Communication method and device
By carrying message verification code in the L1/L2 handover command, the security problem of handover command in inter-CU LTM is solved, and the security protection of cell handover between base stations is realized, preventing tampering and eavesdropping, and improving the security of the handover process.
Patent Information
- Application Number
- PCT/CN2023/142925
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-28
- Publication Date
- 2025-07-03
AI Technical Summary
In the prior art, the L1/L2 layer triggered mobility handover (LTM) mainly involves cell handover within the same base station and does not involve cell handover between base stations, resulting in the lack of security protection of handover commands transmitted through underlying signaling in the inter-CU LTM, and there is a risk of tampering and eavesdropping attacks.
The L1/L2 switching command carries a message verification code to verify the integrity of the switching command, introduces a security protection mechanism to prevent tampering and eavesdropping attacks.
Improves the security of the switching commands transmitted through the underlying signaling, prevents the switching commands from being tampered with or eavesdropped, and ensures the security and reliability of the switching process.
Smart Images

Figure CN2023142925_03072025_PF_FP_ABST
Abstract
Description
Communication method and device Technical Field
[0001] The present application relates to the field of communications, and more specifically, to a communication method and device. Background Art
[0002] Existing LTM (L1 / L2-Triggered Mobility) primarily involves L1 / L2 signaling to trigger handovers within the same base station. It doesn't involve handovers between base stations and, therefore, doesn't involve security parameter updates. However, related protocols discuss introducing inter-CU LTM. In inter-CU LTM, using underlying L1 / L2 signaling (MAC CE) to transmit security parameters or related indications can lead to security issues. Therefore, ensuring the security of handover commands transmitted via underlying signaling becomes a critical issue.
[0003] Summary of the Invention
[0004] The embodiments of the present application provide a communication method and device.
[0005] An embodiment of the present application provides a communication method performed by a terminal, including:
[0006] Receive a layer 1 L1 / layer 2 L2 switching command from a source access network device, wherein the L1 / L2 switching command carries indication information and a message check code, the indication information is used for the terminal to switch to the target access network device, and the message check code is used to verify the integrity of the L1 / L2 switching command.
[0007] An embodiment of the present application provides a communication method performed by a source access network device, including:
[0008] Send a layer 1 L1 / layer 2 L2 switching command to the terminal, wherein the L1 / L2 switching command carries indication information and a message check code, the indication information is used for the terminal to switch to the target access network device, and the message check code is used to verify the integrity of the L1 / L2 switching command.
[0009] An embodiment of the present application provides a terminal, including:
[0010] The first communication unit is used to receive a layer 1 L1 / layer 2 L2 switching command from a source access network device, wherein the L1 / L2 switching command carries indication information and a message check code, the indication information is used for the terminal to switch to the target access network device, and the message check code is used to verify the integrity of the L1 / L2 switching command.
[0011] An embodiment of the present application provides a source access network device, including:
[0012] The second communication unit is used to send a layer 1 L1 / layer 2 L2 switching command to the terminal, wherein the L1 / L2 switching command carries indication information and a message check code, the indication information is used for the terminal to switch to the target access network device, and the message check code is used to verify the integrity of the L1 / L2 switching command.
[0013] By adopting the solution provided in this embodiment, a message verification code can be included in the L1 / L2 handover command used to instruct the terminal to switch to the target access network device. This message verification code is used to verify the integrity of the L1 / L2 handover command. In this way, a security protection mechanism is introduced during the L1 / L2 handover process, preventing tampering attacks or eavesdropping attacks on the handover command message transmitted via the underlying signaling, thereby improving the security of the handover command transmitted via the underlying signaling. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] FIG1 is a schematic diagram of an application scenario according to an embodiment of the present application.
[0015] FIG2 is a schematic flowchart of a communication method according to an embodiment of the present application.
[0016] FIG3 is a schematic flowchart of a communication method according to another embodiment of the present application.
[0017] 4 to 9 are various schematic flow charts of a communication method according to an embodiment of the present application in a single connection scenario or a dual connection scenario.
[0018] FIG10 is a schematic block diagram of a terminal according to an embodiment of the present application.
[0019] FIG11 is a schematic block diagram of a source access network device according to an embodiment of the present application. DETAILED DESCRIPTION
[0020] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.
[0021] The embodiments of the present application describe various embodiments in conjunction with network devices and terminals. The terminals can be mobile or fixed, and can also be referred to as mobile stations, user units, etc. The terminal can be a site in a WLAN, and can be a smart terminal, wireless modem, laptop computer, tablet computer, or other terminal. In the embodiments of the present application, the terminal can be a VR terminal / AR terminal, an industrial control terminal, an unmanned driving terminal, a telemedicine terminal, a smart grid terminal, a transportation safety terminal, a smart city terminal, or a wireless terminal for a smart home, etc. As an example and not a limitation, in the embodiments of the present application, the terminal can also be a wearable device.
[0022] In the embodiment of the present application, the network device may be a device for communicating with a terminal, an access point in a WLAN, an evolved base station in LTE, or a relay station, or a network device (gNB) in an in-vehicle device, a wearable device, and an NR network, or a network device in a future evolved PLMN network or a network device in a non-terrestrial network. As an example and not a limitation, in the embodiment of the present application, the network device may have a mobile feature, for example, the network device may be a mobile device.
[0023] To facilitate understanding of the technical solutions of the embodiments of the present application, the relevant technologies of the embodiments of the present application are described below. The following relevant technologies can be arbitrarily combined with the technical solutions of the embodiments of the present application as optional solutions, and they all fall within the protection scope of the embodiments of the present application.
[0024] Figure 1 exemplarily illustrates a communication system 100. The communication system includes a network device 110 and two terminals 120. In one possible implementation, the communication system 100 may include multiple network devices 110, and each network device 110 may include a different number of terminals 120 within its coverage area, although this embodiment of the present application does not limit this. In one possible implementation, the communication system 100 may also include a mobility management entity, access and mobility management functions, and other network entities, although this embodiment of the present application does not limit this. The network devices may include access network devices and core network devices. That is, the communication system may also include multiple core networks for communicating with the access network devices. The access network devices may be base stations of LTE, LTE-A, or NR systems. Taking the communication system shown in Figure 1 as an example, the communication devices may include network devices and terminals with communication functions. The communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities, although this embodiment of the present application does not limit this.
[0025] Figure 2 is a schematic flow chart of a communication method executed by a terminal according to an embodiment of the present application. The method includes at least part of the following contents.
[0026] S210. Receive a layer 1 (Layer 1, L1) / layer 2 (Layer 2, L2) switching command from a source access network device, wherein the L1 / L2 switching command carries indication information and a message check code, the indication information is used for the terminal to switch to the target access network device, and the message check code is used to verify the integrity of the L1 / L2 switching command.
[0027] Figure 3 is a schematic flow chart of a communication method performed by a source access network device according to another embodiment of the present application. The method includes at least part of the following contents.
[0028] S310. Send an L1 / L2 switching command to the terminal, wherein the L1 / L2 switching command carries indication information and a message check code, the indication information is used for the terminal to switch to the target access network device, and the message check code is used to verify the integrity of the L1 / L2 switching command.
[0029] The L1 / L2 switching command may be carried by a MAC (Medium Access Control) CE (Control Element).
[0030] The L1 / L2 handover command may also be alternatively described as L1 / L2 signaling, or L1 and / or L2 handover command, or cell switch command, etc., and all possible representations or names of the L1 / L2 handover command are not limited or exhaustive here.
[0031] The message check code may be a message integrity check code (MIC) or a message authentication code (MAC). It should be noted that, in order to distinguish it from a MAC (Medium Access Control), MIC is used in some examples below to represent a message check code. These examples do not limit all possible types of message check codes.
[0032] In some possible implementations, in a scenario where a terminal establishes a single connection, the source access network device may be the access network device currently connected to the terminal, and the target access network device may be the access network device to which the terminal switches when performing a switching process.
[0033] The source access network device can be interchangeably referred to as a source base station, a source gNB, an SgNB, or a gNB; the target access network device can be interchangeably referred to as a target base station, a target gNB, or a TgNB.
[0034] Before receiving the L1 / L2 handover command from the source access network device, the terminal may further include: sending an L1 / L2 measurement report to the source access network device. Accordingly, before sending the L1 / L2 handover command to the terminal, the source access network device may further include: receiving the L1 / L2 measurement report from the terminal; and determining the target access network device of the terminal based on the L1 / L2 measurement report (or determining the target cell of the terminal based on the L1 / L2 measurement report, and determining the target access network device to which the target cell belongs). This embodiment does not limit the specific manner in which the source access network device determines the target cell and / or target access network device based on the L1 / L2 measurement report.
[0035] Exemplarily, the L1 / L2 measurement report may include at least one of the following: measurement results corresponding to one or more candidate access network devices, measurement results corresponding to one or more candidate cells, and the like. The L1 / L2 measurement report may also be alternatively referred to as an L1 and / or L2 measurement report. This is merely an example, and this embodiment does not limit or exhaustively describe all possible contents that may be included in the L1 / L2 measurement report.
