Method and apparatus for updating key, and terminal, network-side device, and storage medium
The key update is performed through the terminal and the target next jump link counter NCC is used to solve the problem of large overhead of key update signaling in the new air-interface access network, reducing the processing load and delay of the terminal.
Patent Information
- Application Number
- PCT/CN2024/136509
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-08
- Filing Date
- 2024-12-03
- Publication Date
- 2025-06-12
AI Technical Summary
In the new air-interface access network, cross-CU handover involves changes in the packet data aggregation protocol entity on the network side, resulting in reconfiguration of the configuration information of each candidate cell when key updates, which has a large signaling overhead, which increases the terminal processing load and processing delay.
The target next jump link counter NCC is obtained through the terminal, and the target NCC determines according to the first key information or the first rule. When the target cell is a first candidate cell, the key update is performed according to the target NCC, and the first key information corresponds to all candidate cells of the terminal.
Reduces signaling overhead, reduces the processing load and processing delay of the terminal, and avoids reconfiguration of configuration information for each candidate cell.
Smart Images

Figure CN2024136509_12062025_PF_FP_ABST
Abstract
Description
Key updating method, device, terminal, network side equipment and storage medium
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on December 8, 2023, with application number 2023116915014 and titled “Key Update Method, Apparatus, Terminal, Network Side Equipment and Storage Medium,” the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application belongs to the field of communication technology, and specifically relates to a key updating method, apparatus, terminal, network-side equipment, and storage medium. Background Art
[0004] The New Radio (NR) access network splits the next generation Node B (gNB) into a centralized unit (CU) and a distributed unit (DU). The gNB-CU and gNB-DU are connected via the F1 interface. To reduce handover latency, the Release 18 protocol introduced Layer 1 or Layer 2 triggered mobility (LTM). This means that the network preconfigures multiple LTM candidate cells, and the DU uses L1 / L2 signaling to instruct the terminal to switch to the appropriate candidate cell based on the Layer 1 measurement results reported by the terminal. In the Release 19 protocol version mobility enhancement project, inter-CU LTM will be supported. Inter-CU handover involves changes to the Packet Data Convergence Protocol (PDCP) entity on the network side, requiring a key update. Before the terminal performs the next handover, the key of the candidate cell needs to be reconfigured.
[0005] Currently, key-related information is provided in the configuration information of each candidate cell. When reconfiguring the key, the configuration information of each candidate cell needs to be reconfigured, which results in large signaling overhead and increases terminal processing load and processing delay. Summary of the Invention
[0006] The embodiments of the present application provide a key update method, apparatus, terminal, network-side device, and storage medium, which can effectively reduce signaling overhead, reduce terminal processing load, and reduce processing delay.
[0007] In a first aspect, a key updating method is provided, comprising:
[0008] The terminal obtains a target next hop link counter NCC, where the target NCC is determined according to first key information, and the first key information corresponds to all candidate cells of the terminal; or, the target NCC is determined according to a first rule;
[0009] When the target cell is a first candidate cell, the terminal performs a key update according to the target NCC, wherein the first candidate cell is associated with a different identifier from the source cell.
[0010] In a second aspect, a key updating method is provided, comprising:
[0011] The network side device sends the first key information to the terminal;
[0012] Among them, the first key information corresponds to all candidate cells of the terminal, the first key information is used to determine the target next hop link counter NCC, the target NCC is used for key update when the target cell of the terminal is the first candidate cell, and the first candidate cell is associated with a different identifier from the source cell.
[0013] In a third aspect, a key updating device is provided, comprising:
[0014] An acquisition module, configured to acquire a target next hop link counter NCC, wherein the target NCC is determined according to first key information, the first key information corresponding to all candidate cells of the terminal; or, the target NCC is determined according to a first rule;
[0015] An updating module is configured to perform a key update according to the target NCC when the target cell is a first candidate cell, wherein the first candidate cell is associated with a different identifier from the source cell.
[0016] In a fourth aspect, a key updating device is provided, comprising:
[0017] A sending module, configured to send first key information to a terminal;
[0018] Among them, the first key information corresponds to all candidate cells of the terminal, the first key information is used to determine the target next hop link counter NCC, the target NCC is used for key update when the target cell of the terminal is the first candidate cell, and the first candidate cell is associated with a different identifier from the source cell.
[0019] In a fifth aspect, a terminal is provided, which includes a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the method described in the first aspect are implemented.
[0020] In a sixth aspect, a terminal is provided, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the method described in the first aspect.
[0021] In the seventh aspect, a network side device is provided, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the second aspect are implemented.
[0022] In an eighth aspect, a network side device is provided, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the method described in the second aspect.
[0023] In a ninth aspect, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect or the steps of the method described in the second aspect are implemented.
[0024] In the tenth aspect, a wireless communication system is provided, comprising: a terminal and a network side device, wherein the terminal can be used to execute the steps of the method described in the first aspect, and the network side device can be used to execute the steps of the method described in the second aspect.
[0025] In the eleventh aspect, a chip is provided, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the method described in the first aspect, or to implement the steps of the method described in the second aspect.
[0026] In the twelfth aspect, a computer program / program product is provided, which is stored in a storage medium and is executed by at least one processor to implement the steps of the method described in the first aspect, or to implement the steps of the method described in the second aspect.
[0027] In an embodiment of the present application, the terminal obtains a target NCC, which can be determined based on the first key information or the first rule. When the target cell is the first candidate cell, the key update is performed according to the target NCC. The first key information corresponds to all candidate cells of the terminal. The terminal can obtain the target NCC required for key update when performing switching to the first candidate cell through the first key information or the first rule. When the network side device reconfigures the key, it is not necessary to reconfigure the configuration information of each candidate cell, which can effectively reduce the signaling overhead. Without reconfiguring the configuration information of each candidate cell, the terminal does not need to re-decode the configuration information, which can reduce the terminal processing load and processing delay. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] FIG1 is a block diagram of a wireless communication system applicable to embodiments of the present application;
[0029] FIG2 is a schematic diagram of the architecture of a CU-DU in related art;
[0030] FIG3 is a schematic diagram of an LTM-related switching process in the related art;
[0031] FIG4 is a schematic diagram of a conditional switching process in the related art;
[0032] FIG5 is a schematic diagram of vertical key derivation and horizontal key derivation in the related art;
[0033] FIG6 is a schematic diagram of a handover preparation process for N2 handover in the related art;
[0034] FIG7 is a schematic diagram of a handover execution process of N2 handover in the related art;
[0035] FIG8 is a flowchart of an implementation method of a key update method in an embodiment of the present application;
[0036] FIG9 is a flowchart of another key update method according to an embodiment of the present application;
[0037] FIG10 is a schematic structural diagram of a key updating device corresponding to FIG8 in an embodiment of the present application;
[0038] FIG11 is a schematic structural diagram of a key updating device corresponding to FIG9 in an embodiment of the present application;
[0039] FIG12 is a schematic structural diagram of a communication device according to an embodiment of the present application;
[0040] FIG13 is a schematic structural diagram of a terminal according to an embodiment of the present application;
[0041] FIG14 is a schematic structural diagram of a network-side device in an embodiment of the present application. Specific embodiments
[0042] The following will be combined with the accompanying drawings in the embodiments of this application to clearly describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.
[0043] The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects, for example, the first object can be one or more. In addition, "or" in this application represents at least one of the connected objects. For example, "A or B" covers three options, namely, Option 1: including A but not including B; Option 2: including B but not including A; Option 3: including both A and B. The character " / " generally indicates that the objects associated before and after are in an "or" relationship.
[0044] The term "indication" in this application can be either a direct indication (or explicit indication) or an indirect indication (or implicit indication). A direct indication can be understood as the sender explicitly informing the receiver of specific information, the operation to be performed, or the requested result, etc. in the instruction sent; an indirect indication can be understood as the receiver determining the corresponding information based on the instruction sent by the sender, or making a judgment and determining the operation to be performed or the requested result, etc. based on the judgment result.
[0045] It is worth noting that the technology described in the embodiments of the present application is not limited to the Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency Division Multiple Access (SC-FDMA) or other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the technology described can be used for the systems and radio technologies mentioned above, as well as for other systems and radio technologies. The following description describes the NR system for illustrative purposes, and the NR terminology is used in most of the following description, but these technologies can also be applied to systems other than NR systems, such as the 6th generation (6G) NR system. th Generation, 6G) communication system.
[0046] FIG1 shows a block diagram of a wireless communication system applicable to embodiments of the present application. The wireless communication system includes a terminal 11 and a network-side device 12 .
[0047] The terminal 11 may be a mobile phone, tablet computer, laptop computer, notebook computer, personal digital assistant (PDA), handheld computer, netbook, ultra-mobile personal computer (UMPC), mobile internet device (MID), augmented reality (AR), virtual reality (VR) device, robot, wearable device, flight vehicle, vehicle user equipment (VUE), shipborne equipment, pedestrian user equipment (PUE), smart home (home appliances with wireless communication functions, such as refrigerators, televisions, washing machines, or furniture), game console, personal computer (PC), ATM or self-service machine, etc. Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. The vehicle-mounted device may also be referred to as a vehicle-mounted terminal, a vehicle-mounted controller, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip, or a vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application.
