IAB-DU.
[0047] According to a fourth aspect, a key determination method is provided, wherein the method is applied to a donor-CU-CP, and the method comprises the step of deriving a first key based on a root key, an IP address of an IAB-DU, and a first IP address of a donor-CU-UP—wherein the first key is different from the root key, and the root key is a key obtained by the donor-CU-CP from the network in a procedure in which an integrated access and backhaul node registers with the network—; and the step of transmitting a first message to the donor-CU-UP—wherein the first message contains the first key.
[0048] For example, IAB-DU derives the first key by using the root key as an input key, and by using the IP address of IAB-DU and the first IP address as input parameters.
[0049] The first key is K IAB And, the root key is K gNB am.
[0050] Based on the technical solution described above, Donor-CU-CP derives a first key based on a root key, the IP address of IAB-DU, and the first IP address of Donor-CU-UP, and transmits the first key to Donor-CU-UP via a first message to help Donor-CU-UP establish a user plane secure transmission channel between Donor-CU-UP and IAB-DU based on the first key, and to help avoid the problem of authentication errors generated when Donor-CU-UP and IAB-DU establish the user plane secure transmission channel.
[0051] For example, the first message is a bearer context setup request message. For example, in a procedure where a terminal device accesses a network through IAB-DU, the donor-CU-CP sends a bearer context setup request message to the donor-CU-UP, where the bearer context setup request message includes a first key.
[0052] As another example, the first message is a bearer context modification request message. For example, in a procedure where a terminal device accesses a network via IAB-DU, Donor-CU-CP sends a bearer context modification request message to Donor-CU-UP, where the bearer context modification request message includes a first key.
[0053] Optionally, the first message further includes the first IP address of the donor-CU-UP.
[0054] Optionally, the first message further includes the IP address of the IAB-DU.
[0055] Referring to the fourth aspect, in some embodiments of the fourth aspect, the method further comprises the steps of: transmitting first instruction information to a donor-CU-UP; and receiving one or more IP addresses from the donor-CU-UP, wherein the one or more IP addresses include the first IP address.
[0056] For example, the first instruction information indicates that IAB-DU belongs to the IAB node.
[0057] Referring to the fourth aspect, in some embodiment of the fourth aspect, when one or more IP addresses further include a second IP address, the method further includes the step of deriving a second key based on a root key, an IP address of IAB-DU, and a second IP address, wherein the first message includes a correspondence between the first key and the first IP address, and a correspondence between the second key and the second IP address.
[0058] Based on the technical solution described above, when the donor-CU-UP has multiple IP addresses, the donor-CU-UP can transmit the multiple IP addresses to the donor-CU-CP based on the first instruction information. Accordingly, in order to help the donor-CU-UP establish different user plane secure transmission channels between the donor-CU-UP and the IAB-DU based on multiple keys and multiple IP addresses, the donor-CU-UP can receive keys corresponding to the multiple IP addresses.
[0059] For example, the first message is a bearer context setup request message. For example, in a procedure where IAB-MT accesses the network through Donor-DU, Donor-CU-CP sends a bearer context setup request message to Donor-CU-UP, where the bearer context setup request message includes a one-to-one correspondence between multiple IP addresses and multiple keys of Donor-CU-UP. It should be understood that Donor-DU, Donor-CU-UP, and Donor-CU-CP belong to the same donor node, and IAB-DU and IAB-MT belong to the same IAB node.
[0060] Referring to the fourth aspect, in some embodiment of the fourth aspect, the method further comprises the steps of: deriving a third key based on a root key, the IP address of IAB-DU, and the IP address of Donor-CU-CP; and establishing a control plane secure transmission channel between Donor-CU-CP and IAB-DU based on the third key.
[0061] For example, Donor-CU-CP derives a third key by using the root key as an input key and by using the IP address of IAB-DU and the IP address of Donor-CU-CP as input parameters.
[0062] Based on the above technical solution, in order to efficiently avoid the problem of authentication errors generated when the donor-CU-CP and IAB-DU establish a control plane secure transmission channel, the donor-CU-CP can also derive a third key for establishing a control plane secure transmission channel between the donor-CU-CP and IAB-DU.
[0063] Referring to the fourth aspect, in some implementation of the fourth aspect, the method further includes the step of determining that IAB-DU belongs to an IAB node based on a first identifier within the context of IAB-DU.
[0064] Based on the above-described technical solution, Donor-CU-CP can derive a first key upon request based on a first identifier.
[0065] Referring to the fourth aspect, in some embodiment of the fourth aspect, the method further comprises the step of transmitting first instruction information to a donor-CU-UP, wherein the first instruction information indicates that the IAB-DU belongs to an IAB node.
[0066] Based on the above-described technical solution, Donor-CU-CP transmits first instruction information to Donor-CU-UP, thereby enabling Donor-CU-UP to receive and store a first key upon request based on the first instruction information.
[0067] According to the fifth aspect, a method for establishing a secure transmission channel is provided, wherein the method comprises: a donor-CU-UP receives first information from a donor-CU-CP. The donor-CU-UP determines a first key based on the first information, wherein the first key is different from a root key, and the root key is a key obtained by the donor-CU-CP from the network in a procedure in which an IAB node registers with the network. The donor-CU-UP sets up a user plane secure transmission channel between the donor-CU-UP and the IAB node based on the first key.
[0068] For example, in the procedure for establishing a user plane secure transmission channel by the donor-CU-UP and IAB-DU, the first key is an authentication credential used by the donor-CU-UP and IAB-DU.
[0069] For example, the first key is K IAB And, the root key is K gNB am.
[0070] Based on the above-described technical solution, in order to help Donor-CU-UP and IAB-DU establish a user plane secure transmission channel based on a first key, and to help Donor-CU-UP and IAB-DU avoid the problem of authentication errors generated when establishing the user plane secure transmission channel, Donor-CU-UP determines a first key based on received first information.
[0071] For example, the first information is carried in a bearer context modification request message. For example, in a procedure where IAB-MT accesses the network through Donor-DU, Donor-CU-CP sends a bearer context modification request message to Donor-CU-UP, where the bearer context modification request message contains the first information. It should be understood that Donor-DU, Donor-CU-UP, and Donor-CU-CP belong to the same donor node, and that IAB-DU and IAB-MT belong to the same IAB node.
[0072] Referring to the fifth aspect, in some embodiment of the fifth aspect, the first information comprises: at least one of an intermediate key or a user plane key used between a donor node and an IAB node, wherein the intermediate key and the user plane key are for determining the first key.
[0073] The donor node includes donor-CU-CP and donor-CU-UP, and the IAB node includes IAB-DU.
[0074] Referring to the fifth aspect, in some embodiments of the fifth aspect, the first information comprises an intermediate key, the intermediate key comprises any one of the following: a random number, or a key determined based on a root key and a second parameter, wherein the second parameter comprises one or more of the following: a physical cell identifier, an absolute radio frequency channel number—downlink, an auxiliary node count, a constant, or a freshness parameter. That the donor-CU-UP determines the first key based on the first information comprises: the donor-CU-UP derives the first key based on the intermediate key, the IP address of the IAB-DU, and the IP address of the donor-CU-UP.
[0075] For example, the donor-CU-UP derives the first key by using an intermediate key as an input key and by using the IP address of the IAB-DU and the IP address of the donor-CU-UP as input parameters.
[0076] Based on the technical solution described above, the donor-CU-UP derives a first key based on an intermediate key, thereby allowing the user plane key, the signaling plane key, and the input key for deriving the first key to be maintained independently of each other, and ensuring data transmission security.
[0077] Referring to the fifth aspect, in some embodiment of the fifth aspect, the first information includes a user plane key. That the donor-CU-UP determines the first key based on the first information includes the following: the donor-CU-UP derives the first key based on the user plane key, the IP address of the IAB-DU, and the IP address of the donor-CU-UP.
[0078] For example, the donor-CU-UP derives the first key by using the user plane key as an input key and by using the IP address of the IAB-DU and the IP address of the donor-CU-UP as input parameters.
[0079] Based on the above-described technical solution, the donor-CU-UP derives a first key based on a user flat key, requires no additional signaling transmission, and simplifies the management and implementation of the first key.
[0080] Referring to the fifth aspect, in some embodiment of the fifth aspect, the first information includes a user plane key. That the donor-CU-UP determines the first key based on the first information includes the following: the donor-CU-UP determines a fourth key based on the user plane key. The donor-CU-UP derives the first key based on the fourth key, the IP address of the IAB-DU, and the IP address of the donor-CU-UP.
[0081] For example, the donor-CU-UP derives the first key by using the fourth key as an input key and by using the IP address of the IAB-DU and the IP address of the donor-CU-UP as input parameters.
[0082] Referring to the fifth aspect, in some embodiment of the fifth aspect, the method further includes the step of storing a correspondence between the first key and the IP address of the IAB-DU.
[0083] For example, the donor-CU-UP stores the correspondence between the first key and the IP address of the IAB-DU within the context of the donor-CU-UP.
[0084] Referring to the fifth aspect, in some embodiment of the fifth aspect, the method further comprises: Donor-CU-UP receives first instruction information, and upon receiving the first instruction information, determines a first key based on the first information.
[0085] For example, the first instruction information indicates that IAB-DU belongs to the IAB node.
[0086] Based on the above-described technical solution, the donor-CU-UP can determine that IAB-DU belongs to the IAB node based on the first instruction information, thereby allowing the first key to be derived based on the first information as required.
[0087] According to the sixth aspect, a method for establishing a secure transmission channel is provided, wherein the method comprises: IAB-DU receives a second message from a donor-CU-CP, wherein the second message contains the IP address of a donor-CU-UP. IAB-DU transmits a third request message to an IAB-MT, wherein the third request message requests second information. IAB-DU receives a third response message from an IAB-MT, wherein the third response message contains second information. IAB-DU determines a first key based on the second information, wherein the first key is different from a root key, and the root key is a key generated by the IAB-MT in a network registration procedure. IAB-DU establishes a user plane secure transmission channel between IAB-DU and a donor-CU-UP based on the first key.
[0088] For example, in the procedure for establishing a user plane secure transmission channel by the donor-CU-UP and IAB-DU, the first key is an authentication credential used by the donor-CU-UP and IAB-DU.
[0089] For example, the first key is K IAB And, the root key is K gNB am.
[0090] Based on the technical solution described above, when the IP address of the donor-CU-UP is received, the IAB-DU obtains second information from the IAB-MT, and in order to help the donor-CU-UP establish a user plane secure transmission channel between the donor-CU-UP and the IAB-DU based on the first key, and to help avoid the problem of authentication errors generated when the donor-CU-UP and the IAB-DU establish the user plane secure transmission channel, the IAB-DU determines the first key based on the received second information.
[0091] Referring to the sixth aspect, in some embodiments of the sixth aspect, the second information comprises at least one of: an intermediate key, a root key, and a second parameter, or a user plane key used between a donor node and an IAB node, wherein the intermediate key and the user plane key are for determining the first key, the second parameter is for determining the intermediate key, and the second parameter comprises one or more of: a physical cell identifier, an absolute radio frequency channel number-downlink, a helper node count, a constant, or a freshness parameter.
[0092] The donor node includes donor-CU-CP and donor-CU-UP, and the IAB node includes IAB-DU.
[0093] Referring to the sixth aspect, in some embodiments of the sixth aspect, the second information includes an intermediate key, and the intermediate key includes any one of the following: a random number, or a key determined based on a root key and a second parameter. That IAB-DU determines the first key based on the second information includes the following: IAB-DU derives the first key based on the intermediate key, the IP address of IAB-DU, and the IP address of the donor-CU-UP.
[0094] For example, IAB-DU derives the first key by using an intermediate key as an input key and by using the IP address of IAB-DU and the IP address of Donor-CU-UP as input parameters.
[0095] Based on the technical solution described above, the IAB-DU derives a first key based on an intermediate key, thereby allowing the user plane key, the signaling plane key, and the input key for deriving the first key to be maintained independently of each other, and ensuring data transmission security.
[0096] Referring to the sixth aspect, in some implementation of the sixth aspect, the second information includes a user plane key. That IAB-DU determines the first key based on the second information includes the following: IAB-DU derives the first key based on the user plane key, the IP address of IAB-DU, and the IP address of the donor-CU-UP.
[0097] For example, IAB-DU derives a first key by using a user plane key as an input key and by using the IP address of IAB-DU and the IP address of Donor-CU-UP as input parameters.
[0098] Based on the above-described technical solution, the IAB-DU derives a first key based on a user flat key, requires no additional signaling transmission, and simplifies the management and implementation of the first key.
[0099] Referring to the sixth aspect, in some implementation of the sixth aspect, the second information includes a user plane key. IAB-DU determining the first key based on the second information includes the following: IAB-DU determines the fourth key based on the user plane key. IAB-DU derives the first key based on the fourth key, the IP address of IAB-DU, and the IP address of the donor-CU-UP.
[0100] For example, IAB-DU derives the first key by using the fourth key as an input key and by using the IP address of IAB-DU and the IP address of Donor-CU-UP as input parameters.
[0101] Referring to the sixth aspect, in some embodiment of the sixth aspect, before the IAB-DU transmits the third request message to the IAB-MT, the method further comprises: the IAB-DU receives a user plane data request message from a terminal device, wherein the user plane secure transmission channel is for transmitting user plane data of the terminal device.
[0102] Based on the above-described technical solution, IAB-DU can request second information from IAB-MT as required based on a user flat data request message.
[0103] Referring to the sixth aspect, in some implementation of the sixth aspect, before the IAB-DU transmits the third request message to the IAB-MT, the method further comprises: the IAB-DU receives an authentication request message from the donor-CU-UP, wherein the authentication request message is for establishing a user plane secure transmission channel.
[0104] Based on the above-described technical solution, IAB-DU can request second information from IAB-MT as required based on the authentication request message.
[0105] Referring to the sixth aspect, in some implementation of the sixth aspect, the method further comprises: IAB-DU stores the correspondence between the first key and the IP address of the donor-CU-UP.
[0106] For example, the IAB-DU stores the correspondence between the first key and the IP address of the donor-CU-UP within the context of the IAB-DU.
[0107] According to the seventh aspect, a method for determining a key is provided, wherein the method comprises: an IAB-MT receives a third request message from an IAB-DU, wherein the third request message requests second information, the second information is for determining a first key, the first key is different from a root key, and the root key is a key generated in the procedure for the IAB-MT to register with a network. The IAB-MT transmits a third response message to the IAB-DU, wherein the third response message includes the second information.
[0108] For example, the first key is K IAB And, the root key is K gNB am.
[0109] Based on the above-described technical solution, IAB-MT transmits second information to IAB-DU based on a third request message, thereby helping IAB-DU establish a user plane secure transmission channel between IAB-DU and Donor-CU-UP based on the first key, so that IAB-DU can determine the first key based on the second information.
[0110] Referring to the seventh aspect, in some embodiments of the seventh aspect, the second information comprises at least one of: an intermediate key, a root key, and a second parameter, or a user plane key used between a donor node and an IAB node, wherein the intermediate key and the user plane key are for determining the first key, the second parameter is for determining the intermediate key, and the second parameter comprises one or more of: a physical cell identifier, an absolute radio frequency channel number-downlink, a helper node count, a constant, or a freshness parameter.
[0111] The donor node includes donor-CU-CP and donor-CU-UP, and the IAB node includes IAB-DU.
[0112] Referring to the seventh aspect, in some implementation of the seventh aspect, the intermediate key comprises: any one of a random number, or a key determined based on a root key and a second parameter. The method further comprises: IAB-MT receives a fourth message from donor-CU-CP, wherein the fourth message comprises an intermediate key or a second parameter.
[0113] For example, when the second parameter for deriving the intermediate key includes a parameter unknown to IAB-MT, the donor-CU-CP transmits a fourth message to IAB-MT. Optionally, the fourth message includes a parameter within the second parameter for deriving the intermediate key that is unknown to IAB-MT.
[0114] As another example, if the intermediate key is a random number, the donor-CU-CP sends a fourth message to the IAB-MT, where the fourth message contains the intermediate key.
[0115] For example, the fourth message is a radio resource control (RRC) reconfiguration message transmitted by the donor-CU-CP to the IAB-MT during the procedure in which the IAB-MT accesses the network through the donor-DU. It should be understood that the donor-DU and the donor-CU-CP belong to the same donor node.
[0116] According to the eighth aspect, a method for determining a key is provided, wherein the method comprises: an IAB-MT receives a first request message from an IAB-DU, wherein the first request message requests a first key, the first key is different from a root key, the root key is a key generated by the IAB-MT in a procedure for registering to a network, and the first request message includes the IP address of a donor-CU-UP. The IAB-MT derives the first key based on an intermediate key, the IP address of the IAB-DU, and the IP address of the donor-CU-UP. The IAB-MT transmits a first response message to the IAB-DU, wherein the first response message includes the first key.
[0117] For example, IAB-MT derives the first key by using an intermediate key as an input key and by using the IP address of IAB-DU and the IP address of Donor-CU-UP as input parameters.
[0118] For example, the first key is K IAB And, the root key is K gNB am.
[0119] Based on the above-described technical solution, IAB-MT derives a first key based on the IP address included in the first request message for the donor-CU-UP, and transmits the first key to IAB-DU, thereby enabling IAB-DU to establish a user plane secure transmission channel between IAB-DU and the donor-CU-UP based on the first key.
[0120] Additionally, IAB-MT derives a first key based on an intermediate key, so that the user plane key, the signaling plane key, and the input key for deriving the first key can be maintained independently of each other, and data transmission security is guaranteed.
[0121] Referring to the eighth aspect, in some embodiments of the eighth aspect, the intermediate key comprises any one of the following: a random number, or a key determined based on a root key and a second parameter, wherein the second parameter comprises one or more of the following: a physical cell identifier, an absolute radio frequency channel number—downlink, an auxiliary node count, a constant, or a freshness parameter.
[0122] The donor node includes donor-CU-CP and donor-CU-UP.
[0123] Referring to the eighth aspect, in some implementation of the eighth aspect, the intermediate key includes a key determined based on a root key and a second parameter. The method further includes: IAB-MT receives a fourth message from donor-CU-CP, wherein the fourth message includes an intermediate key or a second parameter.
[0124] For example, when the second parameter for deriving the intermediate key includes a parameter unknown to IAB-MT, Donor-CU-CP transmits a fourth message to IAB-MT. Optionally, the fourth message includes the intermediate key, or a parameter within the second parameter for deriving the intermediate key that is unknown to IAB-MT.
[0125] For example, the fourth message is an RRC reconfiguration message sent to IAB-MT by Donor-CU-CP during the procedure where IAB-MT accesses the network through Donor-DU. It should be understood that Donor-DU and Donor-CU-CP belong to the same donor node.
[0126] Referring to aspect 8, in some implementation of aspect 8, the intermediate key includes a random number. The method further includes: IAB-MT receives a fourth message from donor-CU-CP, wherein the fourth message includes an intermediate key.
[0127] According to the ninth aspect, a method for determining a key is provided, wherein the method comprises: an IAB-MT receives a first request message from an IAB-DU, wherein the first request message requests a first key, the first key is different from a root key, the root key is a key generated by the IAB-MT in a procedure for registering to a network, and the first request message includes the IP address of a donor-CU-UP. The IAB-MT derives the first key based on a user plane key, the IP address of the IAB-DU, and the IP address of the donor-CU-UP, wherein the user plane key is a user plane key used between a donor node and an IAB node. The IAB-MT transmits a first response message to the IAB-DU, wherein the first response message includes the first key.
[0128] For example, IAB-MT derives a first key by using a user plane key as an input key and by using the IP address of IAB-DU and the IP address of Donor-CU-UP as input parameters.
[0129] For example, the first key is K IAB And, the root key is K gNB am.
[0130] Based on the above-described technical solution, IAB-MT derives a first key based on the IP address included in the first request message for the donor-CU-UP, and transmits the first key to IAB-DU, thereby enabling IAB-DU to establish a user plane secure transmission channel between IAB-DU and the donor-CU-UP based on the first key.
[0131] Additionally, IAB-MT derives a first key based on a user flat key, requires no additional signaling transmission, and simplifies the management and implementation of the first key.
[0132] According to the tenth aspect, a method for determining a key is provided, wherein the method comprises: an IAB-MT receives a first request message from an IAB-DU, wherein the first request message requests a first key, the first key is different from a root key, the root key is a key generated by the IAB-MT in a procedure for registering to a network, and the first request message includes the IP address of a donor-CU-UP. The IAB-MT determines a fourth key based on a user plane key, wherein the user plane key is a user plane key used between a donor node and an IAB node. The IAB-MT derives the first key based on the fourth key, the IP address of the IAB-DU, and the IP address of the donor-CU-UP. The IAB-MT transmits a first response message to the IAB-DU, wherein the first response message includes the first key.
[0133] For example, IAB-MT derives the first key by using the fourth key as an input key and by using the IP address of IAB-DU and the IP address of Donor-CU-UP as input parameters.
[0134] For example, the first key is K IAB And, the root key is K gNB am.
[0135] Based on the above-described technical solution, IAB-MT derives a first key based on the IP address included in the first request message for the donor-CU-UP, and transmits the first key to IAB-DU, thereby enabling IAB-DU to establish a user plane secure transmission channel between IAB-DU and the donor-CU-UP based on the first key.
[0136] Additionally, IAB-MT derives a first key based on a fourth key derived from a user flat key, and no additional signaling transmission is required, and the management and implementation of the first key are simplified.
[0137] According to the eleventh aspect, a key determination method is provided, wherein the method comprises: a donor-CU-CP determines first information, wherein the first information is for determining a first key, the first key is different from a root key, and the root key is a key obtained by the donor-CU-CP from the network during the procedure in which an IAB node registers with the network. The donor-CU-CP transmits the first information to the donor-CU-UP.
[0138] For example, the first key is K IAB And, the root key is K gNB am.
[0139] Based on the technical solution described above, Donor-CU-CP transmits first information to Donor-CU-UP to help Donor-CU-UP establish a user plane secure transmission channel between Donor-CU-UP and IAB-DU based on the first key, and to help avoid the problem of authentication errors generated when Donor-CU-UP and IAB-DU establish the user plane secure transmission channel, Donor-CU-UP determines the first key based on the received first information.
[0140] For example, the first information is carried in a bearer context modification request message. For example, in a procedure where IAB-MT accesses the network through Donor-DU, Donor-CU-CP sends a bearer context modification request message to Donor-CU-UP, where the bearer context modification request message contains the first information. It should be understood that Donor-DU, Donor-CU-UP, and Donor-CU-CP belong to the same donor node, and that IAB-DU and IAB-MT belong to the same IAB node.
[0141] Referring to aspect 11, in some implementation of aspect 11, the first information comprises: at least one of an intermediate key or a user plane key used between a donor node and an IAB node, wherein the intermediate key and the user plane key are for determining the first key.
[0142] Referring to aspect 11, in some embodiments of aspect 11, the first information comprises an intermediate key, and the intermediate key comprises a key determined based on a root key and a second parameter. The fact that the donor-CU-CP determines the first information includes: the donor-CU-CP derives an intermediate key based on a root key and a second parameter, wherein the second parameter comprises one or more of the following: a physical cell identifier, an absolute radio frequency channel number—downlink, an auxiliary node count, a constant, or a freshness parameter.
