Interaction method, apparatus and system, terminal and network side device

The terminal receives and processes encryption and integrity protection information in the target wireless signaling, generates security requirements for security processing, solves the problem of large delay in small data transmission and realizes efficient and secure small data transmission.

WO2025119355A1PCT designated stage expired Publication Date: 2025-06-12VIVO MOBILE COMM CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/137563
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-07
Filing Date
2024-12-06
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

In the prior art, the transmission delay of small data is large, and the terminal and network-side equipment need to conduct multiple message interactions to complete small data interactions.

Method used

Receive target wireless signaling through the terminal, including encrypted information and integrity protection information, perform operations such as decryption, confidentiality processing and integrity verification, and generate security requirements based on the derived information to perform secure processing and data transmission.

Benefits of technology

It reduces the data transmission delay, improves the efficiency and security of small data transmission, and reduces the number of message interactions between the terminal and the network-side device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024137563_12062025_PF_FP_ABST
    Figure CN2024137563_12062025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of communications, and discloses an interaction method, apparatus and system, a terminal and a network side device. The interaction method of an embodiment of the present application comprises: a terminal receiving target wireless signaling, wherein the target wireless signaling comprises first identification information and first target information, and the first target information comprises at least one of encrypted information and integrity protection information; and when the terminal is associated with the first identification information, executing at least one of the following: decrypting the encrypted information, performing confidentiality processing on the encrypted information, performing confidentiality processing on the first target information, checking or verifying the integrity protection information, performing security processing on the first target information, performing integrity checking or integrity processing on the first target information, performing integrity checking or integrity processing on the basis of the integrity protection information, generating a second security element, sending first information to an access network node, sending to an access network node first information carrying a third security parameter, and receiving second information from an access network node.
Need to check novelty before this filing date? Find Prior Art

Description

Interaction method, device, system, terminal and network side equipment

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on December 7, 2023, with application number 202311673987.9 and invention name “Interactive method, device, system, terminal and network side equipment”, the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application belongs to the field of communication technology, and specifically relates to an interaction method, apparatus, system, terminal and network-side equipment. Background Art

[0004] With the development of communication technology, in order to improve the efficiency of data transmission in communication systems, terminals can transmit and receive terminal-dedicated data (UE-dedicated data) with network-side devices without entering a connected state, i.e., small data transmission (SDT). Currently, small data transmission mainly includes mobile-initiated small data transmission (MO-SDT) transmitted on the physical uplink shared channel (PUSCH) of the terminal-triggered uplink message 3 (Msg3) or configured grant (CG) or mobile-terminated small data transmission (MT-SDT) triggered by the downlink. In this way, the terminal and the network-side device still need to exchange messages multiple times to complete the small data exchange, which will result in a large delay in the small data transmission. Summary of the Invention

[0005] The embodiments of the present application provide an interaction method, apparatus, system, terminal, and network-side equipment, which can solve the problem of long delay in small data transmission.

[0006] In a first aspect, an interaction method is provided, comprising:

[0007] The terminal receives target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information;

[0008] When the terminal is associated with the first identification information, the terminal performs at least one of the following:

[0009] performing a first operation based on a first safety requirement;

[0010] Second operation;

[0011] The first operation includes at least one of the following:

[0012] decrypting the encrypted information;

[0013] Performing confidentiality processing on the encrypted information;

[0014] Performing confidentiality processing on the first target information;

[0015] Checking or verifying the integrity protection information;

[0016] performing secure processing on the first target information;

[0017] performing integrity checking or integrity processing on the first target information;

[0018] performing, based on the integrity protection information, integrity checking or integrity processing on at least one of the following: the first target information, part of the first target information, and the decryption result;

[0019] The second operation includes at least one of the following:

[0020] generating a second security requirement based on fourth derived information and at least one of the first security requirement;

[0021] Sending first information to the access network node;

[0022] Sending first information carrying a third security parameter to the access network node;

[0023] receiving second information from the access network node;

[0024] Among them, the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a key and a secret stream; the first derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, and a key in the terminal context; the fourth derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in the terminal context, and the third security parameter; the second security requirement includes at least one of a key and a secret stream.

[0025] In a second aspect, an interaction method is provided, comprising:

[0026] The access network node sends target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information;

[0027] The encryption information and integrity protection information are generated based on a first security requirement, and the first security requirement includes at least one of a secret key and a secret stream.

[0028] A third aspect provides an interaction method, comprising:

[0029] The core network node sends third information or target data to the access network node, where the third information includes the second identification information and the second target information;

[0030] The second target information includes at least one of the following:

[0031] First safety requirement or third safety requirement;

[0032] First algorithm information;

[0033] Second safety parameter;

[0034] Second security assistance information, where the second security assistance information includes information in the terminal core network context;

[0035] Among them, the first algorithm information packet security requirement derivation algorithm, confidentiality algorithm, and integrity algorithm; the first security requirement includes at least one of a secret key and a secret stream, the third security requirement includes at least one of a secret key and a secret stream, and the second identification information indicates the terminal, or is generated by the terminal identification, or indicates a group of terminals.

[0036] A fourth aspect provides an interaction method, comprising:

[0037] The access network node sends target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information, where the encryption information and integrity protection information are generated based on the first security requirement;

[0038] The terminal receives the target wireless signaling;

[0039] When the terminal is associated with the first identification information, the terminal performs at least one of the following:

[0040] performing a first operation based on a first safety requirement;

[0041] Second operation;

[0042] The first operation includes at least one of the following:

[0043] decrypting the encrypted information;

[0044] Performing confidentiality processing on the encrypted information;

[0045] Performing confidentiality processing on the first target information;

[0046] Checking or verifying the integrity protection information;

[0047] performing secure processing on the first target information;

[0048] performing integrity checking or integrity processing on the first target information;

[0049] performing, based on the integrity protection information, integrity checking or integrity processing on at least one of the following: the first target information, part of the first target information, and the decryption result;

[0050] The second operation includes at least one of the following:

[0051] generating a second security requirement based on fourth derived information and at least one of the first security requirement;

[0052] Sending first information to the access network node;

[0053] Sending first information carrying a third security parameter to the access network node;

[0054] receiving second information from the access network node;

[0055] Among them, the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a secret key and a secret stream; the first derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in the terminal context, information in the terminal core network context, first identification information, and information in the terminal access network context; the fourth derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in the terminal context, information in the terminal core network context, first identification information, information in the terminal access network context, and the third security parameter; the second security requirement includes at least one of a key and a secret stream.

[0056] In a fifth aspect, an interactive device is provided, comprising:

[0057] A first receiving module is configured to receive target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information;

[0058] The first execution module is configured to execute at least one of the following:

[0059] performing a first operation based on a first safety requirement;

[0060] Second operation;

[0061] The first operation includes at least one of the following:

[0062] decrypting the encrypted information;

[0063] Performing confidentiality processing on the encrypted information;

[0064] Performing confidentiality processing on the first target information;

[0065] Checking or verifying the integrity protection information;

[0066] performing secure processing on the first target information;

[0067] performing integrity checking or integrity processing on the first target information;

[0068] performing, based on the integrity protection information, integrity checking or integrity processing on at least one of the following: the first target information, part of the first target information, and the decryption result;

[0069] The second operation includes at least one of the following:

[0070] generating a second security requirement based on fourth derived information and at least one of the first security requirement;

[0071] Sending first information to the access network node;

[0072] receiving second information from the access network node;

[0073] Among them, the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a key and a secret stream; the first derived information and the fourth derived information include at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, and a key in the terminal context; the second security requirement includes at least one of a key and a secret stream.

[0074] In a sixth aspect, an interactive device is provided, comprising:

[0075] A first sending module, configured to send target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information;

[0076] The encryption information and integrity protection information are generated based on a first security requirement, and the first security requirement includes at least one of a secret key and a secret stream.

[0077] In a seventh aspect, an interactive device is provided, comprising:

[0078] A second sending module, configured to send third information or target data to the access network node, wherein the third information includes second identification information and second target information;

[0079] The second target information includes at least one of the following:

[0080] First safety requirement or third safety requirement;

[0081] First algorithm information;

[0082] Second safety parameter;

[0083] Second security assistance information, where the second security assistance information includes information in the terminal core network context;

[0084] Among them, the first algorithm information packet security requirement derives at least one of an algorithm, a confidentiality algorithm, and an integrity algorithm; the first security requirement includes at least one of a secret key and a secret stream, the third security requirement includes at least one of a secret key and a secret stream, and the second identification information indicates the terminal.

[0085] In an eighth aspect, an interactive system is provided, comprising: an access network node and a terminal, wherein:

[0086] The access network node is configured to send target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information, where the encryption information and integrity protection information are generated based on a first security requirement;

[0087] The terminal is configured to receive the target wireless signaling; and, if the terminal is associated with the first identification information, perform at least one of the following:

[0088] performing a first operation based on a first safety requirement;

[0089] Second operation;

[0090] The first operation includes at least one of the following:

[0091] decrypting the encrypted information;

[0092] Performing confidentiality processing on the encrypted information;

[0093] Performing confidentiality processing on the first target information;

[0094] Checking or verifying the integrity protection information;

[0095] performing secure processing on the first target information;

[0096] performing integrity checking or integrity processing on the first target information;

[0097] performing, based on the integrity protection information, integrity checking or integrity processing on at least one of the following: the first target information, part of the first target information, and the decryption result;

[0098] The second operation includes at least one of the following:

[0099] generating a second security requirement based on fourth derived information and at least one of the first security requirement;

[0100] Sending first information to the access network node;

[0101] receiving second information from the access network node;

[0102] Among them, the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a secret key and a secret stream; the first derived information and the fourth derived information include at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in the terminal context, information in the terminal core network context, first identification information, and information in the terminal access network context; the second security requirement includes at least one of a key and a secret stream.

[0103] In a ninth aspect, a terminal is provided, comprising a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in the first aspect are implemented.

[0104] In a tenth aspect, a terminal is provided, comprising a processor and a communication interface, wherein the communication interface is configured to receive target wireless signaling, the target wireless signaling including first identification information and first target information, the first target information including at least one of encryption information and integrity protection information; and perform at least one of the following:

[0105] performing a first operation based on a first safety requirement;

[0106] Second operation;

[0107] The first operation includes at least one of the following:

[0108] decrypting the encrypted information;

[0109] Performing confidentiality processing on the encrypted information;

[0110] Performing confidentiality processing on the first target information;

[0111] Checking or verifying the integrity protection information;

[0112] performing secure processing on the first target information;

[0113] performing integrity checking or integrity processing on the first target information;

[0114] performing, based on the integrity protection information, integrity checking or integrity processing on at least one of the following: the first target information, part of the first target information, and the decryption result;

[0115] The second operation includes at least one of the following:

[0116] generating a second security requirement based on fourth derived information and at least one of the first security requirement;

[0117] Sending first information to the access network node;

[0118] receiving second information from the access network node;

[0119] Among them, the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a key and a secret stream; the first derived information and the fourth derived information include at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, and a key in the terminal context; the second security requirement includes at least one of a key and a secret stream.

[0120] In the eleventh aspect, a network side device is provided, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the second aspect are implemented, or the steps of the method described in the third aspect are implemented.

[0121] In a twelfth aspect, a network-side device is provided, comprising a processor and a communication interface, wherein the communication interface is used to send target wireless signaling, wherein the target wireless signaling includes first identification information and first target information, wherein the first target information includes at least one of encryption information and integrity protection information; wherein the encryption information and integrity protection information are generated based on a first security requirement, wherein the first security requirement includes at least one of a secret key and a secret stream

[0122] Alternatively, the communication interface is used to send third information or target data to the access network node, the third information including second identification information and second target information;

[0123] The second target information includes at least one of the following:

[0124] First safety requirement or third safety requirement;

[0125] First algorithm information;

[0126] Second safety parameter;

[0127] Second security assistance information, where the second security assistance information includes information in the terminal core network context;

[0128] Among them, the first algorithm information packet security requirement derives at least one of an algorithm, a confidentiality algorithm, and an integrity algorithm; the first security requirement includes at least one of a secret key and a secret stream, the third security requirement includes at least one of a secret key and a secret stream, and the second identification information indicates the terminal.

[0129] In the thirteenth aspect, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented, or the steps of the method described in the third aspect are implemented.

[0130] In the fourteenth aspect, a wireless communication system is provided, including: a terminal and a network side device, wherein the terminal can be used to execute the steps of the method described in the first aspect, and the network side device can be used to execute the steps of the method described in the second aspect and the third aspect.

[0131] In the fifteenth aspect, a chip is provided, which includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the method as described in the first aspect, or the method as described in the second aspect, or the steps of the method as described in the third aspect.

[0132] In the sixteenth aspect, a computer program / program product is provided, which is stored in a storage medium and is executed by at least one processor to implement the method as described in the first aspect, or the method as described in the second aspect, or the steps of the method as described in the third aspect.

