Communication method and device

By receiving and using pre-configured security parameters at the terminal, the problem of security parameters updating during cell handover between base stations is solved, and the security during handover is improved.

WO2025107160A1PCT designated stage expired Publication Date: 2025-05-30GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2023/133131
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-22
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The prior art does not involve the issue of security parameter updates during cell handover between base stations, especially when the current cell where the terminal is located belongs to a different base station and the target cell.

Method used

The first configuration information from the first access network device is received through the terminal, which includes a first security parameter corresponding to the candidate access network device, including an indication of the key derivation method and a first NCC. The terminal updates the security key using pre-configured security parameters during the switching process.

Benefits of technology

The security problems caused by obtaining the corresponding security parameters of the target access network device through underlying signaling interaction during handover are avoided, and the security parameters are pre-configured and updated.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2023133131_30052025_PF_FP_ABST
    Figure CN2023133131_30052025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a communication method and device, a computer-readable storage medium, a computer program product and a computer program. The method comprises: receiving first configuration information from a first access network device, wherein the first configuration information comprises a first security parameter corresponding to at least one candidate access network device, and the first security parameter comprises at least one of the following: an indication for a key derivation mode and a first NCC.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and device Technical Field

[0001] The present application relates to the field of communications, and more particularly, to a communication method, device, computer-readable storage medium, computer program product, and computer program. Background Art

[0002] Existing intra-CU (Centralized Unit) LTM (L1 / L2-Triggered Mobility) primarily involves L1 / L2 signaling to trigger cell handovers within the same base station. It doesn't involve inter-base station handovers and, therefore, doesn't involve security parameter updates. However, related protocols discuss introducing inter-CU LTM, which could potentially result in a situation where the terminal's current cell and the target cell belong to different base stations. This raises the question of how to address security parameter updates associated with base station handovers.

[0003] Summary of the Invention

[0004] Embodiments of the present application provide a communication method, device, computer-readable storage medium, computer program product, and computer program.

[0005] An embodiment of the present application provides a communication method performed by a terminal, including:

[0006] First configuration information is received from a first access network device, wherein the first configuration information includes a first security parameter corresponding to at least one candidate access network device, and the first security parameter includes at least one of the following: an indication of a key derivation method and a first NCC.

[0007] An embodiment of the present application provides a communication method performed by a first access network device, including:

[0008] First configuration information is sent to the terminal, wherein the first configuration information includes a first security parameter corresponding to at least one candidate access network device, and the first security parameter includes at least one of the following: an indication of a key derivation method and a first NCC.

[0009] An embodiment of the present application provides a communication method performed by a core network device, including:

[0010] Send second configuration information to the first access network device, wherein the second configuration information is used by the first access network device to determine a first security parameter corresponding to at least one candidate access network device, and the first security parameter includes at least one of the following: an indication of a key derivation method and a first NCC.

[0011] An embodiment of the present application provides a communication method performed by a second access network device, including:

[0012] Receive third configuration information from the core network device, wherein the third configuration information includes a second security parameter corresponding to the second access network device, wherein the second security parameter includes at least one of the following: an indication of a key derivation method, a first NCC, and a first NH.

[0013] An embodiment of the present application provides a communication method performed by a terminal, including:

[0014] In the case of horizontally deriving the first security key with the second access network device, second information is received from the second access network device, wherein the second information carries a second NCC, and the second NCC is used to vertically derive a third security key with the second access network device.

[0015] An embodiment of the present application provides a communication method performed by a second access network device, including:

[0016] When the horizontally derived first security key between the terminal and the second access network device is obtained, sending a path switching request to the core network device;

[0017] receiving a path switch reply message from the core network device, wherein the path switch reply message carries a second NCC and a second NH, where the second NH is used to vertically derive a third security key between the terminal and the core network device;

[0018] Second information is sent to the terminal, where the second information carries the second NCC, and the second NCC is used by the terminal to vertically derive the third security key.

[0019] An embodiment of the present application provides a communication method performed by a core network device, including:

[0020] receiving a path switching request from a second access network device;

[0021] A path switching reply message is sent to the second access network device, wherein the path switching reply message carries the second NCC and the second NH.

[0022] An embodiment of the present application provides a terminal, including:

[0023] The first communication unit is used to receive first configuration information from a first access network device, wherein the first configuration information includes a first security parameter corresponding to at least one candidate access network device, and the first security parameter includes at least one of the following: an indication of a key derivation method and a first NCC.

[0024] An embodiment of the present application provides a first access network device, including:

[0025] The second communication unit is used to send first configuration information to the terminal, wherein the first configuration information includes a first security parameter corresponding to at least one candidate access network device, and the first security parameter includes at least one of the following: an indication of a key derivation method and a first NCC.

[0026] An embodiment of the present application provides a core network device, including:

[0027] The third communication unit is used to send second configuration information to the first access network device, wherein the second configuration information is used by the first access network device to determine the first security parameter corresponding to at least one candidate access network device, and the first security parameter includes at least one of the following: an indication of a key derivation method and a first NCC.

[0028] An embodiment of the present application provides a second access network device, including:

[0029] The fourth communication unit is used to receive third configuration information from the core network device, wherein the third configuration information includes a second security parameter corresponding to the second access network device, wherein the second security parameter includes at least one of the following: an indication of a key derivation method, a first NCC, and a first NH.

[0030] An embodiment of the present application provides a terminal, including:

[0031] A first communication unit is used to receive second information from the second access network device when horizontally deriving a first security key between the device and the second access network device, wherein the second information carries a second NCC, and the second NCC is used to vertically derive a third security key between the device and the second access network device.

[0032] An embodiment of the present application provides a second access network device, including:

[0033] The fourth communication unit is used to send a path switching request to the core network device when the horizontally derived first security key between the terminal and the second access network device is obtained; receive a path switching reply message from the core network device, wherein the path switching reply message carries a second NCC and a second NH, and the second NH is used to vertically derive a third security key with the terminal; send second information to the terminal, wherein the second information carries the second NCC, and the second NCC is used by the terminal to vertically derive the third security key.

[0034] An embodiment of the present application provides a core network device, including:

[0035] The third communication unit is configured to receive a path switching request from a second access network device; and send a path switching reply message to the second access network device, wherein the path switching reply message carries a second NCC and a second NH.

[0036] An embodiment of the present application provides a terminal including a transceiver, a processor, and a memory. The memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory so that the terminal executes the above method.

[0037] An embodiment of the present application provides a first access network device, comprising a transceiver, a processor, and a memory. The memory is configured to store a computer program, and the processor is configured to call and execute the computer program stored in the memory, so that the first access network device executes the above method.

[0038] An embodiment of the present application provides a core network device, comprising a transceiver, a processor, and a memory. The memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory, so that the core network device performs the above method.

[0039] An embodiment of the present application provides a second access network device, comprising a transceiver, a processor, and a memory. The memory is configured to store a computer program, and the processor is configured to call and execute the computer program stored in the memory, so that the second access network device executes the above method.

[0040] The embodiment of the present application provides a chip for implementing the above method.

[0041] Specifically, the chip includes: a processor, which is used to call and run a computer program from a memory, so that a device equipped with the chip executes the above method.

[0042] An embodiment of the present application provides a computer-readable storage medium for storing a computer program, which enables a device to perform the above method when the computer program is executed by the device.

[0043] An embodiment of the present application provides a computer program product, including computer program instructions, which enable a computer to execute the above method.

[0044] An embodiment of the present application provides a computer program, which, when executed on a computer, enables the computer to execute the above method.

[0045] By adopting the above solution, the terminal can pre-obtain the first security parameters corresponding to the candidate access network device configured on the network side. The first security parameters include an indication of the first NCC and / or a key derivation method. This allows the terminal to use the pre-configured security parameters to update security keys during a handover involving an access network device, avoiding the security issues associated with the related art of requiring underlying signaling interactions during handover to obtain the security parameters corresponding to the target access network device. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] FIG1 is a schematic diagram of an application scenario according to an embodiment of the present application.

[0047] FIG2 is a schematic flowchart of a communication method according to an embodiment of the present application.

[0048] FIG3 is a schematic flowchart of a communication method according to another embodiment of the present application.

[0049] FIG4 is a schematic flowchart of a communication method according to yet another embodiment of the present application.

[0050] FIG5 is a schematic flowchart of a communication method according to yet another embodiment of the present application.

[0051] FIG6 is a schematic diagram of a scenario of candidate cells according to an embodiment of the present application.

[0052] 7-8 are two example flow charts of a communication method according to an embodiment of the present application.

[0053] 9-10 are two schematic flow charts of switching of a communication method according to an embodiment of the present application.

[0054] 11-12 are two more example flow charts of a communication method according to an embodiment of the present application.

[0055] FIG13 is a schematic flowchart of a communication method according to an embodiment of the present application.

[0056] FIG14 is a schematic flowchart of a communication method according to another embodiment of the present application.

[0057] FIG15 is a schematic flowchart of a communication method according to another embodiment of the present application.

[0058] FIG16 is a schematic block diagram of a terminal according to an embodiment of the present application.

[0059] FIG17 is a schematic block diagram of a first access network device according to an embodiment of the present application.

[0060] Figure 18 is a schematic block diagram of a core network device according to an embodiment of the present application.

[0061] Figure 19 is a schematic block diagram of a second access network device according to an embodiment of the present application.

[0062] FIG20 is a schematic block diagram of a communication device according to an embodiment of the present application.

[0063] FIG21 is a schematic block diagram of a chip according to an embodiment of the present application.

[0064] Figure 22 is a schematic block diagram of a communication system according to an embodiment of the present application. DETAILED DESCRIPTION

[0065] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.

[0066] The embodiments of the present application describe various embodiments in conjunction with network devices and terminals. The terminals can be mobile or fixed, and can also be referred to as mobile stations, user units, etc. The terminal can be a site in a WLAN, and can be a smart terminal, wireless modem, laptop computer, tablet computer, or other terminal. In the embodiments of the present application, the terminal can be a VR terminal / AR terminal, an industrial control terminal, an unmanned driving terminal, a telemedicine terminal, a smart grid terminal, a transportation safety terminal, a smart city terminal, or a wireless terminal for a smart home, etc. As an example and not a limitation, in the embodiments of the present application, the terminal can also be a wearable device.

[0067] In the embodiment of the present application, the network device may be a device for communicating with a terminal, an access point in a WLAN, an evolved base station in LTE, or a relay station, or a network device (gNB) in an in-vehicle device, a wearable device, and an NR network, or a network device in a future evolved PLMN network or a network device in a non-terrestrial network. As an example and not a limitation, in the embodiment of the present application, the network device may have a mobile feature, for example, the network device may be a mobile device.