[0036] The indication information is used to indicate at least one of the following: identification information, security parameters, and security activation information related to the target access network device.
[0037] The identification information related to the target access network device may include at least one of the following: an identification (ID) of the target access network device, index information of the target access network device, an identification of the target cell, and index information of the target cell, wherein the target cell is one of one or more cells of the target access network device.
[0038] The identifier of the target cell may include at least one of the following: a cell identifier (Cell ID) of the target cell, or a physical cell identifier (PCI) of the target cell.
[0039] The index information of the target access network device may be an index number (Index) or a number used only between the terminal and the source access network device to identify the target access network device. The index information of the target cell may be an index number (Index) or a number used only between the terminal and the source access network device to identify the target cell.
[0040] Optionally, the processing by the source access network device may further include: sending first information to the terminal, where the first information includes at least one of the following: index information of each candidate access network device among one or more candidate access network devices, index information of each candidate cell among one or more candidate cells, a correspondence between the index information and an identifier of each candidate access network device, and a correspondence between the index information and an identifier of each candidate cell. The identifier of each candidate cell may include the cell ID of the candidate cell and / or the PCI of the candidate cell, etc. Accordingly, the processing by the terminal may further include: receiving the first information from the source access network device.
[0041] Here, the source access network device may send the first information at a timing before sending the L1 / L2 switching command. This does not limit or exhaustively list all possible timings for the source access network device to send the first information.
[0042] The manner in which the source access network device generates the index information of each candidate access network device and / or the index information of each candidate cell is not limited in this embodiment.
[0043] The security parameters may include a next hop chaining counter (NCC). The NCC may be used to derive a basic security key between the terminal and the target access network device.
[0044] The way in which the source access network device obtains the NCC may be that the core network device configures or sends the NCC to the source access network device, or it may be determined by the source access network device based on the NCC corresponding to the security base key between the source access network device and the terminal, or it may be obtained or generated by other methods. This embodiment does not enumerate or limit this.
[0045] The security activation information may be used to instruct the terminal to activate security protection between the terminal and the target access network device. Specifically, the security activation information may include at least one of the following: a security algorithm identifier (algorithm identifier(s)) supported and / or selected by the target access network device, an indication of whether to activate user plane integrity protection between the terminal and the target access network device, and an indication of whether to activate encryption protection between the terminal and the target access network device.
[0046] The security algorithm includes at least one of the following: an integrity protection algorithm, an encryption algorithm (or an encryption / decryption algorithm). The security algorithm identifier of the target access network device may include at least one of the following: an identifier of the integrity protection algorithm of the target access network device, an identifier of the encryption algorithm (or encryption / decryption algorithm) of the target access network device. Here, the integrity protection algorithm of the target access network device is used for integrity protection-related calculations between the terminal and the target access network device; the encryption algorithm (or encryption / decryption algorithm) of the target access network device is used for confidentiality-related calculations (such as encryption and / or decryption processing) between the terminal and the target access network device.
[0047] The indication of whether to activate the user plane integrity between the terminal and the target access network device can be indicated by the value of the first identifier. For example, when the value of the first identifier is the first value, it is used to indicate that the terminal activates the user plane integrity between the terminal and the target access network device. For example, when the value of the first identifier is the second value, it is used to indicate that the terminal does not activate the user plane integrity between the terminal and the target access network device. As long as the first value and the second value are different, they are within the protection scope of this embodiment. For example, the first value can be 1 and the second value can be 0, or the first value can be 01 and the second value can be 10, etc. All possible values of the first value and the second value are not limited or exhaustive here. The first identifier can also be alternatively called the user plane integrity indication identifier (UP integrity indication).
[0048] The indication of whether to activate encryption protection between the terminal and the target access network device can be indicated by the value of the second identifier. For example, when the value of the second identifier is the third value, it is used to indicate that the terminal activates encryption protection between the terminal and the target access network device. For example, when the value of the second identifier is the fourth value, it is used to indicate that the terminal does not activate encryption protection between the terminal and the target access network device. As long as the third value and the fourth value are different, they are within the scope of protection of this embodiment. The second identifier can also be alternatively referred to as an identifier of encryption protection (ciphering indication).
[0049] In some possible embodiments, the L1 / L2 switching command is only integrity protected.
[0050] On the source access network device side, the message check code is calculated based on the integrity protection key shared with the terminal and the first portion of plaintext information. On the terminal side, processing after the terminal receives the L1 / L2 handover command may further include: calculating a verification code based on the integrity protection key shared with the source access network device and the first portion of plaintext information; and verifying the integrity of the L1 / L2 handover command based on the verification code and the message check code.
[0051] In this embodiment, all contents included in the indication information are plain text information. Specifically, the indication information may include at least one of: an identifier (ID) of the target access network device, index information of the target access network device, an identifier of the target cell, index information of the target cell, NCC, an identifier of the security algorithm supported and / or selected by the target access network device, an indication of whether to activate user plane integrity protection between the terminal and the target access network device, and an indication of whether to activate encryption protection between the terminal and the target access network device.
[0052] The first part of the plain text information included in the indication information may be all the plain text information of the indication information, or part of the plain text information of the indication information. The content type or information type that may be contained in the first part of the plain text information of the indication information may be default, or specified by the protocol, or negotiated between the terminal and the source access network device. As long as the content type or information type contained in the first part of the plain text information of the indication information known or determined by the source access network device and the terminal is the same, it is within the protection scope of this embodiment. For example, the first part of the plain text information of the indication information may include at least one of the identification (ID) of the target access network device, the index information of the target access network device, the identification of the target cell, the index information of the target cell, the NCC, etc. This embodiment does not limit or enumerate all the content that may be contained in the first part of the plain text information.
[0053] The integrity protection key is one of the following: a first key, wherein the first key includes one of the following: a control plane integrity check key, a security base key, a user plane integrity check key, a physical layer key; and is calculated based on the first key.
[0054] The security base key can also be called the access layer (AS) security base key, for example, the K specified in the relevant protocol. gNB , or K NG-RAN* This embodiment does not limit any one of the above. Regarding the derivation method of the security base key, this embodiment does not limit it.
[0055] The control plane integrity check key can specifically be the RRC layer integrity protection key, for example, the K specified in the relevant protocol RRCint The access layer signaling plane integrity verification key may be included in a NAS (Non-Access Stratun) security context. The control plane integrity verification key may also be interchangeably referred to as: access layer signaling plane integrity verification key, access layer signaling plane integrity key, access layer signaling plane integrity protection key, etc., and all possible names of the control plane integrity verification key are not exhaustively listed here.
[0056] The user plane integrity check key can be K UPintThe user plane integrity verification key may be included in the AS security context. The user plane integrity verification key may also be interchangeably referred to as a user plane integrity protection key, a user plane integrity protection key, a user plane integrity protection and verification key, and so on. This list does not exhaustively enumerate all possible names for the user plane integrity verification key.
[0057] The physical layer key can be generated based on the characteristics of the physical layer channel between the terminal and the source access network device. This embodiment does not limit the specific generation method of the physical layer key; illustratively, the physical layer key can be expressed as Kphy.
[0058] It should be understood that the above is merely an exemplary description of the first key and does not limit or enumerate all possible types of keys that may serve as the first key.
[0059] Optionally, the first key used by the terminal and the source access network device may be a default key between the two parties or a key specified in an agreement. For example, the terminal and the source access network device may default to using the control plane integrity verification key K RRCint as the first key.
[0060] Optionally, the terminal may determine the first key. The terminal's processing may further include: the terminal sending an identifier of the first key to the source access network device. The source access network device's processing may further include: receiving the identifier of the first key from the terminal; and determining the first key based on the identifier of the first key. Here, the timing at which the terminal sends the identifier of the first key is within the scope of protection of this embodiment as long as it is before the terminal receives the L1 / L2 handover command.
[0061] Optionally, the source access network device can determine the first key. The processing of the source access network device may further include: sending an identifier of the first key to the terminal. The processing of the terminal may further include: receiving the identifier of the first key from the source access network device, and determining the first key based on the identifier of the first key. This embodiment does not limit the timing of the source access network device sending the identifier of the first key to the terminal. As long as the terminal can determine the first key before completing the security verification, it is protected within the scope of this embodiment.
[0062] In one embodiment, the integrity protection key may be the first key. That is, the terminal and the source access network device may directly use the first key among multiple types of keys shared as the integrity protection key. For example, if the first key is the control plane integrity check key K RRCint , then K can be directly RRCint As an integrity protection key.
[0063] In one embodiment, the integrity protection key is calculated based on the first key. In this embodiment, the integrity protection key may also be referred to as any one of the MAC layer integrity protection key, MAC layer integrity key, MAC layer integrity protection key, etc. For example, the integrity protection key may be represented as K MACint .
[0064] It should be understood that since the terminal and the source access network device should use the same key algorithm and the same parameters to calculate the integrity protection key respectively, the integrity protection keys obtained by the two should theoretically be the same. This embodiment no longer distinguishes between the processing of calculating the integrity protection key by the terminal and the source access network device respectively, but explains them in a unified manner.
