Communication method and related apparatus

By receiving the secure communication parameters of the first management node and performing security context-related operations with the terminal node, the problem of delay of the communication node connecting to the new node is solved, and more efficient connection establishment and more stable user service is achieved.

WO2025092760A1PCT designated stage expired Publication Date: 2025-05-08HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/128289
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-31
Filing Date
2024-10-29
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

In the prior art, the delay of connecting communication nodes to new nodes is usually high, especially in roaming scenarios, real-time applications have high requirements for the switching delay of media access control layer.

Method used

By receiving secure communication parameters from the first management node and performing associated operations with the terminal node with a security context based on these parameters, the communication security parameters are directly or indirectly used to ensure the security of the interaction information, thereby reducing signaling interactions during the authentication process.

Benefits of technology

The delay in establishing communication connections is reduced, the computing amount of terminal nodes and management nodes is reduced, and the efficiency of connection establishment and the stability of user services is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024128289_08052025_PF_FP_ABST
    Figure CN2024128289_08052025_PF_FP_ABST
Patent Text Reader

Abstract

A communication method and a related apparatus, applied to the technical field of communications. A second management node in embodiments of the present application can receive secure communication parameters from a first management node, the secure communication parameters comprising parameters used when the first management node is communicationally connected to a terminal node and being associated with security context of the terminal node; and on the basis of the secure communication parameters, the second management node performs, with the terminal node, an association operation with the security context. In this way, the second management node can directly or indirectly use the secure communication parameters to ensure the security of information exchanged in the association operation. On one hand, the second management node does not need to re-negotiate the security context with the terminal node when performing the association operation with the terminal node, reducing signaling interaction, thereby reducing the association delay. On the other hand, there is no need to re-determine the secure communication parameters, negotiate the security context, etc., reducing the amount of computation of the terminal node and the second management node, and further shortening the delay of establishing a connection.
Need to check novelty before this filing date? Find Prior Art

Description

A communication method and related device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on October 31, 2023, with application number 202311444648.3 and application name “A communication method and related device”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communication technology, and in particular to the field of short-range communication technology, such as communications in scenarios such as smart cars, smart homes, smart terminals, and smart manufacturing, and specifically to a communication method and related devices. Background Art

[0003] With the continuous development of communication technology, intelligent application scenarios such as smart homes, smart cockpits, smart driving, smart manufacturing, and smart transportation have emerged. In the mobile Internet era, communication tools are more convenient to use than traditional computers, especially desktop workstations and servers.

[0004] As interconnection between communication nodes becomes increasingly widespread, connections between them are becoming increasingly diverse. For example, in a roaming scenario, a station (STA) can connect to access point (AP) 1. As the STA moves, it can connect to AP 2, which is currently closer, at another point in time. This improves connection stability and ensures transmission efficiency.

[0005] Before a communication node connects to a new communication node, for example, before a STA needs to establish a connection with AP2, it needs to go through handshakes and authentication with the new communication node. These complex connection processes often result in a relatively high latency for the communication node to connect to the new node. To ensure transmission efficiency and improve the stability of user services, various business scenarios place high demands on the latency of establishing connections with new nodes. For example, in roaming scenarios, real-time applications such as augmented reality (AR), online gaming, and online video conferencing require a media access control (MAC) layer handover latency of less than 50ms. For another example, automated guided vehicles (AGVs) typically require roaming latency even lower than 50ms.

[0006] How to reduce the delay when a communication node connects to a new node is a hot issue that technicians in this field are currently studying.

[0007] Summary of the Invention

[0008] The embodiments of the present application provide a communication method and related devices, which can reduce the delay in establishing a communication connection while ensuring secure communication.

[0009] In a first aspect, an embodiment of the present application provides a communication method, the method comprising: receiving security communication parameters from a first management node, and performing an association operation with a terminal node having a security context based on the security communication parameters.

[0010] This method can be applied to the second management node. The secure communication parameters include parameters used when the first management node is connected to the terminal node for communication, and the secure communication parameters are associated with the security context of the terminal node. The aforementioned security context includes parameters for securely protecting the communicated information, such as session keys, and further includes fresh parameters, key algorithms, or temporary identities used for security protection. The secure communication parameters may include some or all of the parameters in the security context, or the secure communication parameters may be used to generate some or all of the parameters in the security context. The associated operations with the security context include: using the parameters in the security context to securely protect the transmitted information (such as encryption, integrity protection, etc.), and the other end may also use the parameters in the security context to securely obtain the corresponding information. The security protection includes one or more of encryption, integrity protection (abbreviated as integrity protection), or authenticated encryption.

[0011] In an embodiment of the present application, when a terminal node associates with a second management node, it can use the secure communication parameters provided by the first management node to perform an association operation with the terminal node with a security context. That is, the communication security parameters are used directly or indirectly to ensure the security of the information exchanged during the association operation. On the one hand, the association operation between the second management node and the terminal does not require re-negotiation with the terminal node to obtain a security context, which can reduce signaling during the authentication process and thus reduce the delay in signaling interaction. On the other hand, without the need to re-determine secure communication parameters, negotiate a security context, etc., the amount of computation required by the terminal node and the second management node can be reduced, further shortening the delay in establishing a connection.

[0012] Furthermore, the method further includes: after establishing the association, performing data transmission with the second management node. Furthermore, during the data transmission, secure communication parameters or a security context may be used to securely protect the data.

[0013] In a possible implementation of the first aspect, the security context of the terminal node includes a key. The key here may include one or more of a shared key or a session key. Optionally, the session key may include one or more of an encryption key, an integrity protection key, an authentication encryption key, etc. Further, the encryption key may include a user plane encryption key or a signaling plane encryption key. Alternatively, the encryption key may also include a unicast encryption key, a multicast encryption key, etc. Similarly, the integrity protection key may include a user plane integrity protection key, a signaling plane integrity protection key, etc., and / or the integrity protection key may include a unicast integrity protection key and a multicast integrity protection key. The authentication encryption key may also include the above-mentioned subdivided categories of keys, which are not described here one by one.

[0014] In one possible implementation of the first aspect, when the security context includes a key, the security context may also include key information, where the key information includes one or more of a key identifier, a key validity period, a key activation time, and the like. Exemplarily, the security context includes a shared key, a shared key ID, and a shared key validity period. Of course, when there are multiple keys, this application does not limit the presence of information about each key in the security context. For example, the security context may include a fully protected key but may not include the validity period of the fully protected key.

[0015] In one possible implementation of the first aspect, the security context of the terminal node includes fresh parameters. Fresh parameters are parameters used in the security domain to obtain keys or participate in security protection processes to enhance security. The first fresh parameter and the second fresh parameter are exemplary fresh parameters. In some implementations, the first fresh parameter is used to derive a session key, and the second fresh parameter is used as a parameter for security protection.

[0016] In one possible implementation of the first aspect, the terminal's security context includes information about a security algorithm, such as information indicating the security algorithm. The security algorithm refers to an algorithm related to security protection, such as one or more of a key agreement algorithm, an encryption algorithm, a security algorithm, an authenticated encryption algorithm, a digest algorithm, and a key derivation algorithm.

[0017] Exemplarily, a possible terminal security context includes one or more of the following parameters: a shared key, a first fresh parameter, a session key, an identifier of a security algorithm, a first identity identifier of a terminal node, and a second fresh parameter.

[0018] In another possible implementation of the first aspect, the second freshness parameter is determined by a first number and a second number, wherein the first number corresponds to a number of a protocol data unit (PDU), for example, the first number is the same as the number of the protocol data unit, or the first number is determined by the number of the protocol data unit.

[0019] The above embodiment is an example of a second fresh parameter. A protocol data unit (PDU) is a unit of data transmitted during communication, and its number changes as data transmission proceeds. Therefore, by determining the second fresh parameter based on the PDU number, the second fresh parameter can be updated as the PDU number changes, thereby allowing the value of the second fresh parameter to be updated. Because the second fresh parameter is encrypted / decrypted during communication, it can be updated after one or more encryption / decryption cycles, thereby improving communication security.

[0020] Optionally, the initial value of the second number is predetermined. The second number can be updated, for example, when the first number is flipped. Optionally, the second freshness parameter is determined by the first number and the second number, including: the second freshness parameter includes the first number and the second number.

[0021] Exemplarily, the second freshness parameter is N bits of data, where the first number contains M bits and the second number contains L bits, where N, M, and L are non-negative integers. The number of bits of the second number is greater than the number of bits of the first number. When the number of bits of the first number changes from all 1s to all 0s, the number of bits represented by the second number is incremented by 1. Optionally, N = M + L.

[0022] Optionally, the second fresh parameter is a global frame number (GFN), and the GFN includes a high frame number (HFN) and a serial number (SN). Optionally, the sequence number is the same as the number of the protocol data unit (PDU), and the HFN is predetermined.

[0023] In a possible implementation of the first aspect, the second fresh parameter is a predefined parameter value, such as HFN. Further, the second fresh parameter can be updated by the number of the protocol data unit. For example, the second fresh parameter is updated when the SN rolls over.

[0024] In yet another possible implementation of the first aspect, the secure communication parameter is a security context of the terminal node.

[0025] In this embodiment, the first management node can provide the terminal node's security context, which it has obtained, to other nodes, thereby enabling the second management node to obtain the terminal node's security context and, based on this, obtain the terminal node's security context that it should store. For example, the second management node can use some or all parameters in the terminal node's security context provided by the first management node as some or all parameters of the terminal node's security context that it should store. For example, the second management node can use the session key between the first management node and the terminal node for communication encryption / decryption.

[0026] When the second management node establishes a connection with the terminal node, the above implementation eliminates the need to spend a lot of time negotiating and generating a security context, thereby greatly shortening the communication delay.

[0027] In another possible implementation of the first aspect, the secure communication parameters include some parameters in the security context and / or parameters used to obtain some parameters in the security context. In this way, the second management node can obtain the security context of the terminal node based on the secure communication parameters and parameters determined by the second management node.

[0028] Exemplarily, the secure communication parameters include a key. The key can be directly used as a session key for secure protection of the communication process, or the key can be used to derive a session key.

[0029] Exemplarily, the secure communication parameter includes a shared key, and the method further includes:

[0030] The session key is obtained based on the shared key. Further, the session key derived by the second management node is included in the security context of the terminal node. Optionally, the security context also includes the shared key.

[0031] Optionally, freshness parameters, key identifiers, etc. may also be used when deriving the session key. For example, the secure communication parameters include a shared key Kgt and a first security parameter counter. The second terminal node determines the user plane encryption key based on the shared key Kgt, the first security parameter counter, and the identifier of the user plane encryption key.

[0032] Exemplarily, the secure communication parameters further include an identifier of the shared key and a first freshness parameter, and obtaining the session key according to the shared key includes:

[0033] A session key is determined according to the shared key, the identifier of the shared key, and the first fresh parameter.

[0034] Understandably, re-determining secure communication parameters requires a negotiation process, which not only requires significant computational effort but also takes significant computational effort and time to ensure the security of the negotiation process. However, the aforementioned implementation allows the second management node to determine the security context based on the secure communication parameters, eliminating the need for extensive negotiation and security context generation, significantly reducing communication latency.

[0035] Exemplarily, the secure communication parameters further include an identifier of a security algorithm and a first identity identifier of the terminal node.

[0036] In another possible implementation of the first aspect, the session key includes an integrity protection key. Performing an association operation with a terminal node having a security context based on the secure communication parameters includes: receiving first information from the terminal node, integrity-protecting the first information using the integrity protection key, and checking the integrity of the first information using the integrity protection key. If the integrity check of the first information is successful, sending second information to the terminal node. Optionally, the second information is used to establish an association between the terminal node and the second management node, and the second information is integrity-protected using the integrity protection key.

[0037] In the above embodiment, the terminal node and the first management node can use the security context to protect the integrity of the transmitted signaling, which can not only prevent the first information from being tampered with, but also authenticate each other's identity through integrity verification (only the two ends with a security context can successfully verify the integrity), thereby improving communication security.

[0038] Optionally, the session key includes an encryption key, and the second information is encrypted using the encryption key.

[0039] In another possible implementation of the first aspect, the terminal's security context includes a session key and an identifier of a first security algorithm. The first information includes first verification information, where the first verification information corresponds to the session key, the first information, and the first security algorithm. Checking the integrity of the second information based on the terminal node's security context includes verifying the first verification information based on the session key, the first information, and the first security algorithm. Exemplarily, the session key is an integrity protection key, and the identifier of the first security algorithm is an identifier of the first integrity protection algorithm.

[0040] In the above embodiment, the terminal node can generate verification information using the session key and the first information, and the second management node can verify the verification information using the session key in the terminal node's security context, thereby improving security. As can be seen, the terminal node and the second management node can conduct integrity-protected communication based on the session key without having to negotiate and determine the session key through interactive signaling, thereby reducing signaling overhead, lowering the computational effort of the node, and shortening the connection establishment latency.

[0041] In another possible implementation of the first aspect, the security context includes a first identity of the terminal node, and the first information includes the first identity of the terminal node. The method further includes: acquiring the security context of the terminal node according to the first identity in the first information.

[0042] In the above implementation, the security context can correspond to the node's identity, and the node's identity can be used to manage the node to retrieve whether it has the terminal's security context, thereby facilitating the storage and management of the terminal's security context and improving the convenience of using the security context.

[0043] In another possible implementation of the first aspect, the method further includes: generating a second identity identifier for the terminal node, and sending the second identity identifier to the terminal node. Optionally, the identity identifier is used to identify the terminal node, and the second identity identifier is carried in the second information.

[0044] In the above embodiment, the second management node can generate a new identity for the terminal node, namely a second identity, which is used to correspond to the terminal node. Updating the identity of the terminal node can prevent the terminal's fixed identity from being leaked, improve the privacy of the terminal's identity, and enhance communication security.

[0045] In another possible implementation of the first aspect, the second fresh parameter in the security context may be determined by the second management node. For example, the second fresh parameter may be predefined, such as being set to all 128 bits of 0, or to a preset value.

[0046] In another possible implementation of the first aspect, the security context of the terminal node includes a second fresh parameter. The method further includes: determining a first number based on a number of a protocol data unit (PDU) from the terminal node, and determining the second fresh parameter based on the second number and the first number. The initial value of the second number is predetermined, and the second number is updated when the first number is flipped.

[0047] The above describes a method for determining the second fresh parameter, wherein the second fresh parameter is determined according to the second number and the first number, wherein the second number may be predefined, and the first number is determined according to the PDU from the terminal node.

[0048] On the one hand, the above method allows the second management node to use the second fresh parameter determined by itself for subsequent security protection, and avoids using the second fresh parameter (or second number) consistent with the first management node, thereby improving security. On the other hand, if the second fresh parameter determined by the first management node is used, since the PUD number will be updated after each transmission and the second number may also be updated, this will cause the second management node to receive the updated value of the second fresh parameter or part of the data in the second fresh parameter multiple times, increasing the transmission pressure of the node, while using the second fresh parameter determined by itself can reduce the transmission pressure of the second management node and save signaling overhead.

[0049] In another possible implementation of the first aspect, the method further includes: receiving parameter update information from the first management node, and updating some or all of the secure communication parameters based on the parameter update information. Updating some or all of the secure communication parameters may include updating some or all of the parameters in the security context.