[0068] It should be understood that the terms "system" and "network" are often used interchangeably in this article. The term "and / or" in this article is merely a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the objects associated before and after are in an "or" relationship. It should be understood that the "indication" mentioned in the embodiments of this application can be a direct indication, an indirect indication, or an indication of an association relationship. For example, A indicates B, which can mean that A directly indicates B, for example, B can be obtained through A; it can also mean that A indirectly indicates B, for example, A indicates C, and B can be obtained through C; it can also mean that there is an association relationship between A and B. In the description of the embodiments of this application, the term "corresponding" can mean that there is a direct or indirect correspondence between the two, or it can mean that there is an association relationship between the two, or it can mean a relationship between indication and indication, configuration and configuration, etc.

[0069] To facilitate understanding of the technical solutions of the embodiments of the present application, the relevant technologies of the embodiments of the present application are described below. The following relevant technologies can be arbitrarily combined with the technical solutions of the embodiments of the present application as optional solutions, and they all fall within the protection scope of the embodiments of the present application.

[0070] Figure 1 exemplarily illustrates a communication system 100. The communication system includes a network device 110 and two terminals 120. In one possible implementation, the communication system 100 may include multiple network devices 110, and each network device 110 may include a different number of terminals 120 within its coverage area, although this embodiment of the present application does not limit this. In one possible implementation, the communication system 100 may also include a mobility management entity, access and mobility management functions, and other network entities, although this embodiment of the present application does not limit this. The network devices may include access network devices and core network devices. That is, the communication system may also include multiple core networks for communicating with the access network devices. The access network devices may be base stations of LTE, LTE-A, or NR systems. Taking the communication system shown in Figure 1 as an example, the communication devices may include network devices and terminals with communication functions. The communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities, although this embodiment of the present application does not limit this.

[0071] FIG2 is a schematic flow chart of a communication method executed by a terminal according to an embodiment of the present application. The method includes at least part of the following contents.

[0072] S210. Receive first configuration information from a first access network device, wherein the first configuration information includes at least one corresponding first security parameter, and the first security parameter includes at least one of the following: an indication of a key derivation method, and a first next hop chaining counter (NCC).

[0073] Figure 3 is a schematic flow chart of a communication method performed by a first access network device according to another embodiment of the present application. The method includes at least part of the following contents.

[0074] S310. Send first configuration information to the terminal, where the first configuration information includes a first security parameter corresponding to at least one candidate access network device, and the first security parameter includes at least one of the following: an indication of a key derivation method and a first NCC.

[0075] Figure 4 is a schematic flow chart of a communication method performed by a core network device according to another embodiment of the present application. The method includes at least part of the following contents.

[0076] S410. Send second configuration information to the first access network device, wherein the second configuration information is used by the first access network device to determine a first security parameter corresponding to at least one candidate access network device, and the first security parameter includes at least one of the following: an indication of a key derivation method and a first NCC.

[0077] Figure 5 is a schematic flow chart of a communication method performed by a second access network device according to another embodiment of the present application. The method includes at least part of the following contents.

[0078] S510. Receive third configuration information from the core network device, wherein the third configuration information includes second security parameters corresponding to the second access network device, wherein the second security parameters include at least one of the following: an indication of a key derivation method, a first NCC, and a first next hop key (NH).

[0079] The at least one candidate access network device refers to one or more candidate access network devices of the terminal.

[0080] The first access network device may be an access network device currently connected to the terminal and / or an access network device currently providing services to the terminal. The second access network device is a target access network device to which the terminal is to be switched after performing a switching process, and the second access network device is one of one or more candidate access network devices for the terminal.

[0081] In the following embodiments, the first access network device may be alternatively referred to as a source base station, or a source gNB, or an SgNB, or a gNB; the second access network device may be alternatively referred to as a target base station, or a target gNB, or a TgNB; and the candidate access network device may be alternatively referred to as a candidate gNB, or a candidate base station.

[0082] The core network device may be a control plane node (or network element) on the core network side. For example, the core network device may include an AMF. This is merely an example, and this embodiment does not limit or exhaustively list the core network device.

[0083] NH can also be alternatively called the next hop parameter, etc., and all possible names are not limited or exhaustive here.

[0084] In some possible implementations, the processing by the first access network device may further include: receiving second configuration information from a core network device, wherein the second configuration information is used to determine a first security parameter corresponding to the at least one candidate access network device. This second configuration information is transmitted before the first access network device sends the first configuration information to the terminal. Here, the first security parameter corresponding to the at least one candidate access network device may refer to the first security parameter corresponding to each of the at least one candidate access network device.

[0085] In one embodiment, the processing by the first access network device may further include: sending a request message to the core network device, wherein the request message is used to request allocation of the second configuration information. Accordingly, the processing by the core network device may further include: receiving a request message from the first access network device, wherein the request message is used to request allocation of the second configuration information. Here, the request message may be transmitted before the second configuration information is transmitted.

[0086] The request message may be sent to the core network device during any interaction between the first access network device and the core network device.

[0087] Optionally, the source gNB may send a request message to the core network device during the handover preparation phase or before the handover preparation phase. The handover preparation phase may be an LTM preparation phase, an Inter LTM handover preparation phase, an inter-CU LTM handover preparation phase, or a preparation phase of other handover processes, which are not limited or exhaustive here.

[0088] Optionally, the source gNB may send a request message to the core network device during a path switch phase. The path switch phase may refer to a path switch phase after the terminal switches from another gNB to the source gNB (for example, an inter-CU LTM handover is completed), and the request message may be a path switch request (Path Switch Request) during the path switch phase.

[0089] Optionally, considering the latency caused by the interaction between the source gNB and the AMF, only vertical key derivation can be performed for inter-CU LTM by default. Exemplarily, the request message can be used to request the second security parameters containing {first NH, first NCC} for each candidate gNB during any interaction between the source gNB and the AMF.

[0090] Optionally, the second configuration information may be sent by the AMF to the source gNB during or before the handover preparation phase of the source gNB. For example, the second configuration information may be carried in a Mobility Control Message.

[0091] Optionally, the second configuration information may be sent by the AMF to the source gNB during the path switching phase of the source gNB. For example, the second configuration information may be carried in a Path Switch Response message.

[0092] In one embodiment, the first access network device does not need to send a request message to the core network device. The core network device determines and sends the second configuration information to the first access network device. The second configuration information is sent in the same manner as in the previous embodiment and will not be described again.

[0093] In some possible implementations, the second configuration information includes at least one of the following: a second security parameter corresponding to the at least one candidate access network device; a second security parameter corresponding to each second candidate access network device, wherein each second candidate access network device is a candidate access network device in the at least one candidate access network device that is not configured with the second security parameter; one or more NCCs and an NH corresponding to each NCC, wherein each NCC and its corresponding NH are used to determine the second security parameter corresponding to the at least one candidate access network device.

[0094] Here, the second security parameter corresponding to at least one candidate access network device may refer to the second security parameter corresponding to each candidate access network device in the at least one candidate access network device.

[0095] The second security parameter includes at least one of the following: an indication of a key derivation method, a first NCC, and a first NH. For example, the second security parameter corresponding to any candidate gNB may include at least one of the following: an indication of a key derivation method corresponding to the candidate gNB, the first NCC corresponding to the candidate gNB, and the first NH corresponding to the candidate gNB.

[0096] The key derivation mode indication includes one of the following: a key vertical derivation indication and a key horizontal derivation indication. In some possible examples, the key vertical derivation indication may be alternatively referred to as a key vertical switching indication or a vertical switching indication; the key horizontal derivation indication may be alternatively referred to as a key horizontal switching indication or a horizontal switching indication, etc.

[0097] In some possible implementations, the second configuration information includes a second security parameter corresponding to the at least one candidate access network device, wherein the second security parameter corresponding to the at least one candidate access network device is used to determine the first security parameter corresponding to the at least one candidate access network device.

[0098] Each candidate access network device of the terminal is determined by the first access network device, and the first access network device indicates each candidate access network device of the terminal to the core network device through the request message. The request message may carry at least one of the following: an identifier of each candidate access network device, and an identifier of each candidate cell in one or more candidate cells corresponding to each candidate access network device. The identifier of each candidate cell may include at least one of the following: a cell identifier (Cell ID) of each candidate cell, and a PCI (Physical Cell Identifier) ​​of each candidate cell.

[0099] The processing of the core network device may also include: determining the key derivation method for each candidate access network device; based on the key derivation method for each candidate access network device, determining the first NCC corresponding to each candidate access network device and / or the first NH corresponding to each candidate access network device.

[0100] The core network device may determine the key derivation method for each candidate access network device based on a local policy and / or the content carried in the request message. In addition to the content described in the preceding embodiment, the content carried in the request message may also include other relevant configurations for each candidate access network device and / or each candidate cell, which is not limited in this embodiment.

[0101] Taking any candidate access network device as the i-th candidate gNB as an example, the core network device determining the first NCC corresponding to each candidate access network device and / or the first NH corresponding to each candidate access network device may include one of the following: in a case where the key corresponding to the i-th candidate gNB is vertically derived, determining that the first NCC corresponding to the i-th candidate gNB is greater than the NCC corresponding to the second security key between the terminal and the source gNB, and calculating the first NH corresponding to the i-th candidate gNB; in a case where the key corresponding to the i-th candidate gNB is horizontally derived, determining that the first NCC corresponding to the i-th candidate gNB is equal to the NCC corresponding to the second security key. i is a positive integer.

[0102] Calculating the first NH corresponding to the i-th candidate gNB may be: based on the first key (K AMF ), vertically derive the first NH corresponding to the i-th candidate gNB from the last derived key. The number of derivation calculations performed to vertically derive the first NH may be equal to the difference between the first NCC corresponding to the i-th candidate gNB and the NCC corresponding to the second security key; the last derived key may include the initial K corresponding to the terminal. gNB Or the last exported NH.

[0103] When the key derivation mode corresponding to the i-th candidate gNB is vertical key derivation, the second security parameters corresponding to the i-th candidate gNB may include: the first NCC corresponding to the i-th candidate gNB and the first NH corresponding to the i-th candidate gNB. It should be noted that the second security parameters corresponding to the i-th candidate gNB may or may not include an indication of vertical key derivation.

[0104] In the case where the key derivation method corresponding to the i-th candidate gNB is key horizontal derivation, the second security parameter corresponding to the i-th candidate gNB may include: an indication of key horizontal derivation corresponding to the i-th candidate gNB and / or a first NCC corresponding to the i-th candidate gNB.

[0105] Since the relevant descriptions of the second security parameters corresponding to each candidate access network device are the same as those of the i-th candidate gNB, they are not repeated here.