[0048] The network-side device 12 may include an access network device or a core network device, wherein the access network device may also be referred to as a radio access network (RAN) device, a radio access network function, or a radio access network unit. The access network device may include a base station, a wireless local area network (WLAN) access point (AP), or a wireless fidelity (WiFi) node. Among them, the base station can be referred to as Node B (NB), Evolved Node B (eNB), Next Generation Node B, New Radio Node B (NR Node B), Access Point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), Radio Base Station, Radio Transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home Evolved Node B (home evolved Node B), Transmission Reception Point (TRP) or other appropriate terms in the relevant field. As long as the same technical effect is achieved, the base station is not limited to specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.
[0049] To facilitate understanding, the relevant technologies and concepts involved in the embodiments of this application are first introduced.
[0050] 1. CU-DU Architecture
[0051] As previously described, the NR access network splits the gNB into the gNB-CU and gNB-DU, which are connected via the F1 interface. CUs are connected via the control plane Xn interface (Xn-C), and the core network connects to the gNB via the NG interface. Figure 2 shows the CU-DU architecture.
[0052] A gNB contains only one CU, one or more DUs, and one DU contains one or more cells.
[0053] The CU includes the PDCP layer and the protocol stack above the PDCP layer, and the DU includes the protocol stack below the PDCP layer, such as the Radio Link Control (RLC) layer, the Media Access Control (MAC) layer, and the Physical (PHY) layer.
[0054] On the control plane, the CU includes Radio Resource Control (RRC) and the PDCP (PDCP-C) of the control plane;
[0055] On the user plane, the CU includes the Service Data Adaptation Protocol (SDAP) and the PDCP of the user plane (PDCP-U).
[0056] 2. Long-Term Transaction (LTM)
[0057] As previously mentioned, to reduce handover latency, Release 18 introduced LTM. This means the network preconfigures multiple LTM candidate cells. The DU uses Layer 1 / L2 signaling to instruct the terminal to switch to an appropriate candidate cell based on the Layer 1 measurement results reported by the terminal. R18 LTM only supports cell handover within the same CU. R19 LTM will explore inter-CU cell handover.
[0058] The relevant switching process is shown in Figure 3, including the LTM preparation phase, early synchronization phase, LTM execution phase, and LTM completion phase:
[0059] During the LTM preparation phase, the UE is in the RRC connected state and reports measurement reports;
[0060] The gNB prepares LTM candidate cells and sends an RRC Reconfiguration message to the UE. The RRC Reconfiguration message carries the configuration information of the LTM candidate cells.
[0061] The UE sends an RRC reconfiguration complete message to the gNB.
[0062] In the early synchronization phase, the UE performs downlink synchronization or uplink synchronization with the candidate cell;
[0063] During the LTM execution phase, the UE reports a layer 1 measurement report;
[0064] The gNB selects LTM candidate cells and sends a cell handover command to the UE via the MAC Control Element (MAC CE).
[0065] The UE is separated from the source cell, applies the configuration information of the target cell, and performs the Random Access Channel (RACH) process;
[0066] During the LTM completion phase, the LTM is completed.
[0067] 3. Conditional Handover (CHO)
[0068] In order to prevent the terminal from being unable to receive the handover command-related message from the source node after the channel condition of the source cell deteriorates, thereby causing handover failure, the R16 protocol version introduces the conditional handover process.
[0069] As shown in Figure 4, the main steps of the conditional switching process are as follows:
[0070] 0.AMF provides mobility control information;
[0071] 1. During the measurement process, the UE reports the measurement report;
[0072] 2. The source node decides to use CHO;
[0073] 3. The source node sends a handover request message to one or more potential target nodes;
[0074] 4. Each destination node may perform admission control;
[0075] 5. Each target node feeds back the switching request confirmation information to the source node;
[0076] 6. The source node sends RRC reconfiguration information including conditional handover to the UE;
[0077] 7. The UE sends an RRC reconfiguration complete message to the source node;
[0078] 7a. The source node sends an advance state transfer message to the target node;
[0079] 8. The UE evaluates whether the candidate cells meet the conditions for conditional handover. If so, it selects a target cell for handover (detaching from the source cell and synchronizing with the target cell).
[0080] The UE initiates a random access procedure in the selected target cell;
[0081] The UE sends an RRC reconfiguration complete message to the target node;
[0082] After successfully completing the handover process, the UE releases the stored conditional handover configuration;
[0083] 8a. The target node sends a switching success message to the source node;
[0084] 8b. The source node sends a sequence number (SN) state transition message to the target node;
[0085] 8c. The source node sends a handover cancellation message to other target nodes.
[0086] Currently, the CHO handover trigger conditions supported by the R16 protocol version are A3 and A5 events. If two handover trigger conditions are configured at the same time, CHO or Conditional Pscell Addition or Change (CPAC) will be triggered only when both conditions are met.
[0087] The definitions of various events and entry and exit conditions are shown in Table 1:
[0088] Table 1
[0089] The meanings of the parameters of entry conditions and exit conditions are as follows:
[0090] Mn: Neighboring cell measurement result, without considering any offset;
[0091] Ofn: Neighborhood measurement object specific offset;
[0092] Ocn: Neighboring cell-level specific offset;
[0093] Mp: primary serving cell (SpCell) measurement result, without considering any offset;
[0094] Ofp: SpCell measurement object specific offset;
[0095] Ocp: SpCell cell-level specific offset;
[0096] Hys: hysteresis parameter of the event;
[0097] Off: The offset parameter of the event.
[0098] Ms: Serving cell measurement result, without considering any offset;
[0099] Mi: interference measurement result, without considering any offset;
[0100] Thresh / Thresh1 / Thresh2: Thresholds for corresponding events.
[0101] To avoid ping-pong handover, the base station conditional trigger configuration (CondTriggerConfig) configures a trigger time parameter, namely the timeToTrigger parameter, for each event. When the L3 filtered signal quality of one or more candidate cells within the timeToTrigger time meets the entry conditions of the event, the UE uses the cells that meet the conditions as trigger cells and selects one of the trigger cells to perform conditional reconfiguration.
[0102] 4. Conditional Switching Recovery (CHO based recovery)
[0103] After a Radio Link Failure (RLF) or Handover Failure (HOF) occurs, the UE performs cell selection. If the selected cell is a CHO candidate cell and the network configuration attemptCondReconfig IE is true, the UE attempts to perform a CHO. Otherwise, the UE performs a re-establishment.
[0104] For LTM or conditional LTM, an LTM based recovery method similar to the conditional switching based recovery is also supported.
[0105] The difference between conditional LTM and LTM is that the UE evaluates network pre-configured events (similar to the conditions of CHO, the conditions of conditional LTM are based on L1 measurement definitions) to determine whether the handover conditions are met, and thus performs the handover itself without the need for the DU to indicate the handover command.
[0106] 5. Key Derivation During the Switching Process
[0107] When the initial connection is established, K gNB By AMF key K AMF The subsequent handover can be an Xn handover or an N2 handover.
[0108] Xn handover refers to inter-CU handover via the Xn interface between the source gNB / ng-eNB and the target gNB / ng-eNB. The key derivation process for the handover is as follows:
[0109] Network side:
[0110] When the source gNB / ng-eNB has an unused {NH, NCC} pair, vertical key derivation is performed, otherwise horizontal key derivation is performed. NH is the next hop, and the key K AMF Derivation, NCC is the link counter of NH; if vertical key derivation is performed, the source gNB / ng-eNB calculates K based on NH and the physical cell identifier (PCI) and frequency of the target cell. NG-RAN *; If horizontal key derivation is performed, the source gNB / ng-eNB uses the currently used key K gNB , using the PCI and frequency of the target cell as input to calculate K NG-RAN *;
[0111] The source gNB / ng-eNB will NG-RAN *,NCC} pair is sent to the target gNB / ng-eNB. The target gNB / ng-eNB uses K NG-RAN * As K when UE switches to the target cell gNB The target gNB / ng-eNB will use NCC and target K gNB The NCC is included in the Handover Command (HO Command) message and transparently transmitted to the source gNB / ng-eNB, which then sends it to the UE.
[0112] After the handover is completed, the target gNB / ng-eNB sends an NGAP PATH SWITCH REQUEST message to the AMF. After receiving the message, the AMF increases the NCC saved locally by 1 and calculates the NCC value based on the K AMF A new NH is derived, and the AMF sends the new {NH, NCC} to the target gNB / ng-eNB via the NGAP PATH SWITCH REQUEST ACKNOWLEDGE for subsequent handovers, and deletes other saved {NH, NCC} pairs.
[0113] UE side:
[0114] When the UE performs a handover and applies the RRC configuration of the target cell:
[0115] If the NCC value received by the UE in the handover command is the same as the K value currently used gNB / K eNB If the associated NCC is the same, the UE will use the current K gNB / K eNB, target PCI and frequency level to derive K NG-RAN *;
[0116] If the NCC value received by the UE in the handover command is the same as the K value currently used gNB / K eNB If the associated NCC is different, the UE first synchronizes the NCC and NH until it matches the NCC indicated by the handover command. Then the UE vertically derives K based on the synchronized NH, target PCI and frequency. NG-RAN *;
[0117] UE uses K NG-RAN *K used for communication with target gNB / ng-eNB gNB / K eNB .