[0143] For example, the donor-CU-CP derives an intermediate key by using the root key as an input key and the second parameter as an input parameter.
[0144] Referring to aspect 11, in some implementation of aspect 11, the method further comprises: Donor-CU-CP transmits a fourth message to IAB-MT, wherein the fourth message includes an intermediate key or a second parameter.
[0145] For example, when the second parameter for deriving the intermediate key includes a parameter unknown to IAB-MT, the donor-CU-CP transmits a fourth message to IAB-MT. Optionally, the fourth message includes a parameter within the second parameter for deriving the intermediate key that is unknown to IAB-MT.
[0146] For example, the fourth message is an RRC reconfiguration message sent to IAB-MT by Donor-CU-CP during the procedure where IAB-MT accesses the network through Donor-DU. It should be understood that Donor-DU and Donor-CU-CP belong to the same donor node.
[0147] Referring to aspect 11, in some implementation of aspect 11, the first information includes an intermediate key, and the intermediate key includes a random number. That the donor-CU-CP determines the first information includes the following: the donor-CU-CP generates a random number.
[0148] Referring to aspect 11, in some implementation of aspect 11, the method further comprises: Donor-CU-CP transmits a fourth message to IAB-MT, wherein the fourth message includes an intermediate key.
[0149] Referring to aspect 11, in some implementation of aspect 11, the first information includes a user plane key. That the donor-CU-CP determines the first information includes: the donor-CU-CP derives the user plane key based on the root key.
[0150] Referring to aspect 11, in some implementation of aspect 11, the method further comprises: donor-CU-CP receives second instruction information, wherein the second instruction information indicates that IAB-DU belongs to an IAB node.
[0151] Based on the above-described technical solution, the donor-CU-CP can determine the first information according to the requirement based on the second instruction information.
[0152] For example, Donor-CU-CP receives second instruction information from IAB-MT, where the second instruction information is an "IAB-instruction" information element. In the procedure where IAB-MT accesses the network through Donor-DU, IAB-MT transmits the "IAB-instruction" information element to Donor-CU-UP through Donor-DU.
[0153] As another example, the donor-CU-CP receives second instruction information from a core network element, where the second instruction information is an "IAB-authorized" information element. In the procedure for the IAB-MT to access the network through the donor-DU, after authentication between the IAB-MT and the core network is completed, the initial context setup request message sent by the AMF to the donor-CU-CP includes an "IAB-authorized" information element.
[0154] Referring to aspect 11, in some embodiment of aspect 11, the method further comprises: Donor-CU-CP transmits first instruction information to Donor-CU-UP.
[0155] For example, the first instruction information indicates that IAB-DU belongs to the IAB node.
[0156] Based on the above-described technical solution, Donor-CU-CP transmits first instruction information to Donor-CU-UP, thereby enabling Donor-CU-UP to determine a first key based on the first information upon request.
[0157] According to the 12th aspect, a communication device is provided, wherein the communication device includes a transceiver unit and a processing unit. The transceiver unit receives a first message from a donor-CU-CP, wherein the first message includes a first key, the first key is different from a root key, and the root key is a key obtained by the donor-CU-CP from the network in the procedure for an IAB node to register with the network. The processing unit is configured to establish a user plane secure transmission channel between the donor-CU-UP and the IAB-DU based on the first key.
[0158] For example, in the procedure for establishing a user plane secure transmission channel by a communication device and an IAB-DU, the first key is an authentication credential used by the communication device and the IAB-DU.
[0159] For example, the first key is K IAB And, the root key is K gNB am.
[0160] For example, the first message is a bearer context setup request message. For example, in a procedure where a terminal device accesses a network through an IAB-DU, the donor-CU-CP transmits a bearer context setup request message to a communication device, wherein the bearer context setup request message includes a first key.
[0161] As another example, the first message is a bearer context modification request message. For example, in a procedure where a terminal device accesses a network via an IAB-DU, the donor-CU-CP transmits a bearer context modification request message to a communication device, wherein the bearer context modification request message includes a first key.
[0162] Referring to aspect 12, in some embodiment of aspect 12, the first message further includes a first IP address of the donor-CU-UP. The processing unit is also configured to determine to establish a user plane secure transmission channel by using the first IP address of the donor-CU-UP. The processing unit is also configured to determine a first key based on the first IP address.
[0163] Optionally, the first message further includes the IP address of the IAB-DU.
[0164] Referring to aspect 12, in some embodiment of aspect 12, the first message includes a one-to-one correspondence between a plurality of IP addresses of the donor-CU-UP and a plurality of keys, the plurality of keys include a first key, and the first key corresponds to the first IP address. The processing unit is also configured to determine to establish a user plane secure transmission channel by using the first IP address of the donor-CU-UP. The processing unit is also configured to determine the first key based on the first IP address.
[0165] For example, the first message is a bearer context setup request message. For example, in a procedure where the IAB-MT accesses the network through the donor-DU, the donor-CU-CP transmits a bearer context setup request message to a communication device, wherein the bearer context setup request message includes a plurality of keys and a plurality of IP addresses.
[0166] Optionally, the first message further includes the IP address of IAB-DU, and multiple keys all correspond to the IP address of IAB-DU. In other words, each of the multiple keys corresponds to one IP address of Donor-CU-UP and the IP address of IAB-DU.
[0167] Referring to aspect 12, in some embodiment of aspect 12, the transceiver unit is also configured to receive first instruction information from donor-CU-CP. The transceiver unit is also configured to transmit a plurality of IP addresses of donor-CU-UP to donor-CU-CP based on the first instruction information.
[0168] For example, the first instruction information indicates that IAB-DU belongs to the IAB node.
[0169] Referring to the 12th aspect, in some implementation of the 12th aspect, the processing unit is also configured to store a correspondence between the first key and the IP address of the IAB-DU.
[0170] Referring to the 12th aspect, in some implementation of the 12th aspect, the first message further includes first instruction information.
[0171] For example, the first instruction information indicates that IAB-DU belongs to the IAB node.
[0172] According to the 13th aspect, a communication device is provided, wherein the communication device comprises a transceiver unit and a processing unit. The transceiver unit is configured to receive a second message from a donor-CU-CP—the second message includes a first IP address of a donor-CU-UP—and to transmit a first request message to an IAB-MT—the first request message requests a first key, the first key is different from a root key, the root key is a key generated by the IAB-MT in a procedure for registering to a network, and the first request message includes a first IP address. The transceiver unit is also configured to receive a first response message from the IAB-MT, wherein the first response message includes a first key. The processing unit is configured to establish a user plane secure transmission channel between the IAB-DU and the donor-CU-UP based on the first key.
[0173] For example, in a procedure to establish a user plane secure transmission channel by a donor-CU-UP and a communication device, the first key is an authentication credential used by the donor-CU-UP and the communication device.
[0174] For example, the first key is K IAB And, the root key is K gNB am.
[0175] Referring to aspect 13, in some embodiment of aspect 13, before transmitting a first request message to the IAB-MT, the transceiver unit is also configured to receive a user plane data request message from a terminal device, wherein the user plane secure transmission channel is for transmitting user plane data of the terminal device.
[0176] Referring to aspect 13, in some implementation of aspect 13, before transmitting the first request message to the IAB-MT, the transceiver unit is also configured to receive an authentication request message from the donor-CU-UP, wherein the authentication request message is for establishing a user plane secure transmission channel.
[0177] Referring to aspect 13, in some implementation of aspect 13, the processing unit is also configured to store a correspondence between a first key and a first IP address of a donor-CU-UP.
[0178] According to the 14th aspect, a communication device is provided, wherein the communication device comprises a transceiver unit and a processing unit. The transceiver unit is configured to receive a second message from Donor-CU-CP, wherein the second message comprises a first IP address of Donor-CU-UP. The transceiver unit is also configured to transmit a second request message to IAB-MT, wherein the second request message requests a root key, the root key is for generating a first key, the first key is different from the root key, and the root key is a key generated by IAB-MT in a procedure for registering to a network. The transceiver unit is also configured to receive a second response message from IAB-MT, wherein the second response message comprises a root key. The processing unit is configured to derive the first key based on the root key, the IP address of IAB-DU, and the first IP address. The processing unit is also configured to establish a user plane secure transmission channel between IAB-DU and Donor-CU-UP based on the first key.
[0179] For example, in a procedure to establish a user plane secure transmission channel by a donor-CU-UP and a communication device, the first key is an authentication credential used by the donor-CU-UP and the communication device.
[0180] For example, the first key is K IAB And, the root key is K gNB am.
[0181] Referring to aspect 14, in some embodiment of aspect 14, before transmitting a second request message to the IAB-MT, the transceiver unit is also configured to receive a user plane data request message from a terminal device, wherein the user plane secure transmission channel is for transmitting user plane data of the terminal device.
[0182] Referring to aspect 14, in some implementation of aspect 14, before transmitting the second request message to the IAB-MT, the transceiver unit is also configured to receive an authentication request message from the donor-CU-UP, wherein the authentication request message is for establishing a user plane secure transmission channel.
[0183] Referring to aspect 14, in some implementation of aspect 14, the processing unit is also configured to store a correspondence between a first key and a first IP address of a donor-CU-UP.
[0184] According to the 15th aspect, a communication device is provided, wherein the communication device comprises a transceiver unit and a processing unit. The processing unit is configured to derive a first key based on a root key, an IP address of IAB-DU, and a first IP address of a donor-CU-UP, wherein the first key is different from the root key, and the root key is a key obtained from the network by the donor-CU-CP in a procedure in which an integrated access and backhaul node registers with the network. The transceiver unit is configured to transmit a first message to the donor-CU-UP, wherein the first message includes the first key.
[0185] For example, in the procedure for establishing a user plane secure transmission channel by the donor-CU-UP and IAB-DU, the first key is an authentication credential used by the donor-CU-UP and IAB-DU.
[0186] The first key is K IAB And, the root key is K gNB am.
[0187] For example, the first message is a bearer context setup request message. For example, in a procedure where a terminal device accesses a network through an IAB-DU, the transceiver unit transmits the bearer context setup request message to the donor-CU-UP, wherein the bearer context setup request message includes a first key.
[0188] As another example, the first message is a bearer context modification request message. For example, in a procedure where a terminal device accesses a network via an IAB-DU, the transceiver unit transmits a bearer context modification request message to a donor-CU-UP, wherein the bearer context modification request message includes a first key.
[0189] Optionally, the first message further includes the first IP address of the donor-CU-UP.
[0190] Optionally, the first message further includes the IP address of the IAB-DU.
[0191] Referring to aspect 15, in some embodiment of aspect 15, the transceiver unit is also configured to transmit first instruction information to the donor-CU-UP. The transceiver unit is also configured to receive one or more IP addresses from the donor-CU-UP, wherein one or more IP addresses include the first IP address.
[0192] For example, the first instruction information indicates that IAB-DU belongs to the IAB node.
[0193] Referring to aspect 15, in some embodiment of aspect 15, when one or more IP addresses further include a second IP address, the processing unit is also configured to derive a second key based on a root key, an IP address of IAB-DU, and a second IP address, wherein the first message includes a correspondence between the first key and the first IP address, and a correspondence between the second key and the second IP address.
[0194] For example, the first message is a bearer context setup request message. For example, in a procedure where IAB-MT accesses the network through Donor-DU, Donor-CU-CP sends a bearer context setup request message to Donor-CU-UP, where the bearer context setup request message includes a one-to-one correspondence between multiple keys and multiple IP addresses of Donor-CU-UP. It should be understood that Donor-DU, Donor-CU-UP, and Donor-CU-CP belong to the same donor node, and IAB-DU and IAB-MT belong to the same IAB node.
[0195] Referring to aspect 15, in some embodiment of aspect 15, the processing unit is also configured to derive a third key based on the root key, the IP address of the IAB-DU, and the IP address of the communication device. The processing unit is also configured to establish a control plane secure transmission channel between the donor-CU-CP and the IAB-DU based on the third key.
[0196] Referring to aspect 15, in some implementation of aspect 15, the processing unit is also configured to determine that IAB-DU belongs to an IAB node based on a first identifier within the context of IAB-DU.
[0197] Referring to aspect 15, in some embodiment of aspect 15, the transceiver unit is also configured to transmit first instruction information to donor-CU-UP, where the first instruction information indicates that IAB-DU belongs to an IAB node.
[0198] According to the 16th aspect, a communication device is provided, wherein the communication device comprises a transceiver unit and a processing unit. The transceiver unit is configured to receive first information from a donor-CU-CP. The processing unit is configured to determine a first key based on the first information, wherein the first key is different from a root key, and the root key is a key obtained from the network by the donor-CU-CP in the procedure for an IAB node to register with the network. The processing unit is also configured to establish a user plane secure transmission channel between the communication device and the IAB node based on the first key.
[0199] For example, in the procedure for establishing a user plane secure transmission channel by a communication device and an IAB-DU, the first key is an authentication credential used by the communication device and the IAB-DU.
[0200] For example, the first key is K IAB And, the root key is K gNB am.
[0201] For example, the first information is carried in a bearer context modification request message. For example, in a procedure where an IAB-MT accesses a network through a donor-DU, a transceiver unit is configured to transmit a bearer context modification request message, wherein the bearer context modification message includes the first information.
[0202] Referring to aspect 16, in some embodiment of aspect 16, the first information comprises: at least one of an intermediate key and a user plane key used between a donor node and an IAB node, wherein the intermediate key and the user plane key are for determining the first key.
[0203] Referring to aspect 16, in some embodiment of aspect 16, the first information comprises an intermediate key, the intermediate key comprises any one of a random number and a root key and a second parameter, wherein the second parameter comprises one or more of a physical cell identifier, an absolute radio frequency channel number-downlink, an auxiliary node count, a constant, or a freshness parameter. Specifically, the processing unit is configured to derive the first key based on the intermediate key, the IP address of the IAB-DU, and the IP address of the communication device.
[0204] Referring to aspect 16, in some embodiment of aspect 16, the first information includes a user plane key. Specifically, the processing unit is configured to derive the first key based on the user plane key, the IP address of the IAB-DU, and the IP address of the communication device.
[0205] Referring to aspect 16, in some embodiment of aspect 16, the first information includes a user plane key. Specifically, the processing unit is configured to determine a fourth key based on the user plane key and to derive a first key based on the fourth key, the IP address of the IAB-DU, and the IP address of the communication device.
[0206] Referring to aspect 16, in some implementation of aspect 16, the processing unit is also configured to store a correspondence between the first key and the IP address of the IAB-DU.
[0207] Referring to aspect 16, in some embodiment of aspect 16, the transceiver unit is also configured to receive first instruction information.
[0208] For example, the first instruction information indicates that IAB-DU belongs to the IAB node.
[0209] According to the 17th aspect, a communication device is provided, wherein the communication device comprises a transceiver unit and a processing unit. The transceiver unit is configured to receive a second message from a donor-CU-CP, wherein the second message includes the IP address of a donor-CU-UP. The transceiver unit is also configured to transmit a third request message to an IAB-MT, wherein the third request message requests second information. The transceiver unit is also configured to receive a third response message from an IAB-MT, wherein the third response message includes second information. The processing unit is configured to determine a first key based on the second information, wherein the first key is different from a root key, and the root key is a key generated by the IAB-MT in a procedure for registering to a network. The processing unit is also configured to establish a user plane secure transmission channel between the communication device and the donor-CU-UP based on the first key.
[0210] For example, in a procedure to establish a user plane secure transmission channel by a donor-CU-UP and a communication device, the first key is an authentication credential used by the donor-CU-UP and the communication device.
[0211] For example, the first key is K IAB And, the root key is K gNB am.
[0212] Referring to aspect 17, in some embodiment of aspect 17, the second information comprises at least one of: an intermediate key, a root key and a second parameter, and a user plane key used between a donor node and an IAB node, wherein the intermediate key and the user plane key are for determining the first key, the second parameter is for determining the intermediate key, and the second parameter comprises one or more of: a physical cell identifier, an absolute radio frequency channel number—downlink, a helper node count, a constant, and a freshness parameter.
[0213] Referring to aspect 17, in some embodiment of aspect 17, the second information includes an intermediate key, and the intermediate key includes any one of the following: a random number, and a root key and a second parameter. Specifically, the processing unit is configured to derive a first key based on the intermediate key, the IP address of the communication device, and the IP address of the donor-CU-UP.
[0214] Referring to aspect 17, in some embodiment of aspect 17, the second information includes a user plane key. Specifically, the processing unit is configured to derive a first key based on the user plane key, the IP address of the communication device, and the IP address of the donor-CU-UP.
[0215] Referring to aspect 17, in some embodiment of aspect 17, the second information includes a user plane key. Specifically, the processing unit is configured to determine a fourth key based on the user plane key and to derive a first key based on the fourth key, the IP address of the communication device, and the IP address of the donor-CU-UP.
[0216] Referring to aspect 17, in some embodiment of aspect 17, before transmitting a third request message to the IAB-MT, the transceiver unit is also configured to receive a user plane data request message from a terminal device, wherein the user plane secure transmission channel is for transmitting user plane data of the terminal device.
[0217] Referring to aspect 17, in some implementation of aspect 17, before transmitting the third request message to the IAB-MT, the transceiver unit is also configured to receive an authentication request message from the donor-CU-UP, wherein the authentication request message is for establishing a user plane secure transmission channel.
[0218] Referring to aspect 17, in some implementation of aspect 17, the processing unit is also configured to store a correspondence between the first key and the IP address of the donor-CU-UP.
[0219] According to the 18th aspect, a communication device is provided, wherein the communication device includes a transceiver unit. The transceiver unit receives a third request message from an IAB-DU, wherein the third request message requests second information, the second information is for determining a first key, the first key is different from a root key, the root key is a key generated in the procedure for the communication device to register with a network. The transceiver unit is also configured to transmit a third response message to the IAB-DU, wherein the third response message includes the second information.
[0220] For example, the first key is K IAB And, the root key is K gNB am.
[0221] Referring to aspect 18, in some embodiment of aspect 18, the second information comprises at least one of: an intermediate key, a root key and a second parameter, and a user plane key used between a donor node and an IAB node, wherein the intermediate key and the user plane key are for determining the first key, the second parameter is for determining the intermediate key, and the second parameter comprises one or more of: a physical cell identifier, an absolute radio frequency channel number-downlink, a helper node count, a constant, and a freshness parameter.
[0222] Referring to aspect 18, in some implementation of aspect 18, the intermediate key comprises: a random number, and any one of a key determined based on the root key of the donor node and a second parameter. The transceiver unit is also configured to receive a fourth message from the donor-CU-CP, wherein the fourth message comprises the intermediate key or the second parameter.
[0223] For example, when the second parameter for deriving an intermediate key includes a parameter unknown to the communication device, the donor-CU-CP transmits a fourth message. Optionally, the fourth message includes a parameter within the second parameter for deriving an intermediate key that is unknown to the communication device.
[0224] In another example, when the intermediate key is a random number, the donor-CU-CP transmits a fourth message, where the fourth message contains the intermediate key.
[0225] For example, the fourth message is an RRC reconfiguration message transmitted by Donor-CU-CP during the procedure in which a communication device accesses the network through Donor-DU. It should be understood that Donor-DU and Donor-CU-CP belong to the same donor node.
[0226] According to the 19th aspect, a communication device is provided, wherein the communication device comprises a transceiver unit and a processing unit. The transceiver unit is configured to receive a first request message from an IAB-DU, wherein the first request message requests a first key, the first key is different from a root key, the root key is a key generated by the communication device in a procedure for registering to a network, and the first request message includes the IP address of a donor-CU-UP. The processing unit is configured to derive the first key based on an intermediate key, the IP address of an IAB-DU, and the IP address of a donor-CU-UP. The transceiver unit is also configured to transmit a first response message to an IAB-DU, wherein the first response message includes the first key.
[0227] For example, the first key is K IAB And, the root key is K gNB am.
[0228] Referring to aspect 19, in some embodiment of aspect 19, the intermediate key comprises: a random number, and any one of a key determined based on a root key and a second parameter, wherein the second parameter comprises: a physical cell identifier, an absolute radio frequency channel number—downlink, an auxiliary node count, a constant, and a freshness parameter.
[0229] Referring to aspect 19, in some embodiment of aspect 19, the intermediate key includes a key determined based on a root key and a second parameter. The transceiver unit is also configured to receive a fourth message from the donor-CU-CP, wherein the fourth message includes the intermediate key or the second parameter.
[0230] For example, when the second parameter for deriving an intermediate key includes a parameter unknown to the communication device, the donor-CU-CP transmits a fourth message. Optionally, the fourth message includes the intermediate key, or a parameter within the second parameter for deriving the intermediate key that is unknown to the communication device.
[0231] For example, the fourth message is an RRC reconfiguration message transmitted by Donor-CU-CP during the procedure in which a communication device accesses the network through Donor-DU. It should be understood that Donor-DU and Donor-CU-CP belong to the same donor node.
[0232] Referring to aspect 19, in some embodiments of aspect 19, the intermediate key includes a random number. The transceiver unit is also configured to receive a fourth message from the donor-CU-CP, wherein the fourth message includes an intermediate key.
[0233] According to the 20th aspect, a communication device is provided, wherein the communication device comprises a transceiver unit and a processing unit. The transceiver unit is configured to receive a first request message from an IAB-DU, wherein the first request message requests a first key, the first key is different from a root key, the root key is a key generated by the communication device in a procedure for registering to a network, and the first request message includes the IP address of a donor-CU-UP. The processing unit is configured to derive a first key based on a user plane key, the IP address of an IAB-DU, and the IP address of a donor-CU-UP, wherein the user plane key is a user plane key used between a donor node and an IAB node. The transceiver unit is also configured to transmit a first response message to an IAB-DU, wherein the first response message includes the first key.
[0234] For example, the first key is K IAB And, the root key is K gNB am.
[0235] According to the 21st aspect, a communication device is provided, wherein the communication device comprises a transceiver unit and a processing unit. The transceiver unit is configured to receive a first request message from an IAB-DU, wherein the first request message requests a first key, the first key is different from a root key, the root key is a key generated by the communication device in a procedure for registering to a network, and the first request message includes the IP address of a donor-CU-UP. The processing unit is configured to determine a fourth key based on a user plane key, wherein the user plane key is a user plane key used between a donor node and an IAB node. The processing unit is also configured to derive a first key based on the fourth key, the IP address of the IAB-DU, and the IP address of the donor-CU-UP. The transceiver unit is also configured to transmit a first response message to the IAB-DU, wherein the first response message includes the first key.
[0236] For example, the first key is K IAB And, the root key is K gNB am.
[0237] According to aspect 22, a communication device is provided, wherein the communication device comprises a transceiver unit and a processing unit. The processing unit is configured to determine first information, wherein the first information is for determining a first key, the first key is different from a root key, and the root key is a key obtained from the network by the donor-CU-CP in the procedure for an IAB node to register with the network. The transceiver unit is configured to transmit the first information to the donor-CU-UP.
[0238] For example, the first key is K IAB And, the root key is K gNB am.