[0133] In an embodiment of the present application, a terminal receives target wireless signaling, wherein the target wireless signaling includes first identification information and first target information, wherein the first target information includes at least one of encryption information and integrity protection information; when the terminal is associated with the first identification information, the terminal performs at least one of a first operation and a second operation. This allows downlink data or signaling to be transmitted based on the target wireless signaling, or data or signaling to be transmitted in the first interactive message between the terminal and the network-side device after the target wireless signaling; therefore, the embodiment of the present application reduces data transmission latency. BRIEF DESCRIPTION OF THE DRAWINGS

[0134] FIG1 is a block diagram of a wireless communication system to which embodiments of the present application may be applied;

[0135] FIG2 is a flow chart of an interactive method according to an embodiment of the present application;

[0136] FIG3 is a second flow chart of the interaction method provided in an embodiment of the present application;

[0137] FIG4 is a third flow chart of the interaction method provided in an embodiment of the present application;

[0138] FIG5 is a fourth flow chart of the interaction method provided in an embodiment of the present application;

[0139] FIG6 is a fifth flow chart of the interaction method provided in an embodiment of the present application;

[0140] FIG7 is a schematic diagram of the structure of an interactive device according to an embodiment of the present application;

[0141] FIG8 is a second schematic diagram of the structure of the interactive device provided in an embodiment of the present application;

[0142] FIG9 is a third structural diagram of the interactive device provided in an embodiment of the present application;

[0143] FIG10 is a schematic structural diagram of a communication device provided in an embodiment of the present application;

[0144] FIG11 is a schematic structural diagram of a terminal provided in an embodiment of the present application;

[0145] FIG12 is a schematic structural diagram of a network-side device provided in an embodiment of the present application;

[0146] FIG13 is a schematic structural diagram of another network-side device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0147] The following will be combined with the accompanying drawings in the embodiments of this application to clearly describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.

[0148] The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects, for example, the first object can be one or more. In addition, "or" in this application represents at least one of the connected objects. For example, "A or B" covers three options, namely, Option 1: including A but not including B; Option 2: including B but not including A; Option 3: including both A and B. The character " / " generally indicates that the objects associated before and after are in an "or" relationship.

[0149] It is worth noting that the technology described in the embodiments of the present application is not limited to the Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency Division Multiple Access (SC-FDMA) or other systems. The terms "system" and "network" in this application are often used interchangeably, and the technology described can be used for the systems and radio technologies mentioned above, as well as for other systems and radio technologies. The following description describes a New Radio (NR) system for example purposes, and NR terminology is used in most of the following description, but these technologies can also be applied to systems other than NR system applications, such as 6th generation (6G) systems. th Generation, 6G) communication system.

[0150] FIG1 is a block diagram of a wireless communication system applicable to an embodiment of the present application. The wireless communication system includes a terminal 11 and a network-side device 12. The terminal 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), an augmented reality (AR), a virtual reality (VR) device, a robot, a wearable device (Wearable Device), an aircraft (Flight Vehicle), a vehicle-mounted device (VUE), a ship-mounted device, a pedestrian user equipment (PUE), a smart home (home appliances with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), a game console, a personal computer (PC), an ATM, or a self-service machine, or other terminal-side devices. Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among them, the vehicle-mounted device can also be called a vehicle-mounted terminal, a vehicle-mounted controller, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip or a vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application. The network side device 12 may include an access network system or a core network device, wherein the access network system may also be called a radio access network (Radio Access Network, RAN) device, a radio access network function or a radio access network unit. The access network system may include a base station, a wireless local area network (WLAN) access point (AP) or a wireless fidelity (WiFi) node, etc.Among them, the base station can be referred to as Node B (NB), Evolved Node B (eNB), the next generation Node B (gNB), New Radio Node B (NR Node B), access point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home evolved Node B (home evolved Node B), Transmission Reception Point (TRP) or other appropriate terms in the relevant field. As long as the same technical effect is achieved, the base station is not limited to specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.

[0151] The core network equipment may include but is not limited to at least one of the following: core network node, core network function, mobility management entity (MME), access mobility management function (AMF), session management function (SMF), user plane function (UPF), policy control function (PCF), policy and charging rules function unit (PCRF), edge application service discovery function (EASDF), unified data management (UDM), unified data repository (UDR), home user server (HSS), centralized network configuration (CNC), network storage function (NRF), network exposure function (NEF), local NEF (L-NEF), binding support function (BSF), application function ( Function, AF), etc. It should be noted that in the embodiments of the present application, only the core network device in the NR system is introduced as an example, and the specific type of the core network device is not limited.

[0152] For ease of understanding, some of the contents involved in the embodiments of this application are described below:

[0153] 1. Small Data Transmission (SDT)

[0154] Efficient small data transmission is a feature that allows users in non-Radio Resource Control (RRC) connected states to avoid excessive signaling overhead associated with RRC state transitions and RRC connection establishment, enabling small data transmission through a minimal signaling process. Non-RRC connected states include idle and inactive states.

[0155] A key feature of the small data transmission solution is that the UE's current Data Radio Bearer (DRB) is suspended, not released. Therefore, the UE can resume the DRB before sending a ResumeRequest message, then use RRC signaling to piggyback small data. At this point, data can be transmitted on the DRB, just like a connected UE. This avoids state transitions and achieves efficient small data transmission with minimal signaling overhead.

[0156] Since small data transmission uses DRB transmission and access layer (Attached Storage, AS) security is activated, small data transmission can provide necessary security protection for the data, such as data encryption and integrity protection. From a security perspective, since the UE may have moved to another base station while in the suspended state, the security key used by the UE to resend the packet needs to be updated. The update method is to perform the next key update operation according to the parameters provided to the UE by the network side equipment when it enters the suspended state for calculating the next hop key.

[0157] Small data transmissions are carried on the Dedicated Traffic Channel (DTCH) and multiplexed with the uplink RRCConnectionResumeRequest message before transmission. Similarly, any downlink reply message can also be carried on the DTCH and multiplexed with the downlink RRCConnectionRelease message. Both uplink and downlink data are encrypted using the next key after the update.

[0158] Optionally, small data can be transmitted on Msg3 PUSCH in a 4-step Random Access Channel (RACH) process. Small data can also be transmitted on MsgA PUSCH in a 2-step RACH process, or on PUSCH resources scheduled by a configured grant (CG) configured in the RRC inactive state. Small data transmission in 2-step RACH and 4-step RACH processes is called RACH-based small data transmission, and small data transmission based on PUSCH scheduled by a configured grant is called CG-based small data transmission.

[0159] 2. Mobile Terminated Early Data Transmission (MT-EDT)

[0160] In the LTE system, the network (NW) carries the MT-EDT trigger message via a paging message. The UE then initiates the EDT process. After receiving the UE's request message (carrying the MT-EDT cause value), the NW concatenates the RRC response message with the DRB data into a protocol data unit (PDU) and sends it to the UE, ultimately enabling the reception of downlink services.

[0161] Data transmission in idle or inactive state is a special transmission mechanism, which allows the UE to send and receive UE-dedicated data with the NW side without entering the connected state. Currently, small data transmission is mainly transmitted in the uplink Msg3 or MO-SDT transmitted on the CG PUSCH triggered by the terminal, or in the downlink MT-SDT. There is no corresponding solution for how to transmit data or schedule data transmission in the paging message. To this end, the interaction method of the present application is proposed, that is, the data or data transmission resources are directly delivered to the UE through the first broadcast signal that the UE can receive, such as paging, thereby reducing the message interaction process.

[0162] The following describes the interaction method provided in the embodiments of the present application in detail through some embodiments and their application scenarios in combination with the accompanying drawings.

[0163] Referring to FIG2 , an embodiment of the present application provides an interaction method. As shown in FIG2 , the interaction method includes:

[0164] Step 201: A terminal receives target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information.

[0165] In step 202, when the terminal is associated with the first identification information, the terminal performs at least one of the following:

[0166] performing a first operation based on a first safety requirement;

[0167] Second operation;

[0168] The first operation includes at least one of the following:

[0169] decrypting the encrypted information;

[0170] Performing confidentiality processing on the encrypted information;

[0171] Performing confidentiality processing on the first target information;

[0172] Checking or verifying the integrity protection information;

[0173] performing secure processing on the first target information;

[0174] performing integrity checking or integrity processing on the first target information;

[0175] performing, based on the integrity protection information, integrity checking or integrity processing on at least one of the following: the first target information, part of the first target information, and the decryption result;

[0176] The second operation includes at least one of the following:

[0177] generating a second security requirement based on fourth derived information and at least one of the first security requirement;

[0178] Sending first information to the access network node;

[0179] Sending first information carrying a third security parameter to the access network node;

[0180] receiving second information from the access network node;

[0181] Among them, the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a key and a secret stream; the first derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, and a key in the terminal context; the fourth derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in the terminal context, and the third security parameter; the second security requirement includes at least one of a key and a secret stream.

[0182] In an embodiment of the present application, the above-mentioned first identification information can be understood as a target identification or a part of the identification intercepted from the target identification, and the target identification may include at least one of a user identification, a group identification, a connection identification, a bearer identification, a transaction identification and an interaction identification.

[0183] Optionally, the encryption information can be understood as information obtained by security processing of at least a portion of the content to be transmitted, and the integrity protection information can be understood as integrity information associated with the content to be transmitted, such as a Media Access Control (MAC) value. When the first target information includes the encryption information and the integrity protection information, it can be understood that both security processing and integrity processing are performed on the transmitted content to ultimately obtain the first target information.

[0184] Optionally, the terminal is associated with the first identification information, which can be understood as the relevant identification of the terminal is associated with the first identification information. For example, the target wireless signaling includes a user identification. When the user identification contained in the target wireless signaling includes the user identification of the terminal, it can be considered that the terminal is associated with the first identification information. At this time, the terminal can perform the above-mentioned first operation.

[0185] It should be understood that, in the case that the terminal is not related to the first identification information, the terminal may discard the received first target information.

[0186] It should be noted that the above-mentioned target wireless signaling can be understood as wireless signaling that the terminal can receive in an idle state or an inactive state. In some embodiments, when the terminal is related to the first identification information, the terminal performs a first operation based on the first security requirement, so that the transmission of downlink data or signaling can be achieved without other interactive information, thereby reducing the data transmission delay. At the same time, since the first target information includes at least one of encryption information and integrity protection information, the first security requirement of the terminal performs the first operation, thereby improving the security of the transmission. In some embodiments, when the terminal is related to the first identification information, the terminal performs the second operation, so that the transmission of data or signaling can be achieved in the first interactive information between the subsequent terminal and the network side device, thereby reducing the data transmission delay.

[0187] Optionally, after decrypting the encrypted information, the content transmitted by the access network node can be obtained, which may specifically include signaling or data.

[0188] Optionally, the key stream (KeyStream) may be a string generated based on a secret key and other parameters.

[0189] Optionally, the above-mentioned core network-related keys may include a long-term key (Long Term Key), an authentication-related key (Kausf), a security and authentication-related key (Kseaf), an AMF key (Kamf), a mobility management entity (Mobility Management Entity, MME) key (Kasme), etc.

[0190] NAS layer related keys may include NAS encryption key (Knas_enc), NAS integrity key (Knas_int), etc.

[0191] Access network related keys may include base station keys (such as Kenb, Kgnb, NH, Kenb*, Kgnb*, Ks-enb, Ks-gnb, etc.).

[0192] AS layer related keys may include signaling encryption key (Krrc_enc), signaling integrity key (Krrc_int), data encryption key (Kup_enc), data integrity key (Kup_int), etc.

[0193] The keys in the terminal context may include any one or a combination of at least two of the core network related keys, the non-access layer NAS layer related keys, the access network related keys, and the access layer AS layer related keys.

[0194] In an embodiment of the present application, a terminal receives target wireless signaling, wherein the target wireless signaling includes first identification information and first target information, wherein the first target information includes at least one of encryption information and integrity protection information; when the terminal is associated with the first identification information, the terminal performs at least one of a first operation and a second operation. This allows downlink data or signaling to be transmitted based on the target wireless signaling, or data or signaling to be transmitted in the first interactive message between the terminal and the network-side device after the target wireless signaling; therefore, the embodiment of the present application reduces data transmission latency.

[0195] It should be noted that before the access network device sends the target wireless signaling, the access network node receives third information or target data from the core network node, where the third information includes third identification information and second target information;

[0196] Wherein, the third information includes second identification information and second target information;

[0197] The second target information includes at least one of the following:

[0198] The first security requirement or the third security requirement, wherein the third security requirement includes at least one of a secret key and a secret stream;

[0199] First algorithm information;

[0200] Second safety parameter;

[0201] Second security assistance information, where the second security assistance information includes information in the terminal core network context;

[0202] The second identification information is used to indicate a terminal, or is generated by a terminal identifier, or indicates a group of terminals, or is related to the first identification information.

[0203] In an embodiment of the present application, the access network node may acquire or generate the first security requirement based on the second target information, and send the target wireless signaling based on the third information.