[0118] The vertical key derivation and horizontal key derivation are shown in FIG5 .
[0119] When the Xn interface is not available, the UE implements N2-based handover between gNBs through N2 interface signaling interaction, i.e., inter-gNB N2-based handover. The handover preparation process for N2 handover is shown in Figure 6:
[0120] The source NG-RAN decides to trigger a relocation via N2.
[0121] 1. The source NG-RAN sends a Handover Required message to the source AMF to notify that a UE is about to be handed over.
[0122] 2. The source AMF selects the target AMF (T-AMF Selection);
[0123] 3. The source AMF sends a Namf_Communication_CreateUEContext Request to the target AMF;
[0124] 4. The target AMF sends an Nsmf protocol data unit (PDU) session update session management (SM) context request (Nsmf_PDUSession_UpdateSMContext Request) to the SMF;
[0125] 5.SMF selects UPF (UPF selection);
[0126] 6a.SMF sends N4Session Modification Request to the anchor UPF (UPF(PSA));
[0127] 6b.UPF (PSA) returns N4Session Modification Response to SMF;
[0128] 6c.SMF sends N4Session Establishment Request to the target UPF;
[0129] 6d target UPF returns N4 session establishment response (N4Session Establishment Response) to SMF;
[0130] 7.SMF returns Nsmf PDU session update SM context response (Nsmf_PDUSession_UpdateSMContext Response) to the target AMF;
[0131] 8. The target AMF monitors the PDU handover response (PDU Handover Response supervision);
[0132] 9. The target AMF sends a Handover Request to the target NG-RAN.
[0133] 10. The target NG-RAN returns a Handover Request Acknowledge to the target AMF.
[0134] 11a. The target AMF sends an Nsmf PDU session update SM context request (Nsmf_PDUSession_UpdateSMContext Request) to the SMF;
[0135] 11b.SMF sends N4Session Modification Request to the target UPF;
[0136] 11c. The target UPF returns an N4 Session Modification Response to the SMF;
[0137] 11d.SMF sends an N4Session Modification Request to the source UPF;
[0138] 11e. The source UPF returns an N4 Session Modification Response to the SMF;
[0139] 11f.SMF returns Nsmf PDU session update SM context response (Nsmf_PDUSession_UpdateSMContext Response) to the target AMF;
[0140] 12. The target AMF returns a Namf communication create UE context response (Namf_Communication_CreateUEContext Response) to the target AMF;
[0141] The handover execution process of N2 handover is shown in Figure 7:
[0142] 1. The source AMF sends a Handover Command to the source NG-RAN.
[0143] 2. The source NG-RAN sends a handover command to the UE.
[0144] 2a. The source NG-RAN performs uplink RAN status transfer to the source AMF;
[0145] 2b. The source AMF and the target AMF perform Namf communication N1 and N2 interface message transfer (Namf_Communication_N1N2MessageTransfer);
[0146] 2c. The target AMF performs downlink RAN status transfer to the target NG-RAN;
[0147] 3a. Direct data forwarding from the source NG-RAN to the target NG-RAN;
[0148] 3b. The source NG-RAN performs indirect data forwarding to the source UPF;
[0149] The UE synchronizes with the new cell;
[0150] 4. The UE sends a Handover Confirm to the target NG-RAN.
[0151] 5. The target NG-RAN sends a handover notification to the target AMF;
[0152] 6a. The target AMF sends a Namf communication N2 interface information notification (Namf_Communication_N2InfoNotify) to the source AMF;
[0153] 6b. The source AMF returns the Namf communication N2 interface information notification response (Namf_Communication_N2InfoNotify Ack) to the target AMF;
[0154] 6c. The source AMF sends an Nsmf PDU session release SM context request (Nsmf_PDUSession_ReleaseSMContext Request) to the SMF;
[0155] 7. The target AMF sends an Nsmf PDU session update SM context request (Nsmf_PDUSession_UpdateSMContext Request) to the SMF;
[0156] 8a.SMF sends N4Session Modification Request to the target UPF;
[0157] 8b. The target UPF returns an N4 session modification response (N4Session Modification Response) to the SMF;
[0158] 9a.SMF sends N4Session Modification Request to the source UPF;
[0159] 9b. The source UPF returns an N4 session modification response (N4Session Modification Response) to the SMF;
[0160] 10a.SMF sends N4Session Modification Request to UPF (PSA);
[0161] 10b.UPF (PSA) returns N4Session Modification Response to SMF;
[0162] 11.SMF returns Nsmf PDU session update SM context response (Nsmf_PDUSession_UpdateSMContext Response) to the target AMF;
[0163] 12. Enter the registration procedure;
[0164] 13a.SMF sends N4Session Release Request to the source UPF;
[0165] 13b. The source UPF returns an N4 session release response (N4Session Release Response) to the SMF;
[0166] 14a. The source AMF sends a UE Context Release Command to the source NG-RAN;
[0167] 14b. The source NG-RAN returns a UE Context Release Command Complete message to the source AMF.
[0168] 15a.SMF sends N4Session Modification Request to the target UPF;
[0169] 15b. The target UPF returns an N4 Session Modification Response to the SMF.
[0170] In N2 handover, due to the lack of Xn interface, the source gNB and target gNB cannot directly exchange signaling, and the candidate target cell preparation needs to be implemented through the NG interface. The main NG interface signaling involved is:
[0171] HANDOVER REQUIRED sent by the source gNB to the AMF;
[0172] HANDOVER REQUEST sent by the AMF to the target gNB;
[0173] The target gNB responds to the AMF's HANDOVER REQUEST ACKNOWLEDGE message.
[0174] The AMF replies to the HANDOVER COMMAND of the source gNB.
[0175] When the handover does not involve a change in AMF, the source AMF and target AMF in Figures 6 and 7 are the same node, and the signaling interaction between them can be omitted.
[0176] The key update during the N2 handover process is as follows:
[0177] Network side:
[0178] After the AMF receives the NGAP HANDOVER REQUIRED message, the source AMF adds 1 to the NCC value stored locally and calculates the value based on K AMF Calculate a new NH and send the {NH, NCC} pair to the target gNB;
[0179] The target gNB calculates K based on NH, target PCI and frequency. NG-RAN *, the target gNB / ng-eNB uses K NG-RAN * As K when UE switches to the target cell gNB The target gNB / ng-eNB will use NCC and target K gNB The NCC is included in the Handover Command (HO Command) message and transparently transmitted to the AMF. The AMF transparently transmits it to the source gNB / ng-eNB, which then sends it to the UE via an RRC Reconfiguration message.
[0180] After the handover is completed, the target gNB / ng-eNB sends an NGAP PATH SWITCH REQUEST message to the AMF. After receiving the message, the AMF increases the NCC saved locally by 1 and calculates the NCC value based on the K AMF A new NH is derived, and the AMF sends the new {NH, NCC} to the target gNB / ng-eNB via the NGAP PATH SWITCH REQUEST ACKNOWLEDGE for subsequent handovers, and deletes other saved {NH, NCC} pairs.
[0181] During the switching process, the network may change K AMF At this time, the target cell configuration in the handover command will carry a key set change indication (KeySetChangeIndicator), indicating K AMF Key change.
[0182] UE side: K AMF When it is unchanged, it is the same as switching with Xn. AMF When the key changes, the UE AMF Derived or updated K gNB .
[0183] 5. UE-side access layer key update
[0184] In conditional handover, each candidate cell configuration includes a MasterKeyUpdate parameter, which indicates key update information when handing over to the current cell.
[0185] If the UE receives a MasterKeyUpdate:
[0186] If the MasterKeyUpdate contains a non-access layer container (nas-Container), the UE submits the nas-Container to the upper layer;
[0187] If the keySetChangeIndicator in MasterKeyUpdate is set to true, the UE AMF Derived or updated K gNB ;
[0188] Otherwise, the UE uses the current K gNB or NH to derive or update the key:
[0189] If nextHopChainingCount and the currently activated K gNB If the associated NCCs are the same, the UE performs horizontal derivation to obtain the target cell key;
[0190] If nextHopChainingCount and the currently activated K gNB If the associated NCC is different, the UE performs vertical derivation to obtain the target cell key.
[0191] The above introduces the relevant technologies and concepts involved in the embodiments of the present application. Now, in conjunction with the accompanying drawings, the key update method provided by the embodiments of the present application is described in detail through some embodiments and their application scenarios.
[0192] FIG8 is a flowchart illustrating an implementation of a key update method according to an embodiment of the present application. The method may include the following steps:
[0193] S810: The terminal obtains the target next hop link counter NCC;
[0194] The target NCC is determined according to the first key information, and the first key information corresponds to all candidate cells of the terminal; or the target NCC is determined according to the first rule;
[0195] S820: When the target cell is the first candidate cell, the terminal performs a key update according to the target NCC;
[0196] The first candidate cell is associated with a different identifier from the source cell.