[0239] For example, the first information is carried in a bearer context modification request message. For example, in a procedure where the IAB-MT accesses the network through the donor-DU, the transceiver unit is configured to transmit the bearer context modification request message to the donor-CU-UP, where the bearer context modification message contains the first information.
[0240] Referring to aspect 22, in some embodiment of aspect 22, the first information comprises: at least one of an intermediate key and a user plane key used between a donor node and an IAB node, wherein the intermediate key and the user plane key are for determining the first key.
[0241] Referring to aspect 22, in some embodiment of aspect 22, the first information includes an intermediate key, and the intermediate key includes a key determined based on a root key and a second parameter. Specifically, a processing unit is configured to derive an intermediate key based on a root key and a second parameter used as an input key, wherein the second parameter includes one or more of the following: a physical cell identifier, an absolute radio frequency channel number—downlink, an auxiliary node count, a constant, and a freshness parameter.
[0242] Referring to aspect 22, in some implementation of aspect 22, the transceiver unit is also configured to transmit a fourth message to the IAB-MT, wherein the fourth message includes an intermediate key or a second parameter.
[0243] For example, when the second parameter for deriving the intermediate key includes a parameter unknown to the IAB-MT, the transceiver unit is configured to transmit a fourth message to the IAB-MT. Optionally, the fourth message includes a parameter within the second parameter for deriving the intermediate key that is unknown to the IAB-MT.
[0244] For example, the fourth message is an RRC reconstruction message transmitted to the IAB-MT by the transceiver unit during the procedure in which the IAB-MT accesses the network through the donor-DU.
[0245] Referring to aspect 22, in some embodiment of aspect 22, the first information includes an intermediate key, and the intermediate key includes a random number. Specifically, the processing unit is configured to generate a random number.
[0246] Referring to aspect 22, in some implementation of aspect 22, the transceiver unit is also configured to transmit a fourth message to the IAB-MT, wherein the fourth message includes an intermediate key.
[0247] Referring to aspect 22, in some implementation of aspect 22, the first information includes a user plane key. Specifically, the processing unit is configured to derive the user plane key based on the root key.
[0248] Referring to aspect 22, in some embodiment of aspect 22, the transceiver unit is also configured to receive second instruction information.
[0249] For example, the second instruction information indicates that IAB-DU belongs to the IAB node.
[0250] Referring to aspect 22, in some embodiment of aspect 22, the transceiver unit is also configured to transmit first instruction information to the donor-CU-UP.
[0251] For example, the first instruction information indicates that IAB-DU belongs to the IAB node.
[0252] According to aspect 23, this application provides a communication device comprising a processor. The processor may be coupled to memory and configured to execute instructions within memory to implement a method according to any one of the possible embodiments of the first aspect or a method according to any one of the possible embodiments of the fifth aspect. The communication device further comprises memory. The communication device further comprises a communication interface. The processor is coupled to the communication interface.
[0253] In an exemplary embodiment, the communication device is a donor-CU-UP. When the communication device is a donor-CU-UP, the communication interface may be a transceiver or an input / output interface.
[0254] In another embodiment, the communication device is a chip or a chip system configured in a donor-CU-UP. When the communication device is a chip or a chip system configured in a donor-CU-UP, the communication interface may be an input / output interface.
[0255] A transceiver can be a transceiver circuit. An input / output interface can be an input / output circuit.
[0256] According to the 24th aspect, this application provides a communication device comprising a processor. The processor may be configured to be coupled to memory and to execute instructions within memory to implement a method according to the second aspect or any one of the possible embodiments of the second aspect, or to implement a method according to the third aspect or any one of the possible embodiments of the third aspect, or to implement a method according to the fifth aspect or any one of the possible embodiments of the fifth aspect, or to implement a method according to the sixth aspect or any one of the possible embodiments of the sixth aspect. The communication device further comprises memory. The communication device further comprises a communication interface. The processor is coupled to the communication interface.
[0257] In an exemplary embodiment, the communication device is an IAB-DU. When the communication device is an IAB-DU, the communication interface may be a transceiver or an input / output interface.
[0258] In another embodiment, the communication device is a chip or a chip system configured in an IAB-DU. When the communication device is a chip or a chip system configured in an IAB-DU, the communication interface may be an input / output interface.
[0259] A transceiver can be a transceiver circuit. An input / output interface can be an input / output circuit.
[0260] According to aspect 25, this application provides a communication device comprising a processor. The processor may be coupled to memory and configured to execute instructions within memory to implement a method according to aspect 4 or any one of possible embodiments of aspect 4, or to implement a method according to aspect 11 or any one of possible embodiments of aspect 11. The communication device further comprises memory. The communication device further comprises a communication interface. The processor is coupled to the communication interface.
[0261] In an exemplary embodiment, the communication device is a donor-CU-CP. When the communication device is a donor-CU-CP, the communication interface may be a transceiver or an input / output interface.
[0262] In another embodiment, the communication device is a chip or a chip system configured in the donor-CU-CP. When the communication device is a chip or a chip system configured in the donor-CU-CP, the communication interface may be an input / output interface.
[0263] A transceiver can be a transceiver circuit. An input / output interface can be an input / output circuit.
[0264] According to aspect 26, this application provides a communication device comprising a processor. The processor may be coupled to memory and configured to execute instructions within memory to implement a method according to any one of aspects 7 through 10 or possible embodiments of aspects 7 through 10. The communication device further comprises memory. The communication device further comprises a communication interface. The processor is coupled to the communication interface.
[0265] In an exemplary embodiment, the communication device is an IAB-MT. When the communication device is an IAB-MT, the communication interface may be a transceiver or an input / output interface.
[0266] In another embodiment, the communication device is a chip or a chip system configured in an IAB-MT. When the communication device is a chip or a chip system configured in an IAB-MT, the communication interface may be an input / output interface.
[0267] A transceiver can be a transceiver circuit. An input / output interface can be an input / output circuit.
[0268] According to the 27th aspect, the present application provides a processor comprising an input circuit, an output circuit, and a processing circuit. The processing circuit is configured to receive a signal through the input circuit and transmit a signal through the output circuit, thereby enabling the processor to perform the method of the above aspect.
[0269] In a specific implementation procedure, the processor may be a chip, the input circuit may be an input pin, the output circuit may be an output pin, and the processing circuit may be a transistor, a gate circuit, a trigger, various logic circuits, etc. The input signal received by the input circuit may be received and input by a receiver, for example, but is not limited to a receiver, and the signal output by the output circuit may be output to a transmitter, for example, but is not limited to a transmitter, and may be transmitted by a transmitter, and the input circuit and the output circuit may be the same circuit, wherein the circuit is used as an input circuit and an output circuit at different moments. Specific embodiments of the processor and various circuits are not limited to this embodiment of this application.
[0270] According to the 28th aspect, the present application provides a processing device comprising a communication interface and a processor. The communication interface is coupled to the processor. The communication interface is configured to input and / or output information. The information includes at least one of commands or data. The processor is configured to execute a computer program, thereby the processing device performs the method of the above aspect.
[0271] According to the 29th aspect, the present application provides a processing device comprising a processor and a memory. The processor is configured to read instructions stored in memory, receive a signal by using a receiver, and transmit a signal by using a transmitter, thereby the processing device performs the method of the above aspect.
[0272] Optionally, there is one or more processors. If there is memory, there may also be one or more memories.
[0273] Optionally, memory and processor can be integrated together, or memory and processor can be placed separately.
[0274] In a specific implementation procedure, the memory may be a non-transitory memory, such as read-only memory (ROM). The memory and processor may be integrated into the same chip or placed separately on different chips. The type of memory and the manner in which the memory and processor are placed are not limited to this embodiment of this application.
[0275] It should be understood that in the related information exchange procedure, for example, transmitting instruction information may be a procedure for outputting instruction information from a processor, and receiving instruction information may be a procedure for inputting the received instruction information into a processor. Specifically, the information output by the processor may be output to a transmitter, and the input information received by the processor may be from a receiver. The transmitter and the receiver may be collectively referred to as a transceiver.
[0276] The device in aspect 28 and aspect 29 may each be a chip. The processor may be implemented using hardware or by using software. When the processor is implemented using hardware, the processor may be a logic circuit, an integrated circuit, etc.; when the processor is implemented using software, the processor may be a general-purpose processor and is implemented by reading software code stored in memory. The memory may be integrated into the processor, located outside the processor, or exist independently.
[0277] According to the 30th aspect, this application provides a computer program product. The computer program product includes a computer program (which may also be referred to as code or instructions). When the computer program is operated, the computer becomes capable of performing the method of the above-described aspect.
[0278] According to the 31st aspect, this application provides a computer-readable medium. The computer-readable medium stores a computer program (which may also be referred to as code or instructions). When the computer program is operated on a computer, the computer becomes able to perform the method of the above-described aspect.
[0279] According to the 32nd aspect, this application provides a communication system comprising the above-mentioned donor-CU-UP, donor-CU-CP, IAB-MT, and IAB-DU. Brief explanation of the drawing
[0280] Figure 1 is a schematic diagram of the architecture of separation between the next-generation NodeB central unit control plane entity and the next-generation NodeB central unit user plane entity. FIG. 2 is a diagram of the architecture of the IAB system used in the technical solution of this application. Figure 3 illustrates an example of a user plane protocol stack architecture of a multi-hop IAB network. Figure 4 illustrates an example of a control plane protocol stack architecture of a multi-hop IAB network. Figures 5 to 11 are each schematic flowcharts of a method according to an embodiment of this application. FIG. 12 is a schematic block diagram of a communication device according to an embodiment of this application. FIG. 13 is a schematic block diagram of a communication device according to an embodiment of this application. Specific details for implementing the invention
[0281] The following describes the technical solution of this application with reference to the attached drawings.
[0282] The embodiments of this application may be applied to various communication systems, for example, wireless local area network (WLAN) systems, narrowband internet of things (NB-IoT) systems, global system for mobile communications (GSM), enhanced data rates for GSM evolution (EDGE) systems, wideband code division multiple access (WCDMA) systems, code division multiple access (CDMA2000) systems, time division-synchronous code division multiple access (TD-SCDMA) systems, long term evolution (LTE) systems, satellite communication systems, 5th generation (5G) systems, and new communication systems that will emerge in the future.
[0283] The terminal device in the embodiments of this application may include various handheld devices, vehicle-mounted devices, wearable devices, computing devices having wireless communication capabilities, or other processing devices connected to a wireless modem. The terminal may be a mobile station (MS), subscriber unit, user equipment (UE), cellular phone, smartphone, wireless data card, personal digital assistant (PDA) computer, tablet computer, wireless modem, handset, laptop computer, machine type communication (MTC) terminal, etc.
[0284] The network device in the embodiments of this application may be a device configured to communicate with a terminal device. The network device may be a base transceiver station (BTS) in a global System for mobile communications (GSM) system or a code division multiple access (CDMA) system, a NodeB (NodeB, NB) in a wideband code division multiple access (WCDMA) system, an evolved NodeB (eNB or eNodeB) in an LTE system, a new radio NodeB (NR NodeB, gNB), or a radio controller in a cloud radio access network (CRAN) scenario. Alternatively, the network device may be a relay station, an access point, a vehicle-mounted device, a wearable device, a network device in a future 5G network, a network device in a future evolved PLMN network, etc. This is not limited to the embodiments of this application.
[0285] In embodiments of this application, a terminal device or network device comprises a hardware layer, an operating system layer operating on the hardware layer, and an application layer operating on the operating system layer. The hardware layer comprises hardware such as a central processing unit (CPU), a memory management unit (MMU), and memory (also referred to as main memory). The operating system may be any one or more types of computer operating systems that implement service processing through processes, for example, a Linux operating system, a Unix operating system, an Android operating system, an iOS operating system, or a Windows operating system. The application layer comprises applications such as a browser, an address book, word processing software, and instant messaging software. Additionally, if a program recording the code of the method provided in the embodiments of this application can be operated to perform communication according to the method provided in the embodiments of this application, the specific structure of the execution body of the method provided in the embodiments of this application is not particularly limited to the embodiments of this application. For example, the execution body of the method provided in the embodiments of this application may be a terminal device or a network device, or a functional module located within the terminal device or a network device that can call and execute a program.
[0286] Additionally, aspects or features of this application may be embodied as methods, devices, or products utilizing standard programming and / or engineering techniques. As used in this application, the term “product” encompasses computer programs accessible from any computer-readable component, carrier, or medium. For example, computer-readable media may include, but are not limited to, magnetic storage components (e.g., hard disks, floppy disks, or magnetic tapes), optical discs (e.g., compact discs (CDs) and digital versatile discs (DVDs)), smart cards, and flash components (e.g., erasable programmable read-only memory (EPROM)), cards, sticks, or key drives). Additionally, the various storage media described herein may refer to one or more devices and / or other machine-readable media configured to store information. The term "machine-readable medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing, and / or carrying commands and / or data.
[0287] In NR technology, an access network device (e.g., gNB) may be composed of one gNB central unit (CU) and one or more gNB distributed units (DU). The gNB-CU and gNB-DU are different logical nodes and may be deployed on different physical devices or on the same physical device.
[0288] When an architecture of separation between the control plane and the user plane is considered, the gNB-CU may also be divided into a central unit control plane (CU-CP) entity (also referred to as a CU-CP node) and a central unit user plane (CU-UP) entity (also referred to as a CU-UP node). The gNB-CU-CP is a control plane entity and is configured to provide signaling control. The gNB-CU-UP is a user plane entity and is configured to provide data transmission for terminal devices. The gNB-CU-CP is connected to the gNB-CU-UP via the E1 interface, the gNB-CU-CP is connected to the gNB-DU via the F1-C interface, and the gNB-CU-UP is connected to the gNB-DU via the F1-U interface. The structure is illustrated in FIG. 1.
[0289] In the architecture illustrated in Fig. 1, there are additional characteristics:
[0290] One gNB includes one gNB-CU-CP, multiple gNB-CU-UPs, and multiple gNB-DUs;
[0291] A single DU can be connected to only one gNB-CU-CP;
[0292] A single CU-UP can be connected to only one gNB-CU-CP;
[0293] A single DU can be connected to multiple gNB-CU-UPs under the control of the same CU-CP; and
[0294] One CU-UP can be connected to multiple gNB-DUs under the control of the same CU-CP.
[0295] It should be understood that FIG. 1 is merely an example and should not impose any restrictions on the architecture of the gNB. For example, in a CU-DU separation and CP-UP separation architecture, the gNB may include only one gNB-CU-UP, one gNB-CU-CP, and one gNB-DU, or may include more gNB-CU-UP and gNB-DU. This is not limited in this application.
[0296] Compared to fourth-generation mobile communication systems, fifth-generation mobile networks (5G) generally have stricter requirements for various network performance indicators. For example, capacity indicators are increased by a thousandfold, wider coverage is required, and ultra-high reliability and ultra-low latency are necessary. Assuming high-frequency carrier frequency resources are abundant, the use of high-frequency small cell networking is becoming increasingly popular in hotspot areas to satisfy the ultra-high-capacity requirements of 5G. High-frequency carriers have poor propagation characteristics, suffer from extreme attenuation due to blocking, and have narrow coverage. Therefore, a large number of small cells need to be deployed densely. Consequently, providing fiber optic backhaul for such densely deployed small cells is costly and difficult to implement. Thus, an economical and convenient backhaul solution is required. Additionally, from the perspective of wide coverage requirements, deploying fiber optics to provide network coverage in some remote areas is difficult and costly. Therefore, flexible and convenient access and backhaul solutions also need to be designed.
[0297] Integrated access and backhaul (IAB) technology provides a concept for solving the aforementioned problem. In IAB technology, wireless transmission solutions are utilized over both the access link and the backhaul link to avoid fiber optic deployment. Figure 2 is a schematic diagram of a wireless relay scenario. In an IAB network, a relay node (RN) can be referred to as an IAB node and can provide wireless access services for user equipment (UE). Service transmission for the UE is performed by an IAB donor node connected to the IAB node via a wireless backhaul link, and the donor node is also referred to as a donor gNodeB (DgNB). An IAB node can perform two roles: mobile termination (MT) and DU. When an IAB node encounters a parent node, the IAB node can be regarded as a terminal device, i.e., an MT, where the parent node may be a donor base station. When an IAB node encounters a child node, the IAB node can be regarded as a network device, i.e., a DU, where the child node may be another IAB node or a common UE. The donor base station may be an access network element with full base station functions, or an access network element in the form of separation between a central unit and a distributed unit. The donor base station is connected to a core network element serving UEs, for example, connected to a 5G core network, and provides wireless backhaul functions for the IAB node.For ease of explanation, the donor base station central unit is referred to as the donor CU for short or directly as the CU, and the donor base station distributed unit is referred to as the donor DU for short or directly as the DU. Alternatively, the donor CU may be a form of separation between the control plane (CP) and the user plane (UP). For example, the CU may be composed of one CU-CP and one or more CU-UPs.
[0298] As illustrated in FIGS. 3 and 4, an F1 interface (also referred to as the F1* interface, whereby the F1 interface and the F1* interface may be collectively referred to as the F1 interface in this specification, but the names are not limited) needs to be established between an IAB node (IAB-DU) and a donor node (IAB-Donor-CU). The interface supports user plane protocols (F1-U / F1*-U) and control plane protocols (F1-C / F1*-C). The user plane protocol includes one or more of the following protocol layers: the general packet radio service tunneling protocol user plane (GTP-U) layer, the user datagram protocol (UDP) layer, the internet protocol (IP) layer, the layer 2 (L2) layer, the layer 1 (L1) layer, the radio link control (RLC) layer, the medium access control (MAC) layer, the physical (PHY) layer, and the backhaul adaptation protocol (BAP) layer. The control plane protocol includes one or more of the following protocol layers: the F1 application protocol (F1AP) layer, the stream control transport protocol (SCTP) layer, the IP layer, the layer 2 layer, the layer 1 layer, the RLC layer, the MAC layer, the PHY layer, and the BAP layer.
[0299] In FIGS. 3 and 4, the radio backhaul link between IAB node 2 and IAB node 1, and the radio backhaul link between IAB node 1 and IAB donor DU may be referred to as a backhaul radio link control channel (BH RLC CH).
[0300] Based on the control plane of the F1 interface, interface management, IAB-DU management, and configuration related to the UE context can be performed between the IAB node and the IAB donor. Based on the user plane of the F1 interface, functions such as user plane data transmission and downlink transmission status feedback can be performed between the IAB node and the IAB donor.
[0301] To protect the security of the F1 interface, an IP security (IPsec) connection can be established between the IAB node and the IAB donor.
[0302] When an architecture of separation between CU-UP and CU-CP is used for an IAB donor, that is, when the IAB donor is split into donor-CU-CP and donor-CU-UP, how to establish an IPsec secure connection between the donor-CU-CP and the IAB node becomes an urgent problem that needs to be solved.
[0303] With this in mind, the embodiments of this application provide a method for establishing a secure transmission channel to establish a user plane secure transmission channel between Donor-CU-UP and IAB-DU.
[0304] It should be noted that in the following embodiments, the first key in Doner-CU-UP is derived by Doner-CU-UP or derived by Doner-CU-CP and transmitted to Doner-CU-UP; and the first key in IAB-DU is derived by IAB-DU or derived by IAB-MT and transmitted to IAB-DU. Since the first key in IAB-DU and the first key in Doner-CU-UP are the same key, the key in IAB-DU and the key in Doner-CU-UP are referred to as the first key in this application. However, it should not be understood that the key in Doner-CU-UP is derived by IAB-DU / IAB-MT, and it should not be understood that the key in IAB-DU is derived by Doner-CU-UP / Doner-CU-CP. Certainly, alternatively, the key in Doner-CU-UP may be designated as the first key, and the key in IAB-DU may be designated as the fifth key, wherein the first key and the fifth key are the same key. This is not limited to the embodiments of this application.
[0305] FIG. 5 illustrates a method for establishing a secure transmission channel according to an embodiment of the present application. As illustrated in FIG. 5, the method (500) includes S510 to S550. The steps are described in detail below.
[0306] S510: Donor-CU-CP transmits the third message. Therefore, at S510, Donor-CU-UP receives the third message.
[0307] The third message is the root key of the donor node (hereinafter K gNB Includes (represented as). K gNBIt is obtained from the network by the donor-CU-CP during the procedure in which the IAB-MT of the IAB node registers with the network. For example, in the procedure in which the IAB-MT of the IAB node accesses the network through the donor-DU and donor-CU-CP or through another IAB node and donor-CU-CP, after the core network performs authentication for the IAB-MT, the access and mobility management function (AMF) network element sends an initial context setup request message to the donor-CU-CP, where the initial context setup request message is K gNB ...includes. After receiving an initial context setup request message, the donor-CU-CP includes K included in the initial context setup request message. gNB It can be stored within the context of an IAB node. It should be understood that IAB-MT and IAB-DU belong to the same IAB node, and that Donor-DU, Donor-CU-UP, and Donor-CU-CP belong to the same IAB Donor node.
[0308] K gNB ...is intended to derive the first key. The first key is an authentication credential used when the donor-CU-UP and IAB-DU establish a user plane secure transmission channel, and the user plane secure transmission channel is for the transmission of user plane data of the terminal device. The user plane secure transmission channel established by the donor-CU-UP and IAB-DU may be a secure transmission channel established by using an IPsec mechanism. The first key is K gNB It should be noted that it is different from
[0309] The third message is not limited to this embodiment of this application.
[0310] In the example, the third message is a bearer context setup request message. For example, when IAB-MT accesses the network through Donor-DU and Donor-CU-CP or through another IAB node and Donor-CU-CP, the bearer context setup request message is sent by Donor-CU-CP to Donor-CU-UP. In another example, when a terminal device accesses the network through IAB-DU, the bearer context setup request message is sent by Donor-CU-CP to Donor-CU-UP. IAB-MT and IAB-DU belong to the same IAB node, and Donor-DU, Donor-CU-CP, and Donor-CU-UP belong to the same IAB donor node.
[0311] In another example, the third message is a bearer context modification request message. For example, when an IAB-MT accesses the network through a donor-DU and a donor-CU-CP, or through another IAB node and a donor-CU-CP, the bearer context modification request message is sent by the donor-CU-CP to the donor-CU-UP. In another example, when a terminal device accesses the network through an IAB-DU, the bearer context modification request message is sent by the donor-CU-CP to the donor-CU-UP.
[0312] Optionally, the third message further includes first instruction information, and the first instruction information indicates that IAB-DU belongs to the IAB-node.
[0313] For example, the first instruction information may be an independent information element. For example, the first instruction information is an "IAB-indicator" information element. As another example, the first instruction information is the IP address of the IAB-DU or K gNB It could be. That is, the IAB-DU's IP address or K gNBIt can also indicate that IAB-DU belongs to the IAB node.
[0314] S520: Donor-CU-UP derives the first key.
[0315] Doner-CU-UP is K gNB A first key is derived based on the IP address of IAB-DU, and the first IP address of Donor-CU-UP.
[0316] For example, Doner-CU-UP is K gNB A first key is derived by using as an input key and by using the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters.