[0065] The key algorithm used to calculate the integrity protection key may be a first algorithm, which may be referred to as a key algorithm used to calculate the MAC layer integrity protection key (for example, may be expressed as N-MAC-int-alg).
[0066] The first algorithm may be tacitly agreed upon by both parties or specified in the agreement. For example, the first algorithm may include at least one of the following: a key derivation function (KDF), a first authentication function, a second authentication function, a third key generation function (for example, f3), a fourth key generation function (for example, f4), a fifth key generation function (for example, f5), a hash algorithm, an Advanced Encryption Standard (AES), a SNOW 3G (Snow Third Generation), and a ZUC (ZUChongzhi).
[0067] For example, the first key is K gNB For example, the integrity protection key (K MACint ), can be expressed by the following formula: K MACint =KDF(K gNB ).
[0068] Optionally, the integrity protection key is calculated based on the first key and at least one of the following parameters: a first fixed value, a first algorithm type, a length of the first algorithm type, an identifier of the first algorithm, a length of the identifier of the first algorithm, an identifier of the terminal, and an identifier of the source access network device.
[0069] The first fixed value may be specified by a protocol, or a default value, or a pre-configured value. The first fixed value may be expressed as FC, such as FC=0xXX.
[0070] The aforementioned first algorithm type can be represented by a type value. For example, the key algorithm used to calculate the MAC layer integrity protection key is N-MAC-int-alg, and its corresponding type value (Value) can be 0xYY; the length of the aforementioned first algorithm type can be represented by a specified base, for example, hexadecimal.
[0071] The identifier of the aforementioned first algorithm may be specified by the protocol or by default. For example, the identifier of the first algorithm may include EIA-1 / 2 / 3, NIA-1 / 2 / 3, where EIA1 represents LTE (or 4G) integrity protection algorithm 1 (which may be Snow 3G), EIA2 represents LTE (or 4G) integrity protection algorithm 2 (which may be AES), and EIA3 represents LTE (or 4G) integrity protection algorithm 3 (which may be ZUC). NIA1 to NIA3 represent NR (or 5G) integrity protection algorithms 1 to NR integrity protection algorithms 3, respectively. This is only for illustrative purposes and does not limit the identifier of the first algorithm.
[0072] Exemplarily, assuming that the integrity protection key is represented by K-mac-int, the input key for calculating K-mac-int is KgNB (ie, the first key is the security base key), and the input parameters include:
[0073] First fixed value FC=0xXX;
[0074] P0=algorithm type distinguisher (algorithm type) value (value), where P0 in this example can be the value of the first algorithm type (such as 0xYY);
[0075] L0 = length of algorithm type distinguisher, where L0 in this example represents the length of the first algorithm type, that is, the length of the value P0 of the type of the MAC layer integrity protection algorithm;
[0076] P1=algorithm identity (EIA-1 / 2 / 3, NIA-1 / 2 / 3), where P1 in this example represents the identity of the first algorithm;
[0077] L1=length of algorithm identity, where L1 in this example represents the length of the identifier of the first algorithm, for example, it can be 0x00 or 0x01, etc.
[0078] The security algorithm used by the source access network device to calculate the message check code should be the same as the security algorithm used by the terminal side to calculate the verification code.
[0079] Optionally, the integrity protection algorithm may refer to the integrity protection algorithm supported and / or selected by the source access network device. The configuration method or configuration timing of the integrity protection algorithm supported and / or selected by the source access network device on the terminal side is not limited here.
[0080] Taking the first part of the plain text information of the indication information including NCC as an example, the message check code can be calculated using the following formula: MIC=MAC(K RRCint ,NCC), where MIC Indicates the message check code, MAC () represents the integrity protection algorithm, K RRCint Integrity protection key.
[0081] It should also be pointed out that the above-mentioned process of calculating the message check code is only an example. In actual processing, the first part of the plaintext information may include NCC but is not limited to NCC. For example, the first part of the plaintext data may also include the identification (ID) of the target access network device, etc., which is not limited or enumerated here.
[0082] Optionally, the calculation of the message check code may include: performing a hash calculation on the integrity protection key to obtain a first hash value, and obtaining the message check code based on the first hash value XORing the first part of the plaintext information of the indication information.
[0083] Preferably, the first part of the plaintext information of the indication information includes a parameter. Preferably, the parameter included in the first part of the plaintext information of the indication information is an NCC. For example, the first part of the plaintext information of the indication information may include the NCC; accordingly, the process of calculating the message check code can be expressed as: Among them, MIC represents the message check code, H() represents the hash calculation, K RRCint Integrity protection key.
[0084] It should be noted that, when the message check code calculation process is preferably performed with respect to the NCC for integrity protection, the identification information associated with the target access network device in the indication information may be the index information of the target access network device and / or the index information of the target cell. That is, the source access network device hides the access network device identifier and the cell identifier by pre-configuring the first information to synchronize the index information corresponding to each access network device and cell with the terminal. Thus, integrity protection is no longer performed on the index information of the target access network device and / or the target cell during the message check code calculation process.
[0085] It should also be pointed out that, when the process of calculating the message check code is preferably for NCC security processing, the indication information may not include security activation information, and the security activation information may be configured to the terminal in a subsequent process. This embodiment does not limit the timing or process of possible configuration of the security activation information.
[0086] The terminal verifies the integrity of the L1 / L2 switching command based on the verification code and the message verification code, which may include at least one of the following: when the verification code and the message verification code are consistent, determining that the integrity verification of the L1 / L2 switching command is successful; when the verification code and the message verification code are inconsistent, determining that the integrity verification of the L1 / L2 switching command has failed.
[0087] In some possible embodiments, the L1 / L2 switching command is integrity protected and encrypted.
[0088] On the source access network device side, the indication information includes a first portion of plaintext information, and the message check code is calculated based on an integrity protection key shared with the terminal and the first portion of plaintext information included in the indication information. Furthermore, on the source access network device side, the indication information also includes ciphertext information, and the ciphertext information is calculated based on a confidentiality key shared with the terminal and a second portion of plaintext information, where the second portion of plaintext information is different from the first portion of plaintext information.
[0089] Accordingly, on the terminal side, the method further includes: calculating a verification code based on the integrity protection key shared with the source access network device and the first portion of plaintext information; and verifying the integrity of the L1 / L2 handover command based on the verification code and the message check code. Furthermore, on the terminal side, the method further includes: calculating a second portion of plaintext information based on the confidentiality key shared with the source access network device and the ciphertext information, wherein the second portion of plaintext information is different from the first portion of plaintext information.
[0090] Here, the ciphertext information is calculated based on the confidentiality key shared with the terminal and the second portion of plaintext information, which may refer to: the ciphertext information is encrypted and calculated based on the confidentiality key shared with the terminal. The terminal calculates the second portion of plaintext information based on the confidentiality key shared with the source access network device and the ciphertext information, which may refer to: the terminal decrypts the ciphertext information based on the confidentiality key shared with the source access network device to obtain the second portion of plaintext information.
[0091] The encryption / decryption algorithm of the source access network device should be the same as or correspond to the encryption / decryption algorithm on the terminal side. Exemplarily, the encryption / decryption algorithm may refer to an encryption / decryption algorithm supported and / or selected by the source access network device. The configuration method or timing of the encryption / decryption algorithm supported and / or selected by the source access network device on the terminal side is not limited herein.
[0092] The confidentiality key is one of the following: a second key, wherein the second key includes one of the following: a control plane confidentiality key, a security base key, a user plane confidentiality key, a physical layer key; and is calculated based on the second key.
[0093] The control plane confidentiality key may specifically be the RRC layer confidentiality key, for example, the K specified in the relevant protocol. RRCenc The control plane confidentiality key may be included in a NAS (Non-Access Stratun) security context.
[0094] The user plane confidentiality key can be K UPenc , the user plane confidentiality key may be included in the AS security context.
[0095] It should be understood that the above is only an exemplary description of the second key. In actual processing, the second key may also be other types of keys generated by other methods and shared by the terminal and the source access network device. The types of all keys that may serve as the second key are not limited or enumerated here.
[0096] Optionally, the second key used by the terminal and the source access network device may be a default key between the two parties or a key specified by an agreement.
[0097] Optionally, the terminal may determine the second key. The terminal's processing may further include: the terminal sending an identifier of the second key to the source access network device. The source access network device's processing may further include: receiving the identifier of the second key from the terminal; and determining the second key based on the identifier of the second key. Here, the timing at which the terminal sends the identifier of the second key is within the scope of protection of this embodiment, as long as it occurs before the terminal receives the L1 / L2 handover command.
[0098] Optionally, the source access network device can determine the second key. The processing of the source access network device may further include: sending an identifier of the second key to the terminal. The processing of the terminal may further include: receiving an identifier of the second key from the source access network device, and determining the second key based on the identifier of the second key. The timing at which the source access network device sends the identifier of the second key to the terminal may be before the source access network device sends the L1 / L2 switching command, or the identifier of the second key may be carried in the aforementioned indication information. As long as the terminal can determine the second key before completing the security verification, it is within the protection scope of this embodiment.
[0099] In one embodiment, the confidentiality key may be the second key, that is, the terminal and the source access network device may directly use the second key among multiple types of keys shared as the integrity protection key.