[0197] By applying the method provided in the embodiment of the present application, the terminal obtains a target NCC, which can be determined based on the first key information or the first rule. When the target cell is the first candidate cell, the key update is performed according to the target NCC. The first key information corresponds to all candidate cells of the terminal. The terminal can obtain the target NCC required for key update when performing switching to the first candidate cell through the first key information or the first rule. When the network side device reconfigures the key, it is not necessary to reconfigure the configuration information of each candidate cell, which can effectively reduce the signaling overhead. Without reconfiguring the configuration information of each candidate cell, the terminal does not need to re-decode the configuration information, which can reduce the terminal processing load and processing delay.
[0198] In the embodiments of the present application, a cell refers to a cell or a cell group. For example, a target cell refers to a target cell or a target cell group, a candidate cell refers to a candidate cell or a candidate cell group, a first candidate cell refers to a first candidate cell or a first candidate cell group, a second candidate cell refers to a second candidate cell or a second candidate cell group, and a source cell refers to a source cell or a source cell group. NCC is used for key derivation or update and other technical terms may be used instead.
[0199] During the handover process to the target cell, the terminal may need to perform a key update.
[0200] The terminal can first obtain the target NCC. The target NCC can be determined based on the first key information. The first key information corresponds to all candidate cells of the terminal and is the information required for key update when performing a handover to a candidate cell. The first key information is different from the configuration information of the candidate cell and is not included in the configuration information of the candidate cell.
[0201] Alternatively, the target NCC may be determined according to a first rule. The first rule may be predefined by a protocol or configured by a network-side device.
[0202] Whether the candidate cell's associated identifier is the same as the source cell's associated identifier can be used to determine whether the candidate cell and the source cell are inter-CU cells. If the candidate cell's associated identifier is the same as the source cell's associated identifier, the candidate cell and the source cell belong to the same CU, and no key update is required during the handover process. If the candidate cell's associated identifier is different from the source cell's associated identifier, the candidate cell and the source cell are inter-CU cells, and a key update is required during the handover process.
[0203] Therefore, when the target cell is the first candidate cell, the terminal can perform a key update according to the target NCC so that after the handover is completed, it can communicate with the target cell based on the new radio access network key. The first candidate cell is associated with a different identifier than the source cell.
[0204] In some embodiments of the present application, the first key information may include at least one of the following:
[0205] 1) Information indicating whether the master key is updated, such as masterKeyUpdate;
[0206] 2) Information used to indicate whether the access mobility management function AMF key has changed, such as keySetChangeIndicator;
[0207] 3) Information used to indicate the NCC for key derivation, such as nextHopChainingCount;
[0208] 4) Information used to indicate non-access stratum information delivered to upper layers, such as nas-Container;
[0209] 5) Information used to indicate security configuration information, such as securityConfig;
[0210] 6) Information indicating whether to use a master key or a secondary key;
[0211] 7) Information used to indicate security algorithm configuration information, such as securityAlgorithmConfig.
[0212] The masterKeyUpdate may include keySetChangeIndicator, nextHopChainingCount, nas-Container, securityConfig, securityAlgorithmConfig, etc. Information indicating whether to use the primary key or the secondary key may be included in the securityConfig.
[0213] In some embodiments of the present application, when the first key information includes information indicating an NCC for key derivation, the target NCC is the NCC indicated by the first key information, and the terminal performs a key update according to the target NCC, which may include the following steps:
[0214] If the target NCC is the same as the NCC associated with the activated radio access network key, the terminal horizontally derives a new radio access network key based on the activated radio access network key or the cell information of the target cell;
[0215] If the target NCC is different from the NCC associated with the activated radio access network key, the terminal synchronizes the NCC associated with the activated radio access network key to the target NCC, updates the next-hop NH, and vertically derives a new radio access network key based on the updated NH or the cell information of the target cell.
[0216] In this embodiment of the present application, if the first key information includes information indicating the NCC from which the key is derived, the target NCC determined based on the first key information is the NCC indicated by the first key information. In this case, the target NCC may be the same as or different from the NCC associated with the activated radio access network key.
[0217] If the target NCC is the same as the NCC associated with the activated radio access network key, the terminal can horizontally derive a new radio access network key based on the activated radio access network key or the cell information of the target cell, so as to communicate with the target cell based on the new radio access network key after the handover is completed.
[0218] The cell information of the target cell may include at least one of the PCI and the frequency of the target cell. The activated radio access network key refers to the radio access network key currently in use.
[0219] If the target NCC is different from the NCC associated with the activated radio access network key, the terminal needs to first synchronize the NCC associated with the activated radio access network key to the target NCC and update the NH, and then vertically derive the new radio access network key based on the updated NH or the cell information of the first cell, so that after the handover is completed, it can communicate with the target cell based on the new radio access network key.
[0220] Optionally, when the target NCC is different from the NCC associated with the activated radio access network key, the terminal may first add 1 to the current NCC (NCC associated with the activated radio access network key) to obtain a first NCC. The NH corresponding to the first NCC can be obtained through K AMF The NH corresponding to the current NCC is calculated. If the first NCC is the same as the target NCC, it is considered that the NCC associated with the activated radio access network key is synchronized to the target NCC, and the updated NH is the NH corresponding to the first NCC. If the first NCC is different from the target NCC, the first NCC is added by 1 to obtain the second NCC. The NH corresponding to the second NCC can be obtained by K AMF The NH corresponding to the first NCC is calculated and the second NCC is judged to be the same as the target NCC, similar to the above steps, until the second NCC is synchronized with the target NCC and the corresponding NH is obtained.
[0221] For example, assuming that the current NCC of the terminal is 1, NH is NH1, and the NCC indicated by the first key information is 3, the terminal adds 1 to the NCC to obtain NCC=2. The NH2 corresponding to NCC=2 can be obtained by K AMF Calculated from NH1, NCC=2 is different from NCC=3, and NCC=3 is obtained by adding 1 to NCC, which is synchronized to the NCC indicated by the first key information. NH3 corresponding to NCC=3 can be obtained by K AMF and NH2, that is, the terminal finally synchronizes the NCC to NCC=3 and updates the NH to NH3.
[0222] The terminal can clearly perform horizontal key derivation or vertical key derivation according to the NCC information for indicating key derivation included in the first key information, and then obtain a new and accurate radio access network key to be able to communicate with the target cell to which it is switched.
[0223] In some embodiments of the present application, when the first key information includes information indicating whether the AMF key is changed, the method may further include the following steps:
[0224] If the first key information indicates that the AMF key is changed, the terminal updates the activated radio access network key according to the changed AMF key.
[0225] In an embodiment of the present application, if the first key information includes information for indicating whether the AMF key has changed, the terminal can determine whether the AMF key has changed based on the first key information. If the AMF key has changed, the terminal can update the activated radio access network key according to the changed AMF key, and the new radio access network key is associated with NCC=0, and communicate with the target cell based on the updated radio access network key.
[0226] The terminal can determine whether the AMF key has changed based on the information included in the first key information for indicating whether the AMF key has changed. If the AMF key has not changed, the key update can be performed based on other information included in the first key information. If the AMF key has changed, the key update is performed based on the changed AMF key, which helps to obtain a new and accurate radio access network key so that it can communicate with the target cell to which it is switched.
[0227] In some embodiments of the present application, when the first key information includes information indicating non-access stratum information submitted to an upper layer, the method may further include the following steps:
[0228] The terminal sends the non-access layer information indicated by the first key information to the upper layer.
[0229] In an embodiment of the present application, if the AMF key changes, the first key information may include information indicating the non-access layer information submitted to the upper layer. In this case, the terminal needs to submit the non-access layer information indicated by the first key information to the upper layer so that the upper layer of the terminal is aware of the change of the AMF key.
[0230] In some embodiments of the present application, if the first key information includes information for indicating security configuration information or information for indicating security algorithm configuration information, the terminal can use the activated wireless access network key to encrypt information according to the security configuration information or security algorithm configuration information indicated by the first key information when switching to the target cell and communicating with the target cell.
[0231] If the first key information includes information for indicating whether to use the primary key or the secondary key, the terminal may determine whether to use the primary key or the secondary key according to the instruction of the first key information.
[0232] In some embodiments of the present application, the first key information is provided by the base station or the base station centralized unit through radio resource control signaling, or the first key information is provided by the base station or the base station distributed unit through the control unit (MAC Control Element, MAC CE) of the media access control layer.
[0233] Before a terminal performs a handover to a target cell, it may receive first key information from a network device. The first key information is used by the terminal to update the key when performing the handover. If the network device is a base station or a centralized base station unit, the network device may send the first key information to the terminal via RRC signaling. Alternatively, if the network device is a base station or a distributed base station unit, the network device may send the first key information to the terminal via MAC CE. The network device sending the first key information to the terminal via RRC signaling or MAC CE facilitates efficient information transmission.
[0234] Optionally, the first key information may be configured via an RRC reconfiguration message or other RRC message configuration. For example, the RRC reconfiguration message carries the first key information and the configuration information of the candidate cell, or the RRC reconfiguration message carries the first key information without carrying the configuration information of the candidate cell.
[0235] In some embodiments of the present application, before the terminal performs handover to the target cell, the method may further include the following steps:
[0236] The terminal receives configuration information of candidate cells from the network side device.