[0050] In some scenarios, when the first management node updates the parameters in the communication parameters, it can instruct other nodes to update the security communication parameters through parameter update information, so that the second management node can use the latest and correct security context when connecting to the terminal node, thereby improving the success rate of connection establishment.

[0051] Exemplarily, the secure communication parameters of the terminal include a shared key, an identifier of the shared key, and a validity period of the shared key, and the parameter update information includes an updated shared key, a validity period of the updated shared key, and a validity period of the updated shared key.

[0052] Exemplarily, the terminal's secure communication parameter includes a first freshness parameter, and the parameter update information includes the updated first freshness parameter.

[0053] Exemplarily, the secure communication parameters of the terminal include the second fresh parameters, and the parameter update information includes the updated second fresh parameters.

[0054] Exemplarily, the secure communication parameter of the terminal includes a portion of the second fresh parameter, and the parameter update information includes an updated portion of the second fresh parameter.

[0055] In another possible implementation of the first aspect, the first management node and the second management node are connected or indirectly connected. The connection can be wired or wireless. When the two are directly connected, the second management node can receive the security communication parameters sent by the first management node. Alternatively, an indirect connection can be made through an intermediate node, which forwards information between the two management nodes.

[0056] Illustratively, receiving the secure communication parameters from the first management node includes: receiving the secure communication parameters forwarded by a control node, wherein the control node is in communication with the first management node and the second management node. In this case, the control node acts as an intermediary node, and the first management node can send the secure communication parameters to the control node, which then provides the secure communication parameters to the second management node. It should be understood that the number of intermediary nodes may be one or more.

[0057] Optionally, the first management node and the terminal node are connected via a wireless communication link, and the first management node, the second management node and the AC are connected via a wired communication link.

[0058] In another possible implementation of the first aspect, the secure communication parameters are transmitted via messages that comply with the CAPWAP protocol. The CAPWAP protocol provides security protection for the transmitted information, thereby enhancing the privacy of the secure communication parameters. For example, the first management node may provide the secure communication parameters to the control node via a CAPWAP tunnel, and the control node may also provide the secure communication parameters to the second management node via the CAPWAP tunnel.

[0059] In yet another possible implementation of the first aspect, the method further includes: in case of association failure, performing an association operation without a security context with the terminal node.

[0060] For example, if the second management node does not have the terminal node's security context, integrity protection key verification fails, or the second management node does not support fast secure connections, the second management node and the terminal node will perform an association operation without a security context. In this case, the second management node needs to renegotiate with the terminal node to determine a new security context in order to establish the association.

[0061] In another possible implementation of the first aspect, the second management node is a node that supports a fast connection establishment method, wherein the fast connection establishment method supports associating with the terminal node using secure communication parameters from other nodes, where the other nodes include the first management node and / or the control node.

[0062] In some scenarios, since fast connection establishment can directly establish an association through the secure communication parameters of other nodes, these secure communication parameters may be used by multiple nodes, which may pose risks for management nodes with high security requirements or management nodes connected to external nodes. In the above implementation, management nodes can be flexibly configured to support fast connection establishment. Nodes that support fast connection establishment can establish secure context-based communication connections with terminal nodes based on the secure communication parameters provided by other nodes. This enhances the personalized settings of the system, is applicable to systems with complex node networks, and improves the user experience.

[0063] Furthermore, whether the second management node supports the fast connection establishment method can be set by the user, determined by the second management node based on security risks, or configured by the management node. For example, the second management node reports one or more of its own security requirements or security capabilities, and the control node evaluates whether it meets the conditions for supporting the fast connection establishment method. If the conditions for supporting fast connection establishment are met, the control node forwards the security communication parameters from other nodes to it.

[0064] In another possible implementation of the first aspect, the method further includes: sending secure communication parameters between the second management node and the terminal node to the control node. The secure communication parameters between the second management node and the terminal node are used to obtain a security context for the terminal node. In this way, when other management nodes, such as the first management node or the third management node, need to connect to the terminal node, they can obtain the security context of the terminal node using the secure communication parameters between the second management node and the terminal node, thereby saving signaling overhead and reducing connection establishment latency.

[0065] Optionally, when the second management node successfully establishes an association, a security communication parameter between the second management node and the terminal node is sent to the control node.

[0066] In yet another possible implementation of the first aspect, the method further includes: sending parameter update information to the control node, where the parameter update information is used to update a security communication parameter between the second management node and the terminal node.

[0067] In a second aspect, an embodiment of the present application provides a communication method, including: transmitting data with a first management node, and when a connection establishment condition is met, performing an association operation with a second management node with a security context, the second management node having a security context with a terminal node.

[0068] The first management node has a security context with the terminal node.

[0069] The method can be applied to a terminal node. Optionally, the security context of the terminal node in the second management node is associated with a security parameter provided by the first management node to the second management node.

[0070] In an embodiment of the present application, after the terminal node is connected to the first management node, it can establish a connection with the second management node with a security context having a security context. For example, the first management node can provide security parameters to the second management node, so that the second management node can obtain the security context of the terminal node. On the one hand, the association operation can reduce the signaling in the authentication process without having to re-negotiate with the second management node to obtain the security context, thereby reducing the delay in signaling interaction. On the other hand, there is no need for the terminal node and the second management node to re-determine the security communication parameters, negotiate the security context, etc., which can reduce the computational complexity of the terminal node and the second management node, further shortening the delay in establishing the connection.

[0071] Optionally, the method further includes: transmitting data with the second management node.

[0072] In a possible implementation of the second aspect, the connection establishment condition includes: receiving a roaming request from the first management node, where the roaming request instructs the terminal node to perform connection switching.

[0073] In another possible implementation of the second aspect, the method further includes: measuring the distances between the first management node and the second management node and the terminal node respectively, and the connection establishment condition includes: the distance between the second management node and the terminal node is less than the distance between the first management node and the terminal node.

[0074] It should be understood that the aforementioned distance can also be replaced by other parameters related to communication quality. For example, distance can also be replaced by evaluation data such as communication efficiency, channel quality, communication stability, and latency. Communication efficiency here can include the rate at which data is transmitted. Exemplarily, the connection establishment condition also includes: the communication efficiency between the second management node and the terminal node is higher than the communication efficiency between the first management node and the terminal node. Other situations can be deduced from this analogy and are not further exemplified here.

[0075] In another possible implementation of the second aspect, after performing an association operation with a security context with the second management node, the method further includes: disconnecting data transmission with the first management node.

[0076] The above describes a communication scenario in which the terminal node disconnects from the first management node after associating with the second management node. In other words, the terminal node roams from the first management node to the second management node.

[0077] In some scenarios, a terminal node may be connected to multiple nodes at the same time. When the terminal node connects to a new management node, the method of the present application is also applicable.

[0078] In yet another possible implementation of the second aspect, the method further includes: receiving switching indication information from the first management node, where the switching indication information includes information indicating the second management node.

[0079] In this implementation, the first management node can instruct the terminal node to which second management node to connect, enabling the terminal node to establish an association with the second management node. This allows operations such as calculation and evaluation to be centralized on the first management node, making it easier for the management node to manage the terminal node and improving the management node's service quality.

[0080] In another possible implementation of the second aspect, the second management node is a node that supports a fast connection establishment method, and the fast connection establishment method is a method that supports associating with the terminal node through secure communication parameters from other nodes, and the other nodes include the first management node.

[0081] In another possible implementation of the second aspect, the security context of the terminal node includes an integrity protection key. Performing an association operation with the second management node including the security context includes: sending first information to the second management node, receiving second information from the second management node, and checking the integrity of the first information based on the integrity protection key. If the integrity check of the first information is successful, the association is completed.

[0082] The first information is integrity protected by an integrity protection key, the second information is used for the terminal node to establish an association with the second management node, and the second information is integrity protected by the integrity protection key.

[0083] In yet another possible implementation of the second aspect, the method further includes: in case of association failure, performing an association operation without a security context with the terminal node.

[0084] In a third aspect, embodiments of the present invention further provide a communication method, comprising: transmitting data with a terminal node, and providing secure communication parameters between a second management node and the terminal node. The secure communication parameters are associated with a security context of the terminal node, and the secure communication parameters are used in a security context-based association process between the second management node and the terminal node.

[0085] Optionally, the method may be applied to a first management node, where the first management node has a security context of the terminal node, or the first management node has a security communication parameter with the terminal node.

[0086] In yet another possible implementation of the third aspect, the method further includes: sending parameter update information to the second management node, where the parameter update information is used to update some or all of the security communication parameters.

[0087] In another possible implementation of the third aspect, the second management node is connected to the control node, and sending security communication parameters between the second management node and the terminal node to the second management node includes: sending security communication parameters between the second management node and the terminal node to the control node, and the control node is used to provide the security communication parameters between the second management node and the terminal node.

[0088] In another possible implementation of the third aspect, the second management node is connected to the control node, and sending the parameter update information to the second management node includes: sending the parameter update information to the control node, and the control node is configured to provide the parameter update information to the second management node.

[0089] In yet another possible implementation of the third aspect, the method further includes: sending switching indication information to the terminal node, where the switching indication information includes information indicating the second management node.

[0090] In another possible implementation of the third aspect, the method also includes: receiving third information from the control node, the third information is used to indicate a node that supports a fast connection establishment method, the node that supports the fast connection establishment method includes a second management node, and the fast connection establishment method is a method that supports association with a terminal node through secure communication parameters from other nodes.

[0091] In a fourth aspect, embodiments of the present invention further provide a communication method, comprising: receiving secure communication parameters between the first management node and a terminal node from a first management node, and sending the secure communication parameters to a second management node. The secure communication parameters are associated with a security context of the terminal node, and the secure communication parameters are used to perform a security context-based association process between the second management node and the terminal node.

[0092] The method may be applied to a control node, where the control node is connected to a first management node and a second management node.

[0093] In a possible implementation of the fourth aspect, the method includes: receiving parameter update information from a first management node, and sending the parameter update information to a second management node, wherein the parameter update information is used to update some or all parameters in the secure communication parameters.

[0094] In one possible implementation of the fourth aspect, the method further includes: sending third information to the first management node, where the third information is used to indicate a node that supports a fast connection establishment method. The node that supports the fast connection establishment method includes the second management node, and the fast connection establishment method supports association with the terminal node using secure communication parameters from other nodes.

[0095] In a possible implementation of the fourth aspect, the method includes: determining nodes among multiple nodes that support a fast connection establishment method based on security requirements of multiple management nodes and / or the degree of trust between multiple management nodes and a first management node, the multiple management nodes are connected to a control node, and the multiple management nodes include a second management node.

[0096] In a fifth aspect, an embodiment of the present application provides a communication device, comprising a communication unit and a processing unit. The communication device is configured to implement any method of the first aspect; or any method of the second aspect; or any method of the third aspect; or any method of the fourth aspect.

[0097] In a sixth aspect, an embodiment of the present application provides a communication device, comprising a processor. When the processor calls a computer program or instruction in a memory, the method of any one of the first aspect, the method of any one of the second aspect, the method of any one of the third aspect, or the method of any one of the fourth aspect is implemented.

[0098] It should be noted that the processor described in the sixth aspect above can be a processor specifically used to execute these methods (for convenience of distinction, it is called a dedicated processor), or it can be a processor that executes these methods by calling a computer program, such as a general-purpose processor.

[0099] Optionally, the computer program may be stored in a memory. For example, the memory may be a non-transitory memory, such as a read-only memory (ROM), which may be integrated with the processor on the same device or provided on separate devices. This application does not limit the type of memory or the configuration of the memory and the processor.

[0100] In a possible implementation, the at least one memory is located outside the communication device.

[0101] In another possible implementation, the at least one memory is located within the communication device.

[0102] In another possible implementation, part of the at least one memory is located inside the communication device, and another part of the memory is located outside the communication device.

[0103] In this application, the processor and the memory may also be integrated into one device, that is, the processor and the memory may also be integrated together.

[0104] In a seventh aspect, an embodiment of the present application provides a communication device, including a logic circuit and an interface, wherein the logic circuit and the interface are coupled;

[0105] The interface is used to input data to be processed, the logic circuit processes the data to be processed according to any one of the methods of the first aspect to the fourth aspect to obtain processed data, and the interface is used to output the processed data.

[0106] In an eighth aspect, an embodiment of the present application provides a computer-readable storage medium, which is used to store instructions or computer programs; when the instructions or computer programs are executed, any method of the first aspect is implemented, or any method of the second aspect is implemented, or any method of the third aspect is implemented, or any method of the fourth aspect is implemented.

[0107] In the ninth aspect, an embodiment of the present application provides a computer program product, which, when the instruction or computer program is executed, implements any method of the first aspect, or implements any method of the second aspect, or implements any method of the third aspect, or implements any method of the fourth aspect.

[0108] In a tenth aspect, an embodiment of the present application provides a terminal, which includes the communication device of any one of the fifth to seventh aspects. Furthermore, the terminal can be an intelligent terminal or a means of transportation such as a vehicle, a robot, a drone, a ship, or a ship. Among them, the vehicle is a vehicle in a broad sense, which can be a means of transportation (such as a commercial vehicle, a passenger car, a motorcycle, a flying car, a train, etc.), an industrial vehicle (such as a forklift, a trailer, a tractor, etc.), an engineering vehicle (such as an excavator, a bulldozer, a crane, etc.), an agricultural equipment (such as a mower, a harvester, etc.), etc. For another example, the robot can be an intelligent handling robot (automated guided vehicle, AGV), a walkable conversational robot, a service robot, and other robots.

[0109] In an eleventh aspect, an embodiment of the present application provides a communication system, which includes a second management node, a first management node and a terminal node.

[0110] Among them, the second management node is used to implement any method of the first aspect; the terminal node is used to implement any method of the second aspect; and the first management node is used to implement any method of the third aspect.

[0111] Optionally, the communication system further includes a control node, which is used to implement any method of the fourth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0112] The following is a brief introduction to the drawings required for describing the embodiments.