[0100] In one embodiment, the confidentiality key is calculated based on the second key. In this embodiment, the confidentiality key can also be called any one of the MAC layer confidentiality key, MAC layer encryption / decryption key, etc. For example, the confidentiality key can be expressed as K MACenc .
[0101] It should be understood that since the terminal and the source access network device should use the same key algorithm and the same parameters to calculate the confidentiality key respectively, the confidentiality keys obtained by the two should theoretically be the same. This embodiment no longer distinguishes between the processing of calculating the confidentiality key by the terminal and the source access network device respectively, but explains them in a unified manner.
[0102] The key algorithm used to calculate the confidentiality key may be a second algorithm, which may also be referred to as a key algorithm used to calculate the MAC layer confidentiality key (e.g., N-MAC-enc-alg). The second algorithm is a default algorithm or a protocol-specified algorithm. For example, the second algorithm may include at least one of the following: a KDF, a first authentication function, a second authentication function, a third key generation function, a fourth key generation function, a fifth key generation function, a hash algorithm, AES, SNOW 3G, or ZUC.
[0103] For example, the second key is K gNB For example, the confidentiality key (K MACenc ), can be expressed by the following formula: K MACenc =KDF(K gNB ).
[0104] Optionally, the confidentiality key is calculated based on the second key and at least one of the following parameters: a second fixed value, a second algorithm type, a length of the second algorithm type, an identifier of the second algorithm, a length of the identifier of the second algorithm, an identifier of the terminal, and an identifier of the source access network device.
[0105] The second fixed value may be specified by a protocol, or a default value, or a pre-configured value. The second fixed value may be expressed as FC, such as FC=0xXX.
[0106] The aforementioned second algorithm type can be represented by a type value, for example, if the second algorithm is N-MAC-enc-alg, its corresponding type value (Value) can be 0xZZ; the length of the aforementioned second algorithm type can be represented by a specified base, for example, it can be hexadecimal; the identifier of the aforementioned second algorithm can be specified by the protocol or by default, for example, it can include EIA-1 / 2 / 3, NIA-1 / 2 / 3, and its description is the same as the aforementioned embodiment and will not be repeated.
[0107] For example, assuming that the confidentiality key is represented by K-mac-enc, the input key for calculating K-mac-mac is KgNB (ie, the second key is the security base key), and the input parameters include:
[0108] The second fixed value FC=0xXX;
[0109] P0=algorithm type distinguisher (algorithm type) value (value), where P0 in this example represents the value of the second algorithm type, which can be 0xZZ.
[0110] L0=length of algorithm type distinguisher, where L0 in this example represents the length of the second algorithm type;
[0111] P1=algorithm identity (EIA-1 / 2 / 3, NIA-1 / 2 / 3), where P1 represents the identity of the second algorithm in this example;
[0112] L1=length of algorithm identity, where L1 in this example represents the length of the identifier of the second algorithm, for example, it can be 0x00 or 0x01, etc.
[0113] It should be pointed out that the embodiments of the present application are merely illustrative, and more other parameters and other values may be used in actual processing. For the sake of brevity, this embodiment does not list them all.
[0114] In some embodiments, the indication information includes: a first portion of plaintext information and ciphertext information. The second portion of plaintext information used to calculate the ciphertext information is different from the first portion of plaintext information included in the indication information, and the message check code is calculated only based on the first portion of plaintext information.
[0115] In this embodiment, the first portion of plaintext information included in the indication information is partial plaintext information of the indication information. Exemplarily, the second portion of plaintext information may include at least one of the following: an identifier (ID) of the target access network device, index information of the target access network device, an identifier of the target cell, index information of the target cell, and security activation information; the first portion of plaintext information may include security parameters (such as NCC). It should be understood that the above is merely an exemplary description, and does not limit or exhaustively enumerate all possible contents of the first portion of plaintext information and the second portion of plaintext information.
[0116] This example does not limit the order in which the message check code calculation and ciphertext calculation are performed on the source access network device side, and the order in which the message check code verification and ciphertext decryption are performed on the terminal side.
[0117] In some embodiments, the source access network device may calculate a message check code in combination with the second portion of plaintext information or ciphertext information.
[0118] On the source access network device side, the message check code is calculated based on the integrity protection key shared with the terminal, the first portion of plaintext information, and one of the following information: the second portion of plaintext information, the ciphertext information. Correspondingly, on the terminal side, calculating the verification code based on the integrity protection key shared with the source access network device and the first portion of plaintext information includes: calculating the verification code based on the integrity protection key shared with the source access network device, the first portion of plaintext information, and one of the following information: the second portion of plaintext information, the ciphertext information.
[0119] Optionally, the source access network device first performs integrity protection processing and then performs encryption processing, that is, the message check code is calculated based on the integrity protection key shared with the terminal, the first portion of plaintext information, and the second portion of plaintext information. The processing by the source access network device may include: calculating the message check code based on the integrity protection key, the first portion of plaintext information, and the second portion of plaintext information; and calculating the ciphertext information based on the confidentiality key and the second portion of plaintext information.
[0120] The processing after receiving the L1 / L2 switching command on the terminal side may include: decrypting the ciphertext information included in the indication information based on the confidentiality key to obtain the second part of plaintext information; calculating the verification code based on the integrity protection key, the first part of plaintext information included in the indication information and the second part of plaintext information; and verifying the integrity of the switching command based on the verification code and the message check code.
[0121] The source access network device, with the exception of adding the second portion of plaintext information when calculating the message check code, performs the same processing as in the aforementioned embodiment, and therefore will not be described in detail. Correspondingly, the terminal, with the exception of adding the second portion of plaintext information when calculating the verification code, performs the same processing as in the aforementioned embodiment, and therefore will not be described in detail.
[0122] Optionally, the source access network device first performs encryption processing and then performs integrity protection processing, that is, the message check code is calculated based on the integrity protection key shared with the terminal, the first part of plaintext information, and the ciphertext information. The processing by the source access network device may include: calculating the ciphertext information based on the confidentiality key shared with the terminal and the second part of plaintext information; and calculating the message check code based on the integrity protection key shared with the terminal, the first part of plaintext information, and the ciphertext information.
[0123] The processing after receiving the L1 / L2 switching command on the terminal side may include: calculating the verification code based on the integrity protection key, the first part of the plaintext information and the ciphertext information; when the verification code and the message check code are consistent, determining that the integrity verification of the switching command is successful; decrypting the ciphertext information included in the indication information based on the confidentiality key to obtain the second part of the plaintext information.
[0124] In this example, the source access network device adds ciphertext information when calculating the message check code. The remaining processing is identical to that in the previous embodiment, and therefore is not described here. Correspondingly, the terminal side also adds ciphertext information when calculating the verification code, and the remaining processing is identical to that in the previous embodiment, and therefore is not described here again.
[0125] In some embodiments, the content included in the indication information is encrypted information.
[0126] Optionally, the source access network device performs encryption processing before performing integrity protection processing. On the source access network device side, the message check code is calculated based on the integrity protection key shared with the terminal and the ciphertext information. The ciphertext information is calculated based on the confidentiality key shared with the terminal and the first portion of plaintext information.
[0127] On the terminal side, the method further includes: calculating a verification code based on an integrity protection key shared with the source access network device and the ciphertext information; and verifying the integrity of the handover command based on the verification code and the message check code. The method further includes: calculating a first portion of plaintext information based on a confidentiality key shared with the source access network device and the ciphertext information.
[0128] In this embodiment, the first part of plaintext data can be at least one of the following: an identifier (ID) of the target access network device, index information of the target access network device, an identifier of the target cell, index information of the target cell, NCC, an identifier of the security algorithm supported and / or selected by the target access network device, an indication of whether to activate user plane security between the terminal and the target access network device, and an indication of whether to activate encryption protection between the terminal and the target access network device.
[0129] Specifically, the processing of the source access network device generating the L1 / L2 switching command may include: encrypting the first part of the plaintext information based on the confidentiality key shared with the terminal to obtain ciphertext information; calculating the message check code based on the integrity protection key and ciphertext information shared with the terminal; using the ciphertext information as the indication information; and adding the indication information and the message check code to the L1 / L2 switching command.
[0130] On the terminal side, the processing after receiving the L1 / L2 switching command may include: calculating the verification code based on the integrity protection key and the ciphertext information included in the indication information; determining that the integrity verification of the switching command is successful when the verification code and the message check code are consistent; decrypting the ciphertext information included in the indication information based on the confidentiality key shared with the source access network device to obtain the first part of plaintext information.
[0131] The security algorithm used by the source access network device to calculate the message check code should be the same as the security algorithm used by the terminal side to calculate the verification code.
[0132] Optionally, the integrity protection algorithm may refer to the integrity protection algorithm supported and / or selected by the source access network device. The configuration method or configuration timing of the integrity protection algorithm supported and / or selected by the source access network device on the terminal side is not limited here. For example, the message check code can be calculated using the following formula: MIC=MAC(K RRCint , ciphertext information), wherein the ciphertext information is calculated based on the first part of the plaintext information. The meanings of the remaining parameters in the formula are the same as those in the aforementioned embodiment and are not repeated here.