[0237] In an embodiment of the present application, before a terminal performs a handover to a target cell, the network-side device may send the terminal configuration information of the terminal's candidate cells to the terminal, i.e., the terminal receives the configuration information of the candidate cells from the network-side device. Each candidate cell has corresponding configuration information. Based on the configuration information of the candidate cells, the terminal can obtain relevant information about the candidate cells, such as the candidate cell's time-frequency resources, the candidate cell's cell configuration identifier, the candidate cell type, the candidate cell's triggering conditions, etc.
[0238] The network-side device may send the candidate cell configuration information and the first key information to the terminal via the same signaling, or may send the candidate cell configuration information and the first key information to the terminal via different signaling. When sending via different signaling, there is no restriction on the order in which the candidate cell configuration information and the first key information are sent.
[0239] In some embodiments of the present application, the terminal obtains the target next hop link counter NCC, which may include the following steps:
[0240] Upon receiving the first key information, the terminal determines the target NCC according to the first key information;
[0241] In case the first key information is not received, the terminal determines the target NCC according to the first rule.
[0242] In an embodiment of the present application, the terminal can determine whether to determine the target NCC based on the first key information or the first rule based on whether the first key information is received. That is, if the first key information is received, the target NCC can be determined based on the first key information, and then, when the target cell is the first candidate cell, the key update is performed based on the target NCC. If the first key information is not received, the target NCC can be determined based on the first rule, and then, when the target cell is the first candidate cell, the key update is performed based on the target NCC.
[0243] Alternatively, the terminal may directly determine the target NCC according to the first rule, that is, regardless of whether the first key information is received, the terminal determines the target NCC according to the first rule.
[0244] Through the embodiments of the present application, it can be clarified whether the terminal determines the target NCC according to the first key information or the first rule, which helps to determine the accurate target NCC and improve the key update accuracy.
[0245] In some embodiments of the present application, when the target NCC is determined according to the first rule, the target NCC may include one of the following:
[0246] NCC associated with the activated radio access network key;
[0247] The NCC associated with the activated radio access network key is incremented by 1.
[0248] In the embodiment of the present application, the terminal may determine the target NCC according to the first rule. When the target cell is the first candidate cell, the terminal may perform a key update according to the target NCC during the handover to the target cell.
[0249] Optionally, the target NCC determined according to the first rule may be the NCC associated with the activated radio access network key, that is, the default NCC remains unchanged. The terminal may determine the activated radio access network key according to the target NCC, and then perform horizontal key derivation based on the activated radio access network key.
[0250] Optionally, the target NCC determined according to the first rule may be the NCC associated with the activated radio access network key plus 1, that is, NCC = NCC + 1. The terminal may generate NH for radio access network key derivation based on the target NCC, and then perform vertical key derivation based on the NH.
[0251] The terminal can accurately determine the target NCC according to the first rule, and then perform key update according to the target NCC, so as to communicate with the target cell based on the updated radio access network key.
[0252] In some embodiments of the present application, when the target NCC is determined according to the first rule, the method may further include at least one of the following:
[0253] The terminal determines that the AMF key has not been changed;
[0254] The terminal determines that there is no non-access stratum information to be submitted to the upper layer.
[0255] When the terminal determines the target NCC according to the first rule, it may default that the AMF key has not changed, or default that there is no non-access layer information submitted to the upper layer, so that the terminal can perform key update according to the target NCC.
[0256] In some embodiments of the present application, the method may further include the following steps:
[0257] If the configuration information of the first candidate cell includes the second key information, the terminal ignores the second key information.
[0258] In an embodiment of the present application, the terminal obtains the target NCC. If the target cell is the first candidate cell, during the handover process to the target cell, the terminal performs a key update based on the target NCC. If the configuration information of the first candidate cell includes second key information, the terminal can ignore the second key information and perform a key update based on the target NCC determined based on the first key information or the first rule. This effectively avoids misuse of the information based on which the key update is performed and ensures the accuracy of the key update.
[0259] The second key information may include at least one of the following:
[0260] Information indicating whether the master key is updated;
[0261] Information indicating whether the AMF key has been changed;
[0262] Information used to indicate the NCC for key derivation;
[0263] Information used to indicate non-access stratum information submitted to upper layers;
[0264] Information used to indicate security configuration information;
[0265] Information indicating whether to use a primary key or a secondary key;
[0266] Information used to indicate security algorithm configuration information.
[0267] In some embodiments of the present application, the method may further include the following steps:
[0268] When the first condition is met, the terminal determines that handover to the target cell is required;
[0269] The first condition includes at least one of the following:
[0270] receiving a first layer 1 or layer 2 triggered mobility LTM handover command, where the first LTM handover command carries an identifier of configuration information of the first cell or the first cell group;
[0271] A conditional handover execution condition for the first cell or the first cell group is met;
[0272] A conditional LTM execution condition for the first cell or the first cell group is met;
[0273] After a Radio Link Failure (RLF) or Handover Failure (HOF), cell selection is performed, a first cell or a first cell group is selected, and fast recovery based on conditional handover is performed;
[0274] After a radio link failure or a handover failure, cell selection is performed, a first cell or a first cell group is selected, and LTM-based fast recovery is performed.
[0275] When at least one of the above first conditions is met, the terminal can perform handover to the target cell to ensure communication quality.
[0276] In some embodiments of the present application, the candidate cells of the terminal may include conditional handover candidate cells or LTM candidate cells.
[0277] In some embodiments of the present application, the method may further include the following steps:
[0278] When the target cell is the second candidate cell, the terminal does not perform key update and Packet Data Convergence Protocol PDCP re-establishment;
[0279] The second candidate cell is associated with the same identifier as the source cell.
[0280] If the identifier associated with the second candidate cell is the same as the identifier associated with the source cell, it means that the second candidate cell and the source cell are cells in the same CU. If the target cell is the second candidate cell, the terminal does not need to perform key update and PDCP reconstruction during the process of switching to the target cell, and can continue to use the activated radio access network key to communicate with the target cell.
[0281] For ease of understanding, the technical solutions provided in the embodiments of the present application are described below through specific examples.
[0282] Example 1: The network device indicates the key information of the inter-CU candidate cell
[0283] 1) The UE receives configuration information of candidate cells provided by the network side device. Each candidate cell is associated with an identifier, which is used to indicate whether key update and PDCP re-establishment are required when the UE switches to the candidate cell;
[0284] 2) The UE receives the first key information for the next handover provided by the network side device;
[0285] If the network-side device includes a gNB or a gNB-CU, the first key information may be provided via RRC signaling. If the network-side device includes a gNB or a gNB-DU, the first key information may be provided via MAC CE.
[0286] The first key information includes at least one of the following:
[0287] masterKeyUpdate, used to indicate whether the master key is updated;
[0288] keySetChangeIndicator, used to indicate K AMF Whether it has changed;
[0289] nextHopChainingCount, used to indicate the NCC for key derivation;
[0290] nas-Container, used to indicate NAS information delivered to the upper layer;
[0291] securityConfig, which indicates the security configuration and the keys used;
[0292] securityAlgorithmConfig, used to indicate security algorithm configuration;
[0293] The execution order of the above steps 1) and 2) is not limited, and may be sent to the terminal through the same signaling or different signaling;
[0294] 3) The UE switches to the target cell when one of the following conditions is met:
[0295] Receive an LTM handover command containing the target cell's configuration information ID;
[0296] Evaluate that the CHO execution conditions of the target cell are met;
[0297] Evaluate the target cell's conditional LTM execution conditions to be met;
[0298] After RLF or HOF occurs, cell selection is performed, the target cell (CHO candidate cell) is selected, and conditional handover based fast recovery (CHO based fast recovery) is performed;
[0299] After an RLF or HOF occurs, cell selection is performed, the target cell (LTM candidate cell) is selected, and LTM-based fast recovery is performed.
[0300] 4) The UE determines whether the identifiers associated with the target cell and the source cell are the same:
[0301] If they are the same, the UE does not perform key update and PDCP re-establishment;
[0302] If they are different, the UE performs PDCP reestablishment and derives or updates the key according to the first key information indicated in step 2); if the configuration information of the candidate cell includes the second key information (MasterKeyUpdate), the second key information in the configuration information of the candidate cell is ignored.
[0303] Example 2: The default NCC of the terminal remains unchanged, keySetChangeIndicator is false, and nas-Container is not carried.
[0304] 1) Same as Example 1;
[0305] 2) (Optional) Same as Example 1;
[0306] 3) Same as Example 1;
[0307] 4) The UE determines whether the identifiers associated with the target cell and the source cell are the same:
[0308] If they are the same, the UE does not perform key update and PDCP re-establishment;
[0309] If different, the UE performs PDCP re-establishment and:
[0310] If the first key information provided by the network side device is not received, the UE defaults to the NCC unchanged (i.e., the same as the activated K gNB The associated NCC is the same), keySetChangeIndicator is false, and no nas-Container is carried; the UE gNB Perform horizontal key derivation;
[0311] If the first key information provided by the network side device is received, the UE derives or updates the key according to the first key information indicated in step 2);
[0312] If the configuration information of the candidate cell includes the second key information (MasterKeyUpdate), the second key information in the configuration information of the candidate cell is ignored.
[0313] Example 3: The terminal defaults to NCC+1, keySetChangeIndicator is false, and nas-Container is not carried.