[0204] For example, in some embodiments, the access network node generates the first security requirement based on at least one of second derived information and the security requirement derivation algorithm, wherein the second derived information includes at least one of the following: an access network-related key, an AS layer-related key, a key in a terminal context, at least a portion of the first security assistance information, at least a portion of the second security assistance information, first identification information, and information in the terminal access network context.

[0205] Optionally, the second identification information may be a global unique temporary identifier (GUTI), and the first identification information may be an RNTI; or the second identification information may be a GUTI, and the first identification information may be a short-term mobile subscriber identity (S-TMSI); or both the second identification information and the first identification information may be S-TMSI.

[0206] Optionally, the above-mentioned target data can be understood as data to be transmitted. In some embodiments, the above-mentioned third information may also include the above-mentioned target data. The above-mentioned target data is associated with the above-mentioned encryption information or integrity protection information, that is, the access network device can generate encryption information and integrity protection information based on at least part of the target data. In other words, part of the data can be transmitted through the target wireless signaling, and the remaining part of the data is associated with the second information, that is, the second information can be generated based on the remaining part of the data. Of course, in some embodiments, the data to be transmitted may not be carried in the target wireless signaling. For example, the above-mentioned encryption information is encrypted resource information, and the above-mentioned second information is encrypted target data (or encrypted data generated based on the target data).

[0207] In this embodiment of the present application, the third information includes at least one of the following:

[0208] at least one second identification information and at least one second target information;

[0209] at least one pair of second identification information and second target information;

[0210] Wherein, the second target information and the second identification information are mapped one to one or more;

[0211] Alternatively, the second identification information and the second target information are a one-to-zero or one mapping;

[0212] Alternatively, there is a correspondence between K pieces of second identification information and all the second target information, and K is less than or equal to the number of second identification information included in the third information.

[0213] In the embodiments of the present application, the second target information and the second identification information being mapped one-to-one or one-to-many can be understood as follows: the second target information and the second identification information can have a one-to-one mapping relationship, or a one-to-many mapping relationship. For example, all of the second target information and the second identification information are mapped one-to-one; or all of the second target information and the second identification information are mapped one-to-many; or some of the second target information and the second identification information are mapped one-to-one, and some of the second target information and the second identification information are mapped one-to-many.

[0214] The second identification information and the second target information being a one-to-zero or one-to-one mapping can be understood as follows: the second identification information can have a one-to-one mapping relationship with the second target information, or a one-to-zero mapping relationship, wherein a one-to-zero mapping relationship indicates that the second identification information does not have any second target information mapped thereto. For example, all of the second identification information and the second target information are mapped one-to-one; or some of the second identification information and the second target information are mapped one-to-one, while some of the second identification information and the second target information are mapped one-to-zero.

[0215] Optionally, when there is a correspondence between K pieces of second identification information and all pieces of second target information, if K is equal to the number of pieces of second identification information included in the target wireless signaling, it can be understood that all pieces of second identification information have mapped second target information; if K is less than the number of pieces of second identification information included in the target wireless signaling, it can be understood that only some pieces of second identification information have mapped second target information, while some pieces of second identification information do not have mapped second target information. The mapping relationship between the second target information and the second identification information can include at least one of the following: a one-to-one mapping relationship; or a one-to-many mapping relationship.

[0216] Optionally, in some embodiments, the second identification information is used to indicate a terminal, or is generated by a terminal identifier, or indicates a group of terminals, or is related to the first identification information.

[0217] Optionally, in some embodiments, the access network node performs at least one of the following:

[0218] generating the first security requirement based on a security requirement derivation algorithm;

[0219] generating the first security requirement based on the second derived information;

[0220] generating the encrypted information based on a confidentiality algorithm;

[0221] generating the integrity protection information based on an integrity algorithm;

[0222] generating at least one of the encryption information and the integrity protection information based on a first calculation parameter;

[0223] The third operation;

[0224] The first calculation parameter includes at least one of the following:

[0225] Information in the terminal access network context;

[0226] the first identification information;

[0227] at least part of the first safety assistance information;

[0228] at least part of the second safety assistance information;

[0229] First algorithm information;

[0230] The second derived information includes at least one of the following:

[0231] Access network related keys;

[0232] Access layer AS layer related keys;

[0233] Keys in the terminal context;

[0234] The third safety requirement;

[0235] Information in the terminal access network context;

[0236] the first identification information;

[0237] at least part of the first safety assistance information;

[0238] at least part of the second safety assistance information;

[0239] First algorithm information;

[0240] The third operation includes at least one of the following:

[0241] generating a second security requirement based on fourth derived information and at least one of the first security requirements, wherein the second security requirement includes at least one of a key and a secret stream, and the fourth derived information includes at least one of the following: a core network-related key, a non-access stratum (NAS) layer-related key, an access network-related key, an AS layer-related key, and a key in a terminal context;

[0242] receiving first information from a terminal;

[0243] The second information is sent to the terminal.

[0244] Optionally, after receiving the first information, the access network node may perform security processing on at least part of the content of the first information and report it to the core network node.

[0245] Optionally, before sending the first security requirement or the third security requirement to the access network node, the core network node may further generate the first security requirement or the third security requirement based on at least one of the third derived information and the security requirement derivation algorithm;

[0246] The third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in a terminal context, the first algorithm information, the second security parameter, and at least part of the second security auxiliary information.

[0247] It should be noted that in the embodiments of the present application, the core network node can be understood or replaced by a device or system having core network functions, that is, it can be referred to as a core network device or core network system, or it can also be referred to as a core network function. The access network node can be understood as a device or system having access network functions, that is, it can be referred to as an access network device or system, or it can also be referred to as a base station or access network function.

[0248] Optionally, in some embodiments, the first target information further includes first safety auxiliary information;

[0249] The first security auxiliary information includes at least one of first algorithm information, first security parameter, and second security parameter;

[0250] The first algorithm information includes at least one of the following:

[0251] a security requirement derivation algorithm, the first security requirement being further generated based on the security requirement derivation algorithm;

[0252] At least one of a confidentiality algorithm and an integrity algorithm, the first operation is also performed based on at least one of the confidentiality algorithm and the integrity algorithm.

[0253] In an embodiment of the present application, the above-mentioned confidentiality algorithm may include an encryption algorithm and a decryption algorithm, and the above-mentioned integrity algorithm may include an algorithm for generating a check code, or an algorithm for checking or verifying a check code.

[0254] Optionally, the first security parameter is used to represent NAS counting information, such as the number of downlink NAS signaling times, or the number of uplink NAS signaling times, or the number of NAS signaling times (the sum of the number of downlink NAS signaling times and the number of uplink NAS signaling times); the second security parameter is used to represent the counting information of access network signaling or the counting information of data messages. For example, the second security parameter can be the number of downlink access network signaling times, the number of uplink access network signaling times, or the number of access network signaling times (that is, the sum of the number of downlink access network signaling times and the number of uplink access network signaling times), or it can be the number of downlink data messages, the number of uplink data messages, or the number of data messages (that is, the number of downlink data messages and the number of uplink data messages). The third security parameter can be understood as information used to represent access network signaling counts or data message counts. For example, the second security parameter can be the number of downlink access network signaling times, the number of uplink access network signaling times, or the number of access network signaling times (i.e., the sum of the number of downlink access network signaling times and the number of uplink access network signaling times), or the number of downlink data messages, the number of uplink data messages, or the number of data messages (i.e., the number of downlink data messages and the number of uplink data messages). Optionally, in some embodiments, the third security parameter is different from the second security parameter.

[0255] It should be understood that the downlink NAS signaling described above can be understood or replaced by NAS downlink signaling, and downlink NAS signaling can be understood or replaced by NAS downlink signaling. Downlink access network signaling can be understood or replaced by AS downlink signaling, and uplink access network signaling can be understood or replaced by AS uplink signaling, and access network signaling can be understood or replaced by AS signaling. Data packets can be understood or replaced by protocol data packets.

[0256] Optionally, the first security requirement being further generated based on the security requirement derivation algorithm can be understood as the first security requirement being generated based on the first derived information and the security requirement derivation algorithm indicated by the access network node. In some embodiments, the security requirement derivation algorithm can also be part of the first derived information. That is, the first security requirement being further generated based on the security requirement derivation algorithm can be understood as the first security requirement being generated based on information in the first derived information other than the security requirement derivation algorithm indicated by the access network node and the security requirement derivation algorithm indicated by the access network node. It should be understood that if the first target information does not include a security requirement derivation algorithm, the security requirement derivation algorithm for generating the first security requirement can be agreed upon by the protocol.

[0257] Optionally, in some embodiments, the first derived information further includes at least one of the following:

[0258] at least part of the first safety assistance information;

[0259] Information in the terminal core network context;

[0260] Information in the terminal access network context;

[0261] The first identification information.

[0262] Optionally, in some embodiments, the terminal performs a first operation based on the first security requirement, including:

[0263] The terminal performs the first operation based on the first security requirement and a first calculation parameter, where the first calculation parameter includes at least one of the following:

[0264] Information in the terminal core network context;

[0265] Information in the terminal access network context;

[0266] the first identification information;

[0267] At least part of the first safety assistance information.

[0268] In embodiments of the present application, at least a portion of the first security assistance information included in the first calculation parameter may be the same as, or different from, or partially the same as at least a portion of the first security assistance information included in the first derived information. For example, in some embodiments, the first security assistance information includes two parts of information, one part (e.g., the first security parameter) being used to perform the first operation, and the other part (e.g., the second security parameter) being used to generate the security requirement.

[0269] Optionally, in some embodiments, the information in the terminal core network context includes at least one of the following:

[0270] Terminal identification information;

[0271] The terminal's group identification information;

[0272] NAS signaling counting information;

[0273] NAS uplink signaling counting information;

[0274] NAS signaling counting information;

[0275] Count information of protocol data packets transmitted through NAS;

[0276] Count information of uplink protocol data packets transmitted through NAS;

[0277] Count information of downlink protocol data packets transmitted through NAS;

[0278] Alternatively, the information in the terminal access network context includes at least one of the following:

[0279] Terminal identification information;

[0280] The terminal's group identification information;

[0281] AS signaling counting information;

[0282] AS uplink signaling counting information;

[0283] AS downlink signaling counting information;

[0284] Counting information of protocol data packets;

[0285] Counting information of uplink protocol data packets;

[0286] Downlink protocol data packet count information.

[0287] Optionally, in some embodiments, the method includes at least one of the following:

[0288] The terminal generates the second security requirement based on at least one of: the first security requirement, the fourth derived information, and the third security parameter;

[0289] The terminal performs security protection on the first information or a portion of the first information based on at least one of the following: the first security requirement or the second security requirement, a first calculation parameter, and the third security parameter;

[0290] The terminal performs security processing on the second information or part of the second information based on at least one of the following: the first security requirement or the second security requirement, a first calculation parameter, and the third security parameter.

[0291] In some embodiments, when the first information includes a third security parameter, the second security requirement is generated based on the third security parameter or the third security parameter and other related information, and the security processing is performed based on the third security parameter or the third security parameter and other related information. The third security parameter can be understood as information used to update the security requirement and security processing. Since the security requirement and security processing can be updated based on the third security parameter, transmission security is improved.

[0292] In some embodiments, when the first information does not include the third security parameter, the terminal generates the second security requirement based on at least one of the following: the first security requirement and the fourth derived information. The terminal performs security processing on the second information or a portion thereof based on at least one of the following: the first security requirement or the second security requirement and the first calculated parameter.

[0293] It should be noted that in the embodiment of the present application, the security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.

[0294] Optionally, in some embodiments, the target wireless signaling includes at least one of the following:

[0295] at least one first identification information and at least one first target information;

[0296] At least one pair of first identification information and first target information;

[0297] Wherein, the first target information and the first identification information are mapped one to one or more;

[0298] Alternatively, the first identification information and the first target information are a one-to-zero or one mapping;

[0299] Alternatively, there is a correspondence between N first identification information and all first target information, and N is less than or equal to the amount of first identification information included in the target wireless signaling.

[0300] In the embodiments of the present application, the one-to-one or one-to-many mapping between the first target information and the first identification information can be understood as follows: the first target information can have a one-to-one mapping relationship with the first identification information, or a one-to-many mapping relationship. For example, all first target information and the first identification information are one-to-one mapped; or all first target information and the first identification information are one-to-many mapped; or some first target information and the first identification information are one-to-one mapped, and some first target information and the first identification information are one-to-many mapped.

[0301] The one-to-zero or one mapping between the first identification information and the first target information can be understood as follows: the first identification information can have a one-to-one mapping relationship with the first target information, or a one-to-zero mapping relationship, wherein a one-to-zero mapping relationship indicates that there is no first target information mapped to the first identification information. For example, all first identification information and the first target information have a one-to-one mapping; or some first identification information and the first target information have a one-to-one mapping, and some first identification information and the first target information have a one-to-zero mapping.