[0317] The first IP address of the donor-CU-UP is an IP address used by the donor-CU-UP to establish a user plane secure transmission channel. It should be understood that the donor-CU-UP may have multiple IP addresses. Before establishing the user plane secure transmission channel, the donor-CU-UP determines a first IP address among the multiple IP addresses, wherein the first IP address is intended for establishing the user plane secure transmission channel. For example, in a procedure in which a terminal device accesses a network through an IAB-DU, after receiving a bearer context setup request message from the donor-CU-CP, the donor-CU-UP determines a first IP address that is for the donor-CU-UP and is intended for establishing the user plane secure transmission channel.
[0318] The IP address of the IAB-DU is obtained from the donor-CU-CP by the donor-CU-UP. For example, in the procedure where a terminal device accesses the network via the IAB-DU, the bearer context modification request message transmitted from the donor-CU-CP to the donor-CU-UP includes the IP address of the IAB-DU.
[0319] The conditions for triggering the donor-CU-UP to derive the first key are not limited to this embodiment of this application.
[0320] In the example, Donor-CU-UP is the IP address of IAB-DU and K gNB The first key can be derived when obtaining .
[0321] In another example, the donor-CU-UP derives the first key when receiving the first instruction information.
[0322] Optionally, after deriving the first key, the donor-CU-UP stores the correspondence between the first key and the IP address of the IAB-DU within the context of the donor-CU-UP.
[0323] S530: Donor-CU-CP transmits the second message. Therefore, at S530, IAB-DU receives the second message.
[0324] The second message includes the first IP address of the donor-CU-UP. For example, the second message is a UE context setup request message. For example, when a terminal device accesses the network through the IAB-DU, the UE context setup request message is sent to the IAB-DU by the donor-CU-CP.
[0325] S540: IAB-DU determines the first key.
[0326] For the method by which IAB-DU determines the first key, refer to the explanation in the method (600) below.
[0327] S550: Donor-CU-UP and IAB-DU establish a user plane secure transmission channel by using the first key.
[0328] For example, the donor-CU-UP and IAB nodes establish a user plane secure transmission channel by using a pre-shared secret key (PSK) supported by the Internet Key Exchange (IKE) v2 protocol. In the first message exchange, the IAB node and the donor-CU-UP complete IKE security association (SA) parameter negotiation in plaintext, including negotiation, encryption, and authentication algorithms, the exchange of temporary random numbers, and Diffie-Hellman (DH) exchange. In the second message exchange, the IAB node and the donor-CU-UP separately generate authentication parameters using the first key and transmit the authentication parameters to the peer end to complete identity authentication.
[0329] It can be understood that when IAB-DU and donor-CU-UP establish a user plane secure transmission channel by using the IKEv2 PSK protocol, IAB-DU determines to use the first key as an authentication credential used when the user plane secure transmission channel is established based on the correspondence between the first key and the first IP address of donor-CU-UP, which is stored within the context of IAB-DU, and donor-CU-UP determines to use the first key as an authentication credential used when the user plane secure transmission channel is established based on the correspondence between the first key and the IP address of IAB-DU, which is stored within the context of donor-CU-UP.
[0330] It should also be understood that the procedure for establishing a user plane secure transmission channel, performed by the IAB-DU and the donor-CU-UP, may be triggered by the IAB-DU or by the donor-CU-UP. For example, if a user plane secure transmission channel between the IAB-DU and the donor-CU-UP is not established when the IAB-DU receives a user plane data request from a terminal device, the IAB-DU triggers the procedure for establishing the user plane secure transmission channel. For another example, if a user plane secure transmission channel between the IAB-DU and the donor-CU-UP is not established when the donor-CU-UP receives downlink data from the terminal device, the donor-CU-UP triggers the procedure for establishing the user plane secure transmission channel.
[0331] In this embodiment of this application, Doner-CU-CP is K gNB By transmitting to the donor-CU-UP, the donor-CU-UP thus becomes K gNB A first key can be derived by using as an input key, and IAB-DU can obtain the same first key. When the same first key exists in Donor-CU-UP and IAB-DU, Donor-CU-UP and IAB-DU can establish a user plane secure transmission channel based on the first key in order to effectively avoid the problem of authentication errors generated when the Donor Node and IAB-DU establish a secure transmission channel of the F1-U interface.
[0332] As described above, in the procedure where the IAB-MT accesses the network via the Donor-DU, the initial context setup request message received from the AMF by the Donor-CU-CP is K gNB Includes. K gNB After acquiring, Donor-CU-CP is K gNB Based on this, a key related to the control plane can be derived. Therefore, based on method (500), Donor-CU-CP is KgNB After sending to the donor-CU-UP, the donor-CU-UP is K gNB Not only can the first key be derived based on, but K gNB Based on this, keys related to the control plane can be derived. Once the donor-CU-UP is K gNB If a key related to the control plane is derived based on this, the transmission security of the control plane is affected, and the requirements for key isolation and least privilege are not satisfied. Additionally, the deployment method of the donor-CU-UP can be a distributed deployment. That is, a single donor-CU-CP can manage multiple donor-CU-UPs. The donor-CU-CP K gNB When transmitting to multiple donor-CU-UPs, the risk of key leakage is added.
[0333] Therefore, a user plane secure transmission channel between the donor-CU-UP and the IAB-DU can be established according to the method (500), but the method (500) has a risk of key leakage.
[0334] FIG. 6 illustrates a method for establishing a secure transmission channel according to an embodiment of the present application. As illustrated in FIG. 6, the method (600) includes S610 to S640. The steps are described in detail below.
[0335] S610: Donor-CU-CP transmits the first message. Therefore, at S610, Donor-CU-UP receives the first message.
[0336] In a possible embodiment, the first message includes a first key, the first key is an authentication credential used when the donor-CU-UP and IAB-DU establish a user plane secure transmission channel, and the user plane secure transmission channel is for the transmission of user plane data of a terminal device. The user plane secure transmission channel established by the donor-CU-UP and IAB-DU may be a user plane secure transmission channel established by using an IPsec mechanism.
[0337] The first key is the root key of the donor node (hereinafter K gNB It is different from (represented as), and K gNB It should be noted that is a key obtained from the network by the donor-CU-CP during the procedure in which the IAB node registers with the network. For example, in the procedure in which the IAB-MT of an IAB node accesses the network through the donor-DU and donor-CU-CP or through another IAB node and donor-CU-CP, after the core network performs authentication for the IAB-MT, the AMF sends an initial context setup request message to the donor-CU-CP, where the initial context setup request message is K gNB ...includes. After receiving an initial context setup request message, the donor-CU-CP includes K included in the initial context setup request message. gNB It can be stored within the context of an IAB node. It should be understood that IAB-MT and IAB-DU belong to the same IAB node, and that Donor-DU and Donor-CU-CP belong to the same IAB Donor node.
[0338] Optionally, the first message further includes the first IP address of the donor-CU-UP. Accordingly, after receiving the first message and after deciding to establish a user plane secure transmission channel between the donor-CU-UP and the IAB-DU based on the first IP address, the donor-CU-UP decides to use the first key when establishing the user plane secure transmission channel based on the first IP address.
[0339] Optionally, the first message further includes the IP address of IAB-DU. Accordingly, after receiving the first message and after deciding to establish a user plane secure transmission channel between Donor-CU-UP and IAB-DU based on the first IP address, Donor-CU-UP decides to use the first key when establishing the user plane secure transmission channel based on the first IP address and the IP address of IAB-DU.
[0340] When the first message contains the first key, the method (600) further includes S611a: the donor-CU-CP determines the first key.
[0341] Doner-CU-CP is K gNB , the first key is derived based on the first IP address of the donor-CU-UP and the IP address of the IAB-DU.
[0342] For example, Doner-CU-CP is K gNB The first key is derived by using as an input key and by using the first IP address of the donor-CU-UP and the IP address of the IAB-DU as input parameters. K gNB It should be understood that is a key shared by IAB-MT and IAB-Donor.
[0343] K gNB It is obtained by the donor-CU-CP from the context stored locally in the IAB node.
[0344] The first IP address of the donor-CU-UP is an IP address used by the donor-CU-UP to establish a user plane secure transmission channel. It should be understood that the donor-CU-UP may have multiple IP addresses. Before establishing the user plane secure transmission channel, the donor-CU-UP determines a first IP address among the multiple IP addresses, wherein the first IP address is intended for establishing the user plane secure transmission channel. For example, in a procedure in which a terminal device accesses a network via an IAB-DU, the donor-CU-CP receives a bearer context setup response message from the donor-CU-UP, wherein the bearer context setup response message includes the first IP address of the donor-CU-UP.
[0345] The IP address of IAB-DU may be assigned by the donor-CU-CP or assigned to IAB-DU by the operation, administration, and maintenance (OAM). When the OAM assigns an IP address to IAB-DU, the donor-CU-CP may obtain the IP address of IAB-DU from the OAM.
[0346] The conditions for triggering the donor-CU-CP to determine the first key are not limited to this embodiment of this application.
[0347] In the example, the donor-CU-CP can determine the first key when it obtains the first IP address of the donor-CU-UP. In other words, once the donor-CU-CP receives a bearer context setup response message from the donor-CU-UP, the donor-CU-CP can determine the first key based on the first IP address that is for the donor-CU-UP and is carried in the bearer context setup response message.
[0348] In another example, the donor-CU-CP determines a first key when determining that IAB-DU belongs to an IAB node. For example, the donor-CU-CP determines whether IAB-DU belongs to an IAB node based on whether the context stored locally in the IAB node contains a first identifier, where the first identifier indicates that IAB-DU belongs to an IAB node. If the context of the IAB node contains the first identifier, the donor-CU-CP determines that IAB-DU belongs to an IAB node; or if the context of the IAB node does not contain the first identifier, the donor-CU-CP determines that IAB-DU does not belong to an IAB node. Optionally, the first identifier is the IP address of IAB-DU.
[0349] In another possible embodiment, the first message includes a one-to-one correspondence between a plurality of IP addresses of the donor-CU-UP and a plurality of keys, the plurality of keys include a first key, and the first key corresponds to a first IP address of the donor-CU-UP.
[0350] Optionally, the first message further includes the IP address of IAB-DU, and multiple keys all correspond to the IP address of IAB-DU. In other words, each of the multiple keys corresponds to one IP address of Donor-CU-UP and the IP address of IAB-DU.
[0351] When the first message has a one-to-one correspondence between multiple IP addresses of the donor-CU-UP and multiple keys, the method (600) further includes S611b: the donor-CU-CP is K gNB Multiple keys are derived based on the IP address of , IAB-DU, and multiple IP addresses of donor-CU-UP.
[0352] For example, multiple IP addresses of Donor-CU-UP include a first IP address and a second IP address. In this case, Donor-CU-CP is KgNB , the IP address of IAB-DU, and derive a first key based on the first IP address, and K gNB A second key is derived based on the IP address of the IAB-DU and the second IP address. Next, the correspondence between the first IP address and the first key, and the correspondence between the second IP address and the second key are transmitted to the donor-CU-UP through the first message.
[0353] Optionally, before Donor-CU-CP determines multiple keys, the method further comprises: Donor-CU-CP transmits first instruction information to Donor-CU-UP; and Donor-CU-CP receives multiple IP addresses of Donor-CU-UP from Donor-CU-UP. Accordingly, after receiving the first instruction information, Donor-CU-UP transmits multiple IP addresses of Donor-CU-UP to Donor-CU-CP based on the first instruction information.
[0354] Specifically, the multiple IP addresses of Doner-CU-UP are all IP addresses of Doner-CU-UP. In other words, after receiving the first instruction information, Doner-CU-UP transmits all IP addresses of Doner-CU-UP to Doner-CU-CP based on the first instruction information.
[0355] For example, the first instruction information indicates that IAB-DU belongs to the IAB node.
[0356] For example, if Donor-CU-UP has three IP addresses represented as CU-UP IP 1, CU-UP IP 2, and CU-UP IP 3, Donor-CU-UP transmits the three IP addresses to Donor-CU-CP. Therefore, after receiving the three IP addresses from Donor-CU-UP, Donor-CU-CP K gNB Three keys are derived based on the IP address of , IAB-DU, and the three IP addresses of donor-CU-UP.
[0357] Specifically, Doner-CU-CP is K gNB By using as an input key, and by using the IP address of the IAB-DU and CU-UP IP 1 as input parameters, the key (K IAB-UP 1 Deriving (represented as); and Donor-CU-CP is K gNB By using as an input key, and by using the IP address of the IAB-DU and CU-UP IP 2 as input parameters, the key (K IAB-UP 2 Deriving (represented as); and Donor-CU-CP is K gNB By using as an input key, and by using the IAB-DU IP address and CU-UP IP 3 as input parameters, the key (K IAB-UP 3 ) is derived. Additionally, Donor-CU-CP transmits three derived keys and the IP addresses of Donor-CU-UP corresponding to each of the three keys to Donor-CU-UP. Optionally, Donor-CU-UP transmits three derived keys and three groups of first parameters corresponding to each of the three keys to Donor-CU-UP, where the first parameters corresponding to each key are input parameters for deriving the keys. For example, three keys and three groups of first parameters corresponding to each of the three keys are {K IAB-UP 1 , CU-UP IP 1, and IAB-DU IP}, {K IAB-UP 2 , CU-UP IP 2, and IAB-DU IP}, and {K IAB-UP 3 It can be expressed as , CU-UP IP 3, and IAB-DU IP}.
[0358] When the first message includes a plurality of keys, the method (600) further includes S612: the donor-CU-UP determines to establish a user plane secure transmission channel between the donor-CU-UP and the IAB-DU based on the first IP address; and determines the first key based on the first IP address.
[0359] For example, Donor-CU-UP is a first key corresponding to a first IP address and determines a key within a plurality of keys. Alternatively, Donor-CU-UP is a first key corresponding to a first IP address and an IP address of IAB-DU and determines a key within a plurality of keys.
[0360] For example, in a procedure where a terminal device accesses a network through an IAB-DU, after receiving a bearer context setup request message from a donor-CU-CP, the donor-CU-UP determines that the IP address for the donor-CU-UP, which is intended to establish a user plane secure transmission channel, is the first IP address. Additionally, the donor-CU-UP receives a bearer context modification request message from the donor-CU-CP, wherein the bearer context modification request message includes an IP address for the IAB-DU, which is intended to establish a user plane secure transmission channel. Additionally, the donor-CU-UP determines, as a first key, a key that is within a plurality of keys and corresponds to the first IP address of the donor-CU-UP and the IP address of the IAB-DU, which is intended to establish a user plane secure transmission channel. For example, if the IP address determined by the donor-CU-UP and intended to establish a user plane secure transmission channel is the aforementioned CU-UP IP 2, the donor-CU-UP is, as a first key, K corresponding to CU-UP IP 2 and IAB-DU IP. IAB-UP 2 Determines.
[0361] Optionally, after obtaining a first key from a first message or determining a first key among a plurality of keys included in the first message, the donor-CU-UP stores the correspondence between the first key and the IP address of the IAB-DU.
[0362] For example, the donor-CU-UP stores the correspondence between the first key and the IP address of the IAB-DU within the context of the donor-CU-UP.
[0363] The IP address of IAB-DU is obtained from Donor-CU-CP by Donor-CU-UP. For example, Donor-CU-CP transmits the IP address of IAB-DU to Donor-CU-UP via a first message. For example, in a procedure where a terminal device accesses a network via IAB-DU, a bearer context modification request message transmitted by Donor-CU-CP to Donor-CU-UP includes a first key and the IP address of IAB-DU. In another example, Donor-CU-CP transmits the IP address of IAB-DU to Donor-CU-UP via another message different from the first message. For example, in a procedure where a terminal device accesses a network via IAB-DU, Donor-CU-CP transmits a bearer context setup request message to Donor-CU-UP, wherein the bearer context setup request message includes a first key. Additionally, Donor-CU-CP sends a bearer context modification request message to Donor-CU-UP, where the bearer context modification request message includes the IP address of IAB-DU.
[0364] The first message transmitted from Donor-CU-CP to Donor-CU-UP is not limited to this embodiment of this application.
[0365] In the example, if the first message includes a first key, the first message may be a bearer context modification request message. Specifically, the bearer context modification request message is transmitted from the donor-CU-CP to the donor-CU-UP in the procedure where the terminal device accesses the network via the IAB-DU. For example, the first key may be carried in security information included within the bearer context modification request message. Alternatively, the first key may be carried in a newly defined information element within the bearer context modification request message.
[0366] In another example, where the first message includes the first key, the first message may be a bearer context setup request message. Specifically, the bearer context setup request message is transmitted from the donor-CU-CP to the donor-CU-UP in the procedure in which the terminal device accesses the network through the IAB-DU.
[0367] For example, Donor-CU-UP has only one IP address. When establishing different user plane secure transmission channels, Donor-CU-UP sets up the user plane secure transmission channel by using the IP address. It is assumed that Donor-CU-UP and one IAB-DU established one user plane secure transmission channel (represented as User Plane Secure Transmission Channel 1) prior to S710. In the procedure for establishing User Plane Secure Transmission Channel 1, Donor-CU-CP can obtain the IP address of Donor-CU-UP. Next, in the procedure for establishing another user plane secure transmission channel (represented as user plane secure transmission channel 2), since the donor-CU-CP obtained the IP address of the donor-CU-UP in the procedure for establishing user plane secure transmission channel 1, before the donor-CU-CP transmits a bearer context setup request message to the donor-CU-UP in the procedure for the terminal device to access the network through the IAB-DU, the donor-CU-CP can determine a first key based on the IP address of the donor-CU-UP and transmit the first key to the donor-CU-UP through the bearer context setup request message.
[0368] In another example, where the first message includes multiple keys and multiple groups of first parameters, the first message may be a bearer context modification request message. Specifically, the bearer context modification request message is transmitted from the donor-CU-CP to the donor-CU-UP in a procedure in which the IAB-MT accesses the network through the donor-DU and donor-CU-CP or through another IAB node and donor-CU-CP.
[0369] For example, Table 1 illustrates some of the information elements included within security information. Table 2 illustrates the IE / groups included within the "IAB pre-shared key" information element.
[0370] A one-to-one correspondence between the first key, or multiple keys, and multiple IP addresses of the donor-CU-UP may be included within the "security information" information element.
[0371]
[0372]
[0373] For example, Table 3 illustrates some information elements included within a bearer context setup request message. Table 4 illustrates the IE / group included within the "IAB pre-shared key" information element. Table 5 illustrates the IE / group included within the "IAB credential" information element.
[0374] A first key, or a plurality of keys and a plurality of first parameters, may be included within an "IAB pre-shared key" information element. Specifically, the first key, or a plurality of keys and a plurality of first parameters, may be included within an "IAB credential" information element within the "IAB pre-shared key" information element.
[0375]
[0376]
[0377]
[0378] Optionally, the method (600) further includes S613: Donor-CU-CP is K gNB A third key is derived based on the IP address of the donor-CU-CP and the IP address of the IAB-DU. The third key is an authentication credential used when the donor-CU-CP and IAB-DU establish a control plane secure transmission channel. The control plane secure transmission channel established by the donor-CU-CP and IAB-DU may be a secure transmission channel established by using an IPsec mechanism.
[0379] For example, Doner-CU-CP is K gNB A third key is derived by using as an input key and by using the IP address of the donor-CU-CP and the IP address of the IAB-DU as input parameters.
[0380] Optionally, the first message further includes first instruction information. Accordingly, based on the first instruction information, the donor-CU-UP uses the first key as an authentication credential when the donor-CU-UP and IAB-DU establish a user plane secure transmission channel. Alternatively, the method of establishing a user plane secure transmission channel by the donor-CU-UP and IAB-DU is not dependent on the first key as an authentication credential.
[0381] For example, the first instruction information indicates that IAB-DU belongs to the IAB node.
[0382] For example, the first instruction information may be an independent information element. For example, the first instruction information is an "IAB-indicator" information element. As another example, the first instruction information may be the IP address of the IAB-DU or the first key. That is, the IP address of the IAB-DU or the first key may also indicate that the IAB-DU belongs to the IAB node.
[0383] S620: Donor-CU-CP transmits the second message. Therefore, at S620, IAB-DU receives the second message.
[0384] The second message includes the first IP address of the donor-CU-UP. For example, the second message is a UE context setup request message. For example, when a terminal device accesses the network through the IAB-DU, the UE context setup request message is sent to the IAB-DU by the donor-CU-CP.
[0385] S630: IAB-DU determines the first key.
[0386] For example, S630 includes S631a to S633a.
[0387] S631a: IAB-DU sends the first request message to IAB-MT.
[0388] The first request message includes the first IP address of the donor-CU-UP, and the first request message requests the first key.
[0389] After receiving the first request message from IAB-DU, IAB-MT K gNB A first key is derived based on the IP address of IAB-DU and the first IP address of the donor-CU-UP, and then the first key is transmitted to IAB-DU. It may be understood that the IP address of IAB-DU is obtained from OAM or donor-CU-CP after IAB-MT has completed registration.
[0390] For example, IAB-MT is K gNB A first key is derived by using as an input key and by using the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters.
[0391] S632a: IAB-MT sends the first response message to IAB-DU.
[0392] The first response message includes the first key.
[0393] Accordingly, after receiving the first key, the IAB-DU stores the correspondence between the first key and the first IP address of the donor-CU-UP. For example, the IAB-DU stores the correspondence between the first key and the first IP address of the donor-CU-UP within the context of the IAB-DU.
[0394] IAB-MT is K gNB It stores, and the IAB-DU obtains the first IP address of the donor-CU-UP. Therefore, in the manner described above, the IAB-MT interacts with the IAB-DU to solve the problem of obtaining the first key by the IAB-DU. Additionally, the first key is K gNB It is different from. The requirements for key isolation and least privilege are satisfied, and key leakage is avoided.
[0395] As another example, S630 includes S631b to S633b.
[0396] S631b: IAB-DU sends the second request message to IAB-MT.
[0397] The second request message is K gNB Requests.
[0398] S632b: IAB-MT sends a second response message to IAB-DU.
[0399] The second response message is K gNB Includes
[0400] It must be understood that S631b and S632b are arbitrary steps. That is, IAB-DU is K gNB When storing locally, S630 includes only S633b. K stored locally by IAB-DU gNBIt is obtained from the IAB-MT after the IAB-DU has started. For example, after the IAB-DU has started, when the IAB-MT transmits the IAB-DU's IP address to the IAB-DU, K gNB Send to IAB-DU.
[0401] S633b: IAB-DU derives the first key.
[0402] IAB-DU is K gNB A first key is derived based on the IP address of IAB-DU, and the first IP address of Donor-CU-UP.
[0403] For example, IAB-DU is K gNB A first key is derived by using as an input key and by using the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters. It can be understood that the IP address of IAB-DU is obtained from IAB-MT after IAB-DU starts.
[0404] IAB-MT is K gNB It stores, and the IAB-DU obtains the first IP address of the donor-CU-UP. Therefore, in the manner described above, the IAB-MT interacts with the IAB-DU to solve the problem of obtaining the first key by the IAB-DU. Additionally, K gNB After acquiring, when the first IP address of the donor-CU-UP changes, IAB-DU K gNB Since there is no need to repeatedly request it, the first key is calculated locally according to the request.