[0106] Taking the i-th candidate gNB as an example, the first access network device determines the first security parameter corresponding to each candidate access network device based on the second security parameter corresponding to each candidate access network device, which may include one of the following: when the second security parameter corresponding to the i-th candidate gNB includes the first NH and the first NCC corresponding to the i-th candidate gNB, the first NCC corresponding to the i-th candidate gNB is used as the first security parameter corresponding to the i-th candidate gNB; when the second security parameter corresponding to the i-th candidate gNB includes the first NH corresponding to the i-th candidate gNB, the first NCC corresponding to the i-th candidate gNB, and the i-th candidate gNB. If the first NCC corresponding to the i-th candidate gNB and / or the key horizontal derivation indication corresponding to the i-th candidate gNB are included in the second security parameters corresponding to the i-th candidate gNB, the first NCC corresponding to the i-th candidate gNB and / or the key horizontal derivation indication corresponding to the i-th candidate gNB are used as the first security parameter corresponding to the i-th candidate gNB. If the first NCC corresponding to the i-th candidate gNB and / or the key horizontal derivation indication corresponding to the i-th candidate gNB are included in the second security parameters corresponding to the i-th candidate gNB, the first NCC corresponding to the i-th candidate gNB and / or the key horizontal derivation indication corresponding to the i-th candidate gNB are used as the first security parameter corresponding to the i-th candidate gNB. The relevant generation method of the first security parameter corresponding to each candidate access network device is the same as that for the i-th candidate gNB, and therefore is not described in detail here.

[0107] In some possible implementations, the second configuration information includes a second security parameter corresponding to each second candidate access network device.

[0108] When the first access network device determines that at least some of one or more candidate access network devices for the terminal are not configured with the second security parameters, the first access network device designates each candidate access network device not configured with the second security parameters as a second candidate access network device for the terminal, and sends a request message to the core network device to indicate each second candidate access network device for the terminal that is not configured with the second security parameters. Specifically, the request message may carry at least one of the following: an identifier of each second candidate access network device, and an identifier of each candidate cell corresponding to each second candidate access network device.

[0109] In addition, it may also include: when the first access network device determines that there are one or more candidate access network devices configured with the second security parameters among the one or more candidate access network devices of the terminal, the candidate access network device configured with the second security parameters is used as the fourth candidate access network device of the terminal.

[0110] Here, a candidate access network device that is not configured with the second security parameters means that the first access network device has not configured or stored the second security parameters corresponding to the terminal for the candidate access network device. A candidate access network device that is configured with the second security parameters means that the first access network device has configured or stored the second security parameters corresponding to the terminal for the candidate access network device. The configured second security parameters may have been sent by the terminal's previous source access network device when the first access network device was the target access network device for the terminal's last handover.

[0111] In this embodiment, the process by which the core network device determines the second security parameters corresponding to each second candidate access network device is similar to that in the aforementioned embodiment. It is only necessary to use any second candidate access network device as the i-th candidate gNB in ​​the aforementioned embodiment, so the description is not repeated.

[0112] After the first access network device receives the second configuration information, it may also include: determining the second security parameter corresponding to each candidate access network device based on the second security parameter corresponding to each second candidate access network device; determining the first security parameter corresponding to each candidate access network device based on the second security parameter corresponding to each candidate access network device.

[0113] Among them, determining the second security parameter corresponding to each candidate access network device based on the second security parameter corresponding to each second candidate access network device can include: using the second security parameter corresponding to each second candidate access network device and the second security parameter corresponding to each fourth candidate access network device as the first security parameter corresponding to each candidate access network device.

[0114] In some possible implementations, when the first access network device determines that one or more candidate access network devices of the terminal have been configured with the second security parameters, it is not necessary to send a request message to the core network device, and the first security parameters corresponding to each candidate access network device are directly determined based on the second security parameters corresponding to each candidate access network device.

[0115] The processing by the first access network device may further include: determining a key derivation method corresponding to each candidate access network device based on the {first NH, first NCC} or the first NCC corresponding to each candidate access network device. Taking the i-th candidate gNB as an example, if the i-th candidate gNB is configured with an unused first NCC value, the handover method corresponding to the i-th candidate gNB is vertical handover (i.e., vertical key derivation). If the first NCC configured for the i-th candidate gNB is equal to the NCC value corresponding to the second security key, the handover method corresponding to the i-th candidate gNB is horizontal handover. For security reasons, the source gNB may be required to use the new first NCC as the first security parameter corresponding to the candidate gNB when a new {first NH, first NCC} is stored.

[0116] In some possible implementations, the second configuration information includes one or more NCCs and an NH corresponding to each NCC.

[0117] In this implementation, the first access network device may send a request message to the core network device to request the core network device to allocate the second configuration information, or the first access network device may not send a request message to the core network device, which is not limited in this embodiment.

[0118] The core network device may determine the second configuration information by: determining that the value of each NCC in one or more NCCs is greater than the NCC corresponding to the second security key, calculating the NH corresponding to each NCC; and adding each NCC and its corresponding NH to the second configuration information. The method for calculating the NH corresponding to each NCC is similar to the method for calculating any first NH in the aforementioned embodiment and is not further described.

[0119] The processing of the first access network device after receiving the second configuration information may include: determining the second security parameter corresponding to each candidate access network device based on the second configuration information; and determining the first security parameter corresponding to each candidate access network device based on the second security parameter corresponding to each candidate access network device. The process of determining the first security parameter corresponding to each candidate access network device based on the second security parameter corresponding to each candidate access network device is the same as in the previous embodiment, and therefore will not be repeated here.

[0120] Exemplarily, the first access network device determines the second security parameter corresponding to each candidate access network device based on the second configuration information, which may include: assigning each NCC and its corresponding NH to each candidate gNB to obtain a first NCC and a first NH corresponding to each candidate gNB, wherein different first NCCs correspond to different candidate gNBs; or assigning each NCC and its corresponding NH to each candidate gNB to obtain a first NCC and a first NH corresponding to each candidate gNB, and if there are remaining candidate gNBs to which no NCC and NH are assigned, determining the key derivation method for the candidate gNBs to which no NCC and NH are assigned as key horizontal derivation, and using the NCC corresponding to the second security key as its corresponding first NCC. It should be understood that the above is only an exemplary description, and all possible methods are not exhaustive.

[0121] In the scenario involved in the aforementioned embodiment where the core network device (AMF) decides and configures the second security parameter, the AMF can be controlled to only perform horizontal key derivation or only vertical key derivation during the inter-CU LTM process of the UE.

[0122] The aforementioned first configuration information may be carried by an AS (Access Stratum) message. For example, the first configuration information may be carried by an RRC message; for another example, the RRC message may be an RRC reconfiguration message carrying LTM candidate configuration (or LTM candidate cell configuration).

[0123] For example, with reference to FIG6 , the second configuration information sent by the AMF to the SgNB includes second security parameters preconfigured for each candidate gNB. The second security parameters include at least one of the following: a first NCC, a first NH, and an indication of the handover mode (i.e., an indication of the key derivation mode). The second security parameters are at the gNB level, not the cell level. As shown in FIG6 , the UE has multiple candidate cells, Cell a through Cell g in FIG6 , which belong to candidate gNB1 and candidate gNB2, respectively. If vertical key derivation is determined for handover from the SgNB to candidate gNB1, the second configuration information sent by the AMF to the candidate SgNB includes {NCC, NH} corresponding to candidate gNB1 and may also include an indication of vertical key derivation. If horizontal key derivation is determined for handover from the SgNB to candidate gNB2, the second configuration information sent by the AMF to the SgNB includes the NCC and the indication of horizontal key derivation corresponding to candidate gNB2.

[0124] The first security parameters for each candidate gNB pre-configured by the SgNB for the UE include a first NCC and / or an indication of the key derivation method. The UE uses the first security parameters pre-configured by the SgNB for each candidate gNB to determine whether to perform horizontal or vertical handover. For example, if the first security parameters for a candidate gNB are configured with only the first NCC, vertical derivation is indicated if the first NCC of the candidate gNB is greater than the NCC corresponding to the second security key. If the first NCC of the candidate gNB is equal to the NCC corresponding to the second security key, horizontal derivation is indicated. It should be noted that the security parameters configured for the UE are also gNB-granular, meaning that the security configuration is the same for candidate cells belonging to the same gNB. After a UE uses the security configuration of a candidate cell for a key update, the security parameters of other candidate cells belonging to the same gNB are no longer used.

[0125] In conjunction with Figure 7, an example is given of SgNB interacting with AMF to obtain security parameters before inter LTM handover preparation, or in the inter LTM handover preparation stage, or in the LTM preparation stage. Specifically:

[0126] Step 701: The SgNB sends a request message to the AMF. The request message may carry: the identifier of the candidate cell and the identifier of the candidate base station to which the candidate cell belongs;

[0127] Step 702: The AMF provides a mobility control message to the SgNB. The mobility control message carries the second configuration information. Specifically, the mobility control message carries the second security parameter corresponding to each candidate base station. The mobility control message may be provided when the connection between the SgNB and the AMF is established or when the last TA update (timing advance (TA)) is updated.

[0128] Step 703: The SgNB sends an RRC reconfiguration message to the UE. The RRC reconfiguration message may be an LTM candidate cell configuration, which includes the first security parameter corresponding to each candidate base station.

[0129] Step 704: The UE sends an RRC reconfiguration complete message to the SgNB to indicate that the configuration is complete.

[0130] In one example, during the Path Switch phase (or process), the gNB interacts with the AMF to obtain the second security parameters corresponding to each candidate base station. During the LTM preparation phase, the first security parameters corresponding to each candidate base station are configured to the UE through RRC signaling that carries the LTM candidate configuration. That is, after the UE switches to the target base station once, the target base station, as the base station connected to the UE (i.e., the gNB in ​​Figure 8), interacts with the AMF to obtain security parameters for the inter-CU LTM handover that the UE may perform later. The handover here can refer to L3-based handover or LTM process. In conjunction with Figure 8, it specifically includes:

[0131] Step 801: When the gNB sends a path switching request to the AMF, the gNB triggers the AMF to switch the DL data path to itself and establish the NG-C interface. The path switching request may include the candidate configuration information of the UE, such as the identifier of the candidate cell and the identifier of the candidate gNB to which the candidate cell belongs.

[0132] Step 802: The AMF decides whether to use vertical key derivation or horizontal key derivation when the UE switches to the candidate cell based on the local policy or the inter-CU LTM candidate configuration information of the UE provided by the SgNB, and sends a path switch reply to the gNB, which carries the second configuration information, i.e., the second security parameters corresponding to each candidate gNB.

[0133] After step 802 is completed, the gNB may send the first configuration information to the UE during any interaction with the UE. The related processing is similar to steps 703 to 704 in Figure 7 and is not repeated here.

[0134] In some possible implementations, the processing performed by the terminal may also include: receiving a cell switching command, wherein the cell switching command is used to indicate a target cell; determining a first security parameter corresponding to the second access network device based on the second access network device to which the target cell belongs and the first configuration information, wherein the second access network device is one of the at least one candidate access network device; and calculating a first security key between the terminal and the second access network device based on the first security parameter corresponding to the second access network device.

[0135] The processing performed by the first access network device may also include: calculating the first security key between the terminal and the second access network device based on the second security parameter corresponding to the second access network device to which the target cell corresponding to the terminal belongs, wherein the second access network device is one of the at least one candidate access network device; sending first information to the second access network device, wherein the first information includes: the first security key and the NCC corresponding to the first security key.