[0302] Optionally, when N first identification information corresponds to all first target information, if N is equal to the number of first identification information included in the target wireless signaling, it can be understood that all first identification information has mapped first target information; if N is less than the number of first identification information included in the target wireless signaling, it can be understood that only some of the first identification information has mapped first target information, and some of the first identification information does not have mapped first target information. The mapping relationship between the first target information and the first identification information can include at least one of the following: a one-to-one mapping relationship; a one-to-many mapping relationship.

[0303] Optionally, in some embodiments, the terminal is in an idle state or an inactive state, or is in an idle state or an inactive state before sending the first information, or is in an idle state or an inactive state before receiving the second information.

[0304] In the embodiment of the present application, the idle state includes two situations: the core network idle state and the wireless idle state. The core network idle state refers to a state of the terminal in which the core network cannot directly send a NAS message targeting the terminal (paging must be performed first), or the terminal cannot directly send a NAS message to the core network (the corresponding sending resources must be obtained first). It can also be said that there is no NAS connection between the terminal and the core network. The wireless idle state means that the terminal has no resources to send signaling to the base station to establish a wireless point-to-point connection between the terminal and the base station (there are dedicated wireless resources of the terminal to send and receive information, including dedicated scrambling code resources, such as Radio Network Temporary Identifier (RNTI)). Identifier, RNTI); the inactive state refers to a state of the terminal, in which the terminal is in a non-core network idle state, there is a connection or tunnel for the terminal between the core network and the base station, but there is no wireless point-to-point connection between the terminal and the base station. The state of the terminal can also be defined using other names, and there are other behaviors between the terminal and the base station. For example, there is a wireless point-to-point connection between the terminal and the base station, but the core network cannot directly send a NAS message with the terminal as the target. This state may use a new name, but still corresponds to the idle state (i.e., core network idle state) description of this application, such as the terminal is in a non-core network idle state (NAS messages with the terminal as the target can be sent directly), there is a wireless point-to-point connection between the terminal and the base station, but there is no connection for the terminal between the core network and the base station (for example, uplink or downlink NAS messages are based on UE ID to identify the source or target, rather than based on a connection or tunnel identifier (Tunnel endpoint identifier, TEID)). This state can be defined using other names, but still corresponds to the inactive state description of this application. For example, there is a NAS connection but the connection between the terminal, the base station, and then the core network is incomplete.

[0305] Optionally, in an embodiment of the present application, after the terminal enters the inactive state and before receiving the target wireless signaling, the terminal does not send any information to the access network system.

[0306] Optionally, in some embodiments, before the terminal receives the target wireless signaling, the method further includes:

[0307] The terminal sends second algorithm information to the network side, where the second algorithm information is used to indicate at least one of the following: an algorithm supported by the terminal and an algorithm used by the terminal;

[0308] The algorithm includes at least one of a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm.

[0309] In the embodiment of the present application, the terminal sending the second algorithm information to the network side can be understood as the terminal sending an NAS message to the core network node, and the NAS message can include the second algorithm information. Furthermore, when the access network node forwards the NAS message to the core network node, it can carry at least one of the algorithms supported by the access network node and the algorithm used by the access network node.

[0310] Optionally, after receiving the second algorithm information, the core network node may indicate the first algorithm information to the access network node.

[0311] Optionally, in some embodiments, the first identification information indicates a terminal, or is generated by a terminal identifier, or indicates a group of terminals.

[0312] In the embodiment of the present application, when the first identification information is generated by the terminal identification, different terminal identifications can generate the same first identification information. For example, the terminal identifications of a group of terminals can generate the same first identification information.

[0313] Optionally, in some embodiments, the target wireless signaling includes any one of broadcast signaling, paging signaling, wireless short message, and system message;

[0314] Alternatively, the target wireless signaling is sent through at least one of a paging channel (Paging Channel, PCH), a multicast channel (Multicast Channel, MCH), a broadcast channel (Broadcast Channel, BCH) and a downlink shared channel (Downlink Shared Channel, DL-SCH);

[0315] Alternatively, the target wireless signaling is sent through at least one of a physical downlink control channel (PDCCH), a physical downlink shared channel (PDSCH), a physical broadcast channel (PBCH) and a physical multicast channel (PMCH).

[0316] In an embodiment of the present application, the above-mentioned target wireless signaling can be a paging message in a new format sent through PCH (i.e., a paging message containing resource information and / or data), or it can be a signaling sent in PCH, and the target wireless signaling includes a traditional paging message (i.e., a paging message that does not contain resource information and data), as well as resource information and / or data, or it can be a traditional paging message sent in PCH, as well as resource information sent through PDCCH and / or data sent through PDSCH.

[0317] Optionally, the wireless short message may be understood as a short message involved in wireless signaling, rather than a short message involved in Short Messaging / Message Service (SMS).

[0318] In order to better understand the present application, some examples are given below for detailed description.

[0319] In the first embodiment, when the terminal is in the idle state, the interaction process is shown in FIG3 , which specifically includes the following steps:

[0320] In step 31, the terminal sends a NAS message to the core network. When the access network node forwards the NAS message to the core network node, it carries the algorithm indication information supported by the terminal (i.e., the second algorithm information), and may further carry the algorithm indication information supported by the access network node. The core network node optionally saves the algorithm indication information supported by the terminal, or the algorithm indication information supported by the terminal and the access network node.

[0321] In step 32, the core network node sends information 1 to the access network node, for example, via a Paging message or an incentive message.

[0322] Information 1 includes a first user identifier and a security requirement (including at least one of a secret key and a secret stream). The security requirement can be generated based on at least one of the secret key, the first user identifier, and the first security parameter in the terminal core network context. Optionally, Information 1 may also include at least one of the first security parameter and an algorithm indication, where the algorithm indication is used to indicate the first algorithm information.

[0323] Optionally, at least part of the information other than the first user identifier in the information 1 may be associated with the first user identifier, thereby carrying multiple pieces of other information associated with the first user identifier. Of course, in other embodiments, at least part of the information other than the first user identifier in the information 1 may also be associated with the first user identifier.

[0324] In step 33 , the access network node may perform operation 1 based on information 1 , where operation 1 includes at least one of an encryption operation and a security operation.

[0325] For encryption operations: use a secret key or a secret stream to encrypt at least one of the resource information (such as SRB information, DRB information, MAC CE scheduling information, grant information, etc.) and other information elements (such as data in the target wireless signaling) (for example, encrypt using a key and an agreed or indicated algorithm, or perform an XOR operation using a secret stream), and the resource information may include at least one of the uplink resource information and the downlink resource information; wherein, when the security requirements include a secret key, the encryption behavior can be performed based on at least one of the first user identifier, the second user identifier, the first security parameter, and the second security parameter.

[0326] Among them, the second user identifier can be generated based on the first user identifier, for example, the first user identifier is a user identifier assigned by the core network node (such as TMSI), and the second user identifier is a user identifier assigned by the access network node (such as RNTI), or the first user identifier is a user identifier assigned by the access network node, and the second user identifier is a user identifier assigned by the core network node.

[0327] For the security operation: when the security requirements include a secret key, a security operation is performed on at least one of the resource information, encrypted resource information and other information elements (such as data in the target wireless signaling); for example, a MAC value is calculated using a key and an agreed or indicated algorithm. Optionally, the security operation can also be performed based on at least one of the first security parameter and the second security parameter, that is, the MAC value is calculated using at least one of the first security parameter and the second security parameter as input to the algorithm.

[0328] Optionally, in some embodiments, if the algorithm indicates no support, step 33 and subsequent steps are not performed.

[0329] In step 34, the access network node broadcasts information 2 via the air interface, for example, via a Paging message, a system message, or an activation message, or sends information 2 in the first message sent to the terminal.

[0330] The information 2 includes the first user identifier or the second user identifier and at least one of the following: encrypted resource information and a MAC value.

[0331] Optionally, other information in addition to the user identification (first user identification or second user identification) in the above information 2 may be associated with the user identification, thereby carrying other information associated with multiple user identifications. Of course, in other embodiments, other information in addition to the user identification in the above information 2 may be unrelated to the user identification.

[0332] Optionally, the information 2 may further include at least one of an algorithm indication, a first security parameter, and a second security parameter. At least part of this information may be independent of or related to the user identification.

[0333] It should be noted that, except for the user identity in the above information 2 which is carried by the message carrying information 2, other information can be carried in the message or in the signaling carrying the message (such as RLC layer signaling, MAC layer signaling).

[0334] At this point, security activation is completed between the terminal and the access network node, and subsequent message and data interactions can be securely protected.

[0335] In step 35, the terminal generates a security requirement (the security requirement includes at least one of a secret key or a secret stream, and the generation method of the security requirement is the same as step 32 and will not be repeated here) and performs operation 2, which includes at least one of a decryption operation and a security verification operation.

[0336] For the decryption operation, the resource information is decrypted using a key or a secret stream (for example, decryption using a key and an agreed or indicated algorithm, or performing an XOR operation based on the secret stream). When the security requirement includes a key, the decryption operation can also be performed using the received user identity, a third user identity obtained based on the received user identity (for example, obtaining the TMSI by receiving the RNTI, or vice versa), the first security parameter, and the second security parameter (i.e., the relevant parameters are also used as input parameters during decryption).

[0337] For the security verification operation, when the security requirements include a key, the resource information and / or encrypted resource information is subjected to security verification (for example, the target MAC value is calculated using the key and an agreed or indicated algorithm and compared with the received MAC). The security verification can also use the received user identifier, a third user identifier obtained based on the received user identifier, the first security parameter 1 and at least one of the second security parameters (that is, the relevant parameters are also used as input in the process of calculating the target MAC value).

[0338] Optionally, after step 35, the terminal may also generate a new security requirement based on the key in the context of the terminal core network or the access network (for example, using the corresponding key and the agreed parameters and / or the information received from the access network node to generate a new security requirement). The terminal sends signaling and / or data to the base station based on the resource information (for example, uplink resource information), and may perform the process of sending signaling and / or data based on the aforementioned security check, for example, after the security check is successful. The signaling may include at least one of the following:

[0339] The entire signaling or part of the signaling cells encrypted based on the key or secret stream in the security requirement or new security requirement (encrypted using the key and the agreed or indicated algorithm, or using the secret stream to perform an exclusive OR operation);

[0340] When the security requirement or new security requirement includes a key, the information after the security operation is performed on the entire signaling (the entire plaintext signaling), the entire encrypted signaling, some information elements in the signaling (plaintext information elements), or some encrypted information elements in the signaling (the MAC value calculated using the key and the agreed or indicated algorithm).

[0341] The data sent can be data encrypted based on the key or secret stream in the security requirements or new security requirements, or data fully protected based on the key in the security requirements or new security requirements, or data encrypted and fully protected based on the key in the security requirements or new security requirements.

[0342] Optionally, when the security requirement or new security requirement includes a key, the above-mentioned encryption and / or security operations can also be performed based on the received user identifier, a third user identifier obtained based on the received user identifier, the first security parameter, the second security parameter 2 and at least one of the third security parameters.

[0343] When security parameter 3 is used, the signaling or data sent may include plaintext security parameter 3 (security parameter 3 as part of the entire signaling, or part of the data, or one of the partial information elements, but not the entire encrypted signaling, nor one of the partial encrypted information elements).

[0344] Optionally, the access network node may generate new security requirements based on the key in the terminal access network context or the security requirements received from the core network node (e.g., using the corresponding key and agreed parameters and / or information sent by the access network node to the terminal to generate new security requirements). The access network node receives signaling and / or data from the terminal based on resource information (e.g., uplink resource information).

[0345] Optionally, the access network node performs at least one of the following on the signaling:

[0346] Decrypting the signaling or part of the signaling based on the key or secret stream in the security element or the new security element;

[0347] Based on the key pair in the security requirement or the new security requirement, perform integrity verification (using the key and the target MAC value calculated by the agreed or indicated algorithm and comparing it with the received MAC value) on the entire signaling (the entire ciphertext signaling), the entire decrypted (plaintext) signaling, some cells in the signaling (ciphertext cells), and / or some decrypted cells in the signaling (plaintext cells);

[0348] Send the decrypted signaling as a whole or partially decrypted cells in the signaling to the core network node.

[0349] Optionally, the access network node performs at least one of the following on the received data:

[0350] decrypting data based on a key or secret stream in a security element or a new security element;

[0351] Perform data integrity verification based on the key in the security element or the new security element;

[0352] Send data or decrypted data (plaintext data) to the core network node.

[0353] Optionally, the access network node may perform the above-mentioned operations on the data based on the integrity check of the received signaling, such as processing if successful. The above-mentioned integrity check and / or decryption operations may also be performed based on the sent user identifier, a third user identifier obtained based on the sent user identifier, the first security parameter, the second security parameter, and the third security parameter (i.e., the corresponding parameters are also used as input during the calculation of the XMAC value and the decryption process).

[0354] After completing the above operation process, the access network node and the terminal can continue to perform subsequent signaling and data transmission processes.

[0355] For example, the terminal sends at least one of signaling and data to the access network node based on the resource information. After the access network node receives the information sent by the terminal based on the uplink resource information, it can report the relevant information to the core network node. The specific encryption and security operations can refer to the description of the above embodiment and are not repeated here.