[0405] Additionally, after deriving the first key, the IAB-DU stores the correspondence between the first key and the first IP address of the donor-CU-UP. For example, the IAB-DU stores the correspondence between the first key and the first IP address of the donor-CU-UP within the context of the IAB-DU.
[0406] It should be understood that the time for obtaining the first key by IAB-DU is not limited to this embodiment of this application.
[0407] In the example, IAB-DU obtains a first key when obtaining the first IP address of the donor-CU-UP. For example, if S630 includes S631a through S633a, IAB-DU transmits a first request message to IAB-MT when obtaining the first IP address of the donor-CU-UP. In another example, if S630 includes S631b through S633b, IAB-DU transmits a second request message to IAB-MT or derives a first key when obtaining the first IP address of the donor-CU-UP.
[0408] In another example, the IAB-DU obtains a first key before initiating the user plane secure transmission channel setup procedure for the donor-CU-UP. For example, if S630 includes S631a through S633a, the IAB-DU transmits a first request message to the IAB-MT before initiating the user plane secure transmission channel setup procedure for the donor-CU-UP. In another example, if S630 includes S631b through S633b, the IAB-DU transmits a second request message to the IAB-MT or derives the first key before initiating the user plane secure transmission channel setup procedure for the donor-CU-UP.
[0409] In another example, IAB-DU obtains a first key after receiving an authentication request message from Donor-CU-UP, wherein the authentication request message is intended to establish a user plane secure transmission channel. For example, if S630 includes S631a through S633a, IAB-DU transmits the first request message to IAB-MT after receiving the authentication request message from Donor-CU-UP. In another example, if S630 includes S631b through S633b, IAB-DU transmits the second request message to IAB-MT or derives the first key after receiving the authentication request message from Donor-CU-UP.
[0410] In another example, the IAB-DU obtains a first key after receiving a user plane data request message from a terminal device. For example, if S630 includes S631a through S633a, the IAB-DU transmits the first request message to the IAB-MT after receiving a user plane data request message from the terminal device. In another example, if S630 includes S631b through S633b, the IAB-DU transmits a second request message to the IAB-MT or derives the first key after receiving a user plane data request message from the terminal device.
[0411] S640: Donor-CU-UP and IAB-DU establish a user plane secure transmission channel by using the first key.
[0412] For example, the donor-CU-UP and IAB nodes establish a user plane secure transmission channel by using a PSK supported by the IKEv2 PSK protocol. In the first message exchange, the IAB node and the donor-CU-UP complete IKE SA parameter negotiation in plaintext, including negotiation, encryption, and authentication algorithms, exchange of temporary random numbers, and DH exchange. In the second message exchange, the IAB node and the donor-CU-UP separately generate authentication parameters using a first key and transmit the authentication parameters to the peer end to complete identity authentication.
[0413] It can be understood that when IAB-DU and donor-CU-UP establish a user plane secure transmission channel by using the IKEv2 PSK protocol, IAB-DU determines to use the first key as an authentication credential used when the user plane secure transmission channel is established based on the correspondence between the first key and the first IP address of donor-CU-UP, which is stored within the context of IAB-DU, and donor-CU-UP determines to use the first key as an authentication credential used when the user plane secure transmission channel is established based on the correspondence between the first key and the IP address of IAB-DU, which is stored within the context of donor-CU-UP.
[0414] It should also be understood that the IKEv2 PSK procedure performed by the IAB-DU and the donor-CU-UP can be triggered by the IAB-DU or by the donor-CU-UP. For example, if a user plane secure transmission channel between the IAB-DU and the donor-CU-UP is not established when the IAB-DU receives a user plane data request from a terminal device, the IAB-DU triggers the IKEv2 PSK procedure. For another example, if a user plane secure transmission channel between the IAB-DU and the donor-CU-UP is not established when the donor-CU-UP receives downlink data from the terminal device, the donor-CU-UP triggers the IKEv2 PSK procedure.
[0415] In this embodiment of this application, Doner-CU-CP is K gNB A first key is derived based on the first IP address of the donor-CU-UP and the IP address of the IAB-DU, and the first key is transmitted to the donor-CU-UP. Additionally, to effectively avoid the problem of authentication errors generated when the donor node and the IAB-DU establish a secure transmission channel of the F1-U interface, the IAB node determines the first key in the same manner, so that the same first key exists in the donor-CU-UP and the IAB node. Additionally, the first key is K gNB Since it is different from, the requirements for first isolation and least privilege are satisfied, and key leakage is avoided.
[0416] Optionally, after the IAB-DU and Donor-CU-UP establish a user plane secure transmission channel, re-authentication between the IAB-MT and the core network may be performed.
[0417] After re-authentication between the IAB-MT and the core network is performed, the AMF sends an initial context setup request message to the donor-CU-CP, where the initial context setup request message is a new K gNBIt can be understood that it includes. Therefore, IAB-MT also includes a new K gNB Creates.
[0418] Additionally, Doner-CU-CP is a new K gNB A new second key can be derived by using as an input key and by using the IP address of IAB-DU and the IP address of Donor-CU-CP as input parameters.
[0419] Additionally, Doner-CU-CP also, new K gNB It can be sent to the donor-CU-UP. For example, the donor-CU-UP sends a new first key to the donor-CU-UP via a bearer context modification request message.
[0420] Therefore, the new K gNB After receiving, the donor-CU-UP receives a new K gNB Based on this, a new first key can be generated, and based on the new first key, the user plane secure transmission channel establishment in FIG. 640 can be updated. Alternatively, the donor-CU-UP can generate a new K gNB Based on this, another user plane secure transmission channel can be established. The new first key is the new K gNB It is different from.
[0421] FIG. 7 illustrates a method for establishing a secure transmission channel according to an embodiment of the present application. As illustrated in FIG. 7, the method (700) includes S710 to S760. The steps are described in detail below.
[0422] S710: Donor-CU-CP transmits the first information. Therefore, at S710, Donor-CU-UP receives the first information.
[0423] The first information is for determining the first key, the first key is an authentication credential used by the donor-CU-UP and IAB-DU to establish a user plane secure transmission channel, and the user plane secure transmission channel is for transmitting user plane data of the terminal device. The user plane secure transmission channel established by the donor-CU-UP and IAB-DU may be a secure transmission channel established by using an IPsec mechanism.
[0424] The first key is the root key of the donor node (hereinafter K gNB It is different from (represented as), and K gNB It should be noted that is a key obtained from the network by the donor-CU-CP during the procedure in which the IAB node registers with the network. For example, in the procedure in which the IAB-MT of an IAB node accesses the network through the donor-DU and donor-CU-CP or through another IAB node and donor-CU-CP, after the core network performs authentication for the IAB-MT, the AMF sends an initial context setup request message to the donor-CU-CP, where the initial context setup request message is K gNB ...includes. After receiving an initial context setup request message, the donor-CU-CP includes K included in the initial context setup request message. gNB It can be stored within the context of an IAB node. It should be understood that IAB-MT and IAB-DU belong to the same IAB node, and that Donor-DU and Donor-CU-CP belong to the same IAB Donor node.
[0425] For example, the first information includes at least one of an intermediate key and a user flat key.
[0426] The intermediate key is an intermediate key for generating the first key. For example, the intermediate key is K gNB and is derived based on the second parameter. As another example, the intermediate key is a random number.
[0427] The user plane key is a user plane key used between the IAB node and the IAB donor node. The second parameter includes one or more of the following: a physical cell identifier (PCI), an absolute radio frequency channel number-downlink (ARFCN-DL), a helper node counter, a constant, and a freshness parameter.
[0428] In a possible implementation, the first information includes an intermediate key.
[0429] Therefore, the fact that Donor-CU-CP transmits the first information to Donor-CU-UP includes the following: Donor-CU-CP generates an intermediate key, and Donor-CU-CP transmits the intermediate key to Donor-CU-UP.
[0430] In the example, the fact that donor-CU-CP generates an intermediate key includes the following: donor-CU-CP is K gNB and derive an intermediate key based on the second parameter.
[0431] Optionally, in this example, the method (700) further includes S750: the donor-CU-CP transmits a fourth message to the IAB-MT, wherein the fourth message includes an intermediate key or a second parameter.
[0432] Specifically, the fourth message includes an intermediate key, or a parameter within the second parameter for generating the intermediate key that is unknown to the IAB-MT. In other words, if the second parameter used by the donor-CU-CP to generate the intermediate key includes a parameter unknown to the IAB-MT, the donor-CU-CP transmits the intermediate key, or the parameter within the second parameter for generating the intermediate key that is unknown to the IAB-MT, to the IAB-MT.
[0433] It should be noted that the PCI, ARFCN-DL, and auxiliary node counters included in the second parameter are parameters known to the IAB-MT.
[0434] For example, the fourth message is an RRC reconfiguration message transmitted by Donor-CU-CP to IAB-MT in the procedure where IAB-MT accesses the network through Donor-DU and Donor-CU-CP, or through another IAB node and Donor-CU-CP. It should be understood that Donor-DU and Donor-CU-CP belong to the same IAB donor node.
[0435] In another example, the fact that the donor-CU-CP generates an intermediate key includes the following: the donor-CU-CP generates a random number and uses the random number as an intermediate key.
[0436] In this example, the method (700) further includes S750: the donor-CU-CP transmits a fourth message to the IAB-MT, wherein the fourth message includes an intermediate key.
[0437] In another possible embodiment, the first information includes a user flat key.
[0438] Therefore, the fact that Donor-CU-CP transmits the first information to Donor-CU-UP includes the following: Donor-CU-CP generates a user plane key, and Donor-CU-CP transmits the user plane key to Donor-CU-UP.
[0439] The fact that Doner-CU-CP generates a user-flat key includes the following: Doner-CU-CP is K gNB Based on this, derive a user flat key.
[0440] For example, in a procedure where the IAB-MT accesses the network through the Donor-DU and Donor-CU-CP or through another IAB node and Donor-CU-CP, after authentication between the IAB-MT and the core network is completed, the initial context setup request message sent by the AMF to the Donor-CU-CP is K gNB ...includes. Additionally, Doner-CU-CP is K gNB A user plane key is derived based on the user plane key, and the user plane key is transmitted to the donor-CU-UP. The user plane key includes a user plane integrity protection key (represented as Kupenc) and / or a user plane encryption protection key (represented as Kupint).
[0441] The conditions for triggering the donor-CU-CP to generate the first information are not limited to this embodiment of this application.
[0442] In a possible implementation, the donor-CU-CP generates first information when it receives second instruction information. The second instruction information indicates that the IAB-DU belongs to the IAB node.
[0443] For example, Donor-CU-CP receives second instruction information from IAB-MT, where the second instruction information is an "IAB-Instruction" information element. In the procedure where IAB-MT accesses the network through Donor-DU and Donor-CU-CP or through another IAB node and Donor-CU-CP, IAB-MT transmits the "IAB-Instruction" information element to Donor-CU-UP through Donor-DU or another IAB node.
[0444] In another example, the donor-CU-CP receives second instruction information from a core network element, where the second instruction information is an "IAB-authorized" information element. In a procedure where the IAB-MT accesses the network through the donor-DU and donor-CU-CP or through another IAB node and donor-CU-CP, after authentication between the IAB-MT and the core network is completed, an initial context setup request message transmitted by the AMF to the donor-CU-CP includes an "IAB-authorized" information element.
[0445] The manner in which Donor-CU-CP transmits the first information to Donor-CU-UP is not limited to this embodiment of this application.
[0446] For example, in the procedure where IAB-MT accesses the network through Donor-DU, Donor-CU-CP transmits first information to Donor-CU-UP through a bearer context setup request message.
[0447] Optionally, the method further comprises: Donor-CU-CP transmits first instruction information to Donor-CU-UP, wherein the first instruction information indicates that IAB-DU belongs to the IAB node. The first instruction information and the second instruction information may be the same or different. This is not limited to this embodiment of the application. For example, the first instruction information is "IAB-indicator". As another example, the first instruction information is first information. That is, the first information also indicates that IAB-DU belongs to the IAB node.
[0448] S720: Donor-CU-UP determines the first key based on the information.
[0449] After receiving first information from Donor-CU-CP, Donor-CU-UP determines a first key based on the first information. Specifically, in the procedure where a terminal device accesses a network through Donor-DU, Donor-CU-UP determines a first key based on the first information.
[0450] As described above, the first information may include different parameters. It should also be understood that the donor-CU-UP determines the first key based on the first information in a different way when the first information includes different parameters.
[0451] In a possible implementation, the first information includes an intermediate key.
[0452] Accordingly, after receiving the first information, the donor-CU-UP derives the first key based on the intermediate key, the IP address of the IAB-DU, and the first IP address of the donor-CU-UP.
[0453] For example, the donor-CU-UP derives the first key by using an intermediate key as an input key and by using the IP address of the IAB-DU and the first IP address of the donor-CU-UP as input parameters.
[0454] In another possible embodiment, the first information includes a user flat key.
[0455] Accordingly, after receiving the first information, the donor-CU-UP derives the first key based on the user plane key, the IP address of the IAB-DU, and the first IP address of the donor-CU-UP.
[0456] For example, the donor-CU-UP derives the first key by using the user plane key as an input key and by using the IP address of the IAB-DU and the first IP address of the donor-CU-UP as input parameters.
[0457] Alternatively, Donor-CU-CP first derives a fourth key based on the user plane key, and then derives a first key based on the fourth key, the IP address of IAB-DU, and the first IP address of Donor-CU-UP.
[0458] For example, the donor-CU-UP derives the first key by using the fourth key as an input key and by using the IP address of the IAB-DU and the first IP address of the donor-CU-UP as input parameters.
[0459] It is for a donor-CU-UP, and the first IP address used by the donor-CU-UP to derive the first key is an IP address for establishing a user plane secure transmission channel. It should be understood that the donor-CU-UP may have multiple IP addresses. Before establishing a user plane secure transmission channel, the donor-CU-UP determines a first IP address among the multiple IP addresses, wherein the first IP address is for establishing a user plane secure transmission channel. For example, in a procedure in which a terminal device accesses a network through an IAB-DU, after receiving a bearer context setup request message from the donor-CU-CP, the donor-CU-UP determines a first IP address that is for the donor-CU-UP and is for establishing a user plane secure transmission channel.
[0460] The IP address of the IAB-DU is obtained from the donor-CU-CP by the donor-CU-UP. For example, in the procedure where a terminal device accesses the network via the IAB-DU, the bearer context modification request message transmitted from the donor-CU-CP to the donor-CU-UP includes the IP address of the IAB-DU.
[0461] The conditions for triggering the donor-CU-UP to determine the first key based on the first information are not limited to this embodiment of the application.
[0462] In the example, the donor-CU-UP can derive the first key when obtaining the IP address and first information of the IAB-DU.
[0463] In another example, the donor-CU-UP derives the first key when receiving the first instruction information.
[0464] Optionally, after determining the first key, the donor-CU-UP stores the correspondence between the first key and the IP address of the IAB-DU. For example, the correspondence between the first key and the IP address of the IAB-DU is stored within the context of the donor-CU-UP.
[0465] S730: Donor-CU-CP transmits the second message. Therefore, at S730, IAB-DU receives the second message.
[0466] The second message includes the first IP address of the donor-CU-UP. For example, the second message is a UE context setup request message. For example, when a terminal device accesses the network through the IAB-DU, the UE context setup request message is sent to the IAB-DU by the donor-CU-CP.
[0467] S740: IAB-DU acquires the first key.
[0468] For example, S740 includes S741a to S743a.
[0469] S741a: IAB-DU sends the first request message to IAB-MT.
[0470] The first request message includes the first IP address of the donor-CU-UP, and the first request message requests the first key.
[0471] After receiving the first request message from IAB-DU, IAB-MT derives the first key based on the intermediate key, the IP address of IAB-DU, and the first IP address of Donor-CU-UP.
[0472] For example, IAB-MT derives the first key by using an intermediate key as an input key and by using the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters.
[0473] Alternatively, IAB-MT derives a first key based on the user plane key, the IP address of IAB-DU, and the first IP address of donor-CU-UP.
[0474] For example, IAB-MT derives a first key by using a user plane key as an input key and by using the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters.
[0475] Alternatively, IAB-MT first derives a fourth key based on the user plane key, and then derives a first key based on the fourth key, the IP address of IAB-DU, and the first IP address of Donor-CU-UP.
[0476] For example, IAB-MT derives the first key by using the fourth key as an input key and by using the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters.
[0477] It can be understood that the IP address of IAB-DU is obtained from the OAM or Donor-CU-CP after IAB-MT has completed registration.
[0478] S742a: IAB-MT sends the first response message to IAB-DU.
[0479] The first response message includes the first key.
[0480] Accordingly, after receiving the first key, the IAB-DU stores the correspondence between the first key and the first IP address of the donor-CU-UP. For example, the IAB-DU stores the correspondence between the first key and the first IP address of the donor-CU-UP within the context of the IAB-DU.
[0481] As another example, S740 includes S741b to S743b.
[0482] S741b: IAB-DU sends a third request message to IAB-MT.
[0483] The third request message requests the second information, and the second information is as follows: intermediate key, K gNB It includes any one of the second parameter and the user plane key.
[0484] S742b: IAB-MT sends a third response message to IAB-DU.
[0485] The third response message includes the second information.
[0486] S743b: IAB-DU derives the first key.
[0487] If the second information includes an intermediate key, IAB-DU derives a first key based on the intermediate key, the IP address of IAB-DU, and the first IP address of Donor-CU-UP.
[0488] For example, IAB-DU derives the first key by using an intermediate key as an input key and by using the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters.
[0489] The second information is K gNB And in the case including the second parameter, IAB-DU first, K gNBAn intermediate key is derived based on the second parameter, and then a first key is derived based on the intermediate key as an input key, the IP address of IAB-DU, and the first IP address of Donor-CU-UP.
[0490] If the second information includes a user plane key, IAB-DU derives a first key based on the user plane key, IAB-DU's IP address, and the first IP address of the donor-CU-UP; or IAB-DU first derives a fourth key based on the user plane key, and then derives a first key based on the fourth key, IAB-DU's IP address, and the first IP address of the donor-CU-UP.
[0491] For example, IAB-DU derives the first key by using a user plane key as an input key and by using the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters; or derives the first key by using a fourth key as an input key and by using the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters.
[0492] It can be understood that the IP address of the IAB-DU is obtained from the IAB-MT after the IAB-DU has started.
[0493] Additionally, after deriving the first key, the IAB-DU stores the correspondence between the first key and the first IP address of the donor-CU-UP. For example, the IAB-DU stores the correspondence between the first key and the first IP address of the donor-CU-UP within the context of the IAB-DU.
[0494] It should be understood that the time for obtaining the first key by IAB-DU is not limited to this embodiment of this application.
[0495] In the example, IAB-DU acquires the first key when acquiring the first IP address of the donor-CU-UP.
[0496] In another example, the IAB-DU obtains a first key before initiating the user plane secure transmission channel setup procedure for the donor-CU-UP.
[0497] In another example, IAB-DU obtains the first key after receiving an authentication request message from Donor-CU-UP.
[0498] In another example, the IAB-DU obtains a first key after receiving a user plane data request message from a terminal device.
[0499] S760: The donor-CU-UP and IAB nodes establish a user plane secure transmission channel by using the first key.
[0500] Specifically, S760 is identical to S640 in the above-described method (600). For brevity, details are not described again in this specification.
[0501] In this embodiment of the application, Donor-CU-CP transmits first information for generating a first key to Donor-CU-UP, thereby enabling Donor-CU-UP to generate a first key based on the first information. Additionally, the IAB node also determines the first key in the same manner. When the same first key exists in Donor-CU-UP and IAB-DU, Donor-CU-UP and IAB-DU can establish a user plane secure transmission channel based on the first key to effectively avoid the problem of authentication errors generated when the Donor node and IAB-DU establish a user plane secure transmission channel. Additionally, the first key is K gNB Since it is different from, the requirements for first isolation and least privilege are satisfied, and key leakage is avoided.
[0502] Additionally, when the donor-CU-UP and IAB-DU use the intermediate key as an input key to derive the first key, the input key to derive the user plane key, the signaling plane key, and the first key can be maintained independently of each other, and data transmission security is guaranteed.
[0503] Alternatively, when the donor-CU-UP and IAB-DU use the user plane key as an input key to derive the first key, no additional signaling transmission is required, and the management and implementation of the first key are simplified.
[0504] Alternatively, when the donor-CU-UP and IAB-DU use a fourth key derived based on a user plane key as an input key to derive the first key, no additional signaling transmission is required, and the management and implementation of the first key are simplified.
[0505] The following uses FIGS. 8 to 11 as an example to explain a method for establishing a secure transmission channel according to an embodiment of this application. In the following embodiment, the first key is K IAB-CP It should be noted that it is represented as and the intermediate height is represented as km.
[0506] FIG. 8 is a schematic flowchart of a method for establishing a secure transmission channel according to an embodiment of the present application. As illustrated in FIG. 8, the method (800) includes S801 to S821. The steps are described in detail below.
[0507] S801: Perform the registration procedure for IAB-MT.
[0508] For example, the IAB-MT registration process includes the following steps.
[0509] Step 1: IAB-MT sends an RRC setup request message to the donor-DU.
[0510] Step 2: The donor-DU sends an initial uplink (UL) RRC message transfer to the donor-CU-CP.
[0511] Step 3: Donor-CU-CP sends a downlink (DL) message transfer to Donor-DU.
[0512] Step 4: IAB-DU sends an RRC setup message to IAB-MT.
[0513] In steps 1 through 4, the IAB node (the IAB-MT part within the IAB node) has some or all of the functions of the UE. After the IAB node is fed, the IAB-MT selects a donor that supports IAB services to access the donor and sets up wireless interface resources.
[0514] Step 5: IAB-MT sends an RRC setup complete message to the donor-DU.
[0515] The RRC setup complete message carries an IAB instruction, and the IAB instruction indicates that the current UE is an IAB node.
[0516] Step 6: Donor-DU sends the RRC message transmission to Donor-CU-CP.
[0517] The RRC message transmission carries an "IAB-instruction" information element. Based on the "IAB-instruction" information element, the donor-CU-CP selects an AMF network element that supports the IAB service.
[0518] Step 7: The donor-CU-CP sends an initial UE message to the AMF.
[0519] The initial UE message carries an "IAB-direction" information element.
[0520] Step 8: AMF sends an initial context setup request message to the donor-CU-CP.
[0521] The initial context setup request message carries an "IAB-authorized" instruction, and also the donor node's first root key ( Carries (represented as). After receiving the initial context setup request message, the donor-CU-CP carries the Stores it within the context of the IAB node.
[0522] In steps 7 and 8, the authentication process is performed between the core network and the IAB-MT. After successful authentication, the core network checks the subscription data to determine whether the IAB-MT belongs to an IAB node. If the IAB-MT belongs to an IAB node, an "IAB-authorized" instruction is transmitted to the donor-CU-CP, where the instruction indicates that the core network has authorized the IAB-MT as an IAB node. Therefore, after authentication between the core network and the IAB-MT is completed, the IAB-MT Creates.