[0314] 1) Same as Example 1;
[0315] 2) (Optional) Same as Example 1;
[0316] 3) Same as Example 1;
[0317] 4) The UE determines whether the identifiers associated with the target cell and the source cell are the same:
[0318] If they are the same, the UE does not perform key update and PDCP re-establishment;
[0319] If different, the UE performs PDCP re-establishment and:
[0320] If the first key information provided by the network-side device is not received, the UE defaults to NCC = NCC + 1, keySetChangeIndicator is false, and no nas-Container is carried; the UE generates NH based on the updated NCC and performs vertical key derivation based on NH;
[0321] If the first key information provided by the network side device is received, the UE derives or updates the key according to the first key information indicated in step 2);
[0322] If the configuration information of the candidate cell includes the second key information (MasterKeyUpdate), the second key information in the configuration information of the candidate cell is ignored.
[0323] Example 4: Signaling structure of the first key information
[0324] For the first key information indication in step 2) of the above examples 1, 2, and 3, taking carrying NCC as an example, the following RRC signaling indication can be used.
[0325] For LTM handover, the first key information is information independent of the configuration information of the LTM candidate cell.
[0326] The LTM configuration information elements (IEs) are as follows:
[0327] For CHO handover, the first key information is information independent of the configuration information of the CHO candidate cell.
[0328] The conditional reconfiguration information elements are as follows:
[0329] The embodiment of the present application optimizes the key information indication method of the candidate cell during the switching process, provides a key update method, helps to reduce signaling overhead, and reduces the terminal processing load and processing delay.
[0330] Corresponding to the above method embodiment, the embodiment of the present application further provides a key update method, as shown in FIG9 , which may include the following steps:
[0331] S910: The network device sends first key information to the terminal;
[0332] Among them, the first key information corresponds to all candidate cells of the terminal, the first key information is used to determine the target next hop link counter NCC, the target NCC is used for key update when the target cell of the terminal is the first candidate cell, and the first candidate cell is associated with a different identifier from the source cell.
[0333] By applying the method provided in the embodiment of the present application, the network side device sends first password information to the terminal. The first key information corresponds to all candidate cells of the terminal and is used to determine the target NCC, so that the terminal updates the key according to the target NCC when performing a switch to the first candidate cell. When the network side device reconfigures the key, it is not necessary to reconfigure the configuration information of each candidate cell, which can effectively reduce the signaling overhead. Without reconfiguring the configuration information of each candidate cell, the terminal does not need to re-decode the configuration information, which can reduce the terminal processing load and processing delay.
[0334] In some embodiments of the present application, the first key information includes at least one of the following:
[0335] Information indicating whether the master key is updated;
[0336] Information used to indicate whether the access mobility management function AMF key has changed;
[0337] Information used to indicate the next hop link counter NCC for key derivation;
[0338] Information used to indicate non-access stratum information submitted to upper layers;
[0339] Information used to indicate security configuration information;
[0340] Information indicating whether to use a primary key or a secondary key;
[0341] Information used to indicate security algorithm configuration information.
[0342] In some embodiments of the present application, the network side device sends the first key information to the terminal, including:
[0343] In the case where the network side device is a base station or a base station centralized unit, the network side device sends the first key information to the terminal through radio resource control signaling;
[0344] Alternatively, when the network side device is a base station or a base station distributed unit, the network side device sends the first key information to the terminal through a control unit of a media access control layer.
[0345] In some embodiments of the present application, the method further includes at least one of the following:
[0346] The network side device sends the configuration information of the candidate cell to the terminal.
[0347] In some embodiments of the present application, the candidate cell includes a conditional handover candidate cell or a layer 1 or layer 2 triggered mobility LTM candidate cell.
[0348] The key update method provided in the embodiment of the present application can implement the various processes implemented in the method embodiment shown in Figure 8 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0349] The key updating method provided in the embodiment of the present application can be executed by a key updating device. In the embodiment of the present application, the key updating device provided in the embodiment of the present application is described by taking the key updating method executed by the key updating device as an example.
[0350] As shown in FIG10 , the key updating apparatus 1000 includes the following modules:
[0351] An acquisition module 1010 is configured to acquire a target next hop link counter NCC, where the target NCC is determined according to first key information corresponding to all candidate cells of the terminal; or the target NCC is determined according to a first rule;
[0352] The updating module 1020 is configured to perform a key update according to the target NCC when the target cell is the first candidate cell, wherein the first candidate cell is associated with a different identifier from the source cell.
[0353] By applying the device provided in the embodiment of the present application, a target NCC is obtained. The target NCC can be determined based on the first key information, or can be determined based on the first rule. When the target cell is the first candidate cell, a key update is performed based on the target NCC. The first key information corresponds to all candidate cells of the terminal. The target NCC required for key update when switching to the first candidate cell can be obtained through the first key information or the first rule. When the network side device reconfigures the key, it is not necessary to reconfigure the configuration information of each candidate cell, which can effectively reduce the signaling overhead. Without reconfiguring the configuration information of each candidate cell, the terminal does not need to re-decode the configuration information, which can reduce the terminal processing load and processing delay.
[0354] In some embodiments of the present application, the update module 1020 is further configured to:
[0355] When the target cell is the second candidate cell, key update and Packet Data Convergence Protocol (PDCP) re-establishment are not performed;
[0356] The second candidate cell is associated with the same identifier as the source cell.
[0357] In some embodiments of the present application, the acquisition module 1010 is configured to:
[0358] Upon receiving the first key information, determining a target NCC according to the first key information;
[0359] In the case that the first key information is not received, the target NCC is determined according to the first rule.
[0360] In some embodiments of the present application, the first key information includes at least one of the following:
[0361] Information indicating whether the master key is updated;
[0362] Information used to indicate whether the access mobility management function AMF key has changed;
[0363] Information used to indicate the NCC for key derivation;
[0364] Information used to indicate non-access stratum information submitted to upper layers;
[0365] Information used to indicate security configuration information;
[0366] Information indicating whether to use a primary key or a secondary key;
[0367] Information used to indicate security algorithm configuration information.
[0368] In some embodiments of the present application, when the first key information includes information indicating an NCC for key derivation, the target NCC is the NCC indicated by the first key information, and the updating module 1020 is configured to:
[0369] In the case where the target NCC is the same as the NCC associated with the activated radio access network key, a new radio access network key is horizontally derived based on the activated radio access network key or the cell information of the target cell;
[0370] When the target NCC is different from the NCC associated with the activated radio access network key, the NCC associated with the activated radio access network key is synchronized to the target NCC, and the next-hop NH is updated. According to the updated NH or the cell information of the target cell, a new radio access network key is vertically derived.
[0371] In some embodiments of the present application, when the first key information includes information indicating whether the AMF key is changed, the update module 1020 is further configured to:
[0372] When the first key information indicates that the AMF key has been changed, the activated radio access network key is updated according to the changed AMF key.
[0373] In some embodiments of the present application, when the first key information includes information indicating non-access stratum information to be delivered to an upper layer, the key updating apparatus 1000 further includes a delivering module configured to:
[0374] The non-access layer information indicated by the first key information is sent to an upper layer.
[0375] In some embodiments of the present application, the first key information is provided by the base station or the base station centralized unit through radio resource control signaling;
[0376] Alternatively, the first key information is provided by the base station or the base station distributed unit through a control unit of a media access control layer.
[0377] In some embodiments of the present application, when the target NCC is determined according to the first rule, the target NCC includes one of the following:
[0378] NCC associated with the activated radio access network key;
[0379] The NCC associated with the activated radio access network key is incremented by 1.
[0380] In some embodiments of the present application, when the target NCC includes an NCC associated with an activated radio access network key, the updating module 1020 is configured to:
[0381] Determine the activated radio access network key based on the target NCC;
[0382] Perform horizontal key derivation based on the activated radio access network key.
[0383] In some embodiments of the present application, when the target NCC includes an NCC associated with an activated radio access network key plus 1, the updating module 1020 is configured to:
[0384] Generate NH for radio access network key derivation according to the target NCC, and perform vertical key derivation according to NH.
[0385] In some embodiments of the present application, when the target NCC is determined according to the first rule, the key updating apparatus 1000 further includes a determination module configured to perform at least one of the following:
[0386] Ensure that the AMF key has not changed; ensure that there is no non-access layer information submitted to the upper layer.
[0387] In some embodiments of the present application, the update module 1020 is further configured to:
[0388] When the configuration information of the first candidate cell includes the second key information, ignoring the second key information;
[0389] The second key information includes at least one of the following:
[0390] Information indicating whether the master key is updated;
[0391] Information indicating whether the AMF key has been changed;
[0392] Information used to indicate the next hop link counter NCC for key derivation;
[0393] Information used to indicate non-access stratum information submitted to upper layers;
[0394] Information used to indicate security configuration information;
[0395] Information indicating whether to use a primary key or a secondary key;
[0396] Information used to indicate security algorithm configuration information.