[0113] FIG1 is a schematic diagram of a communication scenario of a communication system provided in an embodiment of the present application;

[0114] FIG2A is a topology diagram of a possible communication system;

[0115] FIG2B is a topological diagram of yet another possible communication system;

[0116] FIG3 is a schematic diagram of information included in a security context provided by an embodiment of the present application;

[0117] FIG4 is a schematic diagram of a key system;

[0118] FIG5 is a schematic diagram of an association process without a security context;

[0119] FIG6 is a schematic diagram of an association process with a security context;

[0120] FIG7 is a flow chart of a communication method provided in an embodiment of the present application;

[0121] FIG8 is a schematic diagram of a GFN;

[0122] FIG9 is a flow chart of another communication method provided in an embodiment of the present application;

[0123] FIG10A is a flow chart of another communication method provided in an embodiment of the present application;

[0124] FIG10B is a flow chart of another communication method provided in an embodiment of the present application;

[0125] FIG11A is a schematic flow chart of another communication method provided in an embodiment of the present application;

[0126] FIG11B is a flow chart of another communication method provided in an embodiment of the present application;

[0127] FIG12A is a flow chart of another communication method provided in an embodiment of the present application;

[0128] FIG12B is a flow chart of another communication method provided in an embodiment of the present application;

[0129] FIG13 is a schematic structural diagram of a communication device provided in an embodiment of the present application;

[0130] FIG14 is a schematic structural diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0131] The embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0132] The following is an introduction to nodes. A node is a device with communication capabilities, including but not limited to one or more of user equipment, network equipment, and industrial equipment. Among them, user devices include handheld terminals, wearable terminals, vehicles, in-vehicle devices, sensing devices, smart home devices, or leisure and entertainment devices, etc. Handheld terminals include but are not limited to mobile phones, tablets, or laptops, etc. Wearable devices include but are not limited to headphones, smart bracelets, smart watches, or smart glasses, etc. Vehicles include but are not limited to vehicles, ships, aircraft, rail transit (such as subways, high-speed railways, etc.), or logistics robots (such as automated guided vehicles (AGVs)), etc. In-vehicle devices include but are not limited to domain controllers (DCs), screens, microphones, speakers, electronic keys, keyless entry, start system controllers, battery management systems (BMSs), battery packs, or battery cells, etc. Sensing devices include but are not limited to cameras, radars, lidars, light sensors, temperature sensors, or humidity sensors, etc. Smart home devices include but are not limited to projectors, smart TVs, smart refrigerators, smart home gateways, or security equipment, etc. Leisure and entertainment equipment such as virtual reality (VR) equipment, mixed reality (MR) equipment, massage chairs, home theaters, game control devices, or 4D theater cabins.

[0133] Network devices include but are not limited to routers, switches, or base stations, etc. Industrial equipment includes industrial robots or robotic arms, etc.

[0134] The nodes in the embodiments of this application can be applied to various scenarios such as smart cars, smart homes, smart terminals, smart manufacturing, or smart exhibition halls. In some application scenarios or certain network types, devices with similar communication capabilities may not be called nodes. However, for the convenience of description, in the embodiments of this application, devices with communication capabilities are collectively referred to as nodes.

[0135] Please refer to Figure 1, which is a schematic diagram of a communication scenario of a communication system provided in an embodiment of the present application. The communication system 10 includes a management node and a terminal node. The management node is such as a first management node 101 and a second management node 102, and the terminal node is such as a terminal node 103.

[0136] Among them, a management node refers to a node with communication capabilities and management capabilities. Management capabilities may include communication management capabilities, such as nodes that can perform connection management, resource scheduling, and information security-related management. Exemplarily, a management node is a node that can send scheduling information. In some scenarios, a management node may also be called a G node, an access point, etc. It should be understood that management nodes and terminal nodes are exemplary names made to distinguish between communication nodes in a certain communication connection situation. During the specific implementation process, a node may be a terminal node or a management node. In some scenarios, a node even belongs to two or even more communication systems at the same time, serving as a terminal node in some communication systems and as a management node in another communication system.

[0137] Terminal nodes are nodes with communication capabilities that can transmit services to and from management nodes. In some scenarios, terminal nodes are also called T-nodes. These terminal devices can include user equipment (UE), such as barcode scanners, radio frequency identification (RFID), sensors, global positioning systems (GPS), laser scanners, and other information sensing devices.

[0138] The first management node 101 can establish a communication connection with the terminal node 103 and perform service transmission. To ensure security, service transmission between the first management node 101 and the terminal node 103 is protected by keys. Security can be further enhanced by adding fresh parameters to the security protection process. These keys, fresh parameters, and information such as the security algorithm used during security protection can form a security context and be stored on the first management node. Before performing service transmission, the first management node 101 needs to obtain the security context corresponding to the terminal node 103 to ensure the security of service transmission information.

[0139] As communication progresses, the terminal node 103 may need to establish a communication connection with the second management node 102 in various scenarios. Examples include roaming scenarios, the terminal node connecting to multiple management nodes, a failure of the first management node, or the first management node actively exiting the network (e.g., due to node replacement or networking changes). FIG1 illustrates a possible roaming scenario. The terminal node 103 may be mobile. When it is about to leave the first management node 101 and approach the second management node 102, the terminal node 103 may establish a connection with the second management node 102 and may optionally disconnect the communication connection with the first management node 101.

[0140] To ensure the security of data transmission between the terminal node 103 and the second management node 102, the two must first determine keys, freshness parameters, and authenticate each other's identities. The first management node 101 can provide other nodes with communication security parameters between it and the terminal node. These communication security parameters can include the security context corresponding to the terminal node determined by the first management node 101, partial information within the security context, and parameters that can be used to determine the security context. In short, the second management node can obtain the security context of the terminal node based on the communication security parameters. In this way, the second management node can implement security context-related operations, thereby establishing a connection for service transmission.

[0141] Considering some possible scenarios, if the second management node 102 does not have the security context of the terminal node 103, the terminal node 103 and the second management node 102 need to perform key negotiation through signaling interaction to determine the key, freshness parameters, etc., and authenticate each other's identities when establishing a connection. Because key negotiation requires multiple signaling interactions and has privacy requirements, the two parties need to send and receive multiple signaling messages for authentication, resulting in low efficiency and high latency in establishing the communication connection between the terminal node 103 and the second management node 102.

[0142] In the embodiment of the present application, the second management node 102 can obtain the security context of the terminal node 103 in advance before association, so that it can perform an association operation with the terminal node 103 with the security context. On the one hand, the association operation does not require re-negotiation of the security context with the terminal node 103, which can reduce signaling during the authentication process, thereby reducing the delay of signaling interaction. On the other hand, the lack of re-negotiation of the security context can reduce the amount of computation, further reducing the delay of signaling interaction.

[0143] In addition, the second management node 102 and the first management node 101 may be communicatively connected, where the communication connection includes a direct connection, a connection through an intermediate node (eg, a control node), and the like.

[0144] Optionally, in the solution shown in FIG1 , the connection between any two nodes may be wired, wireless, or a combination thereof. For example, the first management node 101 and the second management node 102 are connected via a wired communication technology (including direct and wired connections), as indicated by a solid line in FIG1 ; and the management node and the terminal are connected via a wireless communication technology, as indicated by a dashed line in FIG1 .

[0145] The communication method, communication device, communication system or node of the embodiments of the present application are applicable to a variety of networks, such as wired communication networks, wireless communication networks, or networks comprising a combination of wired and wireless communication networks. For example, the wireless communication network includes a network connected by the following communication technologies: SparkLink, 802.11b / g, Bluetooth, Zigbee, radio frequency identification (RFID), ultra-wideband (UWB) technology, or a wireless short-range communication system (such as a vehicle-mounted wireless short-range communication system), or the long-range connection technology includes a communication technology based on Long Term Evolution (LTE), fifth-generation mobile communication technology (5G or 5G technology), global system for mobile communications (GSM), general packet radio service (GPRS), universal mobile telecommunications system (UMTS), and other wireless access type technologies. For example, the wired communication network includes a network connected by the following communication technologies: one or more of fiber optic connection technology, vehicle-mounted wired communication technology, controller area network (CAN), local interconnect network bus (LIN), CAN flexible data rate (CAN FD), or vehicle-mounted Ethernet.

[0146] As a possible example, FIG2A shows a topology diagram of a possible communication system, where the communication system 20A includes T nodes and G nodes. The G node manages a certain number of T nodes, and the G node connects with these T nodes to jointly complete communication functions. During the process of a T node associating with a G node, the G node can obtain the security context of the T node. For example, G node 201, which can be regarded as the first management node 101, can establish a connection with T node 203 (which can be regarded as the terminal node 103), and the security context of the T node 203 can be stored in the G node 201. The G node 201 can provide secure communication parameters to other G nodes, such as G node 202 (which can be regarded as the second management node 102), and the secure communication parameters can be used to obtain the security context of the T node 203 from the G node 202. When the T node 203 needs to access the G node 202, the G node 202 can perform an access process with a security context with the T node 203.

[0147] Optionally, the connection between G node 201 and G node 202 can be a wireless connection (as shown by the dotted line in Figure 2A), or a wired connection, or a combination of an effective and wireless connection. As another possible example, Figure 2B shows a topology diagram of a possible communication system, where communication system 20B includes a T node, a G node, and a SparkLink access controller (SL-AC). For the relevant descriptions of the G and T nodes, please refer to the above. In Figure 2B, the G node 201 can provide security communication parameters to the SL-AC node 204, and the security communication parameters can be used to obtain the security context of the T node 203 associated with the G node 201. In conjunction with Figure 2B, the SL-AC node 204 can be connected to one or more G nodes, and multiple SL-AC nodes can also be connected to each other. The SL-AC node 204 can forward the security communication parameters provided to it by the G node 201 to other G nodes to which it is connected or to other SL-AC nodes, such as the SL-AC node 205. In the latter case, SL-AC node 205 can forward the security communication parameters to its connected G-node, such as G-node 202. In this way, G-node 202 can receive the security communication parameters from other G-nodes, such as G-node 201, and obtain the security context of the T-node to which the other node is connected. For example, when T-node 203 needs to access G-node 202, G-node 202 can perform a security context-based access procedure with T-node 203.

[0148] Optionally, the SL-AC node may also be connected to other networks, where other networks include but are not limited to the Internet or other networks of the same type.

[0149] The security context has been mentioned several times above, so let's first introduce it here.

[0150] A security context is a set of information containing parameters related to communication security, such as one or more of the following: keys, freshness parameters, key negotiation parameters, security algorithm information, and terminal identity. Security algorithm information includes one or more of the following: security algorithm indication information and security algorithm version.

[0151] The following is an introduction to the parameters in the security context. The key may include one or more of a shared key or a session key. A shared key is a key pre-shared with the terminal node. Optionally, when the security context includes a shared key, the security context also includes an identifier of the shared key and the validity period of the shared key. The identifier of the shared key is used to distinguish different shared keys. A session key refers to a key used to securely protect a communication session, and includes one or more of an encryption key, an integrity protection key, an authentication encryption key, etc. Furthermore, an encryption key may include a user plane encryption key or a signaling plane encryption key. Alternatively, an encryption key may also include a unicast encryption key, a multicast encryption key, etc. Similarly, an integrity key may include a user plane integrity key, a signaling plane integrity key, etc., and / or, an integrity key may include a unicast integrity key, a multicast integrity key. An authentication encryption key may also include the above-mentioned subdivided categories of keys, which are not described here one by one.

[0152] Furthermore, in the case where the security context includes a key, the security context may also include key information, and the key information includes one or more of the key identifier, key validity period, key startup time, etc. Exemplarily, the security context includes a shared key, a shared key ID, and the shared key validity period. Of course, when there are multiple keys, this application does not limit the information of each key to be present in the security context. For example, the security context may include a security key, but may not include the validity period of the security key. After the shared key expires and is updated, the node derives a new security key based on the updated shared key and adds it to the security context, and the old security key can no longer be used.

[0153] Fresh parameters are parameters used in the security field to obtain keys or participate in security protection processes to enhance security. Fresh parameters are typically updated after use to enhance security. Fresh parameters include, but are not limited to, counter values, random numbers, frame numbers, etc. In some scenarios, NONCEs are also commonly used as fresh parameters. For example, the first fresh parameter and second fresh parameter mentioned in some embodiments of this application are exemplary fresh parameters. In some scenarios, the first fresh parameter is used to derive a session key. For example, the secure communication parameters include a shared key, and the session key can be derived from the first fresh parameter and the shared key. Of course, other parameters may also be used in key derivation, which are not listed here. For example, the first fresh parameter may include a counter value, the value of which is updated after each use, for example, increasing by 1 after each use. The second fresh parameter is used as a parameter for security protection. The second fresh parameter is used as input to the cryptographic algorithm used for communication encryption. For example, when encrypting / decrypting information transmitted via a security context, the second fresh parameter can be used to enhance security.

[0154] Key negotiation parameters are the inputs of the key negotiation algorithm used when negotiating keys.

[0155] A security algorithm refers to an algorithm related to security protection, such as one or more of a key agreement algorithm, an encryption algorithm, a security algorithm, an authenticated encryption algorithm, a digest algorithm, and a key derivation algorithm. The indication information of a security algorithm refers to information that can indicate one or several security algorithms. Taking the encryption algorithm as an example, Table 1 shows a possible encryption algorithm identifier. The encryption algorithm is indicated by 2 bits of binary data. When the identifier is 00, it indicates encryption algorithm 1; when the identifier is 01, it indicates encryption algorithm 2, and so on. Encryption algorithms 1-4 are used to refer to encryption algorithms. The specific implementation process can design which algorithms to refer to, and the same applies to the security algorithm and authenticated encryption algorithm.

[0156] Table 1 Identification of encryption algorithms

[0157] The endpoint's identity is used to identify the endpoint, making it easier to distinguish different endpoints. This identity can be temporary or permanent. The temporary identity of an endpoint may be updated to improve security.

[0158] Exemplarily, the security context of the terminal node stored in the management node may include one or more of the following parameters: a shared key, a first fresh parameter, a session key, an identifier of a security algorithm, a first identity identifier of the terminal node, and a second fresh parameter, etc. Optionally, in the case where the security context includes a shared key, the security context may also include an identifier of the shared key and the validity period of the shared key. It should be understood that the number of the above-mentioned shared keys, first fresh parameters, session keys, security algorithms, and second fresh parameters may be multiple, and the scenarios used may also be different. For example, different session keys may be used in different communication modes. Exemplarily, the session key may include a unicast session key, a multicast session key (such as a group encryption key, a group security key, etc.), a broadcast session key, etc., and the security algorithm may include a unicast security algorithm, a multicast security algorithm, a broadcast security algorithm, etc., and the second fresh parameter includes a second fresh parameter for unicast, a second fresh parameter for multicast, etc. The remaining cases are no longer given examples one by one.

[0159] Please refer to Figure 3, which is a schematic diagram of the information contained in a security context provided by an embodiment of the present application. The security context is the security context of the terminal node obtained by the management node, including: the fixed ID of the terminal node, the temporary ID of the terminal node, the shared key (for example, expressed as Kgt), the validity period of the shared key, the identifier of the shared key (for example, Kgt ID), indication information of the key agreement algorithm, indication information of the encryption algorithm of the signaling plane, indication information of the integrity protection algorithm of the signaling plane, the encryption key of the signaling plane, the integrity protection key of the signaling plane, indication information of the encryption algorithm of the user plane, indication information of the integrity protection algorithm of the user plane, indication information of the authentication encryption algorithm of the user plane, the encryption key of the user plane, the integrity protection key of the user plane, the authentication encryption key of the user plane, the key deduction counter counter, COUNTERg, global frame number (GFN), group key (for example, expressed as GK), GK identifier (GK ID), group algorithm (Galgorithm), validity period of the group key (GK expiration), and group global frame number (GGFN).