[0136] The processing by the second access network device may further include: receiving first information from the first access network device.

[0137] Before the terminal receives the cell handover command, the method may further include: sending a measurement report to the first access network device. Accordingly, the method for the first access network device to determine the target cell may include: receiving a measurement report from the terminal, and determining the target cell corresponding to the terminal based on the measurement report. The measurement report may be an L1 (Layer 1) and / or L2 (Layer 2) measurement report. This embodiment does not limit the content that the measurement report may include and the method for the first access network device to determine the target cell.

[0138] Exemplarily, the first access network device calculates the first security key between the terminal and the second access network device based on the second security parameter corresponding to the second access network device to which the target cell corresponding to the terminal belongs. This may refer to: when the second security parameter corresponding to the TgNB to which the target cell corresponding to the terminal belongs includes the first NCC and the first NH, deriving the first security key based on the first NH; when the second security parameter corresponding to the TgNB to which the target cell corresponding to the terminal belongs includes the first NCC and / or an indication of key level derivation, deriving the first security key based on the second security key level. Further, after calculating the first security key, it may also include: using the first NCC in the second security parameter corresponding to the TgNB as the NCC corresponding to the first security key.

[0139] The terminal receiving the cell switching command may include one of the following: receiving a cell switching command from a first access network device; receiving a cell switching command from a second access network device. The cell switching command may be carried by a MAC CE.

[0140] In one example, before or after the first access network device sends the first information to the second access network device, the process may further include: sending a cell handover command to the terminal. In another example, after the second access network device receives the first information from the first access network device, the process may include: sending a cell handover command to the terminal.

[0141] Exemplarily, the processing of calculating the first security key between the terminal and the second access network device based on the first security parameter corresponding to the second access network device by the terminal may include: when the first security parameter corresponding to the TgNB includes a first NCC and the first NCC is greater than the NCC corresponding to the second security key, or the first security parameter corresponding to the TgNB includes a first NCC and an indication of vertical key derivation, vertically deriving a first NH based on the first NCC, and calculating the first security key based on the first NH; when the first security parameter corresponding to the TgNB includes a first NCC and the first NCC is equal to the NCC corresponding to the second security key, or the first security parameter corresponding to the TgNB includes an indication of horizontal key derivation, or the first security parameter corresponding to the TgNB includes a first NCC and an indication of horizontal key derivation, horizontally deriving the first security key based on the second security key. The second security key can be expressed as K gNB -1, the first security key can be expressed as K NG-RAN or K NG-RAN* Other wireless parameters may also be used when deriving the first security key, such as cell ID (PCI), downlink frequency, etc., which are not limited here.

[0142] In some embodiments, the second configuration information includes the second security parameters corresponding to the candidate access network device, or the second security parameters corresponding to the second candidate access network device. In scenarios where the second configuration information includes the second security parameters corresponding to each candidate gNB, the first configuration information provided by the SgNB to the UE includes the first security parameters corresponding to each candidate gNB, for example, the candidate gNBs include candidate gNB1 and candidate gNB2. When the UE is handed over to a TgNB (such as candidate gNB1) via LTM, the TgNB, as the new gNB connected to the UE, sends a new request message to the AMF to obtain the second security parameters corresponding to the new candidate gNB, for example, the new candidate gNB may also include candidate gNB2. In this case, the TgNB and the SgNB may both be configured with candidate cells belonging to the same candidate gNB2, which may cause a security parameter configuration conflict. To avoid using the {NH, NCC} pair in reverse order, the AMF always increments the NCC value and calculates the new NH value, which is then sent to the gNB currently connected to the UE (unless the NCC has reached the maximum value). The following solutions are possible for the gNB and UE:

[0143] Optionally, on the first access network device side, after the first access network device sends the first information to the second access network device, the method further includes: deleting the second security parameter corresponding to each candidate access network device. For example, after the UE completes a handover process, the relevant security parameters are deleted, and unused {first NH, first NCC} are not sent to the TgNB.

[0144] Optionally, on the first access network device side, after receiving the second configuration information from the core network device, the method further includes: if historical security parameters corresponding to a third candidate access network device among the one or more candidate access network devices of the terminal and the terminal are stored, deleting the historical security parameters corresponding to the third candidate access network device and the terminal. The number of the third candidate access network devices may be one or more.

[0145] Optionally, the first information further includes one of the following: a second security parameter corresponding to an unused candidate access network device; a second security parameter corresponding to a candidate access network device whose first NCC is greater than the NCC corresponding to the first security key.

[0146] That is, after calculating the first security key, the SgNB can determine whether it still has the second security parameters corresponding to the currently configured unused candidate gNB. If so, it can further determine whether the first NCC corresponding to the second security parameters of the unused candidate gNB is greater than the NCC corresponding to the first security key. If there are second security parameters corresponding to the candidate gNB of the terminal whose first NCC is greater than the NCC corresponding to the first security key, the second security parameters corresponding to these candidate gNBs are added to the first information and sent to the TgNB. For example, after the UE completes a handover process, the UE updates the first security key with a certain NCC value. The SgNB can delete other first NCCs and their corresponding first NHs that are less than the NCC value, retaining only the {first NH, first NCC} pairs with a greater NCC value and sending them to the TgNB.

[0147] In this way, when the TgNB serves as the source gNB for the next handover, it can only request the second security parameters of the remaining candidate gNBs that are not configured with the second security parameters from the AMF. The processing of the TgNB serving as the source gNB for the next handover requesting the second security parameters of the candidate gNBs that are not configured with the second security parameters is similar to the processing of the first access network device requesting the candidate access network device that is not configured with the second security parameters in the aforementioned embodiment, and is not further described.

[0148] Optionally, after calculating the first security key, the first access network device can determine whether it still has second security parameters corresponding to unused candidate access network devices configured this time; if so, the second security parameters corresponding to these unused candidate access network devices of the terminal are added to the first information and sent to the second access network device.

[0149] Optionally, on the terminal side: after calculating the first security key based on the first security parameter corresponding to the second access network device, the method further includes one of the following: deleting the first security parameter corresponding to the at least one candidate access network device; deleting the first security parameter corresponding to a candidate access network device whose first NCC is less than the NCC corresponding to the first security key. For example, after calculating the first security key, the UE may delete all first security parameter configurations and only receive the new first security parameters. That is, the UE only uses the first security parameters currently configured by the gNB to perform the next handover. Alternatively, after completing a handover, the UE deletes the first security parameter that is less than the currently used NCC value.

[0150] Optionally, after the terminal side receives the first configuration information from the first access network device, the method further includes: deleting the historical security parameters corresponding to a first candidate access network device among the at least one candidate access network device, if historical security parameters corresponding to the first candidate access network device are stored. That is, when the UE receives new first security parameters for the same candidate gNB / candidate cell, the old security parameters are deleted and only the new first security parameters are used to perform the next handover. The number of the first candidate gNBs may be one or more.

[0151] An exemplary description is given with reference to FIG9 , specifically including:

[0152] Step 901: The UE sends a measurement report to the SgNB. The measurement report may be an L1 / L2 measurement report or an L1 measurement report.

[0153] Step 902: The SgNB updates the key horizontally or vertically based on the second security parameter corresponding to the TgNB to which the target cell belongs, and generates the first security key K. NG-RAN* ;

[0154] Step 903: The SgNB sends a cell switch command carried by the MAC CE to the UE to trigger the handover process. The cell switch command includes a candidate configuration index, which indicates which candidate configuration cell, i.e., the target cell, the UE should switch to.

[0155] Step 904: The UE uses the first NCC and / or key derivation method indication in the first security parameter corresponding to the TgNB to which the target cell belongs to calculate the first security key K corresponding to the target cell (the TgNB to which it belongs) NG-RAN* .

[0156] Step 905: SgNB calculates the first security key K NG-RAN*Then, the first security key K NG-RAN* and the first security key K NG- RAN* The corresponding NCC value is sent to TgNB. NG-RAN* Used as KgNB to establish security with UE. Step 905 can be performed after step 902.

[0157] Another exemplary description is provided in conjunction with FIG10 , specifically including:

[0158] Steps 1001 to 1002 are the same as steps 901 to 902 and are not described in detail.

[0159] Step 1003: The SgNB calculates the first security key K NG-RAN* Then, the first security key K NG-RAN* and the first security key K NG-RAN* The corresponding NCC value is sent to TgNB.

[0160] Step 1004: The TgNB sends a cell switching command to the UE. The cell switching command is transparently forwarded to the UE via the SgNB.

[0161] Step 1005 is the same as step 904 and will not be described in detail.

[0162] In step 905 or step 1003, when the AMF configures multiple {first NH, first NCC} for the SgNB, the SgNB may also send unused or remaining {first NH, first NCC} to the TgNB.

[0163] In some possible implementations, the second configuration information includes a first security parameter corresponding to the at least one candidate access network device.

[0164] The processing by the core network device further includes: sending third configuration information to the at least one candidate access network device, wherein the third configuration information corresponding to each candidate access network device includes the second security parameter corresponding to the candidate access network device. For example, if any one of the candidate access network devices is a second access network device, the second access network device can receive the third configuration information from the core network device.

[0165] In this embodiment, each candidate access network device of the terminal can be determined by the first access network device. The specific determination method is the same as that in the aforementioned embodiment and will not be repeated. The core network device determines the key derivation method for each candidate access network device and determines the processing method of the first NCC corresponding to each candidate access network device and / or the first NH corresponding to each candidate access network device, which are the same as those in the aforementioned embodiment and will not be repeated.

[0166] After the first access network device receives the second configuration information from the core network device, the method may include: adding the first security parameter corresponding to each candidate access network device in the second configuration information to the first configuration information.

[0167] In this implementation manner, the transmission method or the message used for transmission of the first configuration information, the request message, and the second configuration information are the same as those described in the previous embodiment and are not elaborated upon.

[0168] The processing performed by the first access network device may also include: sending first information to a second access network device to which the target cell corresponding to the terminal belongs, wherein the first information is used to instruct the second access network device to calculate a first security key between the second access network device and the terminal, and the second access network device is one of the one or more candidate access network devices.

[0169] The processing by the second access network device may further include: receiving first information from the first access network device, wherein the first information is used to instruct the second access network device to calculate a first security key between the second access network device and the terminal; and calculating the first security key based on the second security parameter. The handover processing performed by the terminal is the same as that in the previous embodiment and is not further described.

[0170] The processing of exchanging measurement reports with the first access network device before the terminal receives the cell switching command and the processing of the first access network device determining the target cell are the same as those in the previous embodiment and will not be repeated here.

[0171] The first information may also indicate a target cell. Optionally, the first information may include at least one of the following: a second security key between the first access network device and the terminal, and an NCC corresponding to the second security key.

[0172] The second access network device calculates the first security key based on the second security parameter, which may mean: when the second security parameter includes the first NCC and the first NH, deriving the first security key based on the first NH; when the second security parameter includes the first NCC and / or an indication of key level derivation, deriving the first security key based on the second security key level included in the first information.