[0356] For example, the access network node receives signaling or data from the core network node, and sends signaling and / or data to the terminal based on the downlink resource information. The specific process can refer to the above embodiment and will not be repeated here.

[0357] In the second embodiment, when the terminal is in the INACTIVE state, the difference from the first embodiment is that:

[0358] 1. Data interaction between core network nodes and access network nodes is performed based on the user plane.

[0359] 2. When the access network node generates a security requirement based on the key in the terminal access network context, the key in the security requirement is the key in the terminal access network context.

[0360] 3. The first security parameter does not participate in the interaction process. That is, the information sent during the interaction process in Example 1, the information used to generate security keys, the execution of security operations, encryption operations, and other information or behaviors do not include the first security parameter. For example, message 2 does not include the first security parameter, and security requirements are not generated based on the first security parameter.

[0361] 4 , an embodiment of the present application further provides an interaction method, as shown in FIG4 , the interaction method includes:

[0362] Step 401: An access network node sends target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information.

[0363] The encryption information and integrity protection information are generated based on a first security requirement, and the first security requirement includes at least one of a secret key and a secret stream.

[0364] Optionally, before the access network node sends the target wireless signaling, the method further includes:

[0365] The access network node receives third information or target data from the core network node;

[0366] Wherein, the third information includes second identification information and second target information;

[0367] The second target information includes at least one of the following:

[0368] The first security requirement or the third security requirement, wherein the third security requirement includes at least one of a secret key and a secret stream;

[0369] First algorithm information;

[0370] Second safety parameter;

[0371] Second security assistance information, where the second security assistance information includes information in the terminal core network context;

[0372] The second identification information is used to indicate a terminal, or is generated by a terminal identifier, or indicates a group of terminals, or is related to the first identification information; and the first algorithm information includes at least one of the following:

[0373] Security element derivation algorithm, confidentiality algorithm, and integrity algorithm.

[0374] Optionally, the third information includes at least one of the following:

[0375] at least one second identification information and at least one second target information;

[0376] at least one pair of second identification information and second target information;

[0377] Wherein, the second target information and the second identification information are mapped one to one or more;

[0378] Alternatively, the second identification information and the second target information are a one-to-zero or one mapping;

[0379] Alternatively, there is a correspondence between K pieces of second identification information and all the second target information, and K is less than or equal to the number of second identification information included in the third information.

[0380] Optionally, the first target information further includes at least one of the following:

[0381] The first security auxiliary information includes at least one of first algorithm information, a first security parameter, and a second security parameter.

[0382] Optionally, the method comprises:

[0383] The access network node performs at least one of the following:

[0384] generating the first security element based on at least one of the second derived information and a security element derivation algorithm;

[0385] further generating the encrypted information based on a confidentiality algorithm;

[0386] further generating the integrity protection information based on an integrity algorithm;

[0387] further generating at least one of the encryption information and the integrity protection information based on the first calculation parameter;

[0388] The third operation;

[0389] The first calculation parameter includes at least one of the following:

[0390] Information in the terminal access network context;

[0391] the first identification information;

[0392] at least part of the first safety assistance information;

[0393] at least part of the second safety assistance information;

[0394] The second derived information includes at least one of the following:

[0395] Access network related keys;

[0396] Access layer AS layer related keys;

[0397] Keys in the terminal context;

[0398] The third safety requirement;

[0399] Information in the terminal access network context;

[0400] the first identification information;

[0401] at least part of the first safety assistance information;

[0402] at least part of the second safety assistance information;

[0403] The third operation includes at least one of the following:

[0404] receiving first information from a terminal;

[0405] receiving, from the terminal, first information carrying a third security parameter;

[0406] sending second information to the terminal;

[0407] A second security requirement is generated based on the fourth derived information and at least one of the first security requirements, the second security requirement includes at least one of a key and a secret stream, and the fourth derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an AS layer-related key, a key in the terminal context, and the third security parameter.

[0408] Optionally, the method includes at least one of the following:

[0409] The access network node performs security processing on the first information or a portion of the first information based on at least one of the following: the first security requirement or the second security requirement, the first calculation parameter, and the third security parameter;

[0410] The access network node performs security protection on the second information or part of the second information based on at least one of the following: the first security requirement or the second security requirement, the first calculation parameter, and the third security parameter.

[0411] Optionally, the security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.

[0412] Optionally, the terminal is in an idle state or an inactive state, or is in an idle state or an inactive state before sending the first information, or is in an idle state or an inactive state before receiving the second information.

[0413] Optionally, the target wireless signaling includes at least one of the following:

[0414] at least one first identification information and at least one first target information;

[0415] At least one pair of first identification information and first target information;

[0416] Wherein, the first target information and the first identification information are mapped one to one or more;

[0417] Alternatively, the first identification information and the first target information are a one-to-zero or one mapping;

[0418] Alternatively, there is a correspondence between N first identification information and all first target information, and N is less than or equal to the number of first identification information included in the target wireless signaling.

[0419] Optionally, the first identification information indicates a terminal, or is generated by a terminal identifier, or indicates a group of terminals.

[0420] Optionally, the target wireless signaling is any one of broadcast signaling, paging signaling, wireless short message, and system message;

[0421] Alternatively, the target wireless signaling is sent via at least one of a paging channel PCH, a multicast channel MCH, a broadcast channel BCH, and a downlink shared channel DL-SCH;

[0422] Alternatively, the target wireless signaling is sent through at least one of a physical downlink control channel PDCCH, a physical downlink shared channel PDSCH, a physical broadcast channel PBCH, and a physical multicast channel PMCH.

[0423] 5 , an embodiment of the present application further provides an interaction method, as shown in FIG5 , the interaction method includes:

[0424] Step 501: The core network node sends third information or target data to the access network node, where the third information includes second identification information and second target information.

[0425] The second target information includes at least one of the following:

[0426] First safety requirement or third safety requirement;

[0427] First algorithm information;

[0428] Second safety parameter;

[0429] Second security assistance information, where the second security assistance information includes information in the terminal core network context;

[0430] Among them, the first algorithm information packet security requirement derivation algorithm, confidentiality algorithm, and integrity algorithm; the first security requirement includes at least one of a secret key and a secret stream, the third security requirement includes at least one of a secret key and a secret stream, and the second identification information indicates the terminal, or is generated by the terminal identification, or indicates a group of terminals.

[0431] Optionally, the method further includes:

[0432] The core network node generates the first security requirement or the third security requirement based on at least one of the third derived information and the security requirement derivation algorithm;

[0433] The third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in a terminal context, the first algorithm information, the second security parameter, and at least part of the second security auxiliary information.

[0434] Optionally, the third information includes at least one of the following:

[0435] at least one second identification information and at least one second target information;

[0436] at least one pair of second identification information and second target information;

[0437] Wherein, the second target information and the second identification information are mapped one to one or more;

[0438] Alternatively, the second identification information and the second target information are a one-to-zero or one mapping;

[0439] Alternatively, there is a correspondence between K pieces of second identification information and all the second target information, and K is less than or equal to the number of second identification information.

[0440] Optionally, the method further includes:

[0441] The core network node receives second algorithm information from the terminal, where the second algorithm information is used to indicate at least one of the following: an algorithm supported by the terminal and an algorithm used by the terminal;

[0442] The first algorithm information is generated based on the second algorithm information.

[0443] 6 , an embodiment of the present application further provides an interaction method. As shown in FIG6 , the interaction method includes:

[0444] Step 601: An access network node sends target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information, where the encryption information and integrity protection information are generated based on a first security requirement.

[0445] Step 602: The terminal receives the target wireless signaling;

[0446] Step 603: If the terminal is associated with the first identification information, the terminal performs at least one of the following:

[0447] performing a first operation based on a first safety requirement;

[0448] Second operation;

[0449] The first operation includes at least one of the following:

[0450] decrypting the encrypted information;

[0451] Performing confidentiality processing on the encrypted information;

[0452] Performing confidentiality processing on the first target information;

[0453] Checking or verifying the integrity protection information;

[0454] performing secure processing on the first target information;

[0455] performing integrity checking or integrity processing on the first target information;

[0456] performing, based on the integrity protection information, integrity checking or integrity processing on at least one of the following: the first target information, part of the first target information, and the decryption result;

[0457] The second operation includes at least one of the following:

[0458] generating a second security requirement based on fourth derived information and at least one of the first security requirement;

[0459] Sending first information to the access network node;

[0460] Sending first information carrying a third security parameter to the access network node;

[0461] receiving second information from the access network node;

[0462] Among them, the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a secret key and a secret stream; the first derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in the terminal context, information in the terminal core network context, first identification information, and information in the terminal access network context; the fourth derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in the terminal context, information in the terminal core network context, first identification information, information in the terminal access network context, and the third security parameter; the second security requirement includes at least one of a key and a secret stream.

[0463] Optionally, the method further includes:

[0464] The core network node sends third information or target data to the access network node, where the third information includes the second identification information and the second target information;

[0465] The access network node learns or generates the first security requirement based on the second target information, and sends the target wireless signaling based on the third information;

[0466] The second target information includes at least one of the following: the first security requirement or the third security requirement, the first algorithm information, the second security parameter, and the second security auxiliary information; the first algorithm information includes at least one of a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm;

[0467] Among them, the second security auxiliary information includes information in the terminal core network context, the third security requirement includes at least one of a secret key and a secret flow, and the second identification information indicates the terminal, or is generated by the terminal identification, or indicates a group of terminals, or is related to the first identification information.

[0468] Optionally, the access network node generating the first security requirement based on the second target information includes:

[0469] The access network node generates the first security requirement based on at least one of the second derived information and the security requirement derivation algorithm;

[0470] The second derived information includes at least one of the following: an access network-related key, an AS layer-related key, a key in the terminal context, at least part of the content in the first security auxiliary information, at least part of the content in the second security auxiliary information, first identification information, and information in the terminal access network context.

[0471] Optionally, the method further includes:

[0472] The core network node generates the first security requirement or the third security requirement based on at least one of the third derived information and the security requirement derivation algorithm;

[0473] The third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in the terminal context, the second security parameter, and at least part of the second security auxiliary information.

[0474] Optionally, the target wireless signaling includes first safety assistance information;

[0475] and / or, the first derived information includes at least part of the first safety assistance information;

[0476] The first security auxiliary information includes at least one of first algorithm information, first security parameter, and second security parameter.

[0477] In an embodiment of the present application, the above-mentioned terminal can also execute the various steps of the terminal in the embodiment of Figure 2 above, the above-mentioned access network node can also execute the various steps of the access network node in the embodiment of Figure 4 above, and the core network node can also execute the various steps executed by the core network node in Figure 5 above. For details, please refer to the description of the above embodiment. In order to avoid repetition, it will not be repeated here.

[0478] The interactive method provided in the embodiment of the present application can be executed by an interactive device or an interactive system. In the embodiment of the present application, the interactive device and the interactive system provided in the embodiment of the present application are described by taking the method of executing the interactive method by an interactive device as an example.

[0479] 7 , an embodiment of the present application further provides an interactive device. As shown in FIG7 , the interactive device 700 includes:

[0480] A first receiving module 701 is configured to receive target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information;

[0481] The first execution module 702 is configured to execute at least one of the following:

[0482] performing a first operation based on a first safety requirement;

[0483] Second operation;

[0484] The first operation includes at least one of the following:

[0485] decrypting the encrypted information;

[0486] Performing confidentiality processing on the encrypted information;

[0487] Performing confidentiality processing on the first target information;

[0488] Checking or verifying the integrity protection information;

[0489] performing secure processing on the first target information;

[0490] performing integrity checking or integrity processing on the first target information;

[0491] performing, based on the integrity protection information, integrity checking or integrity processing on at least one of the following: the first target information, part of the first target information, and the decryption result;

[0492] The second operation includes at least one of the following:

[0493] generating a second security requirement based on fourth derived information and at least one of the first security requirement;

[0494] Sending first information to the access network node;

[0495] receiving second information from the access network node;

[0496] Among them, the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a key and a secret stream; the first derived information and the fourth derived information include at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, and a key in the terminal context; the second security requirement includes at least one of a key and a secret stream.

[0497] Optionally, the first target information further includes first safety auxiliary information;

[0498] The first security auxiliary information includes at least one of first algorithm information, first security parameter, and second security parameter;

[0499] The first algorithm information includes at least one of the following:

[0500] a security requirement derivation algorithm, the first security requirement being further generated based on the security requirement derivation algorithm;

[0501] At least one of a confidentiality algorithm and an integrity algorithm, the first operation is also performed based on at least one of the confidentiality algorithm and the integrity algorithm.

[0502] Optionally, the first derived information further includes at least one of the following:

[0503] at least part of the first safety assistance information;

[0504] Information in the terminal core network context;

[0505] Information in the terminal access network context;

[0506] The first identification information.

[0507] Optionally, the first execution module 702 is specifically configured to execute the first operation based on the first safety requirement and a first calculation parameter, where the first calculation parameter includes at least one of the following:

[0508] Information in the terminal core network context;

[0509] Information in the terminal access network context;

[0510] the first identification information;

[0511] At least part of the first safety assistance information.