[0160] In some possible implementations, there is an association between the parameters in the security context, for example, an encryption key, a security key, etc. can be obtained through a shared key. For example, FIG4 shows a schematic diagram of a key system. Among them, KEt and KEg are key negotiation parameters exchanged between the two communicating ends during key negotiation, and in some schemes are respectively referred to as the first key negotiation parameter (i.e., KEt) and the second key negotiation parameter (KEg). Taking the negotiation of keys between GT nodes as an example, KEt is the parameter provided by the T node, and KEg is the parameter provided by the g node. Through the first key negotiation parameter and the second key negotiation parameter, the two communicating ends can negotiate the key K KE . Further, the shared key such as the shared key kgt can be based on the key K KE Obtained, for example, by the key K KE The shared key is obtained with the fresh parameters, such as the third fresh parameter NONCEt and the fourth fresh parameter NONCEg. Similarly, NONCEt can be a parameter provided by the T node, and NONCEg can be a parameter provided by the G node.

[0161] In addition, it should be noted that although kgt is referred to as a shared key in some embodiments of this application, as explained above, a shared key refers to a key shared with another node. Therefore, in some scenarios, the key K shown in FIG4 KE , Kmid, signaling plane encryption key Ks.enc, signaling plane integrity protection key Ks.int, user plane encryption key Ku.enc, user plane integrity protection key Ku.int or user plane encryption key Ku.ac, etc. can also be used as shared keys.

[0162] In some possible implementations, the session key may be a shared key (e.g., kgt, K KE or Kmid). As shown in Figure 4, the key Kmid can be derived based on the shared key kgt and the counter counter, wherein the counter counter is regarded as a fresh parameter and is updated after obtaining Kmid, so that different keys Kmid can be derived multiple times based on the shared key and counter. Furthermore, multiple session keys can be obtained based on the key Kmid and the algorithm identifier. Exemplarily, the signaling plane encryption key Ks.enc can be obtained based on the key Kmid and the algorithm identifier "signalling enc". As another example, the signaling plane encryption key Ku.int can be obtained based on the key Kmid and the algorithm identifier "signallingint". Of course, the keys Kmid used in these two examples may be different. The remaining keys can be found in Figure 4 and will not be described one by one here.

[0163] The following describes an exemplary association process. Specifically, association refers to the process by which two nodes obtain a consistent communication key and establish a connection. In some scenarios, the association of a terminal node with a management node can also be referred to as the terminal node accessing the management node.

[0164] Please refer to Figure 5, which is a schematic diagram of an association process without a security context, including authentication and security context processes. For the sake of convenience, the messages (or information) exchanged during the association process are represented as M1-M5 respectively. Before this association process, there is no security context in the terminal node and the management node, no session key is negotiated, and there is no security context. When associating, the terminal node sends a message M1, which includes the terminal node ID, the first key negotiation parameter and the third fresh parameter. The management node determines the second key negotiation parameter and the fourth fresh parameter, and determines the first key based on the first key negotiation parameter and the second key negotiation parameter. Furthermore, the management node can determine the first key based on the first key (such as the key K KE ), the third freshness parameter, and the fourth freshness parameter determine a second key (e.g., key Kgt). Optionally, the management node can derive a session key based on the second key (or the first key) to securely protect messages. The management node provides the second key negotiation parameter and the fourth freshness parameter to the terminal node via message M2. Message M2 may optionally carry authentication information (i.e., first authentication information) for verifying the key, identity, or message integrity.

[0165] The terminal node obtains the first key, or the second key, in the same manner. Furthermore, the terminal node also derives a session key based on the second key (or the first key) to secure subsequent messages. In this way, the terminal node and the management node negotiate to obtain a consistent key. The terminal node can further generate second authentication information and send it to the management node in message M3. The management node verifies the second authentication information. If the verification is successful, the management node sends message M4 to the terminal node to complete the association. The terminal node optionally responds with message M5, indicating that the association is complete.

[0166] It should be understood that during specific implementations, the association process may exchange more messages, or the messages may carry more or fewer parameters. For example, the third and fourth fresh parameters may not be included, and when obtaining the second key, the second key may be obtained based on the first key and the counter. For another example, the first authentication information or the second authentication information may not be included. For another example, message M1 may optionally carry one or more of the following: the security capabilities of the terminal node (used to indicate the security algorithms supported by the terminal node), information indicating the key agreement algorithm, etc. For another example, message M2 may also carry the length of the authentication information, the length of the session key, the ID of the second key (or the ID of the first key), and information indicating the security algorithm. For another example, message M4 may also carry one or more of the following: the temporary ID assigned by the terminal node to the management node, the validity period of the second key, the validity period of the first key, etc. If the terminal node belongs to a communication group, the management node may also carry one or more of the following: the group key of the communication group, the ID of the group key, the group security algorithm, the validity period of the group key, etc. in message M4.

[0167] Please refer to Figure 6, which is a schematic diagram of an association process with a security context. For ease of distinction, the messages (or information) are represented as M6-M8 below. Before the association process, the management node obtains the security context of the terminal node. The content of the association context can be found in the above, for example, as shown in Figure 3. When associating, the terminal node sends a message M6 to the management node, carrying the identity of the terminal node (optionally a temporary identity or a fixed identity), such as the ID of the terminal node shown in Figure 6. Optionally, the message M6 can also carry an identifier of a shared key, such as a Kgt ID. Optionally, the message M6 can be integrity protected by an integrity protection key. The following description takes the message M6 as an example of being integrity protected. If the message M6 is not integrity protected, the subsequent step of checking the integrity can be skipped. Among them, integrity protection can be achieved by generating verification information for the message content in the message M6. The verification information can be carried in the message M6 to verify the integrity of part or all of the message content in the message M6.

[0168] The management node obtains the integrity protection key shared with the terminal node based on the terminal node's identity and checks the integrity of message M6 using this integrity protection key. If the management node successfully checks the integrity of message M6, it sends message M7, establishing an association between the management node and the terminal node. Optionally, if the management node successfully checks the integrity of message M6, it may also assign a temporary ID to the terminal node. In this case, message M7 may carry the new temporary ID assigned by the management node to the terminal node.

[0169] It is understood that the integrity protection key may be included in the security context, and the aforementioned "checking the integrity of the associated message based on the integrity protection key" may be replaced with "checking the integrity of the associated message based on the security context." Furthermore, the security context may include indication information and the integrity protection key of the integrity protection algorithm. The management node may check the integrity of message M6 using the integrity protection key and the specified integrity protection algorithm. Optionally, the integrity protection key here may be the integrity protection algorithm of the signaling plane.

[0170] Furthermore, the management node uses the signaling plane integrity protection algorithm and signaling plane integrity protection key Ks.int to perform integrity protection on message M7. Optionally, when signaling plane encryption protection is enabled, the management node may also use the signaling plane encryption algorithm and signaling plane encryption key Ks.enc to perform encryption protection on message M7.

[0171] The optional end node responds with message M8, indicating that the association is complete. In some scenarios, if message M7 is encrypted, the end node decrypts message M7. If message M7 is integrity-protected, the end node verifies the integrity of message M7. If the integrity verification succeeds, the association is complete, and the end node can send message M8 to the management node.

[0172] The method of the embodiment of the present application is introduced below.

[0173] Please refer to Figure 7, which is a flow chart of a communication method provided in an embodiment of the present application. Optionally, the method can be implemented based on the communication system described in one or more embodiments such as Figure 1, Figure 2A, or Figure 2B. The communication method shown in Figure 7 may include step S701 and / or step S702. It should be understood that for the convenience of description, the description is given in the order of S701 to S702, and it is not intended to limit the execution to the above order. The embodiment of the present application does not limit the order of execution, execution time, number of executions, etc. of the above one or more steps. S701 to step S702 are as follows:

[0174] Step S701: The second management node receives security communication parameters from the first management node.

[0175] The secure communication parameters include parameters used during communication between the first management node and the terminal node, including at least one of a key, a freshness parameter, security algorithm information, and key negotiation parameters. Furthermore, the secure communication parameters also include key information, freshness parameter information, and the like. Keys include, but are not limited to, shared keys and session keys, and key information includes, but is not limited to, key identifiers and key validity periods. Security algorithm information includes, among other things, a security algorithm identifier.

[0176] As one possible implementation, the secure communication parameters include the security context of the terminal node, or the secure communication parameters are the security context of the terminal node. Specifically, the first management node has established a connection with the terminal, and the first management node has the security context of the associated terminal node. The first management node can directly or indirectly provide this security context to other nodes, such as the second management node.

[0177] As another possible implementation, the secure communication parameters include a key. This key can be used to derive a session key, or it can be directly used as a session key to secure the communication process. In this case, it can be considered that the secure communication parameters do not directly include all parameters in the terminal node's security context, but only some of them, or it can be considered that the second management node can obtain some or all parameters in the terminal node's security context based on the secure communication parameters.

[0178] Exemplarily, the secure communication parameters may include a shared key, a shared key identifier, the validity period of the shared key, etc. Furthermore, the secure communication parameters may include freshness parameters, such as one or more of a first freshness parameter, a second freshness parameter, and a freshness parameter NONCEg. Furthermore, the secure communication parameters may include information indicating a security algorithm, such as information indicating a user plane encryption algorithm or information indicating a user plane integrity algorithm. Furthermore, the secure communication parameters may include an identifier of the terminal.

[0179] In some scenarios, the first management node can directly or indirectly provide secure communication parameters to the second management node. The method used to provide secure communication parameters to the second management node generally depends on the connection relationship between the first and second management nodes, and further on whether the two can sense each other. The following describes several possible connection relationships between the second and first management nodes:

[0180] In connection relationship 1, the first management node and the second management node are each connected to a control node. The first management node sends secure communication parameters to the control node, which are forwarded by the control node and received by the second management node. For details, see Figure 2B . It should be noted that the number of control nodes is not limited here. For example, in the architecture shown in Figure 2B , when G node 201 provides secure communication parameters to G node 202, the secure communication parameters may be forwarded through two SL-AC nodes.

[0181] Optionally, when the first management node and the second management node are not directly connected, the first management node may or may not perceive the second management node. Perceiving the second management node refers to obtaining relevant information about the second management node, such as the communication group to which the second management node belongs, the ID of the second management node, or the communication address of the second management node. When providing secure communication parameters, if the first management node perceives the second management node, the first management node may specify that the secure communication parameters be sent to the second management node or the communication group to which the second management node belongs. In this case, the secure communication parameters or the message carrying the secure communication parameters may include relevant information about the second management node.

[0182] Optionally, the second management node that is provided with security parameters may meet certain conditions. In other words, the control node may not provide security parameters to all connected (or perceived) management nodes. The following are some possible conditions that can be met by the management node that provides security parameters:

[0183] Condition 1: The second management node and the first management node belong to the same communication combination, which includes multiple management nodes and further includes one or more nodes such as control nodes or terminal nodes. The nodes in the communication combination trust each other, or in other words, only nodes that have passed trust verification (or identity verification) can join the communication combination. Nodes (or management nodes) in the same communication combination can provide each other with secure communication parameters. Furthermore, the communication combination can be further divided into multiple small combinations, and different small combinations are distinguished by small combination identifiers, that is, nodes with the same small combination identifier are in the same small combination. Management nodes in the same communication combination or the same small combination can provide each other with secure communication parameters. Nodes (or management nodes) in the same small combination can provide each other with secure communication parameters.

[0184] Exemplarily, the second management node and the first management node belong to the same extended service set (ESS). Furthermore, the first management node and the first management node have the same service set identifier (SSID). In other words, the first management node can provide secure communication parameters to management nodes with the same SSID in the same ESS.

[0185] Optionally, the first management node here may also be replaced by a control node, that is, the second management node and the control node belong to the same communication group, or the second management node and the control node belong to the same small group.

[0186] Condition 2: A secure communication channel is established between the control node and the second management node. For example, the control node and the second management node are connected via a wired communication connection, or a secure channel exists between the control node and the second management node. Exemplarily, the secure channel includes but is not limited to a transmission channel based on one or more of the following protocols: Secure Sockets Layer (SSL), Hypertext Transfer Protocol Secure (HTTPs), Transport Layer Security (TLS), Datagram Transport Layer Security (DTLS), etc.

[0187] Condition 3: The second management node supports fast connection establishment. Among them, fast connection establishment, or fast association, refers to the ability to establish a connection with the terminal node based on the security communication parameters provided by other nodes. For example, since fast connection establishment can directly establish an association through the security communication parameters of other nodes, this security communication parameter may be used by multiple nodes, which may pose risks for management nodes with high security requirements or management nodes connected to external nodes. Therefore, the management node can pre-set security requirement information, which is used to indicate that it can quickly connect based on the security communication parameters of other management nodes (or management nodes that receive a certain security level).

[0188] Furthermore, whether the second management node supports the fast connection establishment method can be set by the user, determined by the second management node based on security risks, or configured by the management node. For example, the second management node reports one or more of its own security requirements or security capabilities, and the control node evaluates whether it meets the conditions for supporting the fast connection establishment method. If the conditions for supporting fast connection establishment are met, the control node forwards the security communication parameters from other nodes to it.

[0189] Condition 4: The second management node is the management node to which the terminal node is about to connect. For example, the terminal node selects or is designated to connect to the second management node. The first management node or the control node can obtain instruction information about the second management node and provide it with secure communication parameters.

[0190] It should be understood that the above conditions are merely exemplary, and more or fewer conditions may exist during specific implementations. Multiple conditions may also be combined. As an example of a combination, the first management node may provide secure communication parameters to management nodes with the same SSID in the same ESS, and the nodes provided with secure communication parameters support fast connection establishment.

[0191] The above is the relevant content under the first connection relationship. The second exemplary connection relationship is introduced below.

[0192] Connection relationship 2: The first management node and the second management node are directly connected. The first management node sends security communication parameters to the second management node, and in return, the second management node receives the security communication parameters from the first management node. For the architecture, please refer to Figure 2A.

[0193] Similarly, the first management node may not provide secure communication parameters to all connected management nodes. In this case, the second management node may be a node in the same communication group or subgroup as the first management node, or a secure communication channel may be established between the two management nodes, or the second management node may establish an association based on the secure communication parameters of the first management node. For more details, please refer to the description of conditions 1 to 4 above and will not be explained here.

[0194] Of course, the above two situations are two exemplary connection situations. During the specific test process, there may be other connections between the two, which will not be explained one by one here.

[0195] In some solutions, the secure communication parameters can be sent through a secure channel. For example, a communication tunnel is established between the two ends of the secure communication parameters, or the two ends of the secure communication parameters are authenticated to ensure the security of the secure communication parameters during transmission.

[0196] As one possible implementation, secure communication parameters are transmitted via messages that comply with the Control and Provisioning of Wireless Access Points Protocol (CAPWAP) specification. CAPWAP is an application layer protocol based on the User Datagram Protocol (UDP) port. Messages transmitted via CAPWAP can be protected using the DTLS protocol. The CAPWAP transmission channel is also referred to as a CAPWAP tunnel.

[0197] For example, in combination with the architecture of Figure 2B and taking connection relationship 1 as an example, a CAPWAP tunnel is established between the first management node and the SL-AC, a CAPWAP tunnel is also established between the SL-ACs, and a CAPWAP tunnel is also established between the SL-AC and the second management node. Taking the security parameter as the security context of the terminal node as an example, the first management node provides the security context of its associated (optionally currently associated and / or previously associated) terminal node to the SL-AC through the CAPWAP tunnel, and the SL-ACs also transmit the security context through the CAPWAP tunnel. Furthermore, the SL-AC can provide the security context of the terminal node to the second management node through the CAPWAP tunnel.