[0173] 11 , the configuration performed during the Inter LTM handover preparation phase or the LTM preparation configuration process is exemplarily described, specifically including:

[0174] Step 1101 is the same as step 701 and will not be described again.

[0175] Step 1102: The AMF provides a mobile control message to the SgNB, where the mobile control message carries the second configuration information. Specifically, the mobile control message carries the first security parameter corresponding to each candidate base station.

[0176] Step 1103: The AMF sends corresponding second security parameters for each candidate TgNB. The second security parameters may include at least one of the first NH and the first NCC. For simplicity, Figure 11 only illustrates one candidate TgNB, and this does not limit the number of candidate TgNBs.

[0177] Steps 1104 to 1105 are the same as the processing of steps 703 to 704 in FIG. 7 , and are not described in detail.

[0178] This example takes forward security into consideration. When security parameters are preconfigured for the SgNB, the SgNB can obtain the NH (which can be considered an intermediate key) used by the UE for the next few handovers. Therefore, the SgNB can obtain the key KgNB between the UE and the target eNB after the next few handovers. Therefore, forward security is considered to be ensured by using the AMF to configure the NH for the candidate eNB and the AMF to return the first security parameters that do not include the NH to the SgNB.

[0179] With reference to FIG12 , the configuration method in the Path Switch stage (or process) is exemplarily described, specifically including:

[0180] Step 1201 is the same as step 801 and will not be described in detail.

[0181] Step 1202: The AMF decides whether to use vertical key derivation or horizontal key derivation when the UE switches to the candidate cell based on the local policy or the inter-CU LTM candidate configuration information of the UE provided by the SgNB, and sends a path switch reply to the gNB, which carries the second configuration information, i.e., the first security parameters corresponding to each candidate gNB.

[0182] After step 1202 is completed, the gNB can send the first configuration information, that is, the first security parameters corresponding to each candidate TgNB, to the UE during any interaction with the UE. The related processing is similar to steps 703 to 704, so it is not repeated.

[0183] Step 1203: The AMF sends corresponding second security parameters for each candidate TgNB. The second security parameters may include at least one of the first NH and the first NCC. For simplicity, Figure 12 shows only one candidate TgNB, which does not limit the number of candidate TgNBs.

[0184] In some possible implementations, the first security parameter corresponding to the at least one candidate access network device is determined by the first access network device. This implementation does not require a core network device to make a decision or interact.

[0185] Specifically, the indication of the key derivation method is an indication of horizontal key derivation, and the first NCC is the NCC corresponding to the second security key between the first access network device and the terminal. The processing performed by the first access network device may also include: horizontally deriving the first security key between the terminal and the second access network device based on the second security key, wherein the second access network device corresponds to the target cell of the terminal; sending first information to the second access network device, wherein the first information includes: the first security key, the NCC corresponding to the first security key, and the NCC corresponding to the first security key is equal to the NCC corresponding to the second security key. The processing of the second access network device may also include: receiving the first information from the first access network device.

[0186] That is, the first security parameter corresponding to each candidate access network device may include: an indication of a key level derivation corresponding to the candidate access network device and / or a first NCC corresponding to the candidate access network device, where the first NCC is equal to the NCC corresponding to the second security parameter. This embodiment is particularly applicable to a scenario where the first access network device has not locally received any new (unused) {NH, NCC} corresponding to the terminal configured by the core network device. In this scenario, the handover processing performed by the terminal is the same as in the aforementioned embodiment and is not further described.

[0187] The processing of the interactive measurement report before the terminal receives the cell switching command and the processing of the first access network device determining the target cell are the same as those in the previous embodiment and will not be described in detail.

[0188] In some possible implementations, the processing performed by the terminal may also include one of the following: receiving first algorithm-related information from the first access network device, wherein the first algorithm-related information is used to determine the target security algorithm corresponding to the second access network device, and the first algorithm-related information includes the security algorithm supported by the at least one candidate access network device, and the target security algorithm includes at least one of the following: a target integrity protection algorithm, a target encryption algorithm; receiving second algorithm-related information from the second access network device, wherein the second algorithm-related information is used to determine the target security algorithm corresponding to the second access network device, and the second algorithm-related information includes the target security algorithm corresponding to the second access network device and / or the security algorithm supported by the second access network device.

[0189] The target integrity protection algorithm is used by the terminal to perform integrity protection-related processing on information based on the integrity protection key. The target encryption algorithm is used by the terminal to perform confidentiality-related processing on information based on the encryption key. The integrity protection key is related to the first security key, and the encryption key is related to the first security key. This embodiment does not limit the generation method of the integrity protection key and the encryption key.

[0190] Optionally, the processing of the first access network device may also include: sending first algorithm-related information to the terminal, wherein the first algorithm-related information is used to determine the target security algorithm corresponding to the second access network device, the first algorithm-related information includes the security algorithm supported by the at least one candidate access network device, and the target security algorithm includes at least one of the following: a target integrity protection algorithm and a target encryption algorithm.

[0191] The first algorithm-related information may be sent to the terminal simultaneously with the first configuration information. For example, the first algorithm-related information and the first configuration information may be carried in the same message. Alternatively, the first algorithm-related information and the first configuration information may be sent to the terminal separately, that is, they may be carried in different messages, which are not limited or exhaustive herein.

[0192] The first access network device may obtain the security algorithm supported by each candidate access network device from the core network device. For example, the second configuration information may include the security algorithm supported by each candidate access network device.

[0193] The terminal may determine the security algorithm supported by the second access network device based on the first algorithm-related information after switching to the second access network device, and determine the target security algorithm corresponding to the second access network device. For example, the second access network device may support only one security algorithm, and the terminal may directly use the security algorithm as the target security algorithm corresponding to the second access network device. For another example, the second access network device may support multiple security algorithms, and the terminal may randomly select one of the multiple security algorithms supported by the second access network device as the target security algorithm corresponding to the second access network device; or, based on one or more security algorithms supported by the terminal, the terminal may select a matching one from the multiple security algorithms supported by the second access network device as the target security algorithm corresponding to the second access network device.

[0194] Optionally, the processing by the second access network device may further include: sending second algorithm-related information to the terminal, wherein the second algorithm-related information is used to determine a target security algorithm corresponding to the second access network device, the second algorithm-related information including the target security algorithm corresponding to the second access network device and / or a security algorithm supported by the second access network device, the target security algorithm including at least one of the following: a target integrity protection algorithm and a target encryption algorithm. The second algorithm-related information may be obtained during any interaction between the terminal and the second access network device after a connection is established.

[0195] The manner in which the terminal determines the target security algorithm corresponding to the second access network device based on the second algorithm-related information may include one of the following: if the second algorithm-related information includes the target security algorithm corresponding to the second access network device, the terminal may directly determine the target security algorithm corresponding to the second access network device; if the second algorithm-related information includes one or more security algorithms supported by the second access network device, the terminal may select the target security algorithm from the one or more security algorithms supported by the second access network device. Here, the manner in which the terminal selects the target security algorithm from the one or more security algorithms supported by the second access network device is the same as in the aforementioned embodiment and is not further described.

[0196] In conjunction with related technologies, Release 18 adds intra-CU LTM, where the base station triggers the UE's handover process via underlying Layer 1 / Layer 2 (L1 / L2) signaling. In Layer 3-based handovers, the gNB and UE use RRC signaling to transmit handover commands. Using underlying Layer 1 / Layer 2 signaling to trigger the handover process reduces latency during UE mobility. The existing LTM process only applies to intra-CU scenarios. LTM candidate cells belong to the same base station or the same CU, so no key update is involved. However, in inter-CU LTM, since the handover target cell may belong to another base station, a key update is required. However, in inter-CU LTM, if the NCC is transmitted using underlying Layer 1 / Layer 2 signaling, the underlying signaling lacks security protection and can be easily obtained or tampered with by eavesdroppers, resulting in inconsistent security contexts between the UE and gNB, leading to handover failure.

[0197] Based on this, an embodiment of the present application provides a security mechanism for the inter-CU LTM process. Specifically, during the interaction between the source base station and the AMF, the AMF provides security parameters to the source and target base stations based on the LTM candidate cell configuration information provided by the source base station. The source base station includes the switching mode indication and some security parameters in the LTM candidate cell configuration, and provides it to the UE during the LTM advance preparation process. During the LTM execution process, the UE determines the target cell for the next switching based on the received switching command, and switches to the target base station where the target cell is located using horizontal or vertical switching according to the switching mode in the configuration information of the target base station to which the target cell belongs, and calculates the security key based on the NCC in the configuration information.

[0198] By adopting the above solution, the terminal can pre-obtain the first security parameters corresponding to each candidate access network device configured on the network side. The first security parameters include an indication of the first NCC and / or a key derivation method. This allows the terminal to use the pre-configured security parameters to update security keys during a handover involving an access network device (such as inter-CU LTM), avoiding the security issues associated with the related art of requiring underlying signaling interaction during handover to obtain the security parameters corresponding to the target access network device.

[0199] Figure 13 is a schematic flow chart of a communication method executed by a terminal according to an embodiment of the present application. The method includes at least part of the following contents.

[0200] S1310. In the case of horizontally deriving a first security key between the second access network device and the second access network device, receive second information from the second access network device, wherein the second information carries a second NCC, and the second NCC is used to vertically derive a third security key between the second access network device and the second access network device.

[0201] Figure 14 is a schematic flow chart of a communication method performed by a second access network device according to another embodiment of the present application. The method includes at least part of the following contents.

[0202] S1410: When a horizontally derived first security key between the terminal and the second access network device is obtained, send a path switching request to the core network device;

[0203] S1420. Receive a path switch reply message from the core network device, where the path switch reply message carries a second NCC and a second NH, where the second NH is used to vertically derive a third security key between the terminal and the core network device.

[0204] S1430: Send second information to the terminal, where the second information carries the second NCC, and the second NCC is used by the terminal to vertically derive the third security key.

[0205] Figure 5 is a schematic flow chart of a communication method performed by a core network device according to another embodiment of the present application. The method includes at least part of the following contents.

[0206] S1510. Receive a path switching request from a second access network device;

[0207] S1520: Send a path switch reply message to the second access network device, where the path switch reply message carries a second NCC and a second NH.

[0208] In some embodiments, the processing of the terminal also includes: receiving a cell switching command, wherein the cell switching command is used to indicate a target cell, and the target cell is one of the one or more cells corresponding to the second access network device; based on the second security key between the first access network device and the terminal, horizontally deriving a first security key.

[0209] The processing of the first access network device further includes: horizontally deriving a first security key between the terminal and the second access network device based on the second security key; and sending first information to the second access network device.