[0512] Optionally, the information in the terminal core network context includes at least one of the following:

[0513] Terminal identification information;

[0514] The terminal's group identification information;

[0515] NAS signaling counting information;

[0516] NAS uplink signaling counting information;

[0517] NAS signaling counting information;

[0518] Count information of protocol data packets transmitted through NAS;

[0519] Count information of uplink protocol data packets transmitted through NAS;

[0520] Count information of downlink protocol data packets transmitted through NAS;

[0521] Alternatively, the information in the terminal access network context includes at least one of the following:

[0522] Terminal identification information;

[0523] The terminal's group identification information;

[0524] AS signaling counting information;

[0525] AS uplink signaling counting information;

[0526] AS downlink signaling counting information;

[0527] Counting information of protocol data packets;

[0528] Counting information of uplink protocol data packets;

[0529] Downlink protocol data packet count information.

[0530] Optionally, the first execution module 702 is further configured to execute at least one of the following:

[0531] Performing security protection on the first information or a portion of the first information based on at least one of the following: the first security requirement or the second security requirement, a first calculation parameter, and the third security parameter;

[0532] The second information or part of the second information is securely processed based on at least one of the following: the first security requirement or the second security requirement, a first calculation parameter, and the third security parameter.

[0533] Optionally, the security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.

[0534] Optionally, the target wireless signaling includes at least one of the following:

[0535] at least one first identification information and at least one first target information;

[0536] At least one pair of first identification information and first target information;

[0537] Wherein, the first target information and the first identification information are mapped one to one or more;

[0538] Alternatively, the first identification information and the first target information are a one-to-zero or one mapping;

[0539] Alternatively, there is a correspondence between N first identification information and all first target information, and N is less than or equal to the number of first identification information included in the target wireless signaling.

[0540] Optionally, the terminal is in an idle state or an inactive state, or is in an idle state or an inactive state before sending the first information, or is in an idle state or an inactive state before receiving the second information.

[0541] Optionally, the first execution module 702 is further configured to: send second algorithm information to the network side, where the second algorithm information is used to indicate at least one of the following: an algorithm supported by the terminal, and an algorithm used by the terminal;

[0542] The algorithm includes at least one of a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm.

[0543] Optionally, the first identification information indicates a terminal, or is generated by a terminal identifier, or indicates a group of terminals.

[0544] Optionally, the target wireless signaling includes any one of broadcast signaling, paging signaling, wireless short message, and system message;

[0545] Alternatively, the target wireless signaling is sent via at least one of a paging channel PCH, a multicast channel MCH, a broadcast channel BCH, and a downlink shared channel DL-SCH;

[0546] Alternatively, the target wireless signaling is sent through at least one of a physical downlink control channel PDCCH, a physical downlink shared channel PDSCH, a physical broadcast channel PBCH, and a physical multicast channel PMCH.

[0547] 8 , an embodiment of the present application further provides an interactive device. As shown in FIG8 , the interactive device 800 includes:

[0548] A first sending module 801 is configured to send target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information;

[0549] The encryption information and integrity protection information are generated based on a first security requirement, and the first security requirement includes at least one of a secret key and a secret stream.

[0550] Optionally, the interaction device further includes:

[0551] A second receiving module, configured to receive third information or target data from a core network node;

[0552] Wherein, the third information includes second identification information and second target information;

[0553] The second target information includes at least one of the following:

[0554] The first security requirement or the third security requirement, wherein the third security requirement includes at least one of a secret key and a secret stream;

[0555] First algorithm information;

[0556] Second safety parameter;

[0557] Second security assistance information, where the second security assistance information includes information in the terminal core network context;

[0558] The second identification information is used to indicate a terminal, or is generated by a terminal identifier, or indicates a group of terminals, or is related to the first identification information; and the first algorithm information includes at least one of the following:

[0559] Security element derivation algorithm, confidentiality algorithm, and integrity algorithm.

[0560] Optionally, the third information includes at least one of the following:

[0561] at least one second identification information and at least one second target information;

[0562] at least one pair of second identification information and second target information;

[0563] Wherein, the second target information and the second identification information are mapped one to one or more;

[0564] Alternatively, the second identification information and the second target information are a one-to-zero or one mapping;

[0565] Alternatively, there is a correspondence between K pieces of second identification information and all the second target information, and K is less than or equal to the number of second identification information included in the third information.

[0566] Optionally, the first target information further includes at least one of the following:

[0567] The first security auxiliary information includes at least one of first algorithm information, a first security parameter, and a second security parameter.

[0568] Optionally, the interaction device 800 further includes:

[0569] The second execution module is configured to execute at least one of the following:

[0570] generating the first security element based on at least one of the second derived information and a security element derivation algorithm;

[0571] further generating the encrypted information based on a confidentiality algorithm;

[0572] further generating the integrity protection information based on an integrity algorithm;

[0573] further generating at least one of the encryption information and the integrity protection information based on the first calculation parameter;

[0574] The third operation;

[0575] The first calculation parameter includes at least one of the following:

[0576] Information in the terminal access network context;

[0577] the first identification information;

[0578] at least part of the first safety assistance information;

[0579] at least part of the second safety assistance information;

[0580] The second derived information includes at least one of the following:

[0581] Access network related keys;

[0582] Access layer AS layer related keys;

[0583] Keys in the terminal context;

[0584] The third safety requirement;

[0585] Information in the terminal access network context;

[0586] the first identification information;

[0587] at least part of the first safety assistance information;

[0588] at least part of the second safety assistance information;

[0589] The third operation includes at least one of the following:

[0590] receiving first information from a terminal;

[0591] receiving, from the terminal, first information carrying a third security parameter;

[0592] sending second information to the terminal;

[0593] A second security requirement is generated based on the fourth derived information and at least one of the first security requirements, the second security requirement includes at least one of a key and a secret stream, and the fourth derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an AS layer-related key, a key in the terminal context, and the third security parameter.

[0594] Optionally, the second execution module is further configured to execute at least one of the following:

[0595] performing security processing on the first information or a portion of the first information based on at least one of the following: the first security requirement or the second security requirement, the first calculation parameter, and the third security parameter;

[0596] The second information or part of the second information is securely protected based on at least one of the following: the first security requirement or the second security requirement, the first calculation parameter, and the third security parameter.

[0597] Optionally, the security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.

[0598] Optionally, the terminal is in an idle state or an inactive state, or is in an idle state or an inactive state before sending the first information, or is in an idle state or an inactive state before receiving the second information.

[0599] Optionally, the target wireless signaling includes at least one of the following:

[0600] at least one first identification information and at least one first target information;

[0601] At least one pair of first identification information and first target information;

[0602] Wherein, the first target information and the first identification information are mapped one to one or more;

[0603] Alternatively, the first identification information and the first target information are a one-to-zero or one mapping;

[0604] Alternatively, there is a correspondence between N first identification information and all first target information, and N is less than or equal to the number of first identification information included in the target wireless signaling.

[0605] Optionally, the first identification information indicates a terminal, or is generated by a terminal identifier, or indicates a group of terminals.

[0606] Optionally, the target wireless signaling is any one of broadcast signaling, paging signaling, wireless short message, and system message;

[0607] Alternatively, the target wireless signaling is sent via at least one of a paging channel PCH, a multicast channel MCH, a broadcast channel BCH, and a downlink shared channel DL-SCH;

[0608] Alternatively, the target wireless signaling is sent through at least one of a physical downlink control channel PDCCH, a physical downlink shared channel PDSCH, a physical broadcast channel PBCH, and a physical multicast channel PMCH.

[0609] 9 , an embodiment of the present application further provides an interactive device. As shown in FIG9 , the interactive device 900 includes:

[0610] A second sending module 901 is configured to send third information or target data to an access network node, where the third information includes second identification information and second target information;

[0611] The second target information includes at least one of the following:

[0612] First safety requirement or third safety requirement;

[0613] First algorithm information;

[0614] Second safety parameter;

[0615] Second security assistance information, where the second security assistance information includes information in the terminal core network context;

[0616] Among them, the first algorithm information packet security requirement derives at least one of an algorithm, a confidentiality algorithm, and an integrity algorithm; the first security requirement includes at least one of a secret key and a secret stream, the third security requirement includes at least one of a secret key and a secret stream, and the second identification information indicates the terminal.

[0617] Optionally, the interaction device 900 further includes:

[0618] a third execution module, configured to generate the first security requirement or the third security requirement based on at least one of third derived information and the security requirement derivation algorithm;

[0619] The third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in a terminal context, the first algorithm information, the second security parameter, and at least part of the second security auxiliary information.

[0620] Optionally, the third information includes at least one of the following:

[0621] at least one second identification information and at least one second target information;

[0622] at least one pair of second identification information and second target information;

[0623] Wherein, the second target information and the second identification information are mapped one to one or more;

[0624] Alternatively, the second identification information and the second target information are a one-to-zero or one mapping;

[0625] Alternatively, there is a correspondence between K pieces of second identification information and all the second target information, and K is less than or equal to the number of second identification information.

[0626] Optionally, the interaction device 900 further includes:

[0627] A third receiving module is configured to receive second algorithm information from the terminal, where the second algorithm information is used to indicate at least one of the following: an algorithm supported by the terminal and an algorithm used by the terminal;

[0628] The first algorithm information is generated based on the second algorithm information.

[0629] The interactive device in the embodiments of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or chip. The electronic device can be a terminal or other device other than a terminal. For example, the terminal can include but is not limited to the types of terminal 11 listed above, and the other device can be a server, a network attached storage (NAS), etc., which is not specifically limited in the embodiments of the present application.

[0630] The interactive device provided in the embodiment of the present application can implement the various processes implemented in the method embodiments of Figures 2 to 5 and achieve the same technical effects. To avoid repetition, they will not be described here.

[0631] The embodiment of the present application further provides an interactive system, which includes: an access network node and a terminal, wherein:

[0632] The access network node is configured to send target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information, where the encryption information and integrity protection information are generated based on a first security requirement;

[0633] The terminal is configured to receive the target wireless signaling; and, if the terminal is associated with the first identification information, perform at least one of the following:

[0634] performing a first operation based on a first safety requirement;

[0635] Second operation;

[0636] The first operation includes at least one of the following:

[0637] decrypting the encrypted information;

[0638] Performing confidentiality processing on the encrypted information;

[0639] Performing confidentiality processing on the first target information;

[0640] Checking or verifying the integrity protection information;

[0641] performing secure processing on the first target information;

[0642] performing integrity checking or integrity processing on the first target information;

[0643] performing, based on the integrity protection information, integrity checking or integrity processing on at least one of the following: the first target information, part of the first target information, and the decryption result;

[0644] The second operation includes at least one of the following:

[0645] generating a second security requirement based on fourth derived information and at least one of the first security requirement;

[0646] Sending first information to the access network node;

[0647] receiving second information from the access network node;

[0648] Among them, the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a secret key and a secret stream; the first derived information and the fourth derived information include at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in the terminal context, information in the terminal core network context, first identification information, and information in the terminal access network context; the second security requirement includes at least one of a key and a secret stream.

[0649] Optionally, the interactive system further includes a core network node, the core network node being configured to send third information or target data to the access network node, the third information including second identification information and second target information;

[0650] The access network node learns or generates the first security requirement based on the second target information, and sends the target wireless signaling based on the third information;

[0651] The second target information includes at least one of the following: the first security requirement or the third security requirement, the first algorithm information, the second security parameter, and the second security auxiliary information; the first algorithm information includes at least one of a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm;

[0652] Among them, the second security auxiliary information includes information in the terminal core network context, the third security requirement includes at least one of a secret key and a secret flow, and the second identification information indicates the terminal, or is generated by the terminal identification, or indicates a group of terminals, or is related to the first identification information.

[0653] Optionally, the access network node is specifically configured to generate the first security requirement based on at least one of the second derived information and the security requirement derivation algorithm;

[0654] The second derived information includes at least one of the following: an access network-related key, an AS layer-related key, a key in the terminal context, at least part of the content in the first security auxiliary information, at least part of the content in the second security auxiliary information, first identification information, and information in the terminal access network context.

[0655] Optionally, the core network node is further configured to generate the first security requirement or the third security requirement based on at least one of third derived information and the security requirement derivation algorithm;

[0656] The third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in the terminal context, the second security parameter, and at least part of the second security auxiliary information.

[0657] Optionally, the target wireless signaling includes first safety assistance information;

[0658] and / or, the first derived information includes at least part of the first safety assistance information;

[0659] The first security auxiliary information includes at least one of first algorithm information, first security parameter, and second security parameter.

[0660] It should be noted that the above description of the interactive system is only a partial example, and the interactive system may include at least two of the terminals, access network nodes and core network nodes in the above embodiments.