[0523] Step 9: Donor-CU-CP sends a bearer context setup request message to Donor-CU-UP.
[0524] The bearer context setup request message carries user flat key #1.
[0525] After receiving an initial context setup request message from AMF, the donor-CU-CP selects a user plane algorithm, and A user plane key #1 is derived based on, wherein the user plane key #1 is intended to establish a bearer context. The user plane key #1 includes a user plane integrity protection key (represented as Kupenc) and / or a user plane cryptographic protection key (represented as Kupint).
[0526] User flat key #1 is It is a key derived from, and it should be noted that this procedure is irreversible. Therefore, after receiving User Plane Key #1, the Donor-CU-UP based on User Plane Key #1 ...cannot be obtained. In other words, in a Donor-CU-UP There is no.
[0527] Step 10: Donor-CU-UP sends a bearer context setup response message to Donor-CU-CP.
[0528] Step 11: The donor-CU-CP sends a UE context setup request message to the donor-DU.
[0529] Step 12: The donor-DU sends a security mode command to the IAB-MT.
[0530] Step 13: The donor-DU sends a UE context setup response message to the donor-CU-CP.
[0531] Step 14: Donor-CU-CP sends a bearer context modification request message to Donor-CU-UP.
[0532] Step 15: Donor-CU-UP sends a bearer context modification response message to Donor-CU-CP.
[0533] Step 16: IAB-MT sends security mode complete to Donor-DU.
[0534] Step 17: Donor-DU sends an uplink RRC message transfer (UL RRC message transfer) to Donor-CU-CP.
[0535] In steps 11 through 17, the donor-CU-CP and IAB-MT perform a security mode command procedure and negotiate the security algorithm and security key used.
[0536] Step 18: Donor-CU-CP sends a downlink RRC message to Donor-DU.
[0537] Step 19: The donor-DU sends an RRC reconfiguration message to the IAB-MT.
[0538] Step 20: The IAB-MT sends an RRC reconfiguration complete message to the donor-DU.
[0539] Step 21: Donor-DU sends an uplink RRC message to Donor-CU-CP.
[0540] In steps 18 through 21, the donor-CU-CP and IAB-MT perform the RRC reconfiguration procedure and complete the initial context setup procedure.
[0541] Step 22: The donor-CU-CP sends an initial context setup response message to the AMF.
[0542] S802: IAB-DU starts and sets up F1-C interface security with donor-CU-CP.
[0543] For example, after IAB-MT completes registration, IAB-MT obtains the IP address of IAB-DU and the IP address of Donor-CU-CP.
[0544] In the example, after establishing a PDU session with the OAM through the core network, the IAB-MT obtains the IP address of the IAB-DU and the IP address of the donor-CU-CP from the OAM by using the user plane.
[0545] In another example, IAB-MT obtains the IP address of IAB-DU and the IP address of the donor-CU-CP from the donor-CU-CP. Specifically, after establishing an IP connection to the OAM, the donor-CU-CP obtains the IP address of IAB-DU and the IP address of the donor-CU-CP from the OAM. Additionally, the donor-CU-CP sends an RRC message to IAB-MT, wherein the RRC message includes the IP address of IAB-DU and the IP address of the donor-CU-CP.
[0546] After obtaining the IP address of IAB-DU and the IP address of Donor-CU-CP, IAB-MT transmits the IP address of IAB-DU and the IP address of Donor-CU-CP to IAB-DU for use.
[0547] Optionally, IAB-MT also, By using as an input key, and by using the IP address of IAB-DU and the IP address of Donor-CU-CP as input parameters, K IAB-CP Derive , and K IAB-CP Send to IAB-DU.
[0548] Arbitrarily, IAB-MT is It transmits to the IAB-DU. Therefore, the IAB-DU By using as an input key, and by using the IP address of IAB-DU and the IP address of Donor-CU-CP as input parameters, K IAB-CP Derives.
[0549] Therefore, Doner-CU-CP also, By using as an input key, and by using the IP address of IAB-DU and the IP address of Donor-CU-CP as input parameters, K IAB-CP Derives.
[0550] IAB-DU and Donor-CU-CP negotiate to establish the F1-C interface and the secure transmission channel of F1-C. The authentication credential used in the procedure for IAB-DU and Donor-CU-CP to negotiate the establishment of the secure transmission channel of the F1-C interface is K IAB-CP am..
[0551] After the IAB-DU and the donor-CU-CP establish a secure transmission channel on the F1-C interface, the donor-CU-CP can configure parameters for the IAB-DU through the F1-C interface. After the donor-CU-CP configures parameters for the IAB-DU through the F1-C interface, the IAB-DU can provide mobile network services for the common UE.
[0552] After Donor-CU-CP and IAB-DU establish a secure transmission channel on the F1-C interface, Donor-CU-CP designates IAB-DU as the IAB node by using a first identifier and stores the first identifier as the context of the IAB node. Optionally, the first identifier is the IP address of IAB-DU.
[0553] S803: The UE accesses the network and performs authentication through the IAB-DU.
[0554] For example, S803 includes the following steps.
[0555] Step 1: The UE sends an RRC setup request message to the IAB-DU.
[0556] Step 2: IAB-DU sends an initial uplink RRC message to the donor-CU-CP.
[0557] Step 3: IAB-CU-CP sends the downlink message transmission to the donor-DU.
[0558] Step 4: The IAB-DU sends an RRC setup message to the UE.
[0559] In steps 1 through 4, after the UE is powered on, the UE selects a base station to access and sets up radio interface resources. The base station selected by the UE is the IAB-DU.
[0560] Step 5: The UE sends an RRC setup complete message to the IAB-DU.
[0561] Step 6: IAB-DU sends the RRC message transmission to Donor-CU-CP.
[0562] Step 7: The donor-CU-CP sends the initial UE message to the AMF.
[0563] Step 8: AMF sends an initial context setup request message to the donor-CU-CP.
[0564] In steps 5 through 8, the UE initiates the registration process, sets up the connection to the core network via the IAB-DU, and completes the authentication process. After authentication is completed, the AMF sends an initial context setup request message to the donor-CU-CP, wherein the initial context setup request message is the donor node's second root key ( Carries (represented as).
[0565] S804: Donor-CU-CP sends a bearer context setup request message to Donor-CU-UP.
[0566] After Donor-CU-CP receives an initial context setup request message from AMF, Donor-CU-CP is triggered to establish a bearer context. Donor-CU-CP sends a bearer context setup request message to Donor-CU-UP, where the bearer context setup request message carries User Plane Key #2, User Plane Key #2 is for interface user plane security protection between Donor-CU-UP and UE.
[0567] S805: Donor-CU-UP sends a bearer context setup response message to Donor-CU-CP.
[0568] The bearer context setup response message carries the first IP address of the donor-CU-UP, and the first IP address is intended to establish a secure transmission channel of the F1-U interface between the IAB-DU and the donor-CU-UP to transmit user plane data.
[0569] S806: Donor-CU-CP sends a UE context setup request message to IAB-DU.
[0570] The UE context setup request message includes the first IP address of the donor-CU-UP.
[0571] S807: IAB-DU sends a security mode command to the UE.
[0572] S808: IAB-DU sends the UE context setup response to the donor-CU-CP.
[0573] S809: IAB-DU is K IAB_UP Acquires.
[0574] For example, S809 includes S8091a to S8093a.
[0575] S8091a: IAB-DU sends the first request message to IAB-MT.
[0576] The first request message includes the first IP address of the donor-CU-UP, and the first request message is K IAB_UP Requests.
[0577] S8092a: IAB-MT is K IAB_UP Derives.
[0578] After receiving the first request message from IAB-DU, IAB-MT By using as an input key and by using the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters, K IAB-UP Derive , and K IAB-UPIt is transmitted to the IAB-DU. It can be understood that the IP address of the IAB-DU is obtained from the OAM or donor-CU-CP after the IAB-MT completes registration.
[0579] S8093a: IAB-MT sends the first response message to IAB-DU.
[0580] The first response message is K IAB_UP Includes
[0581] Therefore, K IAB_UP After receiving, IAB-DU K IAB_UP It stores. For example, IAB-DU is K IAB_UP The correspondence between the first IP address of the donor-CU-UP and the IAB-DU is stored in the context of the IAB-DU.
[0582] As another example, S809 includes S8091b to S8093b.
[0583] S8091b: IAB-DU sends the second request message to IAB-MT.
[0584] The second request message is Requests.
[0585] S8092b: IAB-MT sends a second response message to IAB-DU.
[0586] The second response message is Includes
[0587] It should be understood that S8091b and S8092b are optional steps. That is, IAB-DU When storing locally, S809 includes only S8093b. Stored locally by IAB-DU It is obtained from the IAB-MT before S809 is executed. For example, after the IAB-DU has started, when the IAB-MT transmits the IAB-DU's IP address to the IAB-DU Send to IAB-DU.
[0588] S8093b: IAB-DU is K IAB_UP Derives.
[0589] IAB-DU is By using as an input key and by using the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters, K IAB-UP It is derived. It can be understood that the IP address of the IAB-DU is obtained from the IAB-MT after the IAB-DU has started.
[0590] Additionally, K IAB_UP After deriving, IAB-DU is K IAB_UP It stores. For example, IAB-DU is K IAB_UP The correspondence between the first IP address of the donor-CU-UP and the IAB-DU is stored in the context of the IAB-DU.
[0591] K by IAB-DU IAB_UP It should be understood that the time for obtaining is not limited to this embodiment of this application.
[0592] In the example, when IAB-DU acquires the first IP address of Donor-CU-UP, K IAB_UP ...is obtained. For example, if S809 includes S8091a through S8093a, when IAB-DU obtains the first IP address of donor-CU-UP, it transmits a first request message to IAB-MT. As another example, if S809 includes S8091b through S8093b, when IAB-DU obtains the first IP address of donor-CU-UP, it transmits a second request message to IAB-MT or K IAB_UP Derives.
[0593] In another example, before initiating the IPsec setup procedure for the donor-CU-UP, K IAB_UP...is obtained. For example, if S809 includes S8091a through S8093a, the IAB-DU transmits a first request message to the IAB-MT before initiating the IPsec setup procedure for the donor-CU-UP. As another example, if S809 includes S8091b through S8093b, the IAB-DU transmits a second request message to the IAB-MT or K before initiating the IPsec setup procedure for the donor-CU-UP. IAB_UP Derives.
[0594] In another example, after IAB-DU receives an IPsec authentication request from donor-CU-UP, K IAB_UP ...is obtained. For example, if S809 includes S8091a through S8093a, IAB-DU transmits a first request message to IAB-MT after receiving an IPsec authentication request from Donor-CU-UP. As another example, if S809 includes S8091b through S8093b, IAB-DU transmits a second request message to IAB-MT or K after receiving an IPsec authentication request from Donor-CU-UP. IAB_UP Derives.
[0595] In another example, after receiving a user plane data request from the UE, K IAB_UP ...is obtained. For example, if S809 includes S8091a through S8093a, the IAB-DU transmits a first request message to the IAB-MT after receiving a user plane data request from the UE. As another example, if S809 includes S8091b through S8093b, the IAB-DU transmits a second request message to the IAB-MT or K after receiving a user plane data request from the UE. IAB_UP Derives.
[0596] S810: Doner-CU-CP is K IAB_UP Derives.
[0597] IAB-DU is By using as an input key and by using the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters, K IAB-UP Derives.
[0598] For example, after receiving a bearer context setup response message from donor-CU-UP, donor-CU-CP, based on the first IP address that is for donor-CU-UP and is included in the bearer context setup response message, K IAB_UP Derived. In other words, S810 can be performed after S805. Specifically, S810 can be performed after S805 and before S811.
[0599] As another example, after Donor-CU-CP determines that IAB-DU belongs to the IAB node, K IAB_UP ...is derived. As described in S802, the donor-CU-CP can indicate that IAB-DU belongs to the IAB node by using the first identifier, and can store the first identifier within the context of IAB-DU. Based on this, the donor-CU-CP K IAB_UP Before deriving, the donor-CU-CP may query whether the context of the IAB node contains the first identifier. If the context of the IAB node contains the first identifier, the donor-CU-CP determines that IAB-DU belongs to the IAB node; or if the context of the IAB node does not contain the first identifier, the donor-CU-CP determines that IAB-DU does not belong to the IAB node. Additionally, after determining that IAB-DU belongs to the IAB node, the donor-CU-CP K IAB_UP Derives.
[0600] S811: Donor-CU-CP sends a request message to modify the bearer context to Donor-CU-UP.
[0601] The bearer context modification request message contains the IAB-DU's IP address and K IAB_UP Includes
[0602] For example, K IAB_UP can be carried in the security information element included within the bearer context modification request message. As another example, K IAB_UP It can be carried in the newly defined information element within the bearer context modification request message.
[0603] Optionally, the bearer context modification request message further includes first instruction information, and the first instruction information indicates that the IAB-DU belongs to the IAB-node. For example, the first instruction information may be an independent information element. For example, the first instruction information is an "IAB-indicator" information element. As another example, the first instruction information is the IP address or K of the IAB-DU. IAB_UP It could be. That is, the IAB-DU's IP address or K IAB_UP It can also indicate that IAB-DU belongs to the IAB node.
[0604] In this embodiment of this application, Donor-CU-CP through a Bearer Context Modification Request Message K IAB_UP It should be understood that transmitting to Donor-CU-UP is used merely as an example for illustrative purposes and should not constitute any limitation to this embodiment of this application. For example, Donor-CU-CP alternatively, K through a newly defined message IAB_UP It can send to Donor-CU-UP. As another example, if Donor-CU-CP predicts the IP address of Donor-CU-UP before Donor-CU-UP sends the Bearer Context Setup Request message to Donor-CU-UP, Donor-CU-UP K before sending the Bearer Context Setup Request message. IAB_UPIt can derive, and through the bearer context setup request message K IAB_UP It can be transmitted to the donor-CU-UP.
[0605] S812: Doner-CU-UP is K IAB_UP Saves.
[0606] Donor-CU-UP has the IAB-DU's IP address and K IAB_UP The correspondence between them is stored within the context of the donor-CU-UP.
[0607] For example, Doner-CU-UP is K IAB_UP When receiving K IAB_UP Saves.
[0608] As another example, Donor-CU-UP is the first instruction information and K IAB_UP When receiving K IAB_UP Saves.
[0609] S813: Donor-CU-UP sends a bearer context modification response message to Donor-CU-CP.
[0610] S814: UE sends security mode completion to IAB-DU.
[0611] S815: IAB-DU sends an uplink RRC message to donor-CU-CP.
[0612] S816: Donor-CU-CP sends the downlink RRC message to IAB-DU.
[0613] S817: IAB-DU sends an RRC reconfiguration message to the UE.
[0614] S818: The UE sends an RRC reconfiguration complete message to the IAB-DU.
[0615] S819: IAB-DU sends an uplink RRC message to donor-CU-CP.
[0616] S820: The donor-CU-CP sends an initial context setup response message to the AMF.
[0617] S821: IAB-DU and Donor-CU-UP perform the IKEv2 PSK procedure.
[0618] Specifically, the F1-U interface bearer is established between IAB-DU and the donor-CU-UP, and IAB-DU and the donor-CU-UP negotiate and establish a secure transmission channel for the F1-U interface. For example, IAB-DU and the donor-CU-UP establish an IPsec secure transmission channel by utilizing the IKEv2 PSK protocol. In the first message exchange, IAB-DU and the donor-CU-UP complete IKE SA parameter negotiation in plaintext, which includes negotiation, encryption, and authentication algorithms, the exchange of temporary random numbers, and the DH exchange. In the second message exchange, IAB-DU and the donor-CU-UP K IAB_UP By using, authentication parameters are generated separately, and to complete identity authentication, the authentication parameters are transmitted to the peer end.
[0619] When the IAB-DU and Donor-CU-UP establish an IPsec secure transmission channel using the IKEv2 PSK protocol, the IAB-DU is stored within the context of the IAB-DU, and K IAB_UP Based on the correspondence between and the first IP address of the donor-CU-UP, K IAB_UP It is determined to use as an authentication credential used when an IPsec secure transmission channel is established, and the donor-CU-UP is stored within the context of the donor-CU-UP, and K IAB_UP Based on the correspondence between the IP addresses of and the IAB-DU, K IAB_UP It can be understood that it is decided to use as an authentication credential used when an IPsec secure transmission channel is established.
[0620] It should also be understood that the IKEv2 PSK procedure performed by IAB-DU and Donor-CU-UP can be triggered by IAB-DU or by Donor-CU-UP. For example, if the F1-U interface bearer between IAB-DU and Donor-CU-UP is not established when IAB-DU receives a user plane data request from the UE, IAB-DU triggers the IKEv2 PSK procedure. For another example, if the F1-U interface bearer between IAB-DU and Donor-CU-UP is not established when Donor-CU-UP receives downlink data from the UE, Donor-CU-UP triggers the IKEv2 PSK procedure.
[0621] It should also be understood that whether S821 is performed before or after the UE completes registration is not limited to this embodiment of this application. For example, S821 may be performed after S812. That is, S821 is performed when IAB-DU and Donor-CU-UP are K IAB_UP It can be performed after obtaining. As another example, S821 can be performed after S820. For example, after the UE has completed registration, S821 is performed when there is UE's user plane data for transmission.
[0622] FIG. 9 is a schematic flowchart of a method for establishing a secure transmission channel according to an embodiment of this application. As illustrated in FIG. 9, the method (900) includes S901 to S925. The steps are described in detail below.
[0623] S901: IAB-MT registers with the core network.
[0624] Specifically, in S901, steps 1 to 7 included in S801 of the above-described method (800) are performed.
[0625] S902: AMF sends an initial context setup request message to donor-CU-CP.
[0626] The initial context setup request message carries an "IAB-authorized" instruction, and also the donor node's first root key ( Carries (represented as). After receiving the initial context setup request message, the donor-CU-CP carries the It stores it within the context of the IAB node. The donor-CU-UP can also determine that the IAB-MT belongs to the IAB node based on "IAB-authorized".
[0627] The core network checks the subscription data to determine whether the IAB-MT belongs to the IAB node. If the IAB-MT belongs to the IAB node, the "IAB-authorized" instruction is transmitted to the donor-CU-CP, where the instruction indicates that the core network has authorized the IAB-MT as an IAB node. Therefore, after authentication between the core network and the IAB-MT is completed, the IAB-MT Creates.
[0628] S903: Donor-CU-CP sends a bearer context setup request message to Donor-CU-UP.
[0629] The bearer context setup request message carries user flat key #1.
[0630] After receiving an initial context setup request message from AMF, the donor-CU-CP selects a user plane algorithm, and A user plane key #1 is derived based on, wherein the user plane key #1 is intended to establish a bearer context. The user plane key #1 includes a user plane integrity protection key (represented as Kupenc) and / or a user plane cryptographic protection key (represented as Kupint).
[0631] User flat key #1 is It is a key derived from, and it should be noted that this procedure is irreversible. Therefore, after receiving User Plane Key #1, the Donor-CU-UP based on User Plane Key #1 ...cannot be obtained. In other words, in a Donor-CU-UP There is no.
[0632] The bearer context setup request message further includes first instruction information, and the first instruction information indicates that the IAB-MT belongs to the IAB-node. For example, the instruction information may be an independent information element. For example, the first instruction information is an "IAB-indicator" information element.
[0633] Specifically, when determining that IAB-MT belongs to an IAB node, the donor-CU-CP carries first instruction information in a bearer context setup request message. For example, if the initial context setup request message received by the donor-CU-CP from the AMF contains an "IAB-authorized" instruction, the donor-CU-CP determines that IAB-MT belongs to an IAB node. As another example, in S901, if the RRC message transmission received by the donor-CU-CP from the donor-DU contains an "IAB-instruction," the donor-CU-CP determines that IAB-MT belongs to an IAB node.
[0634] S904: Donor-CU-UP sends a bearer context setup response message to Donor-CU-CP.
[0635] The bearer context setup response message includes all possible IP addresses of the donor-CU-UP. Specifically, the donor-CU-UP reports all possible IP addresses to the donor-CU-CP based on the first instruction information included in the bearer context setup request message.
[0636] For example, if Donor-CU-UP has three IP addresses: CU-UP IP 1, CU-UP IP 2, and CU-UP IP 3, Donor-CU-UP reports the three IP addresses as Donor-CU-CP.
[0637] S905: Donor-CU-CP sends a UE context setup request message to Donor-DU.
[0638] S906: The donor-DU sends a security mode command to the IAB-MT.
[0639] S907: Donor-DU sends a UE context setup response message to Donor-CU-CP.
[0640] S908: Donor-CU-CP is possible K IAB_UP Derives.
[0641] As described above, Donor-CU-UP reports all possible IP addresses to Donor-CU-CP based on instruction information. Accordingly, in S908, Donor-CU-CP, based on the received first IP address of Donor-CU-UP, reports K corresponding to each IP address of Donor-CU-UP. IAB_UP Derives.
[0642] For example, Doner-CU-CP is By using as an input key and by using the IP address of the IAB-DU and CU-UP IP 1 as input parameters, K corresponding to CU-UP IP 1 IAB-UP 1 Deriving; Donor-CU-CP is By using as an input key and by using the IP address of the IAB-DU and CU-UP IP 2 as input parameters, the K corresponding to CU-UP IP 2 IAB-UP 2 Deriving; Donor-CU-CP is By using as an input key and by using the IP address of the IAB-DU and CU-UP IP 3 as input parameters, the K corresponding to CU-UP IP 3 IAB-UPDerivs 3.
[0643] It should be understood that S908 can be performed after S904, after S905, after S906, or after S907.
[0644] S909: Donor-CU-CP sends a bearer context modification request message to Donor-CU-UP.
[0645] The bearer context modification request message consists of multiple keys K derived by the donor-CU-CP. IAB-UP , and multiple keys K IAB-UP It includes a plurality of groups of first parameters corresponding to, and each key K IAB-UP One group of the first parameters corresponding to is K IAB-UP Includes input parameters for deriving.
[0646] For example, a bearer context modification request message is {K IAB-UP 1 , CU-UP 1, and IAB-DU IP}, {K IAB-UP 2 , CU-UP 2, and IAB-DU IP}, and {K IAB-UP 3 Includes , CU-UP 3, and IAB-DU IP}.
[0647] {K IAB-UP 1 , CU-UP 1, and IAB-DU IP} is both the IP address of IAB-DU and CU-UP IP 1 and K IAB-UP 1 Indicating the correspondence between; {K IAB-UP 2 , CU-UP 2, and IAB-DU IP} is both the IP address of IAB-DU and CU-UP IP 2 and K IAB-UP 2 Indicating the correspondence between; {K IAB-UP 3 , CU-UP 3, and IAB-DU IP} is both the IP address of IAB-DU and CU-UP IP 3 and K IAB-UP 3 Indicates the correspondence between.
[0648] S910: Doner-CU-UP is K IAB-UPSaves.
[0649] Specifically, Doner-CU-UP consists of multiple key Ks IAB-UP And, the correspondence between multiple groups of first parameters included in the bearer context modification request message is stored in the context of the donor-CU-UP.