[0133] Optionally, the calculation of the message check code may include: performing a hash calculation on the integrity protection key to obtain a first hash value, and obtaining the message check code based on the first hash value XORing the ciphertext information. For example, the process of calculating the message check code may be expressed as: The meanings of the various parameters in the formula are the same as in the previous embodiment and are therefore not repeated here. It should be noted that in this example, the ciphertext information is preferably encrypted with respect to the NCC, i.e., the first portion of plaintext data includes the NCC. However, in this example, the first portion of plaintext data is not limited to the NCC and may, for example, include identification information and / or security activation information related to the target access network device.
[0134] It should also be noted that when the indication information includes a second portion of plaintext information in addition to the ciphertext information, the source access network device may also calculate a message check code based on the second portion of plaintext information in addition to the ciphertext information. The verification code is calculated on the terminal side based on the integrity protection key, the ciphertext information included in the indication information, and the second portion of plaintext information. In this embodiment, the specific calculations of encryption and the message check code on the source access network device side are similar to those in the previous embodiment. The decryption processing, verification code calculation, and verification-related processing on the terminal side are also similar to those in the previous embodiment, and therefore will not be repeated.
[0135] Optionally, the source access network device performs integrity protection processing first and then encryption processing. At the source access network device side, the message check code is calculated based on the integrity protection key shared with the terminal and the first part of the plaintext information.
[0136] On the terminal side, the method further includes: calculating a verification code based on an integrity protection key shared with the source access network device and the first portion of plaintext information; and verifying the integrity of the L1 / L2 handover command based on the verification code and the message check code. The indication information includes ciphertext information, and the method further includes: calculating the first portion of plaintext information based on a confidentiality key shared with the source access network device and the ciphertext information.
[0137] Specifically, the processing of the source access network device generating the L1 / L2 switching command may include: calculating a message check code based on the integrity protection key shared with the terminal and the first part of the plaintext information; encrypting the first part of the plaintext information based on the confidentiality key shared with the terminal to obtain ciphertext information; using the ciphertext information as the indication information; and adding the indication information and the message check code to the L1 / L2 switching command.
[0138] On the terminal side, the processing after receiving the L1 / L2 switching command may include: decrypting the ciphertext information included in the indication information based on the confidentiality key shared with the source access network device to obtain the first part of plaintext information; calculating the verification code based on the integrity protection key shared with the source access network device and the first part of the plaintext information; and verifying the integrity of the L1 / L2 switching command based on the verification code and the message check code.
[0139] It should also be noted that when the indication information includes a second portion of plaintext information in addition to the ciphertext information, the source access network device may calculate a message check code based on the second portion of plaintext information in addition to the first portion of plaintext information. On the terminal side, the verification code is calculated based on the integrity protection key shared with the source access network device, the first portion of plaintext information, and the second portion of plaintext information.
[0140] In this embodiment, the specific calculation of encryption on the source access network device side and the specific calculation of the message check code are similar to those in the previous embodiment. The decryption processing, calculation of the verification code and related processing of verification on the terminal side are also similar to those in the previous embodiment, so they are not repeated.
[0141] In some embodiments, on the source access network device side, the method further includes: sending the security base key between the target access network device and the terminal to the target access network device. Accordingly, the processing of the target access network device may further include: receiving the security base key between the target access network device and the terminal from the source access network device.
[0142] The security basic key between the target access network device and the terminal (such as K NG-RAN* ) can be calculated based on the NCC. This embodiment does not limit the method by which the source access network device calculates the security base key between the target access network device and the terminal. The timing when the source access network device sends the security base key to the target access network device is within the scope of protection of this embodiment as long as the source access network device receives the L1 / L2 measurement report.
[0143] The processing after receiving the L1 / L2 handover command on the terminal side may further include: sending uplink data (UL Data) to the target access network device if the integrity verification of the handover command is determined to be successful. Accordingly, the processing of the target access network device may further include: receiving uplink data from the terminal.
[0144] If the indication information is used to indicate that the user plane between the activation terminal and the target access network device is intact, the terminal may perform integrity protection on the uplink data based on the integrity protection algorithm supported and / or used by the target access network device and send the uplink data. The uplink data may be uplink encrypted data or uplink plaintext data, both of which are within the scope of protection of this embodiment.
[0145] If the indication information is used to activate encryption protection between the terminal and the target access network device, the uplink data is uplink encrypted data, which can be obtained by encrypting the uplink plaintext data based on the encryption algorithm supported and / or used by the target access network device.
[0146] It should also be noted that before the terminal sends uplink data to the target access network device, it can also calculate the security base key between the terminal and the target access network device based on the NCC; the AS (access layer) key between the terminal and the target access network device is calculated based on the security base key between the terminal and the target access network device, for example, it can include at least one of the following: the integrity protection key between the terminal and the target access network device, the confidentiality key between the terminal and the target access network device. Accordingly, the uplink data is integrity protected and sent based on the integrity protection algorithm supported and / or used by the target access network device and the integrity protection key between the terminal and the target access network device, and / or the uplink plaintext data is encrypted based on the encryption algorithm supported and / or used by the target access network device and the confidentiality key between the terminal and the target access network device.
[0147] Optionally, for an L1 / L2 handover command with integrity protection enabled, or encryption and integrity protection enabled, the terminal may perform integrity verification and / or decryption processing at the MAC layer. Optionally, for an L1 / L2 handover command with integrity protection enabled, or encryption and integrity protection enabled, the terminal may pass the received MAC CE to the PDCP layer for integrity verification and / or decryption processing.
[0148] The solution provided in this embodiment is exemplarily described with reference to FIG4 . FIG4 is directed to a scenario in which integrity protection is added at the MAC layer, specifically including:
[0149] Step 401: The UE reports an L1 measurement report to the SgNB.
[0150] Step 402: The SgNB sends a cell switching command (i.e., the aforementioned L1 / L2 switching command) to the UE. The cell switching command is an integrity-protected command, i.e., it carries a message verification code.
[0151] That is, during the inter-CU LTM process, the SgNB initiates a cell handover command to the UE, which includes at least one of the following: TgNB identifier, TgNB index information, target cell permanent identifier PCI, target cell index information (for example, candidate configuration index, which indicates which candidate configuration cell the UE should switch to), security parameter NCC, security algorithm identifier supported / selected by the target base station, and an identifier used to instruct the UE to activate user plane integrity protection or encryption protection. The cell handover command can trigger the UE to switch to the target base station next. In order to protect the cell handover command message carried by MAC CE, integrity protection can be enabled between the UE and the SgNB to prevent the security parameter NCC and / or security algorithm information from being tampered with, thereby causing the UE's handover failure.
[0152] Step 403: SgNB provides TgNB with the K between TgNB and UE NG-RAN* Furthermore, the TgNB can also calculate the integrity protection key and / or confidentiality key between the UE and the TgNB.
[0153] Step 404: UE updates the key. Specifically, the UE updates the K between itself and the TgNB. NG-RAN* ; Further, the integrity protection key and / or confidentiality key between the UE and the TgNB can be updated, etc., which are not exhaustive and limited here.
[0154] Step 405: The UE sends uplink data to the TgNB, which can be protected by a new key (the new key can be at least one of the following: K NG-RAN* , integrity protection key between UE and TgNB, confidentiality key between UE and TgNB).
[0155] Step 406: TgNB processes uplink data.
[0156] It should be noted that if the SgNB configures the UE with information about candidate gNBs or candidate cells before executing LTM, the SgNB may generate index information for the candidate gNBs or candidate cells. That is, in the cell switch command message, the (permanent) identifiers of the candidate gNBs and candidate cells may not be transmitted, but the index information. In addition, the order of steps 402 and 403 is not limited in this example. Step 402 may be performed first and then step 403, or step 403 may be performed first and then step 402.
[0157] The solution provided by this embodiment is exemplarily described in conjunction with FIG5 . FIG5 targets the scenario of adding encryption and integrity protection at the MAC layer. Specifically, it includes:
[0158] Step 501 is the same as step 401 and will not be described in detail.
[0159] Step 502: The SgNB sends a cell switching command (i.e., the aforementioned L1 / L2 switching command) to the UE. The cell switching command is a command after the plain text information is encrypted and integrity protected, that is, it carries a message verification code, and the indication information includes ciphertext information.
[0160] This step differs from step 402 only in that encryption and integrity protection are enabled between the UE and the SgNB to protect the cell handover command message carried by the MAC CE. The contents of the cell handover command are similar to those in step 402 and are not described in detail here.
[0161] Steps 503 to 506 are the same as steps 403 to 406 and are not described in detail.
[0162] In some possible implementations, in a scenario where the terminal establishes a dual connection (such as NR-DC (New Radio-Dual Connectivity) or MR-DC (Multi-Radio Dual Connectivity)), the target access network device includes at least one of the following: a target primary access network device to which the terminal is to switch when performing a switching process, and a target auxiliary access network device to which the terminal is to switch when performing a switching process.
[0163] In one embodiment, the primary access network device remains unchanged and the auxiliary access network device is switched.