[0661] As shown in Figure 10, an embodiment of the present application also provides a communication device 1000, including a processor 1001 and a memory 1002, and the memory 1002 stores a program or instruction that can be run on the processor 1001. When the program or instruction is executed by the processor 1001, the various steps of the above-mentioned interaction method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0662] The present application also provides a terminal including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps of the method embodiment shown in FIG2 . This terminal embodiment corresponds to the aforementioned terminal-side method embodiment, and each implementation process and implementation method of the aforementioned method embodiment can be applied to this terminal embodiment and achieve the same technical effects. Specifically, FIG11 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of the present application.

[0663] The terminal 1100 includes but is not limited to: a radio frequency unit 1101, a network module 1102, an audio output unit 1103, an input unit 1104, a sensor 1105, a display unit 1106, a user input unit 1107, an interface unit 1108, a memory 1109 and at least some of the components of the processor 1110.

[0664] Those skilled in the art will appreciate that the terminal 1100 may also include a power supply (such as a battery) to power various components. The power supply may be logically connected to the processor 1110 via a power management system, thereby enabling the power management system to manage charging, discharging, and power consumption. The terminal structure shown in FIG11 does not limit the terminal. The terminal may include more or fewer components than shown, or combine certain components, or arrange the components differently, which will not be described in detail here.

[0665] It should be understood that in an embodiment of the present application, the input unit 1104 may include a graphics processing unit (GPU) 11041 and a microphone 11042, and the graphics processor 11041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 1106 may include a display panel 11061, and the display panel 11061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 1107 includes a touch panel 11071 and at least one of other input devices 11072. The touch panel 11071 is also called a touch screen. The touch panel 11071 may include two parts: a touch detection device and a touch controller. Other input devices 11072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be repeated here.

[0666] In the embodiment of the present application, after receiving downlink data from a network-side device, the RF unit 1101 may transmit the data to the processor 1110 for processing. Furthermore, the RF unit 1101 may send uplink data to the network-side device. Typically, the RF unit 1101 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, and the like.

[0667] The memory 1109 can be used to store software programs or instructions and various data. The memory 1109 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 1109 may include a volatile memory or a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DRRAM). The memory 1109 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.

[0668] Processor 1110 may include one or more processing units. Optionally, processor 1110 integrates an application processor and a modem processor. The application processor primarily handles operations related to the operating system, user interface, and application programs, while the modem processor primarily processes wireless communication signals, such as a baseband processor. It is understood that the modem processor may not be integrated into processor 1110.

[0669] The radio frequency unit 1101 is configured to receive target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information;

[0670] If the terminal is associated with the first identification information, perform at least one of the following:

[0671] performing a first operation based on a first safety requirement;

[0672] Second operation;

[0673] The first operation includes at least one of the following:

[0674] decrypting the encrypted information;

[0675] Performing confidentiality processing on the encrypted information;

[0676] Performing confidentiality processing on the first target information;

[0677] Checking or verifying the integrity protection information;

[0678] performing secure processing on the first target information;

[0679] performing integrity checking or integrity processing on the first target information;

[0680] performing, based on the integrity protection information, integrity checking or integrity processing on at least one of the following: the first target information, part of the first target information, and the decryption result;

[0681] The second operation includes at least one of the following:

[0682] generating a second security requirement based on fourth derived information and at least one of the first security requirement;

[0683] Sending first information to the access network node;

[0684] Sending first information carrying a third security parameter to the access network node;

[0685] receiving second information from the access network node;

[0686] Among them, the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a key and a secret stream; the first derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, and a key in the terminal context; the fourth derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in the terminal context, and the third security parameter; the second security requirement includes at least one of a key and a secret stream. It can be understood that the implementation process of each implementation method mentioned in this embodiment can refer to the relevant description of the terminal-side method embodiment and achieve the same or corresponding technical effects. To avoid repetition, it will not be described here.

[0687] The present application also provides a network-side device, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps of the method embodiment shown in FIG4 . This network-side device embodiment corresponds to the aforementioned network-side device method embodiment, and each implementation process and implementation method of the aforementioned method embodiment are applicable to this network-side device embodiment and can achieve the same technical effects.

[0688] Specifically, embodiments of the present application also provide a network-side device. As shown in Figure 12, network-side device 1200 includes an antenna 1201, a radio frequency device 1202, a baseband device 1203, a processor 1204, and a memory 1205. Antenna 1201 is connected to radio frequency device 1202. In the uplink direction, radio frequency device 1202 receives information via antenna 1201 and sends the received information to baseband device 1203 for processing. In the downlink direction, baseband device 1203 processes the information to be transmitted and sends it to radio frequency device 1202. Radio frequency device 1202 processes the received information and then sends it through antenna 1201.

[0689] The method executed by the network-side device in the above embodiment may be implemented in the baseband device 1203 , which includes a baseband processor.

[0690] The baseband device 1203 may include, for example, at least one baseband board, on which multiple chips are arranged, as shown in Figure 12, one of which is a baseband processor, for example, which is connected to the memory 1205 through a bus interface to call the program in the memory 1205 and execute the network side device operations shown in the above method embodiment.

[0691] The network side device may further include a network interface 1206 , which is, for example, a Common Public Radio Interface (CPRI).

[0692] Specifically, the network side device 1200 of the embodiment of the present application also includes: instructions or programs stored in the memory 1205 and executable on the processor 1204. The processor 1204 calls the instructions or programs in the memory 1205 to execute the method of execution of each module shown in Figure 8 and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0693] Specifically, the embodiment of the present application further provides a network-side device. As shown in FIG13 , the network-side device 1300 includes a processor 1301, a network interface 1302, and a memory 1303. The network interface 1302 is, for example, a common public radio interface (CPRI).

[0694] Specifically, the network side device 1300 of the embodiment of the present application also includes: instructions or programs stored in the memory 1303 and executable on the processor 1301. The processor 1301 calls the instructions or programs in the memory 1303 to execute the method of execution of each module shown in Figure 9 and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0695] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned interaction method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0696] The processor is the processor in the terminal described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk. In some examples, the readable storage medium may be a non-transitory readable storage medium.

[0697] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned interaction method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0698] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0699] An embodiment of the present application further provides a computer program / program product, which is stored in a storage medium. The computer program / program product is executed by at least one processor to implement the various processes of the above-mentioned interaction method embodiment and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0700] An embodiment of the present application also provides a wireless communication system, including: a terminal and a network side device, wherein the terminal can be used to execute the steps of the terminal side interaction method described above, and the network side device can be used to execute the steps of the access network node and core network node interaction method described above.

[0701] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the statement "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be noted that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0702] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of a computer software product plus a necessary general-purpose hardware platform, or of course, by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes a number of instructions for enabling a terminal or network-side device to execute the methods described in each embodiment of the present application.

[0703] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms of implementation methods without departing from the purpose of this application and the scope of protection of the claims. These implementation methods are all within the protection of this application.

Claims

1. An interactive method, wherein: include: The terminal receives target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information; When the terminal is related to the first identification information, the terminal performs at least one of the following: Performing a first operation based on a first safety requirement; Second operation: The first operation includes at least one of the following: decrypting the encrypted information; Performing confidentiality processing on the encrypted information; Performing confidentiality processing on the first target information; Checking or verifying the integrity protection information; performing security processing on the first target information; Performing integrity checking or integrity processing on the first target information; Based on the integrity protection information, perform integrity checking or integrity processing on at least one of the following: the first target information, part of the content in the first target information, and the decryption result; The second operation includes at least one of the following: generating a second security requirement based on fourth derived information and at least one of the first security requirements; Sending first information to an access network node; Sending first information carrying a third security parameter to an access network node; receiving second information from an access network node; Among them, the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a key and a secret stream; the first derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, and a key in a terminal context; the fourth derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in a terminal context, and the third security parameter; the second security requirement includes at least one of a key and a secret stream.

2. The method according to claim 1, wherein: The first target information also includes first safety auxiliary information; The first security auxiliary information includes at least one of first algorithm information, first security parameter, and second security parameter; The first algorithm information includes at least one of the following: a security requirement derivation algorithm, the first security requirement being further generated based on the security requirement derivation algorithm; At least one of a confidentiality algorithm and an integrity algorithm, and the first operation is also performed based on at least one of the confidentiality algorithm and the integrity algorithm.

3. The method according to claim 1 or 2, wherein: The first derived information further includes at least one of the following: at least part of the first safety assistance information; Information in the terminal core network context; Information in the terminal access network context; The first identification information.

4. The method according to any one of claims 1 to 3, wherein: The terminal performs a first operation based on a first security requirement, including: The terminal performs the first operation based on the first security requirement and a first calculation parameter, where the first calculation parameter includes at least one of the following: Information in the terminal core network context; Information in the terminal access network context; the first identification information; At least part of the first safety assistance information.

5. The method according to claim 3 or 4, wherein: The information in the terminal core network context includes at least one of the following: Terminal identification information; The terminal's group identification information; NAS signaling counting information; NAS uplink signaling counting information; NAS signaling count information; Count information of protocol data packets transmitted through NAS; Count information of uplink protocol data packets transmitted through NAS; Count information of downlink protocol data packets transmitted through NAS; Or, the information in the terminal access network context includes at least one of the following: Terminal identification information; The terminal's group identification information; AS signaling counting information; Counting information of AS uplink signaling; Counting information of AS downlink signaling; Counting information of protocol data packets; Counting information of uplink protocol data packets; Downstream protocol data packet count information.

6. The method according to any one of claims 1 to 5, wherein: The method comprises at least one of the following: The terminal performs security protection on the first information or part of the first information based on at least one of the following: the first security requirement or the second security requirement, a first calculation parameter, and the third security parameter; The terminal performs security processing on the second information or part of the second information based on at least one of the following: the first security requirement or the second security requirement, a first calculation parameter, and the third security parameter.

7. The method according to claim 6, wherein: The security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.

8. The method according to any one of claims 1 to 7, wherein: The target wireless signaling includes at least one of the following: at least one first identification information and at least one first target information; At least one pair of first identification information and first target information; Wherein, the first target information and the first identification information are one-to-one or multiple mappings; Alternatively, the first identification information and the first target information are a one-to-zero or one mapping; Alternatively, there is a correspondence between N first identification information and all first target information, and N is less than or equal to the number of first identification information included in the target wireless signaling.

9. The method according to any one of claims 1 to 8, wherein: The terminal is in an idle state or an inactive state, or is in an idle state or an inactive state before sending the first information, or is in an idle state or an inactive state before receiving the second information.

10. The method according to any one of claims 1 to 9, wherein: Before the terminal receives the target wireless signaling, the method further includes: The terminal sends second algorithm information to the network side, where the second algorithm information is used to indicate at least one of the following: an algorithm supported by the terminal and an algorithm used by the terminal; The algorithm includes at least one of a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm.

11. The method according to any one of claims 1 to 10, wherein: The first identification information indicates a terminal, or is generated by a terminal identifier, or indicates a group of terminals.

12. The method according to any one of claims 1 to 11, wherein: The target wireless signaling includes any one of broadcast signaling, paging signaling, wireless short message, and system message; Alternatively, the target wireless signaling is sent through at least one of a paging channel PCH, a multicast channel MCH, a broadcast channel BCH, and a downlink shared channel DL-SCH; Alternatively, the target wireless signaling is sent via at least one of a physical downlink control channel PDCCH, a physical downlink shared channel PDSCH, a physical broadcast channel PBCH, and a physical multicast channel PMCH.

13. An interactive method, wherein: include: The access network node sends a target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information; The encryption information and integrity protection information are generated based on a first security requirement, and the first security requirement includes at least one of a secret key and a secret stream.

14. The method according to claim 13, wherein: Before the access network node sends the target wireless signaling, the method further includes: The access network node receives third information or target data from the core network node; Wherein, the third information includes second identification information and second target information; The second target information includes at least one of the following: The first security requirement or the third security requirement, wherein the third security requirement includes at least one of a secret key and a secret stream; First algorithm information; Second safety parameter; Second security assistance information, wherein the second security assistance information includes information in the terminal core network context; The second identification information is used to indicate a terminal, or is generated by a terminal identification, or indicates a group of terminals, or is related to the first identification information; and the first algorithm information includes at least one of the following: Security element derivation algorithm, confidentiality algorithm, and integrity algorithm.

15. The method according to claim 14, wherein: The third information includes at least one of the following: at least one second identification information and at least one second target information; at least one pair of second identification information and second target information; Wherein, the second target information and the second identification information are one-to-one or multiple mappings; Alternatively, the second identification information and the second target information are a one-to-zero or one mapping; Alternatively, there is a correspondence between K pieces of second identification information and all the second target information, and K is less than or equal to the number of second identification information included in the third information.

16. The method according to any one of claims 13 to 15, wherein: The first target information also includes at least one of the following: The first safety auxiliary information includes at least one of first algorithm information, a first safety parameter, and a second safety parameter.