[0198] In a possible implementation manner, there may be multiple possible designs for the timing or conditions for the first management node to send the security communication parameters.

[0199] For example, after establishing an association with the terminal node, the first management node may synchronize the secure communication parameters to other nodes (e.g., the second management node, the control node, etc.). For another example, after establishing an association, the first management node may send the secure communication parameters to other nodes when a subsequent condition is triggered.

[0200] For example, after the first management node establishes an association with the terminal node, it can synchronize the security communication parameters to other nodes (such as the second management node, the control node, etc.). For another example, the first management node provides security communication parameters to other nodes under a certain trigger condition. The trigger conditions here include but are not limited to: the terminal node has the need to establish a connection with other management nodes (such as roaming scenarios), the network relationship changes according to regulation, or the first management node exits the network (such as node replacement), etc.

[0201] Optionally, when the first management node establishes an association with the terminal node, if a first condition is met, the first management node provides secure communication parameters to the other node. For example, several possible conditions are described below:

[0202] Condition 1: When triggering a connection switch, the first management node provides secure communication parameters to other nodes. Specifically, if the terminal node has a need to establish a connection with other management nodes (for example, a roaming scenario), the connection switch is triggered. Exemplarily, the first management node sends a connection switch instruction to the terminal node to trigger the connection switch, and the connection switch instruction is used to instruct the terminal node to connect to the new management node. The connection switch instruction may include indication information of the second management node, so that the terminal node is associated with the second management node. As another example, the terminal node measures the distance to the management node, and the distance between it and the second management node is less than the distance between it and the first management node. The terminal node sends the measurement result to the first management node or sends relevant information of the second management node to trigger the connection switch.

[0203] Condition 2: When the first management node is overloaded, it provides secure communication parameters to other nodes.

[0204] Condition 3: The first management node receives indication information from a terminal node, where the indication information is used to indicate that the terminal node needs to establish a connection with the second management node.

[0205] Condition 4: The first management node receives control information from the control node, where the control information instructs the first management node to provide secure communication parameters to other nodes.

[0206] Optionally, these conditions can be used alone or in combination as the first condition. In addition, the conditions here can also be combined with the conditions of the management node that can be provided with secure communication parameters in the aforementioned connection relationship, which will not be explained here one by one.

[0207] In some possible implementations, secure communication parameters are associated with the security context of the terminal node. This association means that the secure communication parameters directly or indirectly affect some or all parameters in the terminal node. The following is an example of a possible implementation of this association:

[0208] In a first implementation, the secure communication parameters include the security context of the terminal node, and the second management node can directly use the secure communication parameters as the security context of the terminal node. For example, the first management node provides all parameters in the security context of the terminal node, or all required parameters (i.e., all parameters excluding optional parameters). The first management node then establishes the security context of the terminal node based on the secure communication parameters. It should be understood that the security context here can be considered an initial security context, which can be subsequently updated, such as by adding parameters to it, deleting parameters, or updating parameters therein.

[0209] In a second implementation, the secure communication parameters provided by the first management node only include some of the parameters in the security context. The second management node can determine the security context independently, but the secure communication parameters are used in the process of determining the security context. In this case, some of the parameters in the security context can be determined by the second management node itself.

[0210] As one possible example, the secure communication parameters include a shared key, an ID for the shared key, a first freshness parameter, a first identity identifier of the terminal node, and information indicating a security algorithm. The second management node determines a security context for the terminal node, which may include parameters in the secure communication parameters. Furthermore, the second management node may determine a session key based on the shared key and the first freshness parameter, which may also include the session key.

[0211] Taking the second management node determining the second fresh parameter as an example, the second management node may determine the first number based on the number of the protocol data unit (PDU) from the terminal node, and determine the second fresh parameter based on the second number and the first number. The security context includes the second fresh parameter. The initial value of the second number is predetermined, and the second number is updated when the first number is flipped.

[0212] Exemplarily, the second fresh parameter includes a GFN. Figure 8 shows a schematic diagram of a GFN. The GFN includes an HFN and a SN. The SN is the same as the protocol data unit number, while the HFN can be determined by the second management node, for example, set to 0. Alternatively, the second management node can use the HFN in the secure communication parameters as the HFN.

[0213] Optionally, the protocol data unit (PDU) from the terminal node can be, for example, a PDU carrying the first information. In other words, when receiving the first information, the second management node can determine the SN based on the number of the protocol data unit carrying the first information, thereby obtaining the second fresh parameter based on the HFN and SN. Furthermore, the second fresh parameter is added to the security context. In addition, in some solutions, the second fresh parameter can be used in the integrity check process of the first information as input to the integrity protection algorithm.

[0214] In some scenarios, the security communication parameters can also be updated. As a possible implementation, the first management node can send parameter update information after the security communication parameters are updated. Optionally, sending the parameter update information includes sending it directly to the first management node, or forwarding it through an intermediate node (for example, via one or more control nodes). Accordingly, the second management node can receive the parameter update information from the first management node and update some or all of the local security communication parameters. The local security communication parameters here may also include the security context of the terminal node in the second management node.

[0215] Exemplarily, the secure communication parameters of the terminal include a shared key, an identifier of the shared key, and a validity period of the shared key, and the parameter update information includes an updated shared key, a validity period of the updated shared key, and a validity period of the updated shared key.

[0216] Exemplarily, the secure communication parameter of the terminal includes a first freshness parameter, and the parameter update information includes the updated first freshness parameter.

[0217] Exemplarily, the secure communication parameter of the terminal includes a second fresh parameter, and the parameter update information includes the updated second fresh parameter.

[0218] Exemplarily, the terminal's secure communication parameters include a portion of the second fresh parameters, and the parameter update information includes an updated portion of the second fresh parameters. For example, the secure communication parameters include a HFN within the GFN, and the parameter update information includes the updated HFN. In this case, the second management node obtains a new GFN based on the updated HFN and SN.

[0219] Step S702: The second management node performs an association operation with the terminal node having a security context according to the security communication parameters.

[0220] Specifically, operations associated with a security context include: using parameters in the security context to securely protect (e.g., encrypt, secure, etc.) the transmitted information, and the peer end can also use the parameters in the security context to obtain the corresponding information. The following lists several possible implementations based on the different contents of the security communication parameters:

[0221] In the first embodiment, the secure communication parameters include a key, and the second management node uses the key in the secure communication parameters to securely protect the signaling sent to the terminal node, or obtains the content of the securely protected signaling from the terminal node using the key in the secure communication parameters. These signalings include associated related signaling.

[0222] For example, referring to Figure 6 , assuming the secure communication parameter includes an integrity protection key, message M6 can be integrity-protected by the terminal node using the integrity protection key, and the second management node can check the integrity of message M6 using the integrity protection key. If the integrity check of message M6 is successful, message M7 is sent to the secure communication parameter, and message M7 is also integrity-protected using the integrity protection key. If the terminal node passes the integrity check of message M7, the association is complete.

[0223] 6 , taking the example of the secure communication parameter including the encryption key, when signaling plane encryption is enabled, message M7 can be encrypted using the encryption key. When the terminal node successfully decrypts the message M7, the association is completed.

[0224] As another example, referring to FIG6 , the secure communication parameters include a shared key. The second management node derives a session key based on the shared key. Optionally, when a fresh parameter (e.g., a counter) is used in the key derivation process, the fresh parameter can be reset to a preset value, or the fresh parameter can be included in the secure communication parameters. Exemplarily, the derived session key includes a security key and / or an encryption key. For details, see the two aforementioned examples.

[0225] In the second embodiment, the secure communication parameters include key negotiation parameters. Taking FIG4 as an example, the secure communication parameters include parameters for obtaining the key KKE, or parameters for obtaining the key Kgt, or parameters for obtaining the session key.

[0226] 4, taking the example of the secure communication parameters including the key negotiation parameter KEt and the key negotiation parameter KEg, the second management node can obtain the key K according to the key negotiation parameter KEt and the key negotiation parameter KEg. KE NONCEt and NONCEg can be included in the secure communication parameters, or can be determined by the second management node and / or the terminal node during association and provided to the other party. In short, the second management node uses the key K KE , NONCEt and NONCEg obtain a shared key and further obtain a session key. Optionally, counter can be set to a preset value or included in the secure communication parameters.

[0227] In the third embodiment, the secure communication parameters include fresh parameters. For the case where both fresh parameters and keys are included, please refer to the above description. The following describes the case where only fresh parameters are included.

[0228] Taking the example of a scenario where the secure communication parameters only include the first fresh parameter, the second management node and the terminal node exchange key negotiation parameters to obtain a new shared key, and then derive the session key based on the shared key and the first fresh parameter. In this case, since the first fresh parameter is updated after each key generation, the second management node and the terminal node can continue to use the previous first fresh parameter to derive the session key. In some scenarios, because the previous parameters are difficult to crack, even if an attacker eavesdrops on the communication process between the second management node and the terminal node and obtains the relevant parameters for key negotiation, it is difficult to crack the session key, thereby improving the communication security between the second management node and the terminal node.

[0229] Taking the example that the secure communication parameters only include the second fresh parameter, the second fresh parameter can be used for encryption during the session. In conjunction with the association process shown in Figure 5, the second management node and the terminal node obtain a new shared key by exchanging key negotiation parameters, and obtain the session key based on the shared key and the first fresh parameter. The second management node generates verification information based on the session key and the second fresh parameter. The verification information is carried in the message M2, and the terminal node needs to check the integrity of the verification information based on the second fresh parameter and the session key. In other words, the previous second fresh parameter can be used to obtain the session key during association. Since the second fresh parameter is updated after use, it is difficult for attackers to crack it, thereby improving communication security.

[0230] In a fourth embodiment, the secure communication parameter includes an identifier of a security algorithm. The second management node and the terminal node continue to use the previous security algorithm to perform the association process, and there is no need to re-determine the security algorithm.

[0231] In summary, secure communication parameters include previously determined parameters related to communication security. When the terminal node and the second management node associate, these previously determined parameters can be used. This reduces the time it takes to re-determine these parameters between the two nodes, thus lowering latency. It also prevents the exchange of parameters, which can compromise their privacy and improve security. In particular, when secure communication parameters include keys, this can significantly reduce signaling interactions and communication latency.

[0232] In the fifth embodiment, the secure communication parameters may further include one or more of key information, or an identity identifier of a terminal node.

[0233] It should be understood that the above embodiments can be combined. For the case of combination, an exemplary introduction is given below in conjunction with Figures 10A, 10B, 11A, 11B, 12A and 12B. It should be noted that the aforementioned embodiments are all introduced by using the key and fresh parameters in the security communication parameters to perform association operations. In some embodiments, since the key (or fresh parameters, etc.) in the security communication parameters is also consistent with the key of the security context, the two can also be replaced. That is, the present application is also applicable to the following situation: the second management node can also first establish a security context based on the security communication parameters, and perform association operations based on the parameters in the security context.

[0234] In one possible implementation, a terminal node may receive a connection indication from a first management node, instructing the terminal node to connect to a second management node. Accordingly, the terminal node performs an association operation with the second management node based on the connection indication. For example, the connection indication may include information about the second management node, such as the ID and network address of the second management node. Taking a roaming scenario as an example, the connection indication may include a roaming request. Specifically, the first management node sends a roaming request to the terminal node, triggering the terminal node to switch to the second management node. Accordingly, the terminal node establishes a connection with the second management node.

[0235] As a possible implementation method, during the association operation, the second management node can receive a message from the terminal node, the message carrying the terminal node's identity identifier (referred to as the first identity identifier for ease of distinction), and the second management node can query whether it has the security context of the terminal node based on the first identity identifier. If the second management node does not have the security context of the terminal node, it can indicate that the terminal node association failed, or instruct the terminal node to perform an association process without a security context. For example, the process shown in Figure 5.

[0236] Optionally, in the association operation, the second management node may generate a new identity for the terminal node, for example, called a second identity, and send the new identity to the terminal node.

[0237] As a possible implementation, after the second management node successfully establishes an association with the terminal node, the two can perform data transmission via a communication connection.

[0238] Optionally, if the second management node and the terminal node fail to establish an association based on a security context, an association operation without a security context may be performed. For example, as shown in FIG5 . It should be understood that there are various possible reasons for association establishment failure, such as the second management node not having the terminal's security context, the second management node failing to verify the integrity of the message, the terminal node failing to verify the integrity of the message, or the terminal node failing to successfully decrypt the message from the second management node.

[0239] In some possible implementations, before the second management node establishes an association with the terminal node, the terminal node and the first management node may still be in a communication connection state. In this case, after the second management node successfully establishes an association with the terminal node, the terminal node and the first management node may be disconnected.

[0240] In some possible implementations, after the second management node establishes an association with the terminal, the second management node may provide secure communication parameters to other management nodes or control nodes for the other management nodes to perform an association process with the terminal node in a security context.

[0241] Optionally, when the security communication parameters are updated, the second management node may send parameter update information to other management nodes or control nodes.

[0242] In the embodiment shown in FIG. 7 , when a terminal node associates with a second management node, it can use the secure communication parameters provided by the first management node to perform an association operation with the terminal node using a security context. This means that the communication security parameters are used directly or indirectly to ensure the security of the information exchanged during the association operation. On the one hand, the association operation eliminates the need to re-negotiate the security context with the terminal node, which can reduce signaling during the authentication process and thus lower the latency of signaling interactions. On the other hand, the elimination of the need to re-determine secure communication parameters and negotiate a security context can reduce the computational effort between the terminal node and the second management node, further shortening the latency of establishing a connection.

[0243] In the above embodiment, we mentioned that the first management node and the second management node may not be directly connected. The following is an exemplary description based on the case where the two are connected through a control node.

[0244] Please refer to Figure 9, which is a flow chart of another communication method provided by an embodiment of the present application. The communication method shown in Figure 9 may include one or more steps from step S901 to step S905. It should be understood that for the convenience of description, the description is given in the order of S901 to S905, and it is not intended to limit the execution to the above order. The embodiment of the present application does not limit the order of execution, execution time, number of executions, etc. of the above one or more steps. S901 to step S905 are as follows:

[0245] Step S901: The first management node performs data transmission with the terminal node.

[0246] The first management node is associated with the terminal node, that is, the terminal is connected to the first management node, and a communication connection exists between the two, and data can be transmitted based on the communication connection.

[0247] The first management node has the security context of the terminal node, the contents of which are as described above, for example, as shown in FIG3 .

[0248] Step S902: The first management node sends a secure communication parameter to the control node. Correspondingly, the control node may receive the secure communication parameter from the first management node.

[0249] The security communication parameters can be described in detail above. There are many possible designs for when the first management node sends the security parameters, such as sending the security parameters after the terminal node is associated, sending the security parameters when the terminal node is connected to another management node, or sending the security parameters to the control node in response to an instruction from the control node.

[0250] In some scenarios, a terminal node can measure its distance from a management node or the quality of its communication channel with the management node, and determine whether to connect to a new management node based on the measurement results. For example, the quality of the communication channel can be indicated by one or more of the following parameters: communication signal strength, communication stability, communication latency, etc.