[0210] The processing by the second access network device further includes: receiving first information from the first access network device, wherein the first information includes: the first security key and an NCC corresponding to the first security key, wherein the NCC corresponding to the first security key is less than the second NCC. The NCC corresponding to the first security key is equal to the NCC corresponding to the second security key. The processing of horizontally deriving the first security key by the first access network device is the same as in the previous embodiment and is not repeated here.

[0211] The above-mentioned cell switching command may come from the first access network device or the second access network device, and will not be repeated in this embodiment.

[0212] In some implementations, the path switch request may be used to request the core network device to allocate new security parameters to the second access network device for vertically deriving a third security key with the terminal. The core network device may select any value greater than the NCC corresponding to the first security key as the value of the second NCC and calculate a second NH based on the second NCC.

[0213] The terminal side vertically derives the third security key between the terminal and the second access network device based on the second NCC, which can be: performing vertical derivation based on the second NCC to obtain the second NH, and deriving the third security key between the terminal and the second access network device based on the second NH.

[0214] In the above processing, the terminal does not need to access the network side device and the core network device to interact during or before the handover process, but can perform horizontal derivation to obtain the first security key by default.

[0215] Exemplarily, when the UE receives an inter-CU LTM handover command forwarded by the SgNB or the TgNB through the SgNB (the command may not contain the NCC), the UE uses the second security key KgNB between the current UE and the SgNB to horizontally derive the first security key between the UE and the TgNB. The TgNB receives the first security key K calculated horizontally from the SgNB. NG-RAN* When the TgNB receives the new {second NH, second NCC} from the AMF through path switching, it initiates intra-CU handover and uses vertical key update to update the key between the TgNB and the UE to obtain the third security key. This method is intended to avoid the scenario where the UE performs inter-LTM handover and the security keys are all horizontally derived.

[0216] By adopting the above solution, the terminal can obtain a horizontally derived first security key with the second access network device during handover, and then obtain a new NCC to vertically derive a third security key with the second access network device. This allows the terminal to perform handovers involving access network devices (such as inter-CU LTM) without interacting with the core network, avoiding the delay caused by interacting with the core network device and ensuring handover efficiency. Furthermore, by performing a vertical key derivation after the handover, it can also avoid the problem of all security keys used in terminal handover scenarios being horizontally derived.

[0217] FIG16 is a schematic diagram of the structure of a terminal according to an embodiment of the present application, including:

[0218] The first communication unit 1601 is used to receive first configuration information from a first access network device, wherein the first configuration information includes a first security parameter corresponding to at least one candidate access network device, and the first security parameter includes at least one of the following: an indication of a key derivation method and a first NCC.

[0219] As shown in Figure 16, the terminal also includes a first processing unit 1602, configured to determine, based on the second access network device to which the target cell belongs and the first configuration information, a first security parameter corresponding to the second access network device, wherein the second access network device is one of the at least one candidate access network device; and calculate, based on the first security parameter corresponding to the second access network device, a first security key between the terminal and the second access network device;

[0220] The first communication unit is configured to receive a cell switching command, wherein the cell switching command is used to indicate a target cell.

[0221] The first communication unit is used to perform one of the following: receiving first algorithm-related information from the first access network device, wherein the first algorithm-related information is used to determine the target security algorithm corresponding to the second access network device, and the first algorithm-related information includes the security algorithm supported by the at least one candidate access network device, and the target security algorithm includes at least one of the following: a target integrity protection algorithm and a target encryption algorithm; receiving second algorithm-related information from the second access network device, wherein the second algorithm-related information is used to determine the target security algorithm corresponding to the second access network device, and the second algorithm-related information includes the target security algorithm corresponding to the second access network device and / or the security algorithm supported by the second access network device.

[0222] The first processing unit is configured to perform one of the following: deleting the first security parameter corresponding to the at least one candidate access network device; deleting the first security parameter corresponding to the candidate access network device whose first NCC is smaller than the NCC corresponding to the first security key.

[0223] The first processing unit is configured to delete the historical security parameters corresponding to a first candidate access network device among the at least one candidate access network device when the historical security parameters corresponding to the first candidate access network device are stored.

[0224] FIG17 is a schematic diagram of the composition structure of a first access network device according to an embodiment of the present application, including:

[0225] The second communication unit 1701 is used to send first configuration information to the terminal, wherein the first configuration information includes a first security parameter corresponding to at least one candidate access network device, and the first security parameter includes at least one of the following: an indication of a key derivation method, and a first next hop chain counter NCC.

[0226] The second communication unit is used to receive second configuration information from a core network device, wherein the second configuration information is used to determine a first security parameter corresponding to the at least one candidate access network device.

[0227] The second communication unit is used to send a request message to the core network device, wherein the request message is used to request allocation of the second configuration information.

[0228] The second configuration information includes at least one of the following: a second security parameter corresponding to the at least one candidate access network device; a second security parameter corresponding to each second candidate access network device, wherein each second candidate access network device is a candidate access network device in the at least one candidate access network device that is not configured with a second security parameter; one or more NCCs and an NH corresponding to each NCC, wherein each NCC and its corresponding NH are used to determine the second security parameter corresponding to the at least one candidate access network device.

[0229] The second security parameter includes at least one of the following: an indication of a key derivation method, a first NCC, and a first NH.

[0230] As shown in FIG17 , the first access network device further includes a second processing unit 1702, configured to calculate a first security key between the terminal and the second access network device based on a second security parameter corresponding to a second access network device to which a target cell corresponding to the terminal belongs, wherein the second access network device is one of the at least one candidate access network device;

[0231] The second communication unit is configured to send first information to the second access network device, wherein the first information includes: the first security key and the NCC corresponding to the first security key.

[0232] The first information further includes one of the following: a second security parameter corresponding to an unused candidate access network device; a second security parameter corresponding to a candidate access network device whose first NCC is greater than the NCC corresponding to the first security key.

[0233] The second configuration information includes a first security parameter corresponding to the at least one candidate access network device; the second communication unit is used to send first information to the second access network device to which the target cell corresponding to the terminal belongs, wherein the first information is used to instruct the second access network device to calculate a first security key between the second access network device and the terminal, and the second access network device is one of the at least one candidate access network device.

[0234] The first information includes at least one of the following: a second security key between the first access network device and the terminal, and an NCC corresponding to the second security key.

[0235] The indication of the key derivation mode is an indication of a horizontal key derivation, the first NCC is an NCC corresponding to a second security key between the first access network device and the terminal; the second processing unit is configured to horizontally derive the first security key between the terminal and a second access network device based on the second security key, wherein the second access network device corresponds to a target cell of the terminal;

[0236] The second communication unit is used to send first information to the second access network device, wherein the first information includes: the first security key, the NCC corresponding to the first security key, and the NCC corresponding to the first security key is equal to the NCC corresponding to the second security key.

[0237] The second communication unit is used to send first algorithm-related information to the terminal, wherein the first algorithm-related information is used to determine the target security algorithm corresponding to the second access network device, the first algorithm-related information includes the security algorithm supported by the at least one candidate access network device, and the target security algorithm includes at least one of the following: a target integrity protection algorithm and a target encryption algorithm.

[0238] FIG18 is a schematic diagram of the structure of a core network device according to an embodiment of the present application, including:

[0239] The third communication unit 1801 is used to send second configuration information to the first access network device, wherein the second configuration information is used by the first access network device to determine the first security parameters corresponding to at least one candidate access network device, and the first security parameters include at least one of the following: an indication of a key derivation method, and a first next hop chain counter NCC.

[0240] The third communication unit is used to receive a request message from the first access network device, wherein the request message is used to request allocation of the second configuration information.

[0241] The second configuration information includes at least one of the following: a second security parameter corresponding to the at least one candidate access network device; a second security parameter corresponding to each second candidate access network device, wherein each second candidate access network device is a candidate access network device in the at least one candidate access network device that is not configured with a second security parameter; one or more NCCs and an NH corresponding to each NCC, wherein each NCC and its corresponding NH are used to determine the second security parameter corresponding to the at least one candidate access network device.

[0242] The second configuration information includes the first security parameters corresponding to each candidate access network device; the third communication unit is used to send third configuration information to the at least one candidate access network device, wherein the third configuration information corresponding to each candidate access network device includes the second security parameters corresponding to the candidate access network device.

[0243] The second security parameter includes at least one of the following: an indication of a key derivation method, a first NCC, and a first NH.

[0244] FIG19 is a schematic diagram of the structure of a second access network device according to an embodiment of the present application, including:

[0245] The fourth communication unit 1901 is used to receive third configuration information from the core network device, wherein the third configuration information includes second security parameters corresponding to the second access network device, wherein the second security parameters include at least one of the following: an indication of a key derivation method, a first next hop chain counter NCC, and a first next hop key NH.

[0246] As shown in Figure 19, the second access network device also includes a fourth processing unit 1902, which is used to calculate the first security key based on the second security parameter; the fourth communication unit is used to receive first information from the first access network device, wherein the first information is used to instruct the second access network device to calculate the first security key between the second access network device and the terminal.

[0247] The fourth communication unit is used to send second algorithm-related information to the terminal, wherein the second algorithm-related information is used to determine the target security algorithm corresponding to the second access network device, the second algorithm-related information includes the target security algorithm corresponding to the second access network device and / or the security algorithm supported by the second access network device, and the target security algorithm includes at least one of the following: a target integrity protection algorithm and a target encryption algorithm.

[0248] A terminal according to another embodiment of the present application includes:

[0249] A first communication unit is used to receive second information from the second access network device when horizontally deriving a first security key between the device and the second access network device, wherein the second information carries a second NCC, and the second NCC is used to vertically derive a third security key between the device and the second access network device.

[0250] A second access network device according to another embodiment of the present application includes:

[0251] The fourth communication unit is used to send a path switching request to the core network device when the horizontally derived first security key between the terminal and the second access network device is obtained; receive a path switching reply message from the core network device, wherein the path switching reply message carries a second NCC and a second NH, and the second NH is used to vertically derive a third security key with the terminal; send second information to the terminal, wherein the second information carries the second NCC, and the second NCC is used by the terminal to vertically derive the third security key.

[0252] A core network device according to another embodiment of the present application includes:

[0253] The third communication unit is configured to receive a path switching request from a second access network device; and send a path switching reply message to the second access network device, wherein the path switching reply message carries a second NCC and a second NH.

[0254] The device of the embodiment of the present application can realize the corresponding functions of each device in the aforementioned communication method embodiment. The processes, functions, implementation methods and beneficial effects corresponding to each module (sub-module, unit or component, etc.) in the device can be found in the corresponding description in the above-mentioned method embodiment, which will not be repeated here. It should be noted that the functions described by each module (sub-module, unit or component, etc.) in the device of the embodiment of the application can be implemented by different modules (sub-module, unit or component, etc.) or by the same module (sub-module, unit or component, etc.).

[0255] Figure 20 is a schematic structural diagram of a communication device 2000 according to an embodiment of the present application. The communication device 2000 includes a processor 2010, which can call and run a computer program from a memory to enable the communication device 2000 to implement the method according to the embodiment of the present application.