[0650] S911: Donor-CU-UP sends a bearer context modification response message to Donor-CU-CP.
[0651] S912: IAB-MT completes the registration process.
[0652] Specifically, in S912, steps 16 to 22 included in S801 of the above-described method (800) are performed.
[0653] S913: IAB-DU starts and sets up F1-C interface security with donor-CU-CP.
[0654] Specifically, S913 is identical to S802 in the above-described method (800). For brevity, details are not described again in this specification.
[0655] S914: The UE accesses the network and performs authentication through the IAB-DU.
[0656] Specifically, S914 is identical to S803 in the above-described method (800). For brevity, details are not described again in this specification.
[0657] S915: Donor-CU-CP sends a bearer context setup request message to Donor-CU-UP.
[0658] Specifically, S915 is identical to S804 in the above-described method (800). For brevity, details are not described again in this specification.
[0659] S916: Donor-CU-UP sends a bearer context setup response message to Donor-CU-CP.
[0660] The bearer context setup response message carries the first IP address of the donor-CU-UP, and the first IP address is intended to establish a secure transmission channel of the F1-U interface between the IAB-DU and the donor-CU-UP to transmit user plane data. For example, the first IP address of the donor-CU-UP is CU-UP IP 3 in S904.
[0661] S917: Donor-CU-CP sends a UE context setup request message to IAB-DU.
[0662] The UE context setup request message includes the first IP address of the donor-CU-UP. For example, the first IP address of the donor-CU-UP is CU-UP IP 3 in S904.
[0663] S918: IAB-DU sends a security mode command to the UE.
[0664] S919: IAB-DU sends the UE context setup response to the donor-CU-CP.
[0665] S920: IAB-DU is K IAB_UP Acquires.
[0666] Specifically, IAB_DU is K IAB_UP For the method of obtaining, refer to the explanation in S809 of the above-described method (800). As described in S917, this pertains to the donor-CU-UP, and the first IP address received by the IAB-DU is CU-UP IP 3. In this case, at S920, K obtained by the IAB-DU IAB_UP Is It is derived by using as an input key and by using the IAB-DU IP address and CU-UP IP 3 as input parameters. That is, the K obtained by the IAB-DU IAB_UP is K in S908 IAB_UP 3 am.
[0667] S921: Donor-CU-CP sends a request message to modify the bearer context to Donor-CU-UP.
[0668] The bearer context modification request message includes the IP address of the IAB-DU.
[0669] S922: Donor-CU-UP sends a bearer context modification response message to Donor-CU-CP.
[0670] S923: Doner-CU-UP is K IAB_UP Search for.
[0671] Specifically, based on the first IP address for the donor-CU-UP, which is determined in S916 and is intended to establish a secure transmission channel of the F1-U interface between the IAB-DU and the donor-CU-UP, and the IP address for the IAB-DU, which is received in S921, the corresponding K IAB_UP For , the context stored locally by the donor-CU-UP is retrieved. For example, if the first IP address determined by the donor-CU-UP in S916 and intended to establish a secure transmit channel of the F1-U interface is CU-UP IP 3, the donor-CU-UP retrieves a plurality of keys K IAB_UP Based on the stored correspondence between and multiple groups of the first parameter, K IAB_UP 3 It is determined that this corresponds to the address of the IAB-DU and the CU-UP IP 3.
[0672] K IAB_UP 3 After determining, the donor-CU-UP uses the IAB-DU's IP address and K IAB_UP 3 The correspondence between them is stored within the context of the donor-CU-UP.
[0673] S924: The UE completes the registration procedure.
[0674] Specifically, in S924, S814 to S820 in the above-described method (800) are performed.
[0675] S925: IAB-DU and Donor-CU-UP perform the IKEv2 PSK procedure.
[0676] Specifically, S925 is identical to S821 in the above-described method (800). For brevity, details are not described again in this specification.
[0677] FIG. 10 is a schematic flowchart of a method for establishing a secure transmission channel according to an embodiment of the present application. As illustrated in FIG. 10, the method (1000) includes S1001 to S1023. The steps are described in detail below.
[0678] S1001: IAB-MT registers with the core network.
[0679] Specifically, in S1001, steps 1 to 7 included in S801 of the above-described method (800) are performed.
[0680] S1002: AMF sends an initial context setup request message to donor-CU-CP.
[0681] Specifically, S1002 is identical to S902 in the above-described method (900). For brevity, details are not described further in this specification.
[0682] S1003: Donor-CU-CP sends a bearer context setup request message to Donor-CU-UP.
[0683] The bearer context setup request message carries user flat key #1 and intermediate key (represented as Km).
[0684] After receiving an initial context setup request message from AMF, the donor-CU-CP selects a user plane algorithm, and A user plane key #1 is derived based on, wherein the user plane key #1 is intended to establish a bearer context. The user plane key #1 includes a user plane integrity protection key (represented as Kupenc) and / or a user plane cryptographic protection key (represented as Kupint).
[0685] User flat key #1 is It is a key derived from, and it should be noted that this procedure is irreversible. Therefore, after receiving User Plane Key #1, the Donor-CU-UP based on User Plane Key #1 ...cannot be obtained. In other words, in a Donor-CU-UP There is no.
[0686] Km is K IAB_UP It is used as an input key to generate, and K IAB_UP It is intended to generate. For example, Km is and is derived based on the second parameter. The second parameter includes one or more of the following: PCI, ARFCN-DL, auxiliary node counter, constant, and freshness parameter. For another example, Km is a random number generated by the donor-CU-UP.
[0687] Optionally, when it is determined that IAB-MT belongs to the IAB node, Donor-CU-CP generates Km or transmits Km to Donor-CU-UP. For example, if an initial context setup request message received by Donor-CU-CP from AMF contains an "IAB-authorized" instruction, Donor-CU-CP determines that IAB-MT belongs to the IAB node. As another example, in S901, if an RRC message transmission received by Donor-CU-CP from Donor-DU contains an IAB instruction, Donor-CU-CP determines that IAB-MT belongs to the IAB node.
[0688] Optionally, the bearer context setup request message further includes first instruction information, and the first instruction information indicates that the IAB-MT belongs to the IAB-node. For example, the first instruction information may be an independent information element. For example, the first instruction information is the "IAB-indicator" information element. As another example, the first instruction information is Km. That is, Km also indicates that the IAB-MT belongs to the IAB-node.
[0689] Specifically, when IAB-MT determines that it belongs to the IAB node, the donor-CU-CP carries first instruction information in the bearer context setup request message.
[0690] S1004: Donor-CU-UP stores km.
[0691] For example, Donor-CU-UP stores Km within the context of Donor-CU-UP.
[0692] Optionally, if the bearer context setup request message further includes first instruction information, in S1004, the donor-CU-UP also stores the first instruction information.
[0693] S1005: Donor-CU-UP sends a bearer context setup response message to Donor-CU-CP.
[0694] S1006: IAB-MT completes AS security activation.
[0695] Specifically, in S1006, steps 11 to 17 included in S801 of the above-described method (800) are performed.
[0696] S1007: Donor-CU-CP sends a downlink RRC message to Donor-DU.
[0697] The RRC message transmission includes an RRC reconstruction message. Optionally, in S1003, if Km generated by the donor-CU-CP is a random number, the RRC reconstruction message includes Km.
[0698] Alternatively, in S1003, if the second parameter used by the donor-CU-CP to generate Km includes a parameter unknown to the IAB-MT, the RRC reconstruction message includes Km, or a parameter within the second parameter for generating Km that is unknown to the IAB-MT. For example, the second parameter used by the donor-CU-CP to generate Km includes a random number and a PCI, where the random number is a parameter unknown to the IAB-MT and the PCI is a parameter known to the IAB-MT. In this case, the donor-CU-CP carries Km, or the random number included within the second parameter, in the RRC reconstruction message.
[0699] S1008: The donor-DU sends an RRC reconfiguration message to the IAB-MT.
[0700] The Donor-DU transmits the RRC reconfiguration message included within the downlink RRC message transmission to the IAB-MT.
[0701] S1009: IAB-MT stores Km, or a parameter within a second parameter for generating Km that is unknown to IAB-MT.
[0702] If the RRC reconstruction information received by the IAB-MT includes Km, or a parameter within a second parameter for generating Km that is unknown to the IAB-MT, the IAB-MT stores Km, or a parameter within a second parameter for generating Km that is unknown to the IAB-MT.
[0703] S1010: IAB-MT completes registration.
[0704] Specifically, in S1010, steps 20 to 22 included in S801 of the above-described method (800) are performed.
[0705] S1011: IAB-DU starts and sets up F1-C interface security with donor-CU-CP.
[0706] Specifically, S913 is identical to S802 in the above-described method (800). For brevity, details are not described again in this specification.
[0707] S1012: The UE accesses the network and performs authentication through the IAB-DU.
[0708] Specifically, S1012 is identical to S803 in the above-described method (800). For brevity, details are not described further in this specification.
[0709] S1013: Donor-CU-CP sends a bearer context setup request message to Donor-CU-UP.
[0710] Specifically, S1013 is identical to S804 in the above-described method (800). For brevity, details are not described further in this specification.
[0711] S1014: Donor-CU-UP sends a bearer context setup response message to Donor-CU-CP.
[0712] The bearer context setup response message carries the first IP address of the donor-CU-UP, and the first IP address is intended to establish a secure transmission channel of the F1-U interface between the IAB-DU and the donor-CU-UP to transmit user plane data.
[0713] S1015: Donor-CU-CP sends a UE context setup request message to IAB-DU.
[0714] The UE context setup request message includes the first IP address of the donor-CU-UP.
[0715] S1016: IAB-DU sends a security mode command to the UE.
[0716] S1017: IAB-DU sends a UE context setup response message to donor-CU-CP.
[0717] S1018: IAB-DU is K IAB_UP Acquires.
[0718] For example, S1018 includes S10181a to S10183a.
[0719] S10181a: IAB-DU sends the first request message to IAB-MT.
[0720] The first request message includes the first IP address of the donor-CU-UP, and the first request message is K IAB_UP Requests.
[0721] S10182a: IAB-MT is K IAB_UP Derives.
[0722] After receiving the first request message from IAB-DU, IAB-MT uses Km as an input key and uses the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters K IAB-UP Derive , and K IAB-UP It is transmitted to the IAB-DU. It can be understood that the IP address of the IAB-DU is obtained from the OAM or donor-CU-CP after the IAB-MT completes registration.
[0723] S10183a: IAB-MT sends the first response message to IAB-DU.
[0724] The first response message is K IAB_UP Includes
[0725] Therefore, K IAB_UP After receiving, IAB-DU K IAB_UP It stores. For example, IAB-DU is K IAB_UP The correspondence between the first IP address of the donor-CU-UP and the IAB-DU is stored in the context of the IAB-DU.
[0726] As another example, S1018 includes S10181b to S10183b.
[0727] S10181b: IAB-DU sends a third request message to IAB-MT.
[0728] The third request message requests Km, or and request the second parameter.
[0729] S10182b: IAB-MT sends a third response message to IAB-DU.
[0730] The third response message includes Km, or and includes a second parameter.
[0731] S10183b: IAB-DU is K IAB_UP Derives.
[0732] In the case where the third response message includes Km, IAB-DU uses Km as an input key and uses the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters K IAB-UP It is derived. It can be understood that the IP address of the IAB-DU is obtained from the IAB-MT after the IAB-DU has started.
[0733] The third response message and in the case including the second parameter, IAB-DU first, and derive Km based on the second parameter, and then, by using Km as an input key and using the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters, K IAB-UP Derives.
[0734] Additionally, K IAB_UP After deriving, IAB-DU is K IAB_UP It stores. For example, IAB-DU is K IAB_UPThe correspondence between the first IP address of the donor-CU-UP and the IAB-DU is stored in the context of the IAB-DU.
[0735] K by IAB-DU IAB_UP It should be understood that the time for obtaining is not limited to this embodiment of this application.
[0736] In the example, when IAB-DU acquires the first IP address of Donor-CU-UP, K IAB_UP Acquires.
[0737] In another example, before initiating the IPsec setup procedure for the donor-CU-UP, K IAB_UP Acquires.
[0738] In another example, after IAB-DU receives an IPsec authentication request from donor-CU-UP, K IAB_UP Acquires.
[0739] In another example, after receiving a user plane data request from the UE, K IAB_UP Acquires.
[0740] S1019: Donor-CU-CP sends a bearer context modification request message to Donor-CU-UP.
[0741] The bearer context modification request message includes the IP address of the IAB-DU.
[0742] S1020: Donor-CU-UP sends a bearer context modification response message to Donor-CU-CP.
[0743] S1021: Doner-CU-UP is K IAB_UP Derives.
[0744] The donor-CU-UP uses Km as an input key and uses the IP address of the IAB-DU and the first IP address of the donor-CU-UP as input parameters, thereby K IAB-UP Derives.
[0745] Km is obtained from the context stored locally in the donor-CU-UP. The first IP address of the donor-CU-UP is determined in S1014.
[0746] K IAB_UP After deriving, the donor-CU-UP uses the IAB-DU's IP address and K IAB_UP The correspondence between them is stored within the context of the donor-CU-UP.
[0747] S1022: UE completes the registration procedure.
[0748] Specifically, in S1022, S814 to S820 in the above-described method (800) are performed.
[0749] S1023: IAB-DU and Donor-CU-UP perform the IKEv2 PSK procedure.
[0750] Specifically, S1023 is identical to S821 in the above-described method (800). For brevity, details are not described again in this specification.
[0751] FIG. 11 is a schematic flowchart of a method for establishing a secure transmission channel according to an embodiment of the present application. As illustrated in FIG. 11, the method (1100) includes S1101 to S1114. The steps are described in detail below.
[0752] S1101: Perform the registration procedure for IAB-MT.
[0753] Specifically, S1101 is identical to S801 in the above-described method (800). For brevity, details are not described further in this specification.
[0754] In S1001, after authentication between the IAB-MT and the core network is completed, the initial context setup request message sent by the AMF to the donor-CU-CP is the donor node's first root key ( Includes (represented as). Additionally, Donor-CU-CP is Based on this, derive User Plane Key #1 and transmit User Plane Key #1 to the donor-CU-UP. User Plane Key #1 is intended to establish a bearer context. User Plane Key #1 includes a User Plane integrity protection key (represented as Kupenc) and / or a User Plane cryptographic protection key (represented as Kupint).
[0755] Therefore, after authentication between the IAB-MT and the core network is completed, the IAB-MT It generates, and IAB-MT is User Plane Key #1 can be derived based on this.
[0756] S1102: IAB-DU starts and sets up F1-C interface security with donor-CU-CP.
[0757] Specifically, S1102 is identical to S802 in the above-described method (800). For brevity, details are not described further in this specification.
[0758] It should be noted that after Donor-CU-CP and IAB-DU establish a secure transmission channel on the F1-C interface, Donor-CU-CP designates IAB-DU as the IAB node by using a first identifier and stores the first identifier as the context of the IAB node. Optionally, the first identifier is the IP address of IAB-DU.
[0759] S1103: The UE accesses the network and performs authentication through the IAB-DU.
[0760] Specifically, S1103 is identical to S803 in the above-described method (800). For brevity, details are not described again in this specification.
[0761] S1104: Donor-CU-CP sends a bearer context setup request message to Donor-CU-UP.
[0762] S1105: Donor-CU-UP sends a bearer context setup response message to Donor-CU-CP.
[0763] The bearer context setup response message carries the first IP address of the donor-CU-UP, and the first IP address is intended to establish a secure transmission channel of the F1-U interface between the IAB-DU and the donor-CU-UP to transmit user plane data.
[0764] S1106: Donor-CU-CP sends a UE context setup request message to IAB-DU.
[0765] The UE context setup request message includes the first IP address of the donor-CU-UP.
[0766] S1107: IAB-DU sends a security mode comment to the UE.
[0767] S1108: IAB-DU sends the UE context setup response to the donor-CU-CP.
[0768] S1109: IAB-DU is K IAB_UP Acquires.
[0769] For example, S1109 includes S11091a to S11093a.
[0770] S11091a: IAB-DU sends the first request message to IAB-MT.
[0771] The first request message includes the first IP address of the donor-CU-UP, and the first request message is K IAB_UP Requests.
[0772] S11092a: IAB-MT is K IAB_UP Derives.
[0773] After receiving the first request message from IAB-DU, IAB-MT uses user plane key #1 as an input key and uses the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters KIAB-UP Derive , and K IAB-UP It is transmitted to the IAB-DU. It can be understood that the IP address of the IAB-DU is obtained from the OAM or donor-CU-CP after the IAB-MT completes registration.
[0774] Alternatively, IAB-MT uses a key derived from user plane key #1 as an input key, and uses the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters, thereby K IAB-UP Derives.
[0775] S11093a: IAB-MT sends the first response message to IAB-DU.
[0776] The first response message is K IAB_UP Includes
[0777] Therefore, K IAB_UP After receiving, IAB-DU K IAB_UP It stores. For example, IAB-DU is K IAB_UP The correspondence between the first IP address of the donor-CU-UP and the IAB-DU is stored in the context of the IAB-DU.
[0778] In addition, S1109 includes S11091b to S11093b.
[0779] S11091b: IAB-DU sends a third request message to IAB-MT.
[0780] The third request message requests user flat key #1.
[0781] S11092b: IAB-MT sends a third response message to IAB-DU.
[0782] The third response message includes user flat key #1.
[0783] It should be understood that S11091b and S11092b are optional steps. That is, IAB-DU When storing in a local manner, S1109 includes only S11093b. That is, IAB-DU is stored in a local manner User flat key #1 can be derived based on. Stored locally by IAB-DU is obtained from the IAB-MT before S1109 is executed. For example, after the IAB-DU has started, when the IAB-MT transmits the IAB-DU's IP address to the IAB-DU Send to IAB-DU.
[0784] S11093b: IAB-DU is K IAB_UP Derives.
[0785] IAB-DU uses User Plane Key #1 as an input key, and uses the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters, K IAB-UP It is derived. It can be understood that the IP address of the IAB-DU is obtained from the IAB-MT after the IAB-DU has started.
[0786] IAB-DU uses the key derived from User Plane Key #1 as an input key, and uses the IP address of IAB-DU and the first IP address of Donor-CU-UP as input parameters, thereby K IAB-UP Derives.
[0787] Additionally, K IAB_UP After deriving, IAB-DU is K IAB_UP It stores. For example, IAB-DU is K IAB_UP The correspondence between the first IP address of the donor-CU-UP and the IAB-DU is stored in the context of the IAB-DU.
[0788] K by IAB-DU IAB_UP It should be understood that the time for obtaining is not limited to this embodiment of this application.
[0789] In the example, when IAB-DU acquires the first IP address of Donor-CU-UP, K IAB_UP Acquires.
[0790] In another example, before initiating the IPsec setup procedure for the donor-CU-UP, K IAB_UP Acquires.
[0791] In another example, after IAB-DU receives an IPsec authentication request from donor-CU-UP, K IAB_UP Acquires.
[0792] In another example, after receiving a user plane data request from the UE, K IAB_UP Acquires.
[0793] S1110: Donor-CU-CP sends a bearer context modification request message to Donor-CU-UP.
[0794] The bearer context modification request message includes the IP address of the IAB-DU.
[0795] Optionally, the bearer context modification request message further includes first instruction information, and the first instruction information indicates that the IAB-DU belongs to the IAB-node. For example, the first instruction information may be an independent information element. For example, the first instruction information is an "IAB-indicator" information element. As another example, the first instruction information may be the IP address of the IAB-DU. That is, the IP address of the IAB-DU may also indicate that the IAB-DU belongs to the IAB-node.
[0796] Specifically, when determining that IAB-DU belongs to an IAB node, the donor-CU-CP carries first instruction information in a bearer context modification request message. As described in S1102, the donor-CU-CP can indicate that IAB-DU belongs to an IAB node by using the first identifier and can store the first identifier within the context of IAB-DU. Based on this, the donor-CU-CP can query whether the context of the IAB node contains the first identifier. If the context of the IAB node contains the first identifier, the donor-CU-CP determines that IAB-DU belongs to an IAB node; or if the context of the IAB node does not contain the first identifier, the donor-CU-CP determines that IAB-DU does not belong to an IAB node.
[0797] S1111: Doner-CU-UP is K IAB_UP Derives.
[0798] The donor-CU-UP utilizes the user plane key as an input key and utilizes the IP address of the IAB-DU and the first IP address of the donor-CU-UP as input parameters, thereby K IAB-UP Derives.
[0799] Alternatively, the donor-CU-UP uses a key derived from the user plane key as an input key, and uses the IP address of the IAB-DU and the first IP address of the donor-CU-UP as input parameters, thereby K IAB-UP Derives.
[0800] For example, after receiving a bearer context setup request message from Donor-CU-UP, Donor-CU-UP, based on the first IP address that is for Donor-CU-UP and is included in the bearer context setup response message, K IAB-UP Derives.
[0801] As another example, where the bearer context setup request message includes first instruction information, Donor-CU-UP is K based on the first IP address included in the bearer context setup response message, which is for Donor-CU-UP. IAB-UP It derives. In other words, after the donor-CU-UP determines that IAB-DU belongs to the IAB node based on the first instruction information, K IAB-UP Derives.
[0802] K IAB_UP After deriving, the donor-CU-UP uses the IAB-DU's IP address and K IAB_UP The correspondence between them is stored within the context of the donor-CU-UP.
[0803] S1112: Donor-CU-UP sends a bearer context modification response message to Donor-CU-CP.
[0804] S1113: UE completes the registration procedure.
[0805] Specifically, in S1113, S814 to S820 in the above-described method (800) are performed.
[0806] S1114: IAB-DU and Donor-CU-UP perform the IKEv2 PSK procedure.
[0807] Specifically, S1114 is identical to S821 in the above-described method (800). For brevity, details are not described again in this specification.
[0808] Referring to FIGS. 5 through 11, the foregoing describes in detail a method provided in an embodiment of this application. Referring to FIGS. 12 and 13, the following describes in detail a communication device provided in an embodiment of this application. It should be understood that the description of the device embodiment corresponds to the description of the method embodiment. Therefore, for details not described in detail, refer to the method embodiment described above. For brevity, details are not described again in this specification.
[0809] In the embodiments of this application, the division of a transmitting device or a receiving device may be divided into functional modules based on the method example described above. For example, each functional module may be obtained through a division corresponding to each function, or two or more functions may be integrated within a single processing module. The integrated module may be implemented in the form of hardware or in the form of a software functional module. It should be noted that in the embodiments of this application, the division into modules is an example and is merely a logical functional division. Other division methods may be used during actual implementation. Description is provided below by using an example in which each functional module is obtained through a division corresponding to each function.
[0810] FIG. 12 is a schematic block diagram of a communication device (1200) according to an embodiment of this application. As shown in the drawing, the communication device (1200) may include a transceiver unit (1210) and a processing unit (1220).
[0811] In a possible design, the communication device (1200) may be a donor-CU-UP in the above-described method embodiment, or a chip configured to implement the function of a donor-CU-UP in the above-described method embodiment.