[0251] As one possible implementation, the terminal node periodically or aperiodically sends measurement results to the first management node. The first management node can make a decision based on the measurement results, select the best management node as the target management node, and instruct the terminal node to connect to the target management node. The target management node can be the second management node. Further, optionally, the first management node can send information about the target management node to the control node.

[0252] Optionally, the secure communication parameters are sent via a secure channel. For example, the first management node synchronizes the security context of the terminal node connected to it to the control node via a secure channel. The secure channel here includes but is not limited to a CAPWAP channel.

[0253] Step S903: The control node sends the security communication parameters to the second management node. Correspondingly, the second management node receives the security communication parameters from the control node.

[0254] Optionally, the security communication parameter is sent via a secure channel. Exemplarily, the first management node sends the security communication parameter to the second management node via a CAPWAP channel.

[0255] In a possible implementation, the control node sends the security communication parameter to the target management node, and the second management node belongs to the target management node or is the target management node. For details about the target management node, see the description in step S902.

[0256] In some scenarios, the second management node is a node that supports a fast connection establishment method. The fast connection establishment method is a method that supports associating with the terminal node using secure communication parameters from other nodes, including the first management node and / or the control node.

[0257] Furthermore, whether the second management node supports the fast connection establishment method can be set by the user, determined by the second management node based on security risks, or configured by the management node. For example, the second management node reports one or more of its own security requirements or security capabilities to the control node, and the control node evaluates whether it meets the conditions for supporting the fast connection establishment method. If the conditions for supporting fast connection establishment are met, the control node forwards the security communication parameters from the first management node to it.

[0258] In one possible implementation, the control node is connected to multiple management nodes. The management nodes may send security capability information, such as their own security requirements or the trust level between them and the first management node, to the control node. Accordingly, the control node determines, based on the security capability information reported by the management nodes, which nodes among the multiple nodes support the fast connection establishment method.

[0259] Furthermore, the control node may send third information to the first management node, where the third information is used to indicate a node that supports the fast connection establishment method. Exemplarily, the node that supports the fast connection establishment method includes the second management node. The first management node may provide secure communication parameters to the second management node, or the first management node may instruct the terminal node to connect to the second management node via the fast connection establishment method (i.e., perform an association process with a security context).

[0260] Step S904: The second management node performs an association operation with the terminal node having a security context according to the security communication parameters.

[0261] Taking the example of a secure communication parameter containing an integrity protection key or containing a parameter that obtains an integrity protection key, the terminal node can send first information to the second management node, and the first information is integrity-protected using the integrity protection key. Accordingly, the second management node receives the first information and checks the integrity of the first information using the integrity protection key. If the integrity check of the first information is successful, the second management node sends second information to the terminal node, and the second information is integrity-protected using the integrity protection key. Accordingly, the terminal node receives the second information, and if the integrity check of the second information is successful, an association is established. Furthermore, the terminal node can send a response message to the second management node, completing the association.

[0262] Optionally, the secure communication parameter includes indication information of an integrity protection algorithm. When the second management node checks the integrity of the information and performs integrity protection, it may be implemented using the integrity protection algorithm indicated by the indication information.

[0263] Illustratively, the first information includes first verification information, which is obtained by the terminal node based on the integrity protection key, the first information, and the integrity protection algorithm. The first management node may verify the first information based on the integrity protection key, the first information, and the integrity protection algorithm. If the verification is successful, the integrity check passes. The integrity protection algorithm used here may be specified by indication information in the secure communication parameters.

[0264] Optionally, the secure communication parameters further include a second fresh parameter. During the integrity check, the terminal node may perform an integrity check based on the second fresh parameter, the integrity protection key, and the integrity protection algorithm. For example, the first verification information is obtained based on the integrity protection key, the integrity protection algorithm, the second fresh parameter, and the first information.

[0265] Optionally, the secure communication parameter further includes an encryption key, or further includes information indicating an encryption algorithm. The second information may be encrypted using the encryption key and the encryption algorithm. Optionally, a second fresh parameter is also used in the encryption process.

[0266] In one possible implementation, the first management node may send handover indication information to the terminal node, the handover indication information including information about the second management node. The terminal node may receive the handover indication information and then initiate a security context association process with the second management node. Exemplarily, the handover indication information is a roaming request instruction instructing the terminal node to connect to the second management node.

[0267] For related descriptions, please refer to the description of step S702.

[0268] Optionally, the communication method shown in FIG9 further includes step S905, which is specifically as follows:

[0269] Step S905: The terminal node disconnects from the first management node.

[0270] Exemplarily, the terminal node and the first management node originally transmit data through a logical channel, and the terminal node and / or the first management node may release the meta-logical channel.

[0271] In the embodiment shown in Figure 9, the management node can provide the secure communication parameters of its connected terminal nodes to the control node. The control node then distributes the secure communication parameters to other management nodes, such as a second management node, so that the other management nodes can associate with the terminal node using a security context. This not only saves signaling overhead but also reduces the computational effort required by the management node and terminal node during association, significantly shortening the latency of establishing a communication connection.

[0272] Figures 7 and 9 above provide a variety of possible solutions. Some of these possible designs are exemplarily described below in conjunction with Figures 10A, 10B, 11A, 11B, 12A, or 12B. It should be understood that the logic, terminology, etc. in the embodiments shown in Figures 10A, 10B, 11A, 11B, 12A, and 12B can be found in the aforementioned descriptions.

[0273] Please refer to Figure 10A, which is a flowchart of another communication method provided by an embodiment of the present application. The communication method may include some or all of the steps in steps S1001 to S1006. The details are as follows:

[0274] Step S1001: The terminal node and the first management node establish an access layer default bearer.

[0275] That is, the terminal node and the first management node establish an initial connection. This process may include an authentication process in a scenario without a security context, as well as a security context negotiation process. For example, Figure 5 illustrates an authentication and security context negotiation process in a scenario without a security context. It should be understood that after the security context negotiation process, the first management node has the terminal node's security context.

[0276] Figure 10A also illustrates a possible connection establishment process. The first management node can send an X resource control (XRC) setup message to the terminal node, and the terminal node can return a response message. The first management node performs authentication and security context negotiation with the terminal. The first management node sends an XRC reconfiguration message to the terminal node, and the access layer bearer is established, enabling data transmission. The X resource control message can be replaced with other information indicating communication resources, such as channels. It should be understood that the signaling process for connection establishment here is only an example, and the specific implementation process can have other designs.

[0277] Optionally, before establishing a connection between the terminal node and the first management node, the terminal node may perform scanning to select a management node to connect to.

[0278] Optionally, the management nodes, including the first management node and the second management node, can send system messages to facilitate other nodes to perceive the management nodes. For example, the system message includes information about the management node that sent the message, so that the terminal node can obtain the information about the management node.

[0279] Step S1002: The first management node sends a security context to the second management node.

[0280] Correspondingly, the second management node receives the security context from the first management node.

[0281] The first management node may be connected to the second management node via a wired communication technology and / or a wireless communication technology. Optionally, the connection between the two may also pass through an intermediate node, such as a control node.

[0282] Optionally, the method may further include step S1003, which is as follows:

[0283] Step S1003: The first management node sends parameter update information to the second management node.

[0284] Correspondingly, the second management node receives the parameter update information from the first management node.

[0285] It is understandable that after the first management node obtains the security context, the parameters in the security context may be updated. If the security context is updated, such as an update to the key or HFN, the first management node can send the updated parameters to the second management node. Accordingly, the second management node can obtain the parameter updates and replace the parameter values ​​with the updated values. For example, the second management node can replace the shared key with the updated shared key. In another example, the second management node can replace the HFN in the GFN with the updated HFN. When the second management node receives a PDU next time, it will derive the GFN based on the new PDU SN and the updated HFN.

[0286] Optionally, the method may further include step S1004, which is as follows:

[0287] Step S1004: The first management node triggers connection switching.

[0288] For example, the first management node sends a connection instruction to the terminal node, and the connection instruction includes information about the management node to be connected. Optionally, the terminal node can also scan and make a connection switching decision to determine the management node to be connected.

[0289] Step S1005: The terminal node establishes an access layer default bearer with the second management node.

[0290] During the establishment process, the terminal node and the second management node perform an association process with a security context scenario.

[0291] Optionally, the method may further include step S1006, which is as follows:

[0292] Step S1006: The first management node and the terminal node perform connection release request / response.

[0293] For example, the first management node sends a connection release request to the terminal node. Accordingly, the terminal node responds to the request. Both support the release of the access layer default bearer. Of course, the same applies to the case where the terminal node sends a connection release request.

[0294] Optionally, the connection release request may also be replaced by an access link release request, etc., to release the access layer default bearer.

[0295] In the embodiment shown in Figure 10A, after establishing an access layer connection with a terminal node, the first management node can obtain the terminal node's security context and provide the terminal node's security context to the second management node. At some point in the future, the terminal node can switch management nodes and continue the access process with the second management node with a security context.

[0296] Optionally, as mentioned in step S1002, the first management node and the second management node may not be directly connected. Please refer to Figure 10B, which is a flow chart of another communication method provided in an embodiment of the present application, wherein step S1001 and steps S1004-step 1006 can refer to the embodiment of Figure 10A. In Figure 10B, the first management node is not directly connected to the second management node, but is connected through a control node (the number of control nodes passed through in the middle may be multiple). In step S1002, the first management node can send a security context to the control node, and the security context is forwarded to the second management node via the control node. Similarly, in step S1003, the parameter update information is also forwarded through the control node.

[0297] Please refer to Figure 11A, which is a flow chart of another communication method provided in an embodiment of the present application. In Figure 11A, the first management node provides the security context of the terminal node to other nodes after triggering the connection handover.

[0298] Specifically, the communication method shown in FIG11A may include some or all of the steps S1101 to S1106. Specifically, the steps are as follows:

[0299] Step S1101: The terminal node and the first management node establish an access layer default bearer.

[0300] Optionally, the method may further include step S1102, which is as follows:

[0301] Step S1102: The first management node triggers connection switching.

[0302] Step S1103: The first management node sends a security context to the second management node.

[0303] Optionally, the method may further include step S1104, which is as follows:

[0304] Step S1104: the first management node sends parameter update information to the second management node.

[0305] Step S1105: The terminal node establishes an access layer default bearer with the second management node.

[0306] During the establishment process, the terminal node and the second management node perform an association process with a security context scenario.

[0307] Optionally, the method may further include step S1106, which is specifically as follows:

[0308] Step S1106: The first management node and the terminal node perform a connection release request / response.

[0309] Detailed descriptions of some steps shown in FIG. 11A may refer to the aforementioned embodiments, such as the embodiments shown in FIG. 7 , FIG. 9 , and FIG. 10A .

[0310] In the embodiment shown in FIG11A , after establishing an access layer connection with a terminal node, the first management node can obtain the terminal node's security context. At a later point, when the terminal node needs to access a second management node, the first management node provides the terminal node's security context to the second management node, enabling the terminal node to perform a security context-based access process with the second management node.

[0311] Optionally, the first management node and the second management node may not be directly connected. Please refer to Figure 11B, which is a flow chart of another communication method provided in an embodiment of the present application, wherein step S1101, step S1102, and step S1105-step 1106 can refer to the embodiment of Figure 11A. In Figure 11B, the first management node is not directly connected to the second management node, but is connected through a control node (the number of control nodes passed through in the middle may be multiple). In step S1103, the first management node can send a security context to the control node, and the security context is forwarded to the second management node via the control node. Similarly, in step S1104, the parameter update information is also forwarded through the control node.

[0312] Please refer to Figure 12A, which is a flowchart of another communication method provided by an embodiment of the present application. In Figure 12A, the first management node does not directly provide the security context of the terminal node, but instead provides secure communication parameters. The secure communication parameters include some parameters in the security context and / or the secure communication parameters include information used to determine the parameters in the security context. After receiving the secure communication parameters, the second management node obtains the security context and can perform security context-related operations with the terminal node.

[0313] Specifically, the communication method shown in FIG12A may include some or all of the steps S1201 to S1206. Specifically, the steps are as follows:

[0314] Step S1201: The terminal node and the first management node establish an access layer default bearer.

[0315] Optionally, the method may further include step S1202, which is as follows:

[0316] Step S1202: The first management node and the second management node send security communication parameters.

[0317] Optionally, the secure communication parameters include indication information of a security algorithm (such as an encryption algorithm and integrity protection algorithm or an authentication encryption algorithm, a key derivation function), a shared key (such as Kgt), an identifier of the shared key (such as Kgt ID), and a second fresh parameter (such as a counter).

[0318] Furthermore, the secure communication parameter may further include a first identity of the terminal node. Furthermore, the first identity may be allocated to the terminal node by the first management node.

[0319] Optionally, the method may further include step S1203, which is as follows:

[0320] Step S1203: The first management node sends parameter update information to the second management node.

[0321] For example, taking the example of security communication parameters including temporary ID, Kgt, Kgt ID, counter, etc., when the temporary ID, Kgt, Kgt ID, counter, etc. are updated, the first management node sends the updated parameters, such as the updated Kgt, the updated Kgt ID, or the updated counter, to the second management node.

[0322] Step S1204: The first management node triggers connection switching.

[0323] Step S1205: The terminal node establishes an access layer default bearer with the second management node.

[0324] During the establishment process, the terminal node and the second management node perform an association process with a security context scenario.

[0325] Optionally, the method may further include step S1206, which is specifically as follows:

[0326] Step S1206: The first management node and the terminal node perform connection release request / response.

[0327] Detailed descriptions of some steps shown in FIG. 12A may refer to the aforementioned embodiments, such as the embodiments of FIG. 7 , FIG. 9 , FIG. 10A , and FIG. 11B .

[0328] In the embodiment shown in Figure 12A, after establishing an access layer connection with a terminal node, a first management node can obtain the terminal node's security context. The first management node provides secure communication parameters to a second management node, which then determines the terminal node's security context based on the secure communication parameters. Subsequently, when the terminal node accesses the second management node, the two nodes can proceed with a secure context-based access process.

[0329] Optionally, the first management node and the second management node may not be directly connected. Please refer to Figure 12B, which is a flow chart of another communication method provided in an embodiment of the present application. Some steps can be found in the embodiment of Figure 12A. In Figure 12B, the first management node is not directly connected to the second management node, but is connected through a control node (the number of control nodes passed through in the middle may be multiple). In step S1202, the first management node can send a security communication parameter to the control node, and the security communication parameter is forwarded to the second management node via the control node. Similarly, in step S1203, the parameter update information is also forwarded through the control node.

[0330] The above describes in detail the method of the embodiment of the present application. The following provides an apparatus of the embodiment of the present application.

[0331] It should be understood that the division of the units in the device provided in the embodiments of the present application is only a division of logical functions, and in actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated. In addition, the units in the device can be implemented in the form of a processor calling software. For example, the device includes a processor, the processor is connected to a memory, and instructions are stored in the memory. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of each unit of the device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device.

[0332] Alternatively, the units in the device may be implemented in the form of hardware circuits, and the functions of some or all of the units may be implemented by designing the hardware circuits, which may be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), which implements the functions of some or all of the above units by designing the logical relationships between the components within the circuit. For another example, in another implementation, the hardware circuit may be implemented by a programmable logic device (PLD), such as a field programmable gate array (FPGA), which may include a large number of logic gate circuits, and the connection relationships between the logic gate circuits may be configured through configuration files, thereby implementing the functions of some or all of the above units.