17. The method according to any one of claims 13 to 16, wherein: The method comprises: The access network node performs at least one of the following: generating the first security element based on at least one of the second derived information and a security element derivation algorithm; further generating the encrypted information based on a confidentiality algorithm; further generating the integrity protection information based on an integrity algorithm; further generating at least one of the encryption information and the integrity protection information based on the first calculation parameter; The third operation: Wherein, the first calculation parameter includes at least one of the following: Information in the terminal access network context; the first identification information; at least part of the first safety assistance information; at least part of the second safety auxiliary information; The second derived information includes at least one of the following: Access network related keys; Access layer AS layer related keys; Keys in the terminal context; The third safety requirement: Information in the terminal access network context; the first identification information; at least part of the first safety assistance information; at least part of the second safety auxiliary information; The third operation includes at least one of the following: receiving first information from a terminal; receiving, from a terminal, first information carrying a third security parameter; Sending second information to the terminal; A second security requirement is generated based on fourth derived information and at least one of the first security requirements, the second security requirement including at least one of a key and a secret stream, the fourth derived information including at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an AS layer-related key, a key in a terminal context, and the third security parameter.

18. The method according to claim 17, wherein: The method comprises at least one of the following: The access network node performs security processing on the first information or part of the first information based on at least one of the following: the first security requirement or the second security requirement, the first calculation parameter, and the third security parameter; The access network node performs security protection on the second information or part of the second information based on at least one of the following: the first security requirement or the second security requirement, the first calculation parameter, and the third security parameter.

19. The method according to claim 18, wherein: The security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.

20. The method according to any one of claims 17 to 19, wherein: The terminal is in an idle state or an inactive state, or is in an idle state or an inactive state before sending the first information, or is in an idle state or an inactive state before receiving the second information.

21. The method according to any one of claims 13 to 20, wherein: The target wireless signaling includes at least one of the following: at least one first identification information and at least one first target information; At least one pair of first identification information and first target information; Wherein, the first target information and the first identification information are one-to-one or multiple mappings; Alternatively, the first identification information and the first target information are a one-to-zero or one mapping; Alternatively, there is a correspondence between N first identification information and all first target information, and N is less than or equal to the number of first identification information included in the target wireless signaling.

22. The method according to any one of claims 13 to 21, wherein: The first identification information indicates a terminal, or is generated by a terminal identifier, or indicates a group of terminals.

23. The method according to any one of claims 13 to 22, wherein: The target wireless signaling is any one of broadcast signaling, paging signaling, wireless short message, and system message; Alternatively, the target wireless signaling is sent through at least one of a paging channel PCH, a multicast channel MCH, a broadcast channel BCH, and a downlink shared channel DL-SCH; Alternatively, the target wireless signaling is sent via at least one of a physical downlink control channel PDCCH, a physical downlink shared channel PDSCH, a physical broadcast channel PBCH, and a physical multicast channel PMCH.

24. An interactive method, wherein: include: The core network node sends third information or target data to the access network node, where the third information includes second identification information and second target information; The second target information includes at least one of the following: First safety requirement or third safety requirement; First algorithm information; Second safety parameter; Second security assistance information, wherein the second security assistance information includes information in the terminal core network context; Among them, the first algorithm information packet security requirement derives at least one of an algorithm, a confidentiality algorithm, and an integrity algorithm; the first security requirement includes at least one of a secret key and a secret stream, the third security requirement includes at least one of a secret key and a secret stream, and the second identification information indicates a terminal, or is generated by a terminal identification, or indicates a group of terminals.

25. The method according to claim 24, wherein: The method further comprises: The core network node generates the first security requirement or the third security requirement based on at least one of the third derived information and the security requirement derivation algorithm; The third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in a terminal context, the first algorithm information, the second security parameter, and at least part of the second security auxiliary information.

26. The method according to claim 24 or 25, wherein: The third information includes at least one of the following: at least one second identification information and at least one second target information; at least one pair of second identification information and second target information; Wherein, the second target information and the second identification information are one-to-one or multiple mappings; Alternatively, the second identification information and the second target information are a one-to-zero or one mapping; Alternatively, there is a correspondence between K pieces of second identification information and all the second target information, and K is less than or equal to the number of second identification information.

27. The method according to any one of claims 24 to 26, wherein: The method further comprises: The core network node receives second algorithm information from the terminal, where the second algorithm information is used to indicate at least one of the following: an algorithm supported by the terminal and an algorithm used by the terminal; The first algorithm information is generated based on the second algorithm information.

28. An interactive method, wherein: include: The access network node sends a target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information, where the encryption information and the integrity protection information are generated based on the first security requirement; The terminal receives the target wireless signaling; When the terminal is related to the first identification information, the terminal performs at least one of the following: Performing a first operation based on a first safety requirement; Second operation: The first operation includes at least one of the following: decrypting the encrypted information; Performing confidentiality processing on the encrypted information; Performing confidentiality processing on the first target information; Checking or verifying the integrity protection information; performing security processing on the first target information; Performing integrity checking or integrity processing on the first target information; Based on the integrity protection information, perform integrity checking or integrity processing on at least one of the following: the first target information, part of the content in the first target information, and the decryption result; The second operation includes at least one of the following: generating a second security requirement based on fourth derived information and at least one of the first security requirements; Sending first information to an access network node; Sending first information carrying a third security parameter to an access network node; receiving second information from an access network node; Among them, the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a secret key and a secret stream; the first derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in a terminal context, information in a terminal core network context, first identification information, and information in a terminal access network context; the fourth derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in a terminal context, information in a terminal core network context, first identification information, information in a terminal access network context, and the third security parameter; the second security requirement includes at least one of a key and a secret stream.

29. The method according to claim 28, wherein: The method further comprises: The core network node sends third information or target data to the access network node, where the third information includes second identification information and second target information; The access network node learns or generates the first security requirement based on the second target information, and sends the target wireless signaling based on the third information; The second target information includes at least one of the following: the first security requirement or the third security requirement, the first algorithm information, the second security parameter, and the second security auxiliary information; the first algorithm information includes at least one of the security requirement derivation algorithm, the confidentiality algorithm, and the integrity algorithm; Among them, the second security auxiliary information includes information in the terminal core network context, the third security requirement includes at least one of a secret key and a secret stream, and the second identification information indicates the terminal, or is generated by the terminal identification, or indicates a group of terminals, or is related to the first identification information.

30. The method of claim 29, wherein: The access network node generating the first security requirement based on the second target information includes: The access network node generates the first security requirement based on at least one of the second derived information and the security requirement derivation algorithm; Among them, the second derived information includes at least one of the following: access network related keys, AS layer related keys, keys in the terminal context, at least part of the content of the first security auxiliary information, at least part of the content of the second security auxiliary information, first identification information, and information in the terminal access network context.

31. The method of claim 29, wherein: The method further comprises: The core network node generates the first security requirement or the third security requirement based on at least one of the third derived information and the security requirement derivation algorithm; The third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in a terminal context, the second security parameter, and at least part of the content of the second security auxiliary information.

32. The method according to any one of claims 28 to 31, wherein: The target wireless signaling includes first safety assistance information; and / or, the first derived information includes at least part of the first safety auxiliary information; The first safety auxiliary information includes at least one of first algorithm information, first safety parameter, and second safety parameter.

33. An interactive device, applied to a terminal, wherein: include: A first receiving module, configured to receive a target wireless signaling, wherein the target wireless signaling includes first identification information and first target information, wherein the first target information includes at least one of encryption information and integrity protection information; The first execution module is configured to execute at least one of the following: Performing a first operation based on a first safety requirement; Second operation: The first operation includes at least one of the following: decrypting the encrypted information; Performing confidentiality processing on the encrypted information; Performing confidentiality processing on the first target information; Checking or verifying the integrity protection information; performing security processing on the first target information; Performing integrity checking or integrity processing on the first target information; Based on the integrity protection information, perform integrity checking or integrity processing on at least one of the following: the first target information, part of the content in the first target information, and the decryption result; The second operation includes at least one of the following: generating a second security requirement based on fourth derived information and at least one of the first security requirements; Sending first information to an access network node; receiving second information from an access network node; Among them, the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a key and a secret stream; the first derived information and the fourth derived information include at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, and a key in the terminal context; the second security requirement includes at least one of a key and a secret stream.

34. The interactive device according to claim 33, wherein: The first target information also includes first safety auxiliary information; The first security auxiliary information includes at least one of first algorithm information, first security parameter, and second security parameter; The first algorithm information includes at least one of the following: a security requirement derivation algorithm, the first security requirement being further generated based on the security requirement derivation algorithm; At least one of a confidentiality algorithm and an integrity algorithm, and the first operation is also performed based on at least one of the confidentiality algorithm and the integrity algorithm.

35. The interactive device according to claim 33 or 34, wherein: The first derived information further includes at least one of the following: at least part of the first safety assistance information; Information in the terminal core network context; Information in the terminal access network context; The first identification information.

36. An interactive device according to any one of claims 33 to 35, wherein: The performing of the first operation based on the first safety requirement includes: The first execution module executes the first operation based on the first safety requirement and a first calculation parameter, where the first calculation parameter includes at least one of the following: Information in the terminal core network context; Information in the terminal access network context; the first identification information; At least part of the first safety assistance information.

37. An interactive device, applied to an access network node, wherein: include: A first sending module, configured to send a target wireless signaling, wherein the target wireless signaling includes first identification information and first target information, wherein the first target information includes at least one of encryption information and integrity protection information; The encryption information and integrity protection information are generated based on a first security requirement, and the first security requirement includes at least one of a secret key and a secret stream.

38. The interactive device according to claim 37, wherein: The interactive device also includes: A second receiving module, configured to receive third information or target data from a core network node before the first sending module sends the target wireless signaling; Wherein, the third information includes second identification information and second target information; The second target information includes at least one of the following: The first security requirement or the third security requirement, wherein the third security requirement includes at least one of a secret key and a secret stream; First algorithm information; Second safety parameter; Second security assistance information, wherein the second security assistance information includes information in the terminal core network context; The second identification information is used to indicate a terminal, or is generated by a terminal identification, or indicates a group of terminals, or is related to the first identification information; and the first algorithm information includes at least one of the following: Security element derivation algorithm, confidentiality algorithm, and integrity algorithm.

39. The interactive device according to claim 38, wherein: The third information includes at least one of the following: at least one second identification information and at least one second target information; at least one pair of second identification information and second target information; Wherein, the second target information and the second identification information are one-to-one or multiple mappings; Alternatively, the second identification information and the second target information are a one-to-zero or one mapping; Alternatively, there is a correspondence between K pieces of second identification information and all the second target information, and K is less than or equal to the number of second identification information included in the third information.

40. An interactive device, applied to a core network node, wherein: include: A second sending module, used to send third information or target data to the access network node, wherein the third information includes second identification information and second target information; The second target information includes at least one of the following: First safety requirement or third safety requirement; First algorithm information; Second safety parameter; Second security assistance information, wherein the second security assistance information includes information in the terminal core network context; Among them, the first algorithm information packet security requirement derives at least one of an algorithm, a confidentiality algorithm, and an integrity algorithm; the first security requirement includes at least one of a secret key and a secret stream, the third security requirement includes at least one of a secret key and a secret stream, and the second identification information indicates a terminal.

41. The interactive device according to claim 40, wherein: The interactive device also includes: A third execution module, configured to generate the first security requirement or the third security requirement based on at least one of third derived information and the security requirement derivation algorithm; The third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in a terminal context, the first algorithm information, the second security parameter, and at least part of the second security auxiliary information.

42. The interactive device according to claim 40 or 41, wherein: The third information includes at least one of the following: at least one second identification information and at least one second target information; at least one pair of second identification information and second target information; Wherein, the second target information and the second identification information are one-to-one or multiple mappings; Alternatively, the second identification information and the second target information are a one-to-zero or one mapping; Alternatively, there is a correspondence between K pieces of second identification information and all the second target information, and K is less than or equal to the number of second identification information.

43. An interactive device according to any one of claims 40 to 42, wherein: The interactive device also includes: A third receiving module is used to receive second algorithm information from the terminal, where the second algorithm information is used to indicate at least one of the following: an algorithm supported by the terminal, and an algorithm used by the terminal; The first algorithm information is generated based on the second algorithm information.

44. A terminal, wherein: The method comprises a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the interaction method according to any one of claims 1 to 12 are implemented.

45. A network side device, wherein: It comprises a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the interaction method as described in any one of claims 13 to 32 are implemented.

46. ​​An interactive system, wherein: include: Network side equipment and terminals, among which, The network side device is configured to execute the steps of the interaction method as described in any one of claims 13 to 32, and the terminal is configured to execute the steps of the interaction method as described in any one of claims 1 to 12.

47. A readable storage medium, wherein: The readable storage medium stores programs or instructions, and when the programs or instructions are executed by the processor, the steps of the interactive method according to any one of claims 1 to 32 are implemented.

Citation Information

Patent Citations

  • Method and apparatus for securely transmitting mobile network small data

    CN108347726A

  • Communication method and device

    CN115696319A

  • Core network device, access network device, communication terminal, communication system, and communication method

    US20210329452A1

  • GUTI reallocation for mt-edt

    US20230073757A1

  • Device authentication method and apparatus, and terminal and network function

    WO2023143418A1