[0812] It should be understood that the communication device (1200) may correspond to the session management network element in the method (500) to the method (1100) according to the embodiment of this application. The communication device (1200) may include a unit configured to perform the method performed by the donor-CU-UP in the method (500) of FIG. 5, the method (600) of FIG. 6, the method (700) of FIG. 7, the method (800) of FIG. 8, the method (900) of FIG. 9, the method (1000) of FIG. 10, and the method (1100) of FIG. 11. Additionally, the unit in the communication device (1200) and the other operations and / or functions described above are intended to separately implement the corresponding procedures in the method (500) of FIG. 5, the method (600) of FIG. 6, the method (700) of FIG. 7, the method (800) of FIG. 8, the method (900) of FIG. 9, the method (1000) of FIG. 10, and the method (1100) of FIG. 11. It should be understood that the specific process by which the unit performs the corresponding steps described above has been described in detail in the method embodiments described above. For brevity, details are not described again in this specification.
[0813] In another possible design, the communication device (1200) may be the donor-CU-CP in the above-described method embodiment, or a chip configured to implement the function of the donor-CU-CP in the above-described method embodiment.
[0814] It should be understood that the communication device (1200) may correspond to the donor-CU-CP in the method (500) to the method (1100) according to the embodiment of this application. The communication device (1200) may include a unit configured to perform the method performed by the donor-CU-CP in the method (500) of FIG. 5, the method (600) of FIG. 6, the method (700) of FIG. 7, the method (800) of FIG. 8, the method (900) of FIG. 9, the method (1000) of FIG. 10, and the method (1100) of FIG. 11. Additionally, the unit in the communication device (1200) and the other operations and / or functions described above are intended to separately implement the corresponding procedures in the method (500) of FIG. 5, the method (600) of FIG. 6, the method (700) of FIG. 7, the method (800) of FIG. 8, the method (900) of FIG. 9, the method (1000) of FIG. 10, and the method (1100) of FIG. 11. It should be understood that the specific process by which the unit performs the corresponding steps described above has been described in detail in the method embodiments described above. For brevity, details are not described again in this specification.
[0815] In another possible design, the communication device (1200) may be the IAB-DU in the above-described method embodiment, or a chip configured to implement the function of the IAB-DU in the above-described method embodiment.
[0816] It should be understood that the communication device (1200) may correspond to the IAB-DU in the methods (500) to (1100) according to the embodiments of this application. The communication device (1200) may include a unit configured to perform the method performed by the IAB-DU in the method (500) of FIG. 5, the method (600) of FIG. 6, the method (700) of FIG. 7, the method (800) of FIG. 8, the method (900) of FIG. 9, the method (1000) of FIG. 10, and the method (1100) of FIG. 11. Additionally, the unit in the communication device (1200) and the other operations and / or functions described above are intended to separately implement the corresponding procedures in the method (500) of FIG. 5, the method (600) of FIG. 6, the method (700) of FIG. 7, the method (800) of FIG. 8, the method (900) of FIG. 9, the method (1000) of FIG. 10, and the method (1100) of FIG. 11. It should be understood that the specific process by which the unit performs the corresponding steps described above has been described in detail in the method embodiments described above. For brevity, details are not described again in this specification.
[0817] In another possible design, the communication device (1200) may be an IAB-MT in the above-described method embodiment, or a chip configured to implement the function of an IAB-MT in the above-described method embodiment.
[0818] It should be understood that the communication device (1200) may correspond to the IAB-MT in the methods (500) to (1100) according to the embodiments of this application. The communication device (1200) may include a unit configured to perform the method performed by the IAB-MT in the method (500) of FIG. 5, the method (600) of FIG. 6, the method (700) of FIG. 7, the method (800) of FIG. 8, the method (900) of FIG. 9, the method (1000) of FIG. 10, and the method (1100) of FIG. 11. Additionally, the unit in the communication device (1200) and the other operations and / or functions described above are intended to separately implement the corresponding procedures in the method (500) of FIG. 5, the method (600) of FIG. 6, the method (700) of FIG. 7, the method (800) of FIG. 8, the method (900) of FIG. 9, the method (1000) of FIG. 10, and the method (1100) of FIG. 11. It should be understood that the specific process by which the unit performs the corresponding steps described above has been described in detail in the method embodiments described above. For brevity, details are not described again in this specification.
[0819] It should also be understood that the transceiver unit (1210) in the communication device (1200) may correspond to the transceiver (1320) in the communication device (1300) illustrated in FIG. 13, and the processing unit (1220) in the communication device (1200) may correspond to the processor (1310) in the communication device (1300) illustrated in FIG. 13.
[0820] It should also be understood that when the communication device (1200) is a chip, the chip includes a transceiver unit and a processing unit. The transceiver unit may be an input / output circuit or a communication interface. The processing unit may be a processor, a microprocessor, or an integrated circuit integrated on the chip.
[0821] The transceiver unit (1210) is configured to implement signal reception and transmission operations of the communication device (1200), and the processing unit (1220) is configured to implement signal processing operations of the communication device (1200).
[0822] Optionally, the communication device (1200) further includes a storage unit (1230), and the storage unit (1230) is configured to store commands.
[0823] FIG. 13 is a schematic block diagram of a communication device (1300) according to an embodiment of this application. As illustrated in the drawing, the communication device (1300) comprises at least one processor (1310) and a transceiver (1320). The processor (1310) is coupled to a memory and is configured to execute instructions stored in the memory to control the transceiver (1320) to transmit a signal and / or receive a signal. Optionally, the communication device (1300) further comprises a memory (1330) configured to store instructions.
[0824] It should be understood that the processor (1310) and memory (1330) can be integrated into a single processing unit. The processor (1310) is configured to execute program code stored in the memory (1330) to implement the above-mentioned function. In a specific implementation, the memory (1330) may alternatively be integrated into the processor (1310) or be independent of the processor (1310).
[0825] It should also be understood that the transceiver (1320) may include a receiver (also referred to as a receiver) and a transmitter (also referred to as a transmitter). The transceiver (1320) may further include an antenna. There may be one or more antennas. The transceiver (1320) may be a communication interface or an interface circuit.
[0826] When the communication device (1300) is a chip, the chip includes a transceiver unit and a processing unit. The transceiver unit may be an input / output circuit or a communication interface. The processing unit may be a processor, a microprocessor, or an integrated circuit integrated on the chip. Embodiments of this application further provide a processing device comprising a processor and an interface. The processor may be configured to perform the method of the above-described method embodiment.
[0827] It should be understood that the processing unit may be a chip. For example, the processing unit may be a field-programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processing unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD), or another integrated chip.
[0828] In the implementation process, the steps of the method described above may be completed by utilizing integrated logic circuits of hardware within the processor or by utilizing instructions in the form of software. The steps of the method disclosed with reference to the embodiments of this application may be performed and completed directly by a hardware processor, or may be performed and completed by utilizing a combination of hardware and software modules within the processor. The software modules may be located within a storage medium mature in the art, such as random access memory, flash, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. The storage medium is located within memory, and the processor reads information within memory and completes the steps of the method described above in combination with the hardware of the processor. To avoid repetition, details are not described again in this specification.
[0829] It should be noted that the processor in the embodiments of this application may be an integrated circuit chip and possesses signal processing capabilities. In the implementation process, the steps in the above method embodiments may be completed by utilizing integrated logic circuits of hardware within the processor or by utilizing instructions in the form of software. The processor may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or another programmable logic device, an individual gate or transistor logic device, or an individual hardware component. The processor may implement or perform the methods, steps, and logical block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc. The steps in the method disclosed with reference to the embodiments of this application may be performed and completed directly by a hardware decoding processor, or may be performed and completed by utilizing a combination of hardware and software modules within the decoding processor. The software module may be located within a storage medium mature in the art, such as random access memory, flash, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. The storage medium is located within memory, and a processor reads information within memory and, in combination with the processor's hardware, completes the steps of the method described above.
[0830] It may be understood that the memory in the embodiments of this application may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash. The volatile memory may be random access memory (RAM) used as an external cache. Many forms of RAMs, for example, static random access memory (static RAM, SRAM), dynamic random access memory (dynamic RAM, DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchlink dynamic random access memory (synchlink DRAM, SLDRAM), and direct rambus random access memory (direct rambus RAM, DR RAM) may be used. It should be noted that the memory in the system and method of this specification is intended to include these and any other suitable type of memory, but is not limited thereto.
[0831] According to the method provided in the embodiments of this application, this application further provides a computer program product. The computer program product includes computer program code. When the computer program code is operated on a computer, the computer becomes capable of performing the method in any one of the embodiments illustrated in FIGS. 5 through 11.
[0832] According to the method provided in the embodiments of this application, this application further provides a computer-readable medium. The computer-readable medium stores program code. When the computer program code is operated on a computer, the computer becomes capable of performing the method in any one of the embodiments illustrated in FIGS. 5 through 11.
[0833] According to the method provided in the embodiments of this application, this application also provides a system comprising the above-mentioned donor-CU-CP, donor-CU-UP, IAB-DU, and IAB-MT.
[0834] All or part of the above embodiments may be implemented by using software, hardware, firmware, or any combination thereof. When software is used to implement the embodiments, all or part of the embodiments may be implemented in the form of a computer program product. A computer program product comprises one or more computer instructions. When computer instructions are loaded and executed on a computer, a procedure or function according to an embodiment of this application is created in whole or in part. The computer may be a general-purpose computer, a dedicated computer, a computer network, or another programmable device. Computer instructions may be stored in a computer-readable storage medium or transmitted from a computer-readable storage medium to another computer-readable storage medium. For example, computer instructions may be transmitted from a website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, fiber optic, or digital subscriber line (DSL)) or wireless (e.g., infrared, radio, or microwave) method. A computer-readable storage medium may be any available medium accessible by a computer or data storage device, such as a server or data center, that incorporates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disk drives, or magnetic tapes), optical media (e.g., digital video discs (DVDs)), semiconductor media (e.g., solid state drives (SSDs)), etc.
[0835] The network-side device and terminal device in the above-described device embodiment correspond to the network-side device or terminal device in the method embodiment. The corresponding module or unit performs the corresponding step. For example, a communication unit (transceiver) performs the receiving step or the transmitting step in the method embodiment, and steps other than the transmitting step and the receiving step may be performed by a processing unit (processor). For specific unit functions, refer to the corresponding method embodiment. There may be one or more processors.
[0836] Terms such as “component,” “module,” and “system” as used in this specification refer to computer-related entities, hardware, firmware, combinations of hardware and software, software, or software being executed. For example, a component may be, but is not limited to, a process running on a processor, a processor, an object, an executable file, an execution thread, a program, and / or a computer. As illustrated by use of the drawings, both a computing device and an application running on the computing device may be components. One or more components may reside within a process and / or execution thread, and components may be located on a single computer and / or distributed among two or more computers. Additionally, these components may be executed by various computer-readable media storing various data structures. For example, a component may communicate by utilizing local and / or remote processes and based on a signal having one or more data packets (e.g., data from two components interacting with another component across a network such as the Internet, interacting with another system by utilizing signals in a local system or a distributed system, and / or by utilizing signals).
[0837] A person skilled in the art will recognize that, in combination with the examples described in the embodiments disclosed herein, unit and algorithm steps may be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether a function is performed by hardware or software depends on the specific application and the design constraints of the technical solution. A person skilled in the art may use different methods to implement functions for each specific application, but it should not be considered that the implementations are beyond the scope of this application.
[0838] For the purpose of convenient and simple explanation, regarding the detailed operation process of the above-described system, device, and unit, reference is made to the corresponding process in the above-described method example, and it will be clearly understood by those skilled in the art that details are not described again in this specification.
[0839] It should be understood that in some of the embodiments provided in this application, the disclosed systems, devices, and methods may be implemented in different ways. For example, the device embodiments described above are merely examples. For example, a division into units is merely a logical functional division, and may be a different division during actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not performed. Additionally, the mutual coupling or direct coupling or communication connection shown or discussed may be implemented by using some interfaces. Indirect coupling or communication connection between devices or units may be implemented electrically, mechanically, or in other forms.
[0840] The unit described as a separate part may or may not be physically separate, and the part displayed as a unit may or may not be a physical unit, that is, it may be located in a single position or distributed across multiple network units. Some or all of the unit may be selected based on practical requirements to achieve the purpose of the solution of the embodiment.
[0841] Additionally, the functional units in the embodiments of this application may be integrated into a single processing unit, each unit may exist physically independently, or two or more units may be integrated into a single unit.
[0842] When a function is implemented in the form of a software functional unit and is sold or used as an independent product, the function may be stored within a computer-readable storage medium. Based on this understanding, the technical solution in this application may essentially be implemented in the form of a software product, a part that contributes to the present technology, or a part of the technical solution. The computer software product is stored on a storage medium and includes some instructions for instructing a computer device (which may be a personal computer, a server, a network device, etc.) to perform all or part of the steps in the method in the embodiments of this application. The said storage medium includes any medium capable of storing program code, such as a USB flash drive, a removable hard disk, Read-Only Memory (ROM), Random Access Memory (RAM), a magnetic disk, or an optical disk.
[0843] The foregoing description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any modification or substitution readily derived by a person skilled in the art within the technical scope disclosed in this application will fall within the scope of protection of this application. Therefore, the scope of protection of this application will be the scope of protection of the claims.
Claims
Claim 1 A key determination method, wherein the key determination method is applied to a control plane entity of a donor node central unit, and the donor node central unit further includes a user plane entity, and the key determination method comprises the step of deriving a first key based on a root key, an Internet Protocol (IP) address of a distributed unit of an integrated access and backhaul node, and a first IP address of the user plane entity - wherein the first key is different from the root key, and the root key is a key obtained by the control plane entity from the network in a procedure in which the integrated access and backhaul node registers with the network -; and the step of transmitting a first message to the user plane entity - wherein the first message includes a one-to-one correspondence between the first key and the first IP address, and the first key and the first IP address are intended to establish a user plane secure transmission channel between the user plane entity and the distributed unit. Claim 2 A key determination method according to claim 1, further comprising: transmitting first instruction information to the user plane entity; and receiving one or more IP addresses from the user plane entity, wherein the one or more IP addresses include the first IP address. Claim 3 In paragraph 2, when the one or more IP addresses further include a second IP address, the key determination method further includes the step of deriving a second key based on the root key, the IP address of the distributed unit, and the second IP address, and the first message further includes a one-to-one correspondence between the second key and the second IP address. Claim 4 In any one of paragraphs 1 to 3, the first key is K IAB and, the above root key is K gNB In, key determination method. Claim 5 A key determination method according to any one of claims 1 to 3, further comprising: a step of deriving a third key based on the root key, the IP address of the distributed unit, and the IP address of the control plane entity; and a step of establishing a control plane secure transmission channel between the control plane entity and the distributed unit based on the third key. Claim 6 A method for establishing a secure transmission channel, wherein the method is applied to a user plane entity of a donor node central unit, and the donor node central unit further comprises a control plane entity, and the method comprises the step of receiving a first message from the control plane entity - the first message comprises a one-to-one correspondence between a first key and a first IP address of the user plane entity, wherein the first key is different from a root key, and the root key is a key obtained by the control plane entity from the network in a procedure in which an integrated access and backhaul node registers with the network -; and the step of establishing a user plane secure transmission channel between the user plane entity and a distributed unit of the integrated access and backhaul node based on the first key and the first IP address. Claim 7 In claim 6, the first message comprises a one-to-one correspondence between a plurality of IP addresses of the user plane entity and a plurality of keys, the plurality of keys comprises a first key, and the first key corresponds to the first IP address, and the method further comprises the step of determining to establish the user plane secure transmission channel by using the first IP address of the user plane entity; and the step of determining that the key corresponding to the first IP address is the first key based on the one-to-one correspondence. Claim 8 A method according to claim 7, further comprising: receiving first instruction information from the control plane entity; and transmitting the plurality of IP addresses of the user plane entity to the control plane entity based on the first instruction information. Claim 9 In any one of paragraphs 6 through 8, the first key is K IAB and, the above root key is K gNB Person, method. Claim 10 A method for establishing a secure transmission channel, wherein the method is applied to a donor node central unit, the donor node central unit includes a control plane entity and a user plane entity, and the method comprises the step of deriving a first key based on a root key, an Internet Protocol (IP) address of a distributed unit of an integrated access and backhaul node, and a first IP address of the user plane entity by the control plane entity - wherein the first key is different from the root key, and the root key is a key obtained by the control plane entity from the network in a procedure in which the integrated access and backhaul node registers with the network -; and the step of transmitting a first message to the user plane entity by the control plane entity - wherein the first message includes a one-to-one correspondence between the first key and the first IP address -; and the step of receiving the first message by the user plane entity; A method comprising the step of establishing a user plane secure transmission channel between the user plane entity and the distributed unit based on the first key and the first IP address by the user plane entity. Claim 11 In claim 10, the first message comprises a one-to-one correspondence between a plurality of IP addresses of the user plane entity and a plurality of keys, the plurality of keys comprises the first key, and the first key corresponds to the first IP address, and the method further comprises the step of determining by the user plane entity to establish the user plane secure transmission channel by using the first IP address; and the step of determining by the user plane entity, based on the one-to-one correspondence, that the key corresponding to the first IP address is the first key. Claim 12 A method according to claim 11, further comprising: a step of transmitting a first instruction information to a user plane entity by the control plane entity; a step of receiving the first instruction information from the control plane entity by the user plane entity; a step of transmitting one or more IP addresses of the user plane entity to the control plane entity based on the first instruction information by the user plane entity, wherein the one or more IP addresses include the first IP address; and a step of receiving the one or more IP addresses from the user plane entity by the control plane entity. Claim 13 In claim 12, when the above one or more IP addresses further include a second IP address, the method further comprises the step of deriving a second key based on the root key, the IP address of the distributed unit, and the second IP address by the control plane entity, and the first message further comprises a one-to-one correspondence between the second key and the second IP address. Claim 14 In any one of paragraphs 10 to 13, the first key is K IAB and, the above root key is K gNB Person, method. Claim 15 A method further comprising, in any one of claims 10 to 13, deriving a third key based on the root key, the IP address of the distributed unit, and the IP address of the control plane entity by the control plane entity; and establishing a control plane secure transmission channel between the control plane entity and the distributed unit based on the third key. Claim 16 A control plane entity of a donor node central unit, wherein the donor node central unit further comprises a user plane entity, and the control plane entity derives a first key based on a root key, an Internet Protocol (IP) address of a distributed unit of an integrated access and backhaul node, and a first IP address of the user plane entity—wherein the first key is different from the root key, and the root key is a key obtained by the control plane entity from the network in a procedure in which the integrated access and backhaul node registers with the network—and transmits a first message to the user plane entity—wherein the first message includes a one-to-one correspondence between the first key and the first IP address, and the first key and the first IP address are intended to establish a user plane secure transmission channel between the user plane entity and the distributed unit. Claim 17 A user plane entity of a donor node central unit, wherein the donor node central unit further comprises a control plane entity, and the user plane entity is configured to receive a first message from the control plane entity—the first message comprises a one-to-one correspondence between a first key and a first IP address of the user plane entity, wherein the first key is different from a root key, and the root key is a key obtained by the control plane entity from the network in a procedure in which an integrated access and backhaul node registers with the network—and establish a user plane secure transmission channel between the user plane entity and a distributed unit of the integrated access and backhaul node based on the first key and the first IP address. Claim 18 As a control plane entity of a donor node central unit, the donor node central unit further includes a user plane entity, and the control plane entity includes a memory - said memory is configured to store a computer program -; A control plane entity configured to include a processor, wherein the processor calls the computer program from the memory and operates the computer program so as to enable the control plane entity to derive a first key based on a root key, an Internet Protocol (IP) address of a distributed unit of an integrated access and backhaul node, and a first IP address of the user plane entity—wherein the first key is different from the root key, and the root key is a key obtained by the control plane entity from the network in a procedure in which the integrated access and backhaul node registers with the network—and transmit a first message to the user plane entity—wherein the first message includes a one-to-one correspondence between the first key and the first IP address, and the first key and the first IP address are intended to establish a user plane secure transmission channel between the user plane entity and the distributed unit. Claim 19 A user plane entity of a donor node central unit, wherein the donor node central unit further comprises a control plane entity, and the user plane entity comprises: a memory—the memory is configured to store a computer program—; and a processor, wherein the processor calls the computer program from the memory and operates the computer program so that the user plane entity receives a first message from the control plane entity—the first message includes a one-to-one correspondence between a first key and a first IP address of the user plane entity, wherein the first key is different from a root key, and the root key is a key obtained by the control plane entity from the network in a procedure in which an integrated access and backhaul node registers with the network—and is configured to enable the establishment of a user plane secure transmission channel between the user plane entity and a distributed unit of the integrated access and backhaul node based on the first key and the first IP address. Claim 20 A computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is operated on a computer, the computer derives a first key based on a root key, an Internet Protocol (IP) address of a distributed unit of an integrated access and backhaul node, and a first IP address of a user plane entity of a donor node central unit, wherein the first key is different from the root key, and the root key is a key obtained from the network in a procedure in which the integrated access and backhaul node registers with the network, and transmits a first message to the user plane entity of the donor node central unit, wherein the first message includes a one-to-one correspondence between the first key and the first IP address, and wherein the first key and the first IP address are intended to establish a user plane secure transmission channel between the user plane entity and the distributed unit. Claim 21 A computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is operated on a computer, the computer receives a first message from a control plane entity of a donor node central unit, wherein the first message includes a one-to-one correspondence between a first key and a first IP address of a user plane entity, wherein the first key is different from a root key, and the root key is a key obtained by the control plane entity from the network in a procedure in which an integrated access and backhaul node registers with the network, and wherein the computer-readable storage medium enables the establishment of a user plane secure transmission channel with a distributed unit of the integrated access and backhaul node based on the first key and the first IP address. Claim 22 A communication system comprising a user plane entity of a donor node central unit and a control plane entity of said donor node central unit, wherein the control plane entity derives a first key based on a root key, an Internet Protocol (IP) address of a distributed unit of an integrated access and backhaul node, and a first IP address of said user plane entity, wherein the first key is different from the root key, and the root key is a key obtained by said control plane entity from the network in a procedure in which said integrated access and backhaul node registers with the network, and is configured to transmit a first message to said user plane entity, wherein the first message includes a one-to-one correspondence between said first key and said first IP address, and said user plane entity receives said first message and is configured to establish a user plane secure transmission channel between said user plane entity and said distributed unit based on said first key and said first IP address. Claim 23 delete Claim 24 delete Claim 25 delete Claim 26 delete Claim 27 delete Claim 28 delete Claim 29 delete Claim 30 delete Claim 31 delete Claim 32 delete Claim 33 delete Claim 34 delete Claim 35 delete Claim 36 delete Claim 37 delete Claim 38 delete Claim 39 delete Claim 40 delete Claim 41 delete
Citation Information
Patent Citations
Method for establishing a secure transmission channel, key determination method and communication device
JP7824400B2
Method for establishing secure transmission channel, key determining method, and communication apparatus
US12568360B2
Method of dynamically provisioning a key for authentication in relay device
US20200396611A1
Key generation method and related apparatus
US20210058771A1