[0333] In an embodiment of the present application, each unit in the device may be one or more processors (or processing circuits) configured to implement the above method, such as: CPU, (graphics processing unit, GPU), neural network processing unit (neural network processing unit, NPU), tensor processing unit (tensor processing unit, TPU), deep learning processing unit (deep learning processing unit, DPU), microprocessor (micro processor unit, MPU), digital signal processor (digital signal processor, DSP), ASIC, FPGA, or a combination of at least two of these processor forms.

[0334] In addition, the various units in the above devices can be fully or partially integrated together, or can be implemented independently. In one implementation, these units are integrated together and implemented in the form of a system-on-a-chip (SOC). The SOC may include at least one processor for implementing any of the above methods or implementing the functions of the various units of the device. The type of the at least one processor may be different, for example, including a CPU and an FPGA, or including a CPU and an artificial intelligence processor, or including a CPU and a GPU, etc. Several possible devices are listed below.

[0335] Please refer to Figure 13, which is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. Optionally, the communication device 130 can be an independent device, such as a node. Alternatively, the communication device 130 can also be a device in an independent device (such as a node), such as a chip or an integrated circuit. The communication device 130 is used to implement the aforementioned communication method, such as the communication method shown in Figure 7, Figure 9, Figure 10A, Figure 10B, Figure 11A, Figure 11B, Figure 12A, or Figure 12B.

[0336] In one possible design, the communication device 130 includes a communication unit 1301 and a processing unit 1302, and the communication device 130 is used to implement the method on the second management node side in the aforementioned communication method.

[0337] In one possible implementation, the communication unit 1301 is configured to receive security communication parameters from the first management node, where the security communication parameters include parameters used when the first management node communicates with the terminal node, and the security communication parameters are associated with a security context of the terminal node;

[0338] The processing unit 1302 and the communication unit 1301 are further configured to perform an association operation with a security context with the terminal node according to the security communication parameters.

[0339] For example, the processing unit is used to complete one or more of the aforementioned operations such as determination, checking (or verification), calculation, generation, update, encryption, or decryption, and the communication unit is used to complete one or more of the aforementioned operations such as sending and receiving.

[0340] In yet another possible implementation, the processing unit 1302 and the communication unit 1301 are further configured to perform data transmission with the second management node after establishing an association.

[0341] In another possible implementation, the security context of the terminal node includes a key. Optionally, when the security context includes a key, the security context may also include key information, where the key information includes one or more of a key identifier, a key validity period, a key activation time, and the like.

[0342] In another possible implementation, the security context of the terminal node includes fresh parameters. The first fresh parameter and the second fresh parameter are exemplary fresh parameters. In some embodiments, the first fresh parameter is used to derive a session key, and the second fresh parameter is used as a parameter for security protection.

[0343] Optionally, the second freshness parameter is determined by the first number and the second number. Optionally, the initial value of the second number is predetermined. The second number can be updated, for example, when the first number is flipped. Optionally, the second freshness parameter is a global frame number (GFN), where the GFN includes a high frame number (HFN) and a serial number (SN). Optionally, the sequence number is the same as the number of the protocol data unit (PDU), and the HFN is predetermined.

[0344] Alternatively, the second fresh parameter is a predefined parameter value, such as HFN. Further, the second fresh parameter can be updated by the number of the protocol data unit. For example, the second fresh parameter is updated when the SN rolls over.

[0345] In another possible implementation, the security context of the terminal includes information about a security algorithm, such as indication information of the security algorithm.

[0346] In yet another possible implementation, the secure communication parameter is a security context of the terminal node.

[0347] In yet another possible implementation, the secure communication parameters include some parameters in the security context and / or parameters used to obtain some parameters in the security context.

[0348] Exemplarily, the secure communication parameters include a key. The key can be directly used as a session key for secure protection of the communication process, or the key can be used to derive a session key.

[0349] Exemplarily, the secure communication parameter includes a shared key, and the processing unit 2601 is further configured to obtain a session key based on the shared key. Further, the session key derived by the second management node is included in the security context of the terminal node. Optionally, the security context also includes the shared key.

[0350] Optionally, freshness parameters, key identifiers, etc. may also be used when deriving the session key. For example, the secure communication parameters include a shared key Kgt and a first security parameter counter. The second terminal node determines the user plane encryption key based on the shared key Kgt, the first security parameter counter, and the identifier of the user plane encryption key.

[0351] Exemplarily, the secure communication parameters further include an identifier of the shared key and a first freshness parameter, and the processing unit is configured to determine the session key according to the shared key, the identifier of the shared key, and the first freshness parameter.

[0352] Exemplarily, the secure communication parameters further include an identifier of a security algorithm and a first identity identifier of the terminal node.

[0353] In another possible implementation, the session key includes an integrity protection key. The communication unit 1301 is further configured to receive first information from the terminal node, the first information being integrity protected using the integrity protection key;

[0354] The processing unit 1302 is further configured to check the integrity of the first information according to the integrity protection key;

[0355] The communication unit 1301 is further configured to send second information to the terminal node if the integrity check of the first information is successful. Optionally, the second information is used for the terminal node to establish an association with the second management node, and the second information is integrity protected using an integrity protection key.

[0356] Optionally, the session key includes an encryption key, and the second information is encrypted using the encryption key.

[0357] In another possible implementation, the security context of the terminal includes a session key and an identifier of the first security algorithm. The first information includes first verification information, and the first verification information corresponds to the session key, the first information, and the first security algorithm.

[0358] The processing unit 1302 is further configured to verify the first verification information according to the session key, the first information and the first security algorithm.

[0359] Exemplarily, the session key is an integrity protection key, and the identifier of the first security algorithm is an identifier of the first integrity protection algorithm.

[0360] In another possible implementation, the security context includes the first identity of the terminal node. The processing unit 1302 is further configured to obtain the security context of the terminal node according to the first identity in the first information.

[0361] In another possible implementation, the processing unit 1302 is further configured to generate a second identity identifier for the terminal node, the identity identifier being used to identify the terminal node. The communication unit 1301 is further configured to send the second identity identifier to the terminal node. Optionally, the second identity identifier is carried in the second information.

[0362] In another possible implementation, the second fresh parameter in the security context may be determined by the second management node. For example, the second fresh parameter may be predefined, such as 128 bits of all 0s, or a preset value.

[0363] In another possible implementation, the security context of the terminal node includes a second fresh parameter. Processing unit 1302 is further configured to determine the first number based on the number of the protocol data unit (PDU) from the terminal node. Processing unit 1302 is further configured to determine the second fresh parameter based on the second number and the first number, where the initial value of the second number is predetermined and the second number is updated when the first number is flipped.

[0364] In another possible implementation, the communication unit 1301 is further configured to receive parameter update information from the first management node. The processing unit 1302 is further configured to update some or all of the security communication parameters based on the parameter update information. Updating some or all of the security communication parameters may include updating some or all of the parameters in the security context.

[0365] In another possible implementation, the first management node and the communication device 130 are connected or indirectly connected. The connection can be wired or wireless. In a direct connection, the communication device 130 can receive secure communication parameters sent by the first management node. An indirect connection can be established through an intermediate node, which forwards information between the two nodes.

[0366] Exemplarily, the communication device 130 receives the security communication parameters from the first management node, including: the communication unit 1301 receives the security communication parameters forwarded via the control node, and the control node is communicatively connected with the first management node and the communication device 130.

[0367] In yet another possible implementation, the security communication parameters are transmitted via messages that comply with the CAPWAP protocol.

[0368] In yet another possible implementation, the communication unit 1301 and the processing unit 1302 are further configured to perform an association operation with the terminal node without a security context when the association fails.

[0369] In another possible implementation, the communication device 130 is a node that supports a fast connection establishment mode, or the communication device 130 belongs to a node that supports a fast connection establishment mode.

[0370] In another possible implementation, the communication unit 1301 is further configured to send security communication parameters between the second management node and the terminal node to the control node. The security communication parameters between the second management node and the terminal node are used to obtain a security context of the terminal node.

[0371] In yet another possible implementation, the communication unit 1301 is further configured to send parameter update information to the control node, where the parameter update information is used to update security communication parameters between the second management node and the terminal node.

[0372] In one possible design, the communication device 130 includes a communication unit 1301 and a processing unit 1302, and the communication device 130 is used to implement the method on the terminal node side in the aforementioned communication method.

[0373] In one possible implementation, the communication unit 1301 and the processing unit 1302 are configured to perform data transmission with a first management node, where the first management node has a security context with the terminal node;

[0374] The communication unit 1301 and the processing unit 1302 are further configured to perform an association operation with a security context with the second management node when a connection establishment condition is met, and the second management node has a security context with the terminal node.

[0375] Optionally, the communication unit 1301 and the processing unit 1302 are further configured to perform data transmission with the second management node.

[0376] In another possible implementation, the communication unit 1301 is further configured to receive a roaming request from the first management node, the roaming request instructing the terminal node to perform a connection handover. Further, in response to the roaming request, the communication device 130 performs an association operation with the second management node with a security context.

[0377] In another possible implementation, the communication unit 1301 and the processing unit 1302 are further configured to measure the distances between the first management node and the second management node and the terminal node, respectively. The connection establishment condition includes: the distance between the second management node and the terminal node is less than the distance between the first management node and the terminal node.

[0378] In yet another possible implementation, the communication unit 1301 and the processing unit 1302 are further configured to disconnect data transmission with the first management node.

[0379] In yet another possible implementation, the communication unit 1301 is further configured to receive switching indication information from the first management node, where the switching indication information includes information indicating the second management node.

[0380] In another possible implementation, the second management node is a node that supports a fast connection establishment mode.

[0381] In another possible implementation, the security context of the terminal node includes an integrity protection key. The communication unit 1301 is further configured to send the first information to the second management node, where the first information is integrity protected using the integrity protection key.

[0382] The communication unit 1301 is further configured to receive second information from the second management node, where the second information is used to establish an association between the terminal node and the second management node, and the second information is integrity protected using the integrity protection key;

[0383] The processing unit 1302 is further configured to check the integrity of the first information according to the integrity protection key;

[0384] In case the integrity check of the first information is successful, the association is completed.

[0385] In yet another possible implementation, the communication unit 1301 and the processing unit 1302 are further configured to perform an association operation with the terminal node without a security context when the association fails.

[0386] In one possible design, the communication device 130 includes a communication unit 1301 and a processing unit 1302, and the communication device 130 is used to implement the method on the first management node side in the aforementioned communication method.

[0387] In one possible implementation, the communication unit 1301 and the processing unit 1302 are used to perform data transmission with the terminal node;

[0388] The communication unit 1301 is also used to send security communication parameters between the first management node and the terminal node. The security communication parameters are associated with the security context of the terminal node. The security communication parameters are used for the second management node to perform a security context association process with the terminal node.

[0389] In yet another possible implementation, the communication unit 1301 is further configured to send parameter update information to the first management node, where the parameter update information is used to update some or all of the security communication parameters.

[0390] In a possible implementation, the communication unit 1301 is further configured to send security communication parameters between the control node and the terminal node to the control node, and the control node is configured to provide the security communication parameters between the control node and the terminal node to the second management node.

[0391] In a possible implementation, the parameter update information is sent to the control node, and the control node is configured to provide the parameter update information to the second management node.

[0392] In yet another possible implementation, the communication unit 1301 is further configured to send switching indication information to the terminal node, where the switching indication information includes information indicating the second management node.

[0393] In another possible embodiment, the communication unit 1301 is also used to receive third information from the control node, and the third information is used to indicate nodes that support the fast connection establishment method. The nodes that support the fast connection establishment method include a second management node. The fast connection establishment method is a method that supports association with the terminal node through security communication parameters from other nodes.

[0394] In one possible design, the communication device 130 includes a communication unit 1301 and a processing unit 1302, and the communication device 130 is used to implement the method on the control node side in the aforementioned communication method.

[0395] In one possible implementation, the communication unit 1301 is configured to receive security communication parameters between the first management node and the terminal node from the first management node. The communication unit 1301 is further configured to send the security communication parameters to the second management node. The security communication parameters are associated with the security context of the terminal node and are used in the security context association process between the second management node and the terminal node.

[0396] In one possible implementation, the communication unit 1301 is further configured to receive parameter update information from the first management node, the parameter update information being used to update some or all of the security communication parameters, and to send the parameter update information to the second management node.

[0397] In one possible embodiment, the communication unit 1301 is also used to send third information to the first management node, and the third information is used to indicate nodes that support the fast connection establishment method. The nodes that support the fast connection establishment method include the second management node. The fast connection establishment method is a method that supports association with the terminal node through security communication parameters from other nodes.

[0398] In one possible embodiment, the communication unit 1301 is also used to determine the nodes among the multiple nodes that support the fast connection establishment method based on the security requirements of the multiple management nodes and / or the trust between the multiple management nodes and the first management node, the multiple management nodes are connected to the control node, and the multiple management nodes include the second management node.

[0399] Please refer to Figure 14, which is a schematic diagram of the structure of another communication device provided in an embodiment of the present application. The communication device 140 can be an independent device, such as a node, or a device included in an independent device, such as a chip, a software module, or an integrated circuit. The communication device 140 may include at least one processor 1401 and a communication interface 1402. Optionally, it may also include at least one memory 1403. Further optionally, it may also include a connection line 1404, wherein the processor 1401, the communication interface 1402 and / or the memory 1403 are connected via the connection line 1404, and / or communicate with each other via the connection line 1404 to transmit control signals and / or data signals.

[0400] in:

[0401] The processor 1401 is a module that performs arithmetic operations and / or logical operations, and may specifically include one or more of the following modules: a filter, a modem, a power amplifier, a low noise amplifier (LNA), a baseband processor, a radio frequency processor, a radio frequency circuit, a central processing unit (CPU), an application processor (AP), a microcontroller unit (MCU), an electronic control unit (ECU), a graphics processing unit (GPU), a microprocessor unit (MPU), an application specific integrated circuit (ASIC), an image signal processor (ISP), a digital signal processor (DSP), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), or a coprocessor, etc.

[0402] The communication interface 1402 may be used to provide information input or output for the at least one processor, or to receive externally transmitted signals and / or send externally transmitted signals.

[0403] For example, communication interface 1402 may include interface circuitry.

[0404] For example, the communication interface 1402 may include a wired link interface such as an Ethernet cable, or a wireless link interface (Wi-Fi, Bluetooth, general wireless transmission, vehicle-mounted short-range communication technology, and other short-range wireless communication technologies, etc.).

[0405] Optionally, the communication interface 1402 may further include a radio frequency transmitter, an antenna, etc. When the communication interface 1402 includes an antenna, the number of antennas may be one or more.

[0406] As a possible design, if the communication device 140 is a standalone device, the communication interface 1402 may include a receiver and a transmitter. The receiver and the transmitter may be the same component or different components. When the receiver and the transmitter are the same component, the component may be referred to as a transceiver.