[0256] In one possible implementation, the communication device 2000 may further include a memory 2020. The processor 2010 may call and run a computer program from the memory 2020 so that the communication device 2000 implements the method in the embodiment of the present application. The memory 2020 may be a separate device independent of the processor 2010, or may be integrated into the processor 2010. In one possible implementation, the communication device 2000 may further include a transceiver 2030, and the processor 2010 may control the transceiver 2030 to communicate with other devices. Specifically, the transceiver 2030 may send information or data to other devices, or receive information or data sent by other devices. The transceiver 2030 may include a transmitter and a receiver. The transceiver 2030 may further include an antenna, and the number of antennas may be one or more.

[0257] An embodiment of the present application provides a terminal, comprising: a processor, a memory communicating with the processor, the memory being used to store instructions, and when the instructions are executed by the processor, the instructions cause the terminal to execute: receiving first configuration information from a first access network device, wherein the first configuration information includes a first security parameter corresponding to at least one candidate access network device, and the first security parameter includes at least one of the following: an indication of a key derivation method, and a first NCC.

[0258] An embodiment of the present application provides a first access network device, comprising: a processor, a memory communicating with the processor, the memory being used to store instructions, and when the instructions are executed by the processor, the instructions cause the first access network device to execute: sending first configuration information to a terminal, wherein the first configuration information includes a first security parameter corresponding to at least one candidate access network device, and the first security parameter includes at least one of the following: an indication of a key derivation method, and a first NCC.

[0259] An embodiment of the present application provides a core network device, comprising: a processor, a memory communicating with the processor, the memory being used to store instructions, and when the instructions are executed by the processor, the instructions cause the core network device to execute: sending second configuration information to a first access network device, wherein the second configuration information is used by the first access network device to determine a first security parameter corresponding to at least one candidate access network device, and the first security parameter includes at least one of the following: an indication of a key derivation method, and a first NCC.

[0260] An embodiment of the present application provides a second access network device, comprising: a processor, a memory communicating with the processor, the memory being used to store instructions, and when the instructions are executed by the processor, the instructions cause the second access network device to execute: receiving third configuration information from a core network device, wherein the third configuration information includes second security parameters corresponding to the second access network device, wherein the second security parameters include at least one of the following: an indication of a key derivation method, a first NCC, and a first NH.

[0261] An embodiment of the present application provides a terminal, comprising: a processor, a memory communicating with the processor, the memory being used to store instructions, wherein when the instructions are executed by the processor, the instructions cause the terminal to execute: receiving second information from the second access network device in the case of horizontally deriving a first security key with the second access network device, wherein the second information carries a second NCC, and the second NCC is used to vertically derive a third security key with the second access network device.

[0262] An embodiment of the present application provides a second access network device, comprising: a processor, a memory communicating with the processor, the memory being used to store instructions, and when the instructions are executed by the processor, the instructions cause the second access network device to execute: upon obtaining a first security key between a horizontally derived terminal and the second access network device, sending a path switching request to a core network device; receiving a path switching reply message from the core network device, wherein the path switching reply message carries a second NCC and a second NH, and the second NH is used to vertically derive a third security key with the terminal; and sending second information to the terminal, wherein the second information carries the second NCC, and the second NCC is used by the terminal to vertically derive the third security key.

[0263] An embodiment of the present application provides a core network device, including: a processor, a memory communicating with the processor, the memory being used to store instructions, and when the instructions are executed by the processor, the instructions cause the core network device to execute: receiving a path switching request from a second access network device; and sending a path switching reply message to the second access network device, wherein the path switching reply message carries a second NCC and a second NH.

[0264] Figure 21 is a schematic structural diagram of a chip 2100 according to an embodiment of the present application. The chip 2100 includes a processor 2110, which can call and run a computer program from a memory to implement the method in the embodiment of the present application. In one possible implementation, the chip 2100 may also include a memory 2120. The processor 2110 can call and run a computer program from the memory 2120 to implement the method performed by each device in the embodiment of the present application. The memory 2120 can be a separate device independent of the processor 2110, or it can be integrated into the processor 2110. In one possible implementation, the chip 2100 may also include an input interface 2130. The processor 2110 can control the input interface 2130 to communicate with other devices or chips, specifically, to obtain information or data sent by other devices or chips. In one possible implementation, the chip 2100 may also include an output interface 2140. Among them, the processor 2110 can control the output interface 2140 to communicate with other devices or chips, specifically, it can output information or data to other devices or chips. In one possible implementation, the chip can be applied to each device in the embodiment of the present application, and the chip can implement the corresponding processes implemented by each device in the various methods of the embodiment of the present application. For the sake of brevity, it is not repeated here. It should be understood that the chip mentioned in the embodiment of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0265] The processor mentioned above may be a general-purpose processor, a digital signal processor, an off-the-shelf programmable gate array, an application-specific integrated circuit, or other programmable logic device, a transistor logic device, a discrete hardware component, etc. The general-purpose processor mentioned above may be a microprocessor or any conventional processor, etc. The memory mentioned above may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories.

[0266] It should be understood that the above-mentioned memory is exemplary but not restrictive. For example, the memory in the embodiment of the present application may also be a static random access memory, a dynamic random access memory, etc.

[0267] Figure 22 is a schematic block diagram of a communication system 2200 according to an embodiment of the present application. The communication system 2200 includes a terminal 2210, a first access network device 2220, a core network device 2230, and a second access network device 2240. In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions according to the embodiments of the present application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available medium can be a magnetic medium (such as a hard disk) or a semiconductor medium (such as a solid-state drive).

[0268] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0269] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0270] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included within the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A communication method executed by a terminal, comprising: receiving first configuration information from a first access network device, where the first configuration information includes first security parameters corresponding to at least one candidate access network device, and the first security parameters include at least one of the following: an indication of a key derivation method, a first next-hop chain counter NCC.

2. The method according to claim 1, wherein, the method further comprises: receiving a cell handover command, where the cell handover command is used to indicate a target cell; determining, based on the second access network device to which the target cell belongs and the first configuration information, the first security parameters corresponding to the second access network device, where the second access network device is one of the at least one candidate access network device; calculating a first security key between the terminal and the second access network device based on the first security parameters corresponding to the second access network device.

3. The method according to claim 2, wherein, the method further comprises one of the following: receiving first algorithm-related information from the first access network device, where the first algorithm-related information is used to determine a target security algorithm corresponding to the second access network device, the first algorithm-related information includes security algorithms supported by the at least one candidate access network device, and the target security algorithm includes at least one of the following: a target integrity protection algorithm, a target encryption algorithm; receiving second algorithm-related information from the second access network device, where the second algorithm-related information is used to determine a target security algorithm corresponding to the second access network device, and the second algorithm-related information includes the target security algorithm corresponding to the second access network device and / or security algorithms supported by the second access network device.

4. The method according to claim 2 or 3, wherein, the method further comprises one of the following: deleting the first security parameters corresponding to the at least one candidate access network device; deleting the first security parameters corresponding to candidate access network devices whose first NCC is less than the NCC corresponding to the first security key.

5. The method according to any one of claims 1-3, wherein, after receiving the first configuration information from the first access network device, the method further comprises: deleting the historical security parameters corresponding to the first candidate access network device among the at least one candidate access network device if the historical security parameters corresponding to the first candidate access network device are saved.

6. A communication method executed by a first access network device, comprising: sending first configuration information to a terminal, where the first configuration information includes first security parameters corresponding to at least one candidate access network device, and the first security parameters include at least one of the following: an indication of a key derivation method, a first next-hop chain counter NCC.

7. The method according to claim 6, wherein, the method further comprises: receiving second configuration information from a core network device, where the second configuration information is used to determine the first security parameters corresponding to the at least one candidate access network device.

8. The method according to claim 7, wherein, the method further comprises: Send a request message to the core network device, where the request message is used to request allocation of the second configuration information.

9. The method according to claim 7 or 8, wherein, the second configuration information includes at least one of the following: the second security parameter corresponding to the at least one candidate access network device; the second security parameter corresponding to each second candidate access network device, where each second candidate access network device is a candidate access network device among the at least one candidate access network devices that has not been configured with the second security parameter; one or more NCCs and the NH corresponding to each NCC, where each NCC and its corresponding NH are used to determine the second security parameter corresponding to the at least one candidate access network device.

10. The method according to claim 9, wherein, the second security parameter includes at least one of the following: an indication of the key derivation method, a first NCC, a first next-hop key NH.

11. The method according to claim 10, wherein, the method further includes: Based on the second security parameter corresponding to the second access network device to which the target cell to which the terminal belongs belongs, calculate a first security key between the terminal and the second access network device, where the second access network device is one of the at least one candidate access network devices; Send a first message to the second access network device, where the first message includes: the first security key, the NCC corresponding to the first security key.

12. The method according to claim 11, wherein, the first message further includes one of the following: the second security parameter corresponding to the unused candidate access network device; the second security parameter corresponding to the candidate access network device whose first NCC is greater than the NCC corresponding to the first security key.

13. The method according to claim 7 or 8, wherein, the second configuration information includes the first security parameter corresponding to the at least one candidate access network device; the method further includes: Send a first message to the second access network device to which the target cell to which the terminal belongs belongs, where the first message is used to instruct the second access network device to calculate a first security key between the second access network device and the terminal, and the second access network device is one of the one or more candidate access network devices.

14. The method according to claim 13, wherein, the first message includes at least one of the following: the second security key between the first access network device and the terminal, the NCC corresponding to the second security key.

15. The method according to claim 6, wherein, the indication of the key derivation method is an indication of key horizontal derivation, and the first NCC is the NCC corresponding to the second security key between the first access network device and the terminal; the method further includes: Based on the second security key, horizontally derive a first security key between the terminal and the second access network device, where the second access network device corresponds to the target cell of the terminal. Send first information to the second access network device, where the first information includes: the first security key, the NCC corresponding to the first security key, and the NCC corresponding to the first security key is equal to the NCC corresponding to the second security key.

16. The method according to any one of claims 6-15, wherein, the method further includes: Sending first algorithm-related information to the terminal, where the first algorithm-related information is used to determine a target security algorithm corresponding to the second access network device, the first algorithm-related information includes security algorithms supported by the at least one candidate access network device, and the target security algorithm includes at least one of the following: a target integrity protection algorithm, a target encryption algorithm.

17. A communication method performed by a core network device, including: Sending second configuration information to a first access network device, where the second configuration information is used for the first access network device to determine first security parameters corresponding to at least one candidate access network device, and the first security parameters include at least one of the following: an indication of a key derivation method, a first next-hop chain counter NCC.

18. The method according to claim 17, wherein, the method further includes: Receiving a request message from the first access network device, where the request message is used to request allocation of the second configuration information.