[0397] In some embodiments of the present application, the key updating apparatus 1000 further includes a switching module configured to:
[0398] If the first condition is met, determining that switching to the target cell is required;
[0399] The first condition includes at least one of the following:
[0400] receiving a first layer 1 or layer 2 triggered mobility LTM handover command, where the first LTM handover command carries an identifier of configuration information of the first cell or the first cell group;
[0401] A conditional handover execution condition for the first cell or the first cell group is met;
[0402] A conditional LTM execution condition for the first cell or the first cell group is met;
[0403] After a radio link failure or a handover failure, performing cell selection, selecting a first cell or a first cell group, and performing fast recovery based on conditional handover;
[0404] After a radio link failure or a handover failure, cell selection is performed, a first cell or a first cell group is selected, and LTM-based fast recovery is performed.
[0405] The key update device in the embodiments of the present application can be an electronic device, such as an electronic device with an operating system, or a component of an electronic device, such as an integrated circuit or chip. The electronic device can be a terminal or other device other than a terminal. For example, the terminal can include but is not limited to the types of terminal 11 listed above, and other devices can include servers, network attached storage (NAS), etc., which are not specifically limited in the embodiments of the present application.
[0406] The key updating device 1000 provided in the embodiment of the present application can implement each process implemented by the method embodiment shown in Figure 8 and achieve the same technical effect. To avoid repetition, it will not be described here.
[0407] As shown in FIG11 , the key updating apparatus 1100 includes the following modules:
[0408] The sending module 1110 is configured to send the first key information to the terminal;
[0409] Among them, the first key information corresponds to all candidate cells of the terminal, the first key information is used to determine the target next hop link counter NCC, the target NCC is used for key update when the target cell of the terminal is the first candidate cell, and the first candidate cell is associated with a different identifier from the source cell.
[0410] By using the device provided in the embodiment of the present application, first password information is sent to the terminal. The first key information corresponds to all candidate cells of the terminal and is used to determine the target NCC, so that the terminal updates the key according to the target NCC when performing a switch to the first candidate cell. When reconfiguring the key, there is no need to reconfigure the configuration information of each candidate cell, which can effectively reduce the signaling overhead. Without reconfiguring the configuration information of each candidate cell, the terminal does not need to re-decode the configuration information, which can reduce the terminal processing load and processing delay.
[0411] In some embodiments of the present application, the first key information includes at least one of the following:
[0412] Information indicating whether the master key is updated;
[0413] Information used to indicate whether the access mobility management function AMF key has changed;
[0414] Information used to indicate the next hop link counter NCC for key derivation;
[0415] Information used to indicate non-access stratum information submitted to upper layers;
[0416] Information used to indicate security configuration information;
[0417] Information indicating whether to use a primary key or a secondary key;
[0418] Information used to indicate security algorithm configuration information.
[0419] In some embodiments of the present application, the sending module 1110 is configured to:
[0420] When the network side device is a base station or a base station centralized unit, the first key information is sent to the terminal through wireless resource control signaling; or, when the network side device is a base station or a base station distributed unit, the first key information is sent to the terminal through the control unit of the media access control layer.
[0421] The key updating device 1100 provided in the embodiment of the present application can implement each process implemented by the method embodiment shown in Figure 9 and achieve the same technical effect. To avoid repetition, it will not be described here.
[0422] As shown in Figure 12, an embodiment of the present application further provides a communication device 1200, including a processor 1201 and a memory 1202. The memory 1202 stores a program or instruction that can be run on the processor 1201. For example, when the communication device 1200 is a terminal, the program or instruction, when executed by the processor 1201, implements the various steps of the method embodiment shown in Figure 8 above, and can achieve the same technical effect. When the communication device 1200 is a network-side device, the program or instruction, when executed by the processor 1201, implements the various steps of the method embodiment shown in Figure 9 above, and can achieve the same technical effect. To avoid repetition, they are not repeated here.
[0423] The present application also provides a terminal including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps of the method embodiment shown in FIG8 . This terminal embodiment corresponds to the aforementioned terminal-side method embodiment, and each implementation process and implementation method of the aforementioned method embodiment is applicable to this terminal embodiment and can achieve the same technical effects. Specifically, FIG13 is a schematic diagram of the structure of a terminal implementing an embodiment of the present application.
[0424] The terminal 1300 includes but is not limited to: a radio frequency unit 1301, a network module 1302, an audio output unit 1303, an input unit 1304, a sensor 1305, a display unit 1306, a user input unit 1307, an interface unit 1308, a memory 1309 and at least some of the components of the processor 1310.
[0425] Those skilled in the art will appreciate that the terminal 1300 may also include a power supply (such as a battery) to power various components. The power supply may be logically connected to the processor 1310 via a power management system, thereby enabling the power management system to manage charging, discharging, and power consumption. The terminal structure shown in FIG13 does not limit the terminal. The terminal may include more or fewer components than shown, or may combine certain components, or have different component arrangements, which will not be described in detail here.
[0426] It should be understood that in an embodiment of the present application, the input unit 1304 may include a graphics processing unit (GPU) 13041 and a microphone 13042, and the graphics processor 13041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 1306 may include a display panel 13061, and the display panel 13061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 1307 includes a touch panel 13071 and at least one of the other input devices 13072. The touch panel 13071 is also called a touch screen. The touch panel 13071 may include two parts: a touch detection device and a touch controller. Other input devices 13072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be repeated here.
[0427] In the embodiment of the present application, after receiving downlink data from a network-side device, the RF unit 1301 may transmit the data to the processor 1310 for processing. Furthermore, the RF unit 1301 may send uplink data to the network-side device. Typically, the RF unit 1301 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, and the like.
[0428] The memory 1309 can be used to store software programs or instructions and various data. The memory 1309 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 1309 may include a volatile memory or a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DRRAM). The memory 1309 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.
[0429] Processor 1310 may include one or more processing units. Optionally, processor 1310 integrates an application processor and a modem processor. The application processor primarily handles operations related to the operating system, user interface, and application programs, while the modem processor primarily processes wireless communication signals, such as a baseband processor. It is understood that the modem processor may not be integrated into processor 1310.
[0430] It can be understood that the implementation process of each implementation method mentioned in this embodiment can refer to the relevant description of the method embodiment shown in Figure 8, and achieve the same or corresponding technical effects. To avoid repetition, it will not be repeated here.
[0431] The present application also provides a network-side device, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps of the method embodiment shown in FIG9 . This network-side device embodiment corresponds to the aforementioned network-side device method embodiment, and each implementation process and implementation method of the aforementioned method embodiment are applicable to this network-side device embodiment and can achieve the same technical effects.
[0432] Specifically, embodiments of the present application also provide a network-side device. As shown in Figure 14, network-side device 1400 includes an antenna 1401, a radio frequency device 1402, a baseband device 1403, a processor 1404, and a memory 1405. Antenna 1401 is connected to radio frequency device 1402. In the uplink direction, radio frequency device 1402 receives information via antenna 1401 and sends the received information to baseband device 1403 for processing. In the downlink direction, baseband device 1403 processes the information to be transmitted and sends it to radio frequency device 1402. Radio frequency device 1402 processes the received information and then sends it through antenna 1401.
[0433] The method executed by the network-side device in the above embodiment may be implemented in the baseband device 1403 , which includes a baseband processor.
[0434] The baseband device 1403 may include, for example, at least one baseband board, on which multiple chips are arranged, as shown in Figure 14, one of which is a baseband processor, for example, which is connected to the memory 1405 through a bus interface to call the program in the memory 1405 and execute the network side device operations shown in the above method embodiment.
[0435] The network side device may further include a network interface 1406 , which is, for example, a Common Public Radio Interface (CPRI).
[0436] Specifically, the network side device 1400 of the embodiment of the present application also includes: instructions or programs stored in the memory 1405 and executable on the processor 1404. The processor 1404 calls the instructions or programs in the memory 1405 to execute the methods executed by the modules shown in FIG11 and achieve the same technical effect. To avoid repetition, they will not be elaborated here.
[0437] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned key update method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0438] The processor is the processor in the terminal described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk. In some examples, the readable storage medium may be a non-transitory readable storage medium.
[0439] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned key update method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0440] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
[0441] An embodiment of the present application further provides a computer program / program product, which is stored in a storage medium. The computer program / program product is executed by at least one processor to implement the various processes of the above-mentioned key update method embodiment and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0442] An embodiment of the present application also provides a wireless communication system, including: a terminal and a network-side device, wherein the terminal can be used to execute the steps of the method shown in Figure 8 above, and the network-side device can be used to execute the steps of the method shown in Figure 9 above.
[0443] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted or combined. In addition, the features described with reference to certain examples may be combined in other examples.
[0444] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of a computer software product plus a necessary general-purpose hardware platform, or of course, by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes a number of instructions for enabling a terminal or network-side device to execute the methods described in each embodiment of the present application.
[0445] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms of implementation methods without departing from the purpose of this application and the scope of protection of the claims. These implementation methods are all within the protection of this application.
Claims
1. A key updating method, wherein: include: The terminal obtains a target next hop link counter NCC, wherein the target NCC is determined according to first key information, and the first key information corresponds to all candidate cells of the terminal; or, the target NCC is determined according to a first rule; When the target cell is a first candidate cell, the terminal performs key update according to the target NCC, wherein the first candidate cell is associated with a different identifier from the source cell.