[0407] As another possible design, if the communication device 140 is a chip or a circuit, the communication interface 1402 may include an input interface and an output interface. The input interface and the output interface may be the same interface, or may be different interfaces.

[0408] Optionally, the functions of the communication interface 1402 may be implemented by a transceiver circuit or a dedicated transceiver chip.

[0409] Memory 1403 is used to provide storage space for storing data such as the operating system and computer programs. Memory 1403 can be one or a combination of random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM).

[0410] The functions and actions of the modules or units in the communication device 140 listed above are merely exemplary.

[0411] Each functional unit in the communication device 140 can be used to implement the aforementioned communication method, such as the communication method shown in Figure 7, Figure 9, Figure 10A, Figure 10B, Figure 11A, Figure 11B, Figure 12A, or Figure 12B, for example, for executing a method executed by a first management node, a second management node, a terminal node or a management node.

[0412] Optionally, processor 1401 may be a processor specifically configured to execute the aforementioned method (referred to as a dedicated processor for ease of distinction), or may be a processor configured to execute the aforementioned method by invoking a computer program (referred to as a dedicated processor for ease of distinction). Optionally, the at least one processor may include both a dedicated processor and a general-purpose processor.

[0413] Optionally, in the case where the communication device 140 includes at least one memory 1403 , if the processor 1401 implements the aforementioned communication method by calling a computer program, the computer program may be stored in the memory 1403 .

[0414] An embodiment of the present application further provides a chip comprising a logic circuit and a communication interface. The communication interface is configured to receive or transmit signals, and the logic circuit is configured to receive or transmit signals via the communication interface. The chip is configured to implement the aforementioned communication methods, such as those shown in Figures 7, 9, 10A, 10B, 11A, 11B, 12A, or 12B.

[0415] An embodiment of the present application also provides a computer-readable storage medium, which stores instructions. When the instructions are executed on at least one processor (or communication device), the aforementioned communication method is implemented, such as the communication method shown in Figures 7, 9, 10A, 10B, 11A, 11B, 12A, or 12B.

[0416] An embodiment of the present application also provides a computer program product, which includes computer instructions, and the computer instructions are used to implement the aforementioned communication method, such as the communication method shown in Figure 7, Figure 9, Figure 10A, Figure 10B, Figure 11A, Figure 11B, Figure 12A, or Figure 12B.

[0417] An embodiment of the present application further provides a terminal, which includes the aforementioned communication device 130 and / or communication device 140.

[0418] As a possible implementation, the terminal includes a terminal node. Further, the terminal also includes a first management node and / or a second management node. Further, the terminal also includes a control node.

[0419] For example, terminals may include intelligent terminals or vehicles such as vehicles, robots, drones, ships, and boats. Vehicles are broadly defined and may include transportation vehicles (e.g., commercial vehicles, passenger cars, motorcycles, flying cars, trains, etc.), industrial vehicles (e.g., forklifts, trailers, tractors, etc.), engineering vehicles (e.g., excavators, bulldozers, cranes, etc.), agricultural equipment (e.g., mowers, harvesters, etc.), and so on. Robots may also include automated guided vehicles (AGVs), mobile conversational robots, service robots, and other robots.

[0420] It should be noted that in the embodiments of this application, words such as "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplarily" or "for example" is intended to present the relevant concepts in a concrete manner.

[0421] In the embodiments of this application, "at least one" refers to one or more, and "more" refers to two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items.

[0422] For example, at least one of a, b, or c can represent: a, b, c, (a and b), (a and c), (b and c), or (a and b and c), where a, b, and c can be single or plural. "And / or" describes the relationship between associated objects, indicating that three possible relationships exist. For example, A and / or B can represent: A alone, A and B together, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects are in an "or" relationship.

[0423] Furthermore, unless otherwise specified, ordinal numbers such as "first" and "second" in the embodiments of this application are used to distinguish multiple objects and are not used to define the order, timing, priority, or importance of multiple objects. For example, the terms "first node" and "second node" are merely used to facilitate the description of new parameters in different implementations and do not indicate differences in their execution operations, importance, structure, etc.

[0424] In the above embodiments, the term "when" can be interpreted to mean "if...", "after...", "in response to determining...", or "in response to detecting...", depending on the context. The above are merely optional embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the concepts and principles of the present application shall be included in the scope of protection of the present application.

[0425] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.

Claims

1. A communication method, characterized in that: Applied to the second management node (AP2), the method comprises: Receiving a security communication parameter from the first management node, the security communication parameter including a parameter used when the first management node communicates with the terminal node, the security communication parameter being associated with a security context of the terminal node; An association operation having a security context is performed with the terminal node according to the security communication parameter.

2. The method according to claim 1, characterized in that The security context of the terminal node includes one or more of the following parameters: A shared key, a first fresh parameter, a session key, information indicating a security algorithm, a first identity identifier of a terminal node, and a second fresh parameter; The first fresh parameter is used to derive a session key, and the second fresh parameter is used as a parameter used in communication encryption.

3. The method according to claim 2, characterized in that The secure communication parameters include a security context of the terminal node.

4. The method according to claim 1 or 2, characterized in that: The secure communication parameter includes a shared key, and the method further comprises: A session key is obtained according to the shared key, and the session key is included in the security context.

5. The method according to claim 4, characterized in that The secure communication parameter further includes an identifier of the shared key and a first freshness parameter, and obtaining a session key according to the shared key includes: The session key is determined according to the shared key, an identifier of the shared key, and the first fresh parameter.

6. The method according to any one of claims 4 or 5, characterized in that: The session key includes an integrity protection key; The performing an association operation with the terminal node having a security context according to the security communication parameter includes: receiving first information from the terminal node, the first information being integrity protected by the integrity protection key; checking the integrity of the first information according to the integrity protection key; In case the integrity of the first information is successfully checked, second information is sent to the terminal node, the second information is used for the terminal node to establish an association with the second management node, and the second information is integrity protected by the integrity protection key.

7. The method according to claim 4 or 5, characterized in that: The security context of the terminal node includes a second fresh parameter, and the method further includes: Determine a first number according to the number of the protocol data unit PDU from the terminal node; A second freshness parameter is determined according to a second number and the first number, wherein an initial value of the second number is predetermined and the second number is updated when the first number is flipped.

8. The method according to any one of claims 1 to 7, characterized in that: The method further comprises: Receiving parameter update information from the first management node; According to the parameter update information, some or all of the security communication parameters are updated.

9. The method according to claim 8, characterized in that The secure communication parameters of the terminal include a shared key, an identifier of the shared key, and a validity period of the shared key, and the parameter update information includes an updated shared key, a validity period of the updated shared key, and a validity period of the updated shared key; Alternatively, the secure communication parameter of the terminal includes a first freshness parameter, and the parameter update information includes an updated first freshness parameter; Alternatively, the secure communication parameter of the terminal includes a second fresh parameter, and the parameter update information includes the updated second fresh parameter; Alternatively, the secure communication parameter of the terminal includes a portion of the second fresh parameter, and the parameter update information includes an updated portion of the second fresh parameter.

10. The method according to any one of claims 1 to 9, characterized in that: The receiving of the security communication parameter from the first management node includes: The secure communication parameter forwarded via a control node is received, and the control node is communicatively connected with the first management node and the second management node.

11. The method according to any one of claims 1 to 10, characterized in that: The security communication parameters are transmitted via messages that meet the CAPWAP protocol.

12. The method according to any one of claims 1 to 11, characterized in that: The method further comprises: In case of association failure, an association operation without a security context is performed with the terminal node.

13. The method according to any one of claims 1 to 12, characterized in that: The second management node is a node that supports a fast connection establishment mode. The fast connection establishment method is a method that supports associating with the terminal node through security communication parameters from other nodes, and the other nodes include the first management node and / or the control node.

14. A communication method, characterized in that: Applied to a terminal node, the method comprises: Performing data transmission with a first management node, the first management node having a security context with the terminal node; When the connection establishment condition is met, an association operation with a security context is performed with a second management node, where the second management node has a security context with the terminal node.

15. The method according to claim 14, characterized in that The connection establishment conditions include: A roaming request is received from the first management node, where the roaming request instructs the terminal node to perform a connection switch.

16. The method according to claim 14, characterized in that The method further comprises: measuring the distances between the first management node and the second management node and the terminal node respectively, The connection establishment condition includes: a distance between the second management node and the terminal node is smaller than a distance between the first management node and the terminal node.

17. The method according to claim 16, characterized in that After performing an association operation with a security context with the second management node, the method further includes: Disconnect the data transmission with the first management node.

18. The method according to any one of claims 15 to 17, characterized in that The method further comprises: Receive switching indication information from the first management node, where the switching indication information includes information indicating the second management node.

19. The method according to any one of claims 15 to 18, characterized in that The second management node is a node that supports a fast connection establishment mode. The fast connection establishment method is a method that supports association with the terminal node through security communication parameters from other nodes, and the other nodes include the first management node.

20. The method according to any one of claims 15 to 17, characterized in that The security context of the terminal node includes an integrity protection key; The associating operation with the second management node having a security context includes: Sending first information to the second management node, where the first information is integrity protected by the integrity protection key; receiving second information from the second management node, where the second information is used for the terminal node to establish an association with the second management node, and the second information is integrity protected by the integrity protection key; checking the integrity of the first information according to the integrity protection key; In case the integrity check of the first information is successful, the association is completed.

21. The method according to any one of claims 1 to 11, characterized in that The method further comprises: In case of association failure, an association operation without a security context is performed with the terminal node.

22. A communication method, characterized in that: Applied to a first management node, the first management node having a security context of a terminal node, the method comprising: Performing data transmission with the terminal node; Sending to the second management node a security communication parameter between the second management node and the terminal node, wherein the security communication parameter is associated with a security context of the terminal node, and the security communication parameter is used for the second management node to perform an association process with the terminal node having a security context.

23. The method according to claim 22, characterized in that The security context of the terminal node includes one or more of the following: A shared key, a first fresh parameter, a session key, an identifier of a security algorithm, a first identity identifier of a terminal node, and a second fresh parameter; The first fresh parameter is used to derive a session key, and the second fresh parameter is used as an input of a cryptographic algorithm used in communication encryption.

24. The method according to claim 22 or 23, characterized in that The secure communication parameter is the security context of the terminal node, Alternatively, the secure communication parameter includes a shared key, and the shared key is used to derive a session key.

25. The method according to any one of claims 22 to 24, characterized in that The method further comprises: Send parameter update information to the second management node, where the parameter update information is used to update some or all of the security communication parameters.

26. The method according to any one of claims 22 to 25, characterized in that The method further comprises: Sending switching indication information to the terminal node, where the switching indication information includes information indicating the second management node.

27. The method according to any one of claims 22 to 26, characterized in that The second management node is connected to the control node, and the sending of the security communication parameter between the second management node and the terminal node to the second management node includes: The secure communication parameter between the control node and the terminal node is sent to the control node, and the control node is used to provide the secure communication parameter between the control node and the terminal node to the second management node.

28. The method according to claim 25, characterized in that The second management node is connected to the control node, and the sending of parameter update information to the second management node includes: The parameter update information is sent to the control node, and the control node is used to provide the parameter update information to the second management node.

29. The method according to claim 27 or 28, characterized in that The method further comprises: Receive third information from the control node, the third information is used to indicate a node that supports a fast connection establishment method, the node that supports the fast connection establishment method includes the second management node, and the fast connection establishment method is a method that supports association with a terminal node through security communication parameters from other nodes.

30. A communication method, characterized in that: Applied to a control node, the control node is connected to a first management node and a second management node, the method comprising: receiving, from the first management node, a security communication parameter between the first management node and the terminal node; The secure communication parameter is sent to the second management node, the secure communication parameter is associated with the security context of the terminal node, and the secure communication parameter is used for the second management node to perform an association process with the terminal node in a security context.

31. The method according to claim 30, characterized in that The security context of the terminal node includes one or more of the following: A shared key, a first fresh parameter, a session key, an identifier of a security algorithm, a first identity identifier of a terminal node, and a second fresh parameter; The first fresh parameter is used to derive a session key, and the second fresh parameter is used as a cryptographic algorithm for communication encryption. Input.

32. The method according to claim 30 or 31, characterized in that The secure communication parameter is the security context of the terminal node, Alternatively, the secure communication parameter includes a shared key, and the shared key is used to derive a session key.

33. The method according to any one of claims 30 to 32, characterized in that The method comprises: receiving parameter update information from the first management node, where the parameter update information is used to update some or all of the security communication parameters; Send the parameter update information to the second management node.

34. The method according to any one of claims 30 to 33, characterized in that The method further comprises: Send third information to the first management node, where the third information is used to indicate nodes that support a fast connection establishment method, where the nodes that support a fast connection establishment method include the second management node, and the fast connection establishment method is a method that supports associating with a terminal node through secure communication parameters from other nodes.

35. The method according to claim 34, characterized in that The method comprises: According to the security requirements of multiple management nodes and / or the trust between the multiple management nodes and the first management node respectively, determine the nodes among the multiple nodes that support the fast connection establishment method. The multiple management nodes are connected to the control node, and the multiple management nodes include the second management node.

36. A communication device, characterized in that: The communication device comprises a communication unit and a processing unit, and the communication device is used to execute the method according to any one of claims 1 to 13, claims 14 to 21, claims 22 to 29, and claims 30 to 35.

37. A communication device, characterized in that: include: processor; When the processor calls the computer program or instruction in the memory, the method according to any one of claims 1 to 13, claims 14 to 21, claims 22 to 29, and claims 30 to 35 is executed.

38. A communication device, characterized in that: comprising a logic circuit and an interface, wherein the logic circuit and the interface are coupled; The interface is used to input data to be processed, the logic circuit processes the data to be processed according to the method described in any one of claims 1 to 13, claims 14 to 21, claims 22 to 29, and claims 30 to 35 to obtain processed data, and the interface is used to output the processed data.

39. A computer-readable storage medium, characterized in that: include: The computer-readable storage medium is used to store instructions or computer programs; when the instructions or the computer program are executed, the method according to any one of claims 1 to 13, claims 14 to 21, claims 22 to 29, and claims 30 to 35 is implemented.

40. A computer program product, characterized in that include: instructions or computer programs; When the instructions or the computer program are executed, the method according to any one of claims 1 to 13, claims 14 to 21, claims 22 to 29, and claims 30 to 35 is performed.

41. A vehicle, characterized in that: Comprising the communication device as claimed in claim 36, or the communication device as claimed in claim 37, or the communication device as claimed in claim 38.

42. A communication system, characterized in that: include: A second management node, a terminal node, and a first management node; The second management node is used to execute the method according to any one of claims 1 to 13, The terminal node is used to perform the method according to any one of claims 14 to 21, The first management node is used to execute the method according to any one of claims 22 to 29.

43. The communication system according to claim 41, characterized in that The communication system further comprises a control node, wherein the control node is configured to execute the method according to any one of claims 30 to 35.

Citation Information

Patent Citations

  • Communication method and related device

    CN119922554A

  • Security processing method, device and system in conversion process

    CN102340772A

  • Communication method and related device

    CN118175541A

  • Transfer / cloning of security context

    US20210058773A1

  • Method, apparatus and system for generating key evolving parameters

    WO2010105442A1