[0164] In this embodiment, the source access network device is a primary access network device; the primary access network device can be referred to as any one of a master base station, a master node (MN), and a source MN. The source access network device, i.e., the primary access network device, does not perform handovers. Its primary function is to send an L1 / L2 handover command to a terminal. The L1 / L2 handover command instructs the terminal to handover from the source auxiliary access network device to the target auxiliary access network device. The source auxiliary access network device can be referred to as any one of a source auxiliary base station, a source secondary node (SN), and a source SN. The target auxiliary access network device can be referred to as any one of a target auxiliary base station, a target SN, and a target SN.
[0165] Before receiving the L1 / L2 handover command from the primary access network device, the terminal may further include: sending an L1 / L3 measurement report to the primary access network device. Accordingly, before sending the L1 / L2 handover command to the terminal, the primary access network device may further include: receiving an L1 / L3 measurement report from the terminal; and determining a target auxiliary access network device for the terminal based on the L1 / L3 measurement report. This embodiment does not limit the content that the L1 / L3 measurement report may carry, or the specific manner in which the primary access network device determines the target auxiliary access network device based on the L1 / L3 measurement report.
[0166] The indication information is used to indicate at least one of the following: identification information, security parameters, and security activation information related to the target access network device.
[0167] The security parameter may include an SN counter (count value). The SN counter may be used to derive a security key between the terminal and the target auxiliary access network device, and the security key may be Ksn. This embodiment does not limit the manner in which the source access network device obtains or determines the SN counter.
[0168] The identification information related to the target access network device and the related descriptions of each content in the security activation information are similar to those in the aforementioned embodiment. The only difference is that the target access network device in the aforementioned embodiment is replaced by the target auxiliary access network device in this embodiment, so no repeated description is given.
[0169] In this embodiment, the integrity protection and / or encryption processing of the L1 / L2 switching command by the main access network device and the corresponding integrity verification and / or decryption processing of the L1 / L2 switching command by the terminal are similar to the various possible processing between the source access network device and the terminal in the aforementioned single connection-related embodiments, and therefore are not repeated.
[0170] On the primary access network device side, the method further includes: sending a security key Ksn between the target auxiliary access network device and the terminal to the target auxiliary access network device (which may be carried by an SN Addition Request); receiving confirmation information from the target auxiliary access network device (which may be carried by an SN Addition Acknowledge); sending an SN Release Request to the source auxiliary access network device, and receiving an SN Release Acknowledge from the source auxiliary access network device. Accordingly, the processing of the target auxiliary access network device may further include: receiving the security key Ksn between the target auxiliary access network device and the terminal from the primary access network device; and sending confirmation information to the primary access network device.
[0171] The security key Ksn between the target auxiliary access network device and the terminal can be calculated based on the SN counter. This embodiment does not limit how the primary access network device calculates Ksn. The primary access network device sends Ksn to the target auxiliary access network device only after the primary access network device receives the L1 / L3 measurement report, which is within the scope of this embodiment.
[0172] The processing after receiving the L1 / L2 handover command on the terminal side may further include: if it is determined that the integrity verification of the L1 / L2 handover command is successful, sending uplink data (UL Data) to the target auxiliary access network device. Accordingly, the processing after receiving the security key Ksn by the target auxiliary access network device may further include: receiving uplink data from the terminal.
[0173] If the indication information indicates that the user plane between the activated terminal and the target auxiliary access network device is intact, the terminal may perform integrity protection on the uplink data based on the integrity protection algorithm supported and / or used by the target auxiliary access network device and transmit the uplink data. The uplink data may be uplink encrypted data or uplink plaintext data, both of which are within the scope of protection of this embodiment.
[0174] The processing of the terminal to secure and / or encrypt uplink data is similar to that in the aforementioned embodiment. The only difference is that this embodiment replaces the target access network device in the aforementioned embodiment with a target auxiliary access network device, so it will not be repeated.
[0175] Before the terminal sends uplink data to the target auxiliary access network device, the terminal may also calculate the security key Ksn between the terminal and the target auxiliary access network device based on the SN Counter; and / or calculate at least one of the following based on the security key between the terminal and the target auxiliary access network device: the integrity protection key between the terminal and the target auxiliary access network device, and the confidentiality key between the terminal and the target auxiliary access network device. Accordingly, the terminal performs integrity protection on the uplink data and sends it based on the integrity protection algorithm supported and / or used by the target access network device and the integrity protection key between the terminal and the target access network device, and / or encrypts the uplink plaintext data based on the encryption algorithm supported and / or used by the target access network device and the confidentiality key between the terminal and the target access network device.
[0176] The solution provided by this embodiment is exemplarily described in conjunction with FIG6 , in which FIG6 shows a dual-connection scenario where the same MN switches to different SNs (MN triggering). Specifically, the solution includes:
[0177] Step 601: The UE reports an L1 / L3 measurement report to the MN;
[0178] Step 602: The MN sends a cell handover command (ie, the aforementioned L1 / L2 handover command) to the UE. The cell handover command is an integrity-protected and encrypted command.
[0179] That is, the MN triggers the UE to switch from the source auxiliary base station (source SN) to the target auxiliary base station (target SN) through a cell handover command. Figure 6 shows the LTM execution process. Other LTM processes, such as LTM preparation, early sycn (early synchronization), and LTM completion, are not limited. The cell handover command includes at least one of the following: a security parameter (SN counter) for generating a new Ksn, an identifier of the security algorithm supported / selected by the target SN, an identifier for instructing the UE to activate user plane security or encryption protection, an identifier of the target SN or an index of the target SN, and an identifier of the target candidate cell or an index of the target candidate cell.
[0180] Step 603: MN provides the K between Target SN and UE to Target SN through SN add request. SN MN receives the SN addition confirmation fed back by Target SN. Here, Target SN can also calculate the integrity protection key and / or confidentiality key between UE and Target SN based on Ksn.
[0181] Specifically, the MN provides the K between the Target SN and the UE to the Target SN through the SN add request. SN It may include: the MN uses the new SN counter to generate a new key Ksn, and sends a UE context to the Target SN through an SN add request to provide a UE context, where the UE context includes the key Ksn used between the target SN and the UE.
[0182] Step 604: The MN exchanges SN release request / confirmation with the Source SN.
[0183] Step 605: The UE updates the key. Specifically, the UE generates a key Ksn between the target SN and the mobile node based on the SN counter contained in the received cell handover command and the key KgNB between the UE and the mobile node. The UE uses Ksn as the key KgNB between the UE and the mobile node. The UE uses the security algorithm selected by the target SN to generate the AS key and, according to the target SN's instructions, enables UP plane protection accordingly.
[0184] Step 606: The UE sends uplink data to the Target SN, and the uplink data may be protected using the new key.
[0185] Step 607: The Target SN processes the uplink data.
[0186] It should be noted that if the MN configures the candidate SN or candidate cell information to the UE before LTM is executed, the MN can generate index information for the candidate SN or candidate cell, that is, in the cell switch command message, the (permanent) identifiers of the candidate SN and candidate cell may not be transmitted, but the index information. The SN counter is a value, which can also be called an SN counter value, an sk counter, or an sk counter value. The L1 / L3 measurement report can be an L1 measurement report, or an L3 measurement report in the LTM preparation phase. The execution order of steps 602, 603, and 604 is not limited. Step 602 can be executed first, and then step 603 and step 604; or step 603 and step 604 can be executed first, and then step 602. The execution order of steps 603 and 604 is also not limited. Step 603 can be executed first, and then step 604. In some possible examples, step 604 can also be executed first, and then step 603.
[0187] In one embodiment, the primary access network device remains unchanged and the auxiliary access network device is switched. The source access network device is a source auxiliary access network device; and the L1 / L2 switching command is used to instruct the terminal to switch from the source auxiliary access network device to the target auxiliary access network device.
[0188] Before receiving the L1 / L2 handover command from the source auxiliary access network device, the terminal may further include: sending an L1 / L3 measurement report to the source auxiliary access network device. Correspondingly, before sending the L1 / L2 handover command to the terminal, the source auxiliary access network device may further include: receiving the L1 / L3 measurement report from the terminal.
[0189] Optionally, the L1 / L3 measurement report may include an L3 measurement report and an L1 measurement report.
[0190] The terminal may report the L3 measurement report during the LTM preparation phase. After receiving the L3 measurement report, the source auxiliary access network device may include: determining the target auxiliary access network device of the terminal based on the L1 / L3 measurement report; sending an SN change request (SN Change Required) to the primary access network device, which may carry the identifier or index of the target auxiliary access network device; receiving an SN change confirmation (SN Change Confirm) from the primary access network device, which may carry the SN count value. The processing of the primary access network device may include: receiving the SN change request (SN Change Required); sending an SN change confirmation (SN Change Confirm) to the source auxiliary access network device, which may carry the SN count value; sending an SN add request to the target auxiliary access network device, which may carry the Ksn between the target auxiliary access network device and the terminal.
[0191] The terminal may report an L1 measurement report during the LTM execution phase. After receiving the SN change confirmation from the primary access network device, the source auxiliary access network device may also include: receiving the L1 measurement report from the terminal and sending an L1 / L2 switching command to the terminal.
[0192] Optionally, the L1 / L3 measurement report may include an L1 measurement report.
[0193] During the LTM execution phase, the terminal may submit an L1 measurement report. The processing performed by the source auxiliary access network device after receiving the L1 measurement report may include: determining the target auxiliary access network device for the terminal based on the L1 measurement report; sending an SN change request to the primary access network device, which may include the identifier or index of the target auxiliary access network device; receiving an SN change confirmation from the primary access network device, which may include the SN count value; and sending an L1 / L2 handover command to the terminal.
[0194] The processing of the primary access network device may include: receiving an SN change request; sending an SN change confirmation to the source auxiliary access network device; and sending an SN add request to the target auxiliary access network device, where the SN add request may carry the Ksn between the target auxiliary access network device and the terminal.
[0195] This embodiment does not limit the specific manner in which the source auxiliary access network device determines the target auxiliary access network device based on the L1 / L3 measurement report.
[0196] After determining the target access network device, the source auxiliary access network device may generate indication information and calculate the message check code. In this embodiment, the content indicated by the indication information is the same as that in the above dual connectivity related embodiment and will not be described in detail.
[0197] In this embodiment, the relevant descriptions regarding the source auxiliary access network device performing integrity protection and / or encryption processing on the L1 / L2 switching command, and correspondingly, the terminal performing integrity verification and / or decryption processing on the L1 / L2 switching command are similar to the relevant processing between the source access network device and the terminal in the embodiment of the aforementioned single connection scenario, and therefore are not repeated.
[0198] The processing after receiving the L1 / L2 handover command on the terminal side may further include: upon determining that the integrity verification of the L1 / L2 handover command is successful, sending uplink data (UL Data) to the target auxiliary access network device. Accordingly, the processing after receiving the security key Ksn by the target auxiliary access network device may further include: receiving uplink data from the terminal. The terminal sending uplink data, the target auxiliary access network device receiving uplink data, and the related processing are the same as in the previous embodiment, and therefore will not be repeated here.
[0199] The solution provided by this embodiment is exemplarily described with reference to FIG7 , in which the same MN switches to different SNs (triggered by the source SN) in a dual connectivity scenario. Specifically, the solution includes:
[0200] Step 701: The UE reports an L1 / L3 measurement report to the source SN;
[0201] Steps 702-703: The source SN sends an SN change request to the mobile node. The source SN receives an SN change confirmation from the mobile node, which may include the SN count. The source SN triggers the mobile node to generate a new key, Ksn, for the target SN by sending the SN change request. The request includes the candidate target node ID and may include measurement results for the target SN.
[0202] Step 704: MN provides the K between Target SN and UE to Target SN through SN Add Request. SN ; MN receives the SN addition confirmation fed back by the Target SN.
[0203] MN sends K SN The MN may generate a new key Ksn using a new SN counter, and send a UE context to the Target SN via an SN add request to provide the UE context. The UE context includes the key Ksn used between the Target SN and the UE.
[0204] The Target SN may also calculate, based on Ksn, an integrity protection key and / or a confidentiality key between the UE and the Target SN.
[0205] Step 705: The UE reports an L1 measurement report to the Source SN.
[0206] Step 706: The Source SN sends a cell handover command (i.e., the aforementioned L1 / L2 handover command) to the UE. The cell handover command is integrity protected and encrypted. The contents of the cell handover command are the same as those in the example corresponding to FIG6 , and are not described in detail here.
[0207] Steps 707 to 709 are the same as steps 605 to 607 in the above example and are not described again.
[0208] It should be noted that the L1 / L3 measurement report in step 701 may be a layer 3 measurement report, that is, steps 701 to 704 occur during the LTM preparation process, and LTM execution is still triggered by the L1 measurement report in step 705. Alternatively, the L1 / L3 measurement report in step 701 is a layer 1 measurement report, that is, steps 701 to 704 occur during the LTM execution process, in which case step 705 is not executed.
[0209] In one embodiment, the auxiliary access network device remains unchanged and the primary access network device is switched. The source access network device is the source primary access network device; the target access network device is the target primary access network device. The L1 / L2 switching command is used to instruct the terminal to switch from the source primary access network device to the target primary access network device.
[0210] Before receiving the L1 / L2 handover command from the source primary access network device, the terminal may further include: sending an L1 / L3 measurement report to the source primary access network device. Correspondingly, before sending the L1 / L2 handover command to the terminal, the source primary access network device may further include: receiving the L1 / L3 measurement report from the terminal.
[0211] Optionally, the L1 / L3 measurement report may include an L3 measurement report and an L1 measurement report.
[0212] The terminal may report the L3 measurement report during the LTM preparation phase. The processing after the source primary access network device receives the L3 measurement report may include: determining the target primary access network device of the terminal based on the L1 / L3 measurement report; sending a handover request (Handover Request) to the target primary access network device, which may carry the security base key K between the target primary access network device and the terminal. NG-RAN*; receiving a handover acknowledgment (Handover Request Acknowledge) from the target primary access network device. The processing of the target primary access network device may include: receiving the handover request; sending a handover acknowledgment to the source primary access network device; and sending an SN add request to the auxiliary access network device.
[0213] The handover request may include at least one of the following: configuration information (MCG and SCG configuration, primary cell group and secondary cell group configuration); SN ID indicating the SN to which the UE is currently connected; SN UE XnAP ID used to indicate that the UE context on the SN is the SN generated by the source MN; UE context; security basic key K generated for the target primary access network device and the terminal. NG-RAN* The target target main access network device will K NG-RAN* As the K between the terminal gNB use.
[0214] The SN add request may carry the SN UE XnAP ID for referencing the UE context, i.e., instructing the SN to continue using the UE context generated by the Source MN.
[0215] The terminal may report the L1 measurement report during the LTM execution phase. After receiving the L1 measurement report, the source primary access network device may process the L1 measurement report by sending an L1 / L2 switching command to the terminal.
[0216] Optionally, the L1 / L3 measurement report may include an L1 measurement report. The terminal may report the L1 measurement report during the LTM execution phase. The processing of the source primary access network device after receiving the L1 measurement report may include: determining the target primary access network device of the terminal based on the L1 / L3 measurement report; sending a handover request (Handover Request) to the target primary access network device, which may carry the security base key K between the target primary access network device and the terminal. NG-RAN* ; Receive the handover confirmation from the target primary access network device; Send an L1 / L2 handover command to the terminal. The processing of the target primary access network device is the same as the above example and will not be repeated here.
[0217] In this embodiment, the source main access network device performs integrity protection and / or encryption processing on the L1 / L2 switching command, and correspondingly, the terminal performs integrity verification and / or decryption processing on the L1 / L2 switching command, which are similar to the related processing between the source access network device and the terminal in the aforementioned embodiment, and therefore will not be repeated.
[0218] The processing after receiving the L1 / L2 handover command on the terminal side may further include: upon determining that the integrity verification of the L1 / L2 handover command is successful, sending uplink data (UL Data) to the target primary access network device. Accordingly, the processing of the target primary access network device may further include: receiving uplink data from the terminal. The terminal sending uplink data, the target primary access network device receiving uplink data, and the related processing are similar to those in the previous embodiment and are not repeated here.
[0219] The solution provided by this embodiment is exemplarily described in conjunction with FIG8 . FIG8 shows a dual-connection scenario in which different MNs are switched (triggered by the source MN) while keeping the SN unchanged. Specifically, the solution includes:
[0220] Step 801: The UE reports an L1 / L3 measurement report to the source MN;
[0221] Steps 802 to 803: The source MN sends a handover request to the target MN, and the source MN receives the SN handover confirmation sent by the target MN. The content included in the handover request is the same as that in the previous embodiment and will not be described in detail.
[0222] Step 804: The Target MN provides the SN UE XnAP ID to the SN through an SN Add Request for referencing the UE context, ie, instructs the SN to continue using the UE context generated by the Source MN.
[0223] Step 805: The UE reports an L1 measurement report to the Source MN.
[0224] Step 806: The Source MN sends a cell handover command (i.e., the aforementioned L1 / L2 handover command) to the UE. The cell handover command is integrity-protected and encrypted. The cell handover command includes or indicates at least one of the following: a Target MN identifier, Target MN index information, a target cell permanent identifier (PCI), a target cell index information, and a security parameter (NCC). It may also include algorithm identifiers (s) supported / selected by the Target MN, and an UP integrity / ciphering indication indicating to the UE whether to activate user plane integrity or ciphering protection.
[0225] Step 807: UE updates the key. Specifically, UE updates the K between itself and the Target MN. NG-RAN* ; Further, the integrity protection key and / or confidentiality key between the UE and the Target MN may be updated, etc., which are not exhaustive or limited here.
[0226] Step 808: The UE sends uplink data to the Target MN. The uplink data may be protected by using the new key.
[0227] Step 809: The Target MN processes the uplink data.
[0228] It should be noted that the L1 / L3 measurement report in step 801 may be a layer 3 measurement report, that is, steps 801 to 804 occur during the LTM preparation process, and LTM execution is still triggered by the L1 measurement report in step 805. Alternatively, the L1 / L3 measurement report in step 801 is a layer 1 measurement report, that is, steps 801 to 804 occur during the LTM execution process. In this case, step 805 is not executed.
[0229] In one embodiment, a primary access network device and an auxiliary access network device are switched. The source access network device is a source primary access network device; and the L1 / L2 switching command is used to instruct the terminal to switch from the source primary access network device to the target primary access network device, and from the source auxiliary access network device to the target auxiliary access network device.
[0230] Before receiving the L1 / L2 handover command from the source primary access network device, the terminal may further include: sending an L1 / L3 measurement report to the source primary access network device. Correspondingly, before sending the L1 / L2 handover command to the terminal, the source primary access network device may further include: receiving the L1 / L3 measurement report from the terminal.
[0231] Optionally, the L1 / L3 measurement report may include an L3 measurement report and an L1 measurement report.
[0232] The terminal may report the L3 measurement report during the LTM preparation phase. The processing after the source primary access network device receives the L3 measurement report may include: determining the target primary access network device of the terminal based on the L1 / L3 measurement report; sending a handover request (Handover Request) to the target primary access network device, which may carry the security base key K between the target primary access network device and the terminal. NG-RAN* ; receiving a handover acknowledgment (Handover Request Acknowledge) from the target primary access network device. The processing of the target primary access network device may include: receiving the handover request; sending an SN add request to the target auxiliary access network device, receiving an SN add acknowledgment sent by the target auxiliary access network device; and sending a handover acknowledgment to the source primary access network device.
[0233] The handover request may include at least one of the following: a security base key K generated for the target primary access network device and the terminal; NG- RAN*, configuration information (e.g., MCG and SCG configuration, primary cell group and secondary cell group configuration), information related to the source SN SN UE XnAP ID, SN ID, SN's UE context.
[0234] The SN add request may carry one of the following: UE context (ie, UE context generated by the source primary access network device for the source auxiliary access network device (ie, Ksn remains unchanged)), and the key Ksn updated by the target primary access network device.
[0235] The handover confirmation may carry at least one of the following: the target auxiliary access network device selection algorithm, UP indication, and may include SN counter (if the Target MN is the Target SN using K NG-RAN* and SN counter to generate a new key Ksn).
[0236] The terminal may report the L1 measurement report during the LTM execution phase. After receiving the L1 measurement report, the source primary access network device may process the L1 measurement report by sending an L1 / L2 switching command to the terminal.
[0237] Optionally, the L1 / L3 measurement report may include an L1 measurement report.
[0238] The terminal can report the L1 measurement report during the LTM execution phase. The processing after the source primary access network device receives the L1 measurement report may include: determining the target primary access network device of the terminal based on the L1 / L3 measurement report; sending a handover request (Handover Request) to the target primary access network device, which may carry the security base key K between the target primary access network device and the terminal. NG-RAN* ; Receive a handover request acknowledgement from the target primary access network device; Send an L1 / L2 handover command to the terminal. The processing of the target primary access network device is the same as the above example and will not be repeated here.
[0239] In this embodiment, the relevant descriptions of the source main access network device performing integrity protection and / or encryption processing on the L1 / L2 switching command and the corresponding terminal performing integrity verification and / or decryption processing on the L1 / L2 switching command are similar to the relevant processing between the source access network device and the terminal in the aforementioned embodiment, and therefore are not repeated.
[0240] The processing after receiving the L1 / L2 handover command on the terminal side may further include: if it is determined that the integrity verification of the L1 / L2 handover command is successful, sending uplink data (UL Data) to the target primary access network device and / or sending uplink data to the target auxiliary access network device. Accordingly, the processing of the target primary access network device may further include: receiving uplink data from the terminal. The processing of the target auxiliary access network device may further include: receiving uplink data from the terminal.
[0241] Regarding the terminal sending uplink data, the target primary access network device receiving uplink data and its related processing, the target auxiliary access network device receiving uplink data and its related processing are similar to the above embodiments, so they are not repeated.
[0242] The solution provided by this embodiment is exemplarily described in conjunction with FIG9 . FIG9 shows switching different MNs (triggered by the source MN) and switching different SNs in a dual connectivity scenario. Specifically, the solution includes:
[0243] Step 901: The UE reports an L1 / L3 measurement report to the source MN;
[0244] Step 902: The source MN sends a handover request to the target MN. The source MN provides the target MN with the key K used between the target MN and the UE. NG-RAN* , configuration information, information related to the source SN SN UE XnAP ID, SN ID, UE context of the SN.
[0245] Step 903: The Target MN provides the SN UE XnAP ID to the Target SN via an SN Add Request for referencing the UE context or new Ksn. Specifically, the Target MN can send the UE context, i.e., the UE context generated by the Source MN for the Source SN (i.e., the Ksn remains unchanged), to the Target SN, or the Target MN updates the key Ksn and provides the new Ksn to the Target SN.
[0246] Step 904: The Target SN sends an SN adding confirmation to the Target MN.
[0247] Step 905: The source MN receives the handover confirmation sent by the target MN.
[0248] Step 906: The UE reports an L1 measurement report to the Source MN.
[0249] Step 907: The Source MN sends a cell handover command (ie, the aforementioned L1 / L2 handover command) to the UE. The cell handover command is an integrity-protected and encrypted command.
[0250] The cell handover command includes or is used to indicate at least one of the following:
[0251] (1) At least one of the following related to the Target MN: Target MN identity, Target MN index information, target cell permanent identity PCI, target cell index information, security parameter NCC, which may include the security algorithm identity supported / selected by the Target MN, and an UP integrity / ciphering indication used to instruct the UE to activate user plane integrity or encryption protection;
[0252] (2) At least one of the following related to the Target SN: the Target SN identifier, the Target SN index information, the target cell permanent identifier PCI, the target cell index information, the security parameter SN counter, the security algorithm identifier supported / selected by the Target SN, and the identifier used to instruct the UE to activate user plane integrity protection or encryption protection.
[0253] Step 908: UE updates the key. Specifically, UE updates the K between itself and the Target MN. NG-RAN* Furthermore, the integrity protection key and / or confidentiality key between the UE and the target MN may be updated, and these are not exhaustive or limiting. Alternatively, the UE may generate a key Ksn between the UE and the target SN based on the SN counter and the key KgNB between the UE and the MN, and use Ksn as the key KgNB between the UE and the SN. The UE may use the security algorithm selected by the target SN to generate an AS key and, according to the target SN's instructions, enable UP plane protection accordingly.
[0254] Step 909: The UE sends uplink data 1 to the Target MN. The uplink data 1 may be protected by using the new key.
[0255] Step 910: The UE sends uplink data 2 to the Target SN. The uplink data 1 can be protected by using a new key or an original key.
[0256] Step 911: The Target MN processes uplink data 1.
[0257] Step 912: The Target SN processes uplink data 2.
[0258] It should be noted that the L1 / L3 measurement report in step 901 may be a layer 3 measurement report, that is, steps 901 to 905 occur during the LTM preparation process, and LTM execution is still triggered by the L1 measurement report in step 906. Alternatively, the L1 / L3 measurement report in step 901 is a layer 1 measurement report, that is, steps 901 to 905 occur during the LTM execution process. In this case, step 906 is not executed.
[0259] By adopting the solution provided by this embodiment, a message verification code can be included in the L1 / L2 handover command used to instruct the terminal to switch to the target access network device. This message verification code is used to verify the integrity of the L1 / L2 handover command. This allows a security protection mechanism to be introduced during the L1 / L2 handover process, preventing tampering attacks or eavesdropping attacks on the handover command message transmitted by the underlying signaling, thereby improving the security of the handover command transmitted via the underlying signaling.
[0260] In the related art, in the upcoming standardized inter-CU LTM (single or dual connectivity), the handover target cell may belong to another base station, which creates a need for key updates. In existing L3-based handovers, the HO command message includes the security parameter NCC, while the dual-connectivity handover message includes the security parameter SN counter. Both types of handover messages may also contain instructions related to the generation of security contexts. This information is directly related to how the UE calculates the key with the target base station and how to enable security protection with the target base station. However, in inter-CU LTM, if security parameters or related instructions are transmitted using underlying L1 / L2 signaling (MAC CE), due to the lack of security protection in the underlying signaling, it is easy for eavesdroppers to obtain important access network information (such as base station identifiers and selected cell identifiers). Security parameters can be tampered with, resulting in inconsistencies between the security context generated by the UE and the gNB, causing handover failures. Alternatively, algorithm identifiers and security policies can be tampered with, leading to price-down attacks and degrading security protection between the UE and the target base station. Therefore, new security mechanisms are needed to ensure the security of inter-CU LTM.
[0261] The various embodiments provided above, for the security and key update mechanisms in a single-connection inter-CU LTM process or a dual-connection inter-CU LTM process, employ integrity protection, or encryption and integrity protection, for handover command messages transmitted using MAC CE to prevent tampering attacks or eavesdropping attacks. Furthermore, the various embodiments provided above also provide protection mechanisms for important security parameters, such as