19. The method according to claim 17 or 18, wherein, the second configuration information includes at least one of the following: Second security parameters corresponding to the at least one candidate access network device; Second security parameters corresponding to each second candidate access network device, where each second candidate access network device is a candidate access network device among the at least one candidate access network device that has not been configured with second security parameters; One or more NCCs and an NH corresponding to each NCC, where each NCC and its corresponding NH are used to determine second security parameters corresponding to the at least one candidate access network device.

20. The method according to claim 17 or 18, wherein, the second configuration information includes the first security parameters corresponding to the at least one candidate access network device; the method further includes: Sending third configuration information to the at least one candidate access network device, where the third configuration information corresponding to each candidate access network device includes the second security parameters corresponding to the candidate access network device.

21. The method according to claim 19 or 20, wherein, the second security parameters include at least one of the following: an indication of a key derivation method, a first NCC, a first NH.

22. A communication method performed by a second access network device, including: Receiving third configuration information from a core network device, where the third configuration information includes second security parameters corresponding to the second access network device, and the second security parameters include at least one of the following: an indication of a key derivation method, a first next-hop chain counter NCC, a first next-hop key NH.

23. The method according to claim 22, wherein, the method further includes: Receive first information from a first access network device, where the first information is used to instruct the second access network device to calculate a first security key between the second access network device and a terminal; Calculate the first security key based on the second security parameter.

24. The method according to claim 22 or 23, wherein, the method further includes: Sending second algorithm-related information to the terminal, where the second algorithm-related information is used to determine a target security algorithm corresponding to the second access network device, and the second algorithm-related information includes the target security algorithm corresponding to the second access network device and / or the security algorithms supported by the second access network device, and the target security algorithm includes at least one of the following: a target integrity protection algorithm, a target encryption algorithm.

25. A communication method executed by a terminal, including: When horizontally deriving a first security key between the terminal and the second access network device, receiving second information from the second access network device, where the second information carries a second NCC, and the second NCC is used to vertically derive a third security key between the terminal and the second access network device.

26. A communication method executed by a second access network device, including: When obtaining the first security key between the horizontally derived terminal and the second access network device, sending a path switching request to a core network device; Receiving a path switching reply message from the core network device, where the path switching reply message carries a second NCC and a second NH, and the second NH is used to vertically derive a third security key between the second access network device and the terminal; Sending second information to the terminal, where the second information carries the second NCC, and the second NCC is used for the terminal to vertically derive the third security key.

27. A communication method executed by a core network device, including: Receiving a path switching request from a second access network device; Sending a path switching reply message to the second access network device, where the path switching reply message carries a second NCC and a second NH.

28. A terminal, including: A first communication unit, configured to receive first configuration information from a first access network device, where the first configuration information includes first security parameters corresponding to at least one candidate access network device, and the first security parameters include at least one of the following: an indication of a key derivation method, a first next-hop chain counter NCC.

29. The terminal according to claim 28, wherein, the terminal further includes: a first processing unit, configured to determine the first security parameters corresponding to the second access network device based on the second access network device to which the target cell belongs and the first configuration information, where the second access network device is one of the at least one candidate access network device; calculate a first security key between the terminal and the second access network device based on the first security parameters corresponding to the second access network device; The first communication unit is configured to receive a cell handover command, where the cell handover command is used to indicate a target cell.

30. The terminal according to claim 29, wherein, The first communication unit is configured to perform one of the following: receiving first algorithm-related information from the first access network device, where the first algorithm-related information is used to determine a target security algorithm corresponding to the second access network device, the first algorithm-related information includes security algorithms supported by the at least one candidate access network device, and the target security algorithm includes at least one of the following: a target integrity protection algorithm, a target encryption algorithm; receiving second algorithm-related information from the second access network device, where the second algorithm-related information is used to determine a target security algorithm corresponding to the second access network device, and the second algorithm-related information includes the target security algorithm corresponding to the second access network device and / or security algorithms supported by the second access network device.

31. The terminal according to claim 29 or 30, wherein, The first processing unit is configured to perform one of the following: deleting first security parameters corresponding to the at least one candidate access network device; deleting first security parameters corresponding to candidate access network devices whose first NCC is less than the NCC corresponding to the first security key.

32. The terminal according to any one of claims 28 - 30, wherein, The first processing unit is configured to delete historical security parameters corresponding to the first candidate access network device in the case where historical security parameters corresponding to the first candidate access network device among the at least one candidate access network device are saved.

33. A first access network device, comprising: A second communication unit, configured to send first configuration information to a terminal, where the first configuration information includes first security parameters corresponding to at least one candidate access network device, and the first security parameters include at least one of the following: an indication of a key derivation method, a first next-hop chain counter NCC.

34. The first access network device according to claim 33, wherein, The second communication unit is configured to receive second configuration information from a core network device, where the second configuration information is used to determine first security parameters corresponding to the at least one candidate access network device.

35. The first access network device according to claim 34, wherein, The second communication unit is configured to send a request message to the core network device, where the request message is used to request allocation of the second configuration information.

36. The first access network device according to claim 34 or 35, wherein, The second configuration information includes at least one of the following: Second security parameters corresponding to the at least one candidate access network device; Second security parameters corresponding to each second candidate access network device, where each second candidate access network device is a candidate access network device among the at least one candidate access network device that has not been configured with second security parameters; One or more NCCs and an NH corresponding to each NCC, where each NCC and its corresponding NH are used to determine second security parameters corresponding to the at least one candidate access network device.

37. The first access network device according to claim 36, wherein, The second security parameter includes at least one of the following: an indication of a key derivation method, a first NCC, and a first next-hop key NH.

38. The first access network device according to claim 37, wherein, the first access network device further includes: a second processing unit, configured to calculate a first security key between the terminal and the second access network device based on a second security parameter corresponding to the second access network device to which the target cell corresponding to the terminal belongs, where the second access network device is one of the at least one candidate access network devices; the second communication unit is configured to send first information to the second access network device, where the first information includes: the first security key and the NCC corresponding to the first security key.

39. The first access network device according to claim 38, wherein, the first information further includes one of the following: a second security parameter corresponding to an unused candidate access network device; a second security parameter corresponding to a candidate access network device whose first NCC is greater than the NCC corresponding to the first security key.

40. The first access network device according to claim 34 or 35, wherein, the second configuration information includes a first security parameter corresponding to the at least one candidate access network device; the second communication unit is configured to send first information to the second access network device to which the target cell corresponding to the terminal belongs, where the first information is used to instruct the second access network device to calculate a first security key between the second access network device and the terminal, and the second access network device is one of the at least one candidate access network devices.

41. The first access network device according to claim 40, wherein, the first information includes at least one of the following: a second security key between the first access network device and the terminal, and the NCC corresponding to the second security key.

42. The first access network device according to claim 33, wherein, the indication of the key derivation method is an indication of key horizontal derivation, and the first NCC is the NCC corresponding to the second security key between the first access network device and the terminal; the first access network device further includes: a second processing unit, configured to horizontally derive a first security key between the terminal and the second access network device based on the second security key, where the second access network device corresponds to the target cell of the terminal; the second communication unit is configured to send first information to the second access network device, where the first information includes: the first security key, the NCC corresponding to the first security key, and the NCC corresponding to the first security key is equal to the NCC corresponding to the second security key.

43. The first access network device according to any one of claims 33-42, wherein, The second communication unit is configured to send first algorithm-related information to the terminal, where the first algorithm-related information is used to determine a target security algorithm corresponding to the second access network device, the first algorithm-related information includes security algorithms supported by the at least one candidate access network device, and the target security algorithm includes at least one of the following: a target integrity protection algorithm, a target encryption algorithm.

44. A core network device comprising: A third communication unit configured to send second configuration information to a first access network device, where the second configuration information is used by the first access network device to determine first security parameters corresponding to at least one candidate access network device, and the first security parameters include at least one of the following: an indication of a key derivation method, a first next-hop chain counter NCC.

45. The core network device according to claim 44, wherein the third communication unit is configured to receive a request message from the first access network device, where the request message is used to request allocation of the second configuration information.

46. The core network device according to claim 44 or 45, wherein the second configuration information includes at least one of the following: second security parameters corresponding to the at least one candidate access network device; second security parameters corresponding to each second candidate access network device, where each second candidate access network device is a candidate access network device among the at least one candidate access network device that has not been configured with second security parameters; one or more NCCs and an NH corresponding to each NCC, where each NCC and its corresponding NH are used to determine second security parameters corresponding to the at least one candidate access network device.

47. The core network device according to claim 44 or 45, wherein the second configuration information includes the first security parameters corresponding to the at least one candidate access network device; the third communication unit is configured to send third configuration information to the at least one candidate access network device, where the third configuration information corresponding to each candidate access network device includes the second security parameters corresponding to the candidate access network device.

48. The core network device according to claim 46 or 47, wherein the second security parameters include at least one of the following: an indication of a key derivation method, a first NCC, a first NH.

49. A second access network device comprising: A fourth communication unit configured to receive third configuration information from a core network device, where the third configuration information includes second security parameters corresponding to the second access network device, and the second security parameters include at least one of the following: an indication of a key derivation method, a first next-hop chain counter NCC, a first next-hop key NH.

50. The second access network device according to claim 49, wherein the second access network device further includes: a fourth processing unit configured to calculate the first security key based on the second security parameters: the fourth communication unit is configured to receive first information from a first access network device, where the first information is used to instruct the second access network device to calculate a first security key between the second access network device and the terminal.

51. The second access network device according to claim 49 or 50, wherein, the fourth communication unit is configured to send second algorithm-related information to a terminal, where the second algorithm-related information is used to determine a target security algorithm corresponding to the second access network device, and the second algorithm-related information includes the target security algorithm corresponding to the second access network device and / or the security algorithms supported by the second access network device, and the target security algorithm includes at least one of the following: a target integrity protection algorithm, a target encryption algorithm.

52. A terminal, comprising: a first communication unit configured to receive second information from the second access network device when horizontally deriving a first security key between the terminal and the second access network device, where the second information carries a second NCC, and the second NCC is used to vertically derive a third security key between the terminal and the second access network device.

53. A second access network device, comprising: a fourth communication unit configured to send a path switching request to a core network device when obtaining a horizontally derived first security key between the terminal and the second access network device; receive a path switching reply message from the core network device, where the path switching reply message carries a second NCC and a second NH, and the second NH is used to vertically derive a third security key between the terminal and the second access network device; send second information to the terminal, where the second information carries the second NCC, and the second NCC is used for the terminal to vertically derive the third security key.

54. A core network device, comprising: a third communication unit configured to receive a path switching request from a second access network device; send a path switching reply message to the second access network device, where the path switching reply message carries a second NCC and a second NH.

Citation Information

Patent Citations

  • Method for guaranteeing safety of multi-carrier switching or reconstructing in multi-carrier communication system

    CN102215485A

  • Method and system to enable secure communication for inter-enb transmission

    CN105557007A

  • Method for instructing user equipment to obtain key, user equipment and network device

    CN110710238A

  • System and method for communicating with provisioned security protection

    CN111448813A

  • Switching key determination method, switching method and device

    CN116782211A