2. The method according to claim 1, wherein: The method further comprises: When the target cell is the second candidate cell, the terminal does not perform key update and packet data convergence protocol PDCP reestablishment; The second candidate cell is associated with the same identifier as the source cell.
3. The method according to claim 1 or 2, wherein: The terminal obtains a target next hop link counter NCC, including: Upon receiving the first key information, the terminal determines the target NCC according to the first key information; In case the first key information is not received, the terminal determines the target NCC according to the first rule.
4. The method according to any one of claims 1 to 3, wherein: The first key information includes at least one of the following: Information indicating whether the master key is updated; Information used to indicate whether the access mobility management function AMF key has been changed; Information used to indicate the NCC for key derivation; Information used to indicate non-access stratum information delivered to an upper layer; Information used to indicate security configuration information; Information indicating whether a primary key or a secondary key is used; Information used to indicate security algorithm configuration information.
5. The method according to claim 4, wherein: In a case where the first key information includes information indicating an NCC for key derivation, the target NCC is the NCC indicated by the first key information, and the terminal performs key update according to the target NCC, including: If the target NCC is the same as the NCC associated with the activated radio access network key, the terminal horizontally derives a new radio access network key according to the activated radio access network key or the cell information of the target cell; If the target NCC is different from the NCC associated with the activated radio access network key, the terminal synchronizes the NCC associated with the activated radio access network key to the target NCC, updates the next hop NH, and vertically derives a new radio access network key based on the updated NH or the cell information of the target cell.
6. The method according to claim 4 or 5, wherein: In a case where the first key information includes information for indicating whether the AMF key is changed, the method further includes: If the first key information indicates that the AMF key is changed, the terminal updates the activated radio access network key according to the changed AMF key.
7. The method according to any one of claims 4 to 6, wherein: In a case where the first key information includes information for indicating non-access stratum information delivered to an upper layer, the method further includes: The terminal sends the non-access layer information indicated by the first key information to an upper layer.
8. The method according to any one of claims 1 to 7, wherein: The first key information is provided by the base station or the base station centralized unit through radio resource control signaling; Alternatively, the first key information is provided by the base station or the base station distributed unit through a control unit of a media access control layer.
9. The method according to any one of claims 1 to 8, wherein: In the case where the target NCC is determined according to the first rule, the target NCC includes one of the following: NCC associated with the activated radio access network key; The NCC associated with the activated radio access network key is incremented by 1.
10. The method according to claim 9, wherein: In a case where the target NCC includes an activated radio access network key-associated NCC, the terminal performs key update according to the target NCC, including: The terminal determines, according to the target NCC, an activated radio access network key; The terminal performs horizontal key derivation based on the activated radio access network key.
11. The method according to claim 9, wherein: In a case where the target NCC includes an NCC associated with an activated radio access network key plus 1, the terminal performs key update according to the target NCC, including: The terminal generates a NH for radio access network key derivation according to the target NCC, and performs vertical key derivation according to the NH.
12. The method according to any one of claims 1 to 11, wherein: In the case where the target NCC is determined according to the first rule, the method further includes at least one of the following: The terminal determines that the AMF key has not been changed; The terminal determines that there is no non-access stratum information to be delivered to an upper layer.
13. The method according to any one of claims 1 to 12, wherein: The method further comprises: If the configuration information of the first candidate cell includes second key information, the terminal ignores the second key information; The second key information includes at least one of the following: Information indicating whether the master key is updated; Information used to indicate whether the AMF key has been changed; Information used to indicate the NCC for key derivation; Information used to indicate non-access stratum information delivered to an upper layer; Information used to indicate security configuration information; Information indicating whether a primary key or a secondary key is used; Information used to indicate security algorithm configuration information.
14. The method according to any one of claims 1 to 13, wherein: The method further comprises: When the first condition is met, the terminal determines that it needs to switch to the target cell; The first condition includes at least one of the following: Receiving a first layer 1 or layer 2 triggered mobility LTM handover command, the first LTM handover command carrying an identifier of the configuration information of the target cell; Satisfying the conditional handover execution condition of the target cell; Satisfying the conditional LTM execution condition of the target cell; After a radio link failure or a handover failure, performing cell selection, selecting the target cell, and performing fast recovery based on conditional handover; After a radio link failure or a handover failure, a cell selection is performed, the target cell is selected, and a fast recovery based on LTM is performed.
15. A key updating method, wherein: include: The network side device sends the first key information to the terminal; Among them, the first key information corresponds to all candidate cells of the terminal, the first key information is used to determine the target next hop link counter NCC, the target NCC is used for key update when the target cell of the terminal is the first candidate cell, and the first candidate cell is associated with a different identifier from the source cell.
16. The method according to claim 15, wherein: The first key information includes at least one of the following: Information indicating whether the master key is updated; Information used to indicate whether the access mobility management function AMF key has been changed; Information used to indicate the NCC for key derivation; Information used to indicate non-access stratum information delivered to an upper layer; Information used to indicate security configuration information; Information indicating whether a primary key or a secondary key is used; Information used to indicate security algorithm configuration information.
17. The method according to claim 15 or 16, wherein: The network side device sends first key information to the terminal, including: In the case where the network side device is a base station or a base station centralized unit, the network side device sends the first key information to the terminal through radio resource control signaling; Or, in the case where the network side device is a base station or a base station distributed unit, the network side device sends the first key information to the terminal through a control unit of a media access control layer.
18. A key updating device, wherein: include: An acquisition module, configured to acquire a target next hop link counter NCC, wherein the target NCC is determined according to first key information, and the first key information corresponds to all candidate cells of the terminal; or, the target NCC is determined according to a first rule; An updating module is used to perform key update according to the target NCC when the target cell is a first candidate cell, wherein the first candidate cell is associated with a different identifier from the source cell.
19. The device according to claim 18, wherein: The update module is further used for: When the target cell is the second candidate cell, key update and packet data convergence protocol PDCP reestablishment are not performed; The second candidate cell is associated with the same identifier as the source cell.
20. The device according to claim 18 or 19, wherein: The acquisition module is used to: Upon receiving the first key information, determining the target NCC according to the first key information; In case the first key information is not received, the target NCC is determined according to the first rule.
21. The device according to any one of claims 18 to 20, wherein: The first key information includes at least one of the following: Information indicating whether the master key is updated; Information used to indicate whether the access mobility management function AMF key has been changed; Information used to indicate the NCC for key derivation; Information used to indicate non-access stratum information delivered to an upper layer; Information used to indicate security configuration information; Information indicating whether a primary key or a secondary key is used; Information used to indicate security algorithm configuration information.
22. The device according to claim 21, wherein In the case where the first key information includes information indicating an NCC for key derivation, the target NCC is the NCC indicated by the first key information, and the updating module is configured to: In a case where the target NCC is the same as the NCC associated with the activated radio access network key, horizontally deriving a new radio access network key according to the activated radio access network key or the cell information of the target cell; When the target NCC is different from the NCC associated with the activated radio access network key, the NCC associated with the activated radio access network key is synchronized to the target NCC, and the next hop NH is updated, and a new radio access network key is vertically derived based on the updated NH or the cell information of the target cell.
23. The device according to claim 21 or 22, wherein: In a case where the first key information includes information for indicating whether the AMF key is changed, the updating module is further configured to: When the first key information indicates that the AMF key has been changed, the activated radio access network key is updated according to the changed AMF key.
24. The device according to any one of claims 18 to 23, wherein: In the case where the target NCC is determined according to the first rule, the target NCC includes one of the following: NCC associated with the activated radio access network key; The NCC associated with the activated radio access network key is incremented by 1.
25. The device according to claim 24, wherein: In the case where the target NCC includes an NCC associated with an activated radio access network key, the updating module is configured to: Determining an activated radio access network key according to the target NCC; A horizontal key derivation is performed based on the activated radio access network key.
26. The device according to claim 24, wherein: In the case where the target NCC includes an NCC associated with an activated radio access network key plus 1, the updating module is configured to: A NH for radio access network key derivation is generated according to the target NCC, and vertical key derivation is performed according to the NH.
27. A key updating device, wherein: include: A sending module, used for sending first key information to a terminal; Among them, the first key information corresponds to all candidate cells of the terminal, the first key information is used to determine the target next hop link counter NCC, the target NCC is used for key update when the target cell of the terminal is the first candidate cell, and the first candidate cell is associated with a different identifier from the source cell.
28. A terminal, wherein: The method comprises a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the key updating method according to any one of claims 1 to 14 are implemented.
29. A network side device, wherein: The method comprises a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the key updating method according to any one of claims 15 to 17 are implemented.
30. A readable storage medium, wherein: The readable storage medium stores a program or instruction, and when the program or instruction is executed by the processor, the steps of the key update method according to any one of claims 1 to 14 are implemented, or the steps of the key update method according to any one of claims 15 to 17 are implemented.
Citation Information
Patent Citations
Method for updating and generating air interface key and wireless access system
CN101867924A
Communication methods, base stations and terminal equipment
CN109309918A
Key updating method, network equipment and terminal
CN110830996A
Switching method, network equipment, user equipment and communication system
CN113938970A
Method, Apparatus and System for Processing Security Key when Reestablishing Radio Resource Control (RRC) Connection
US20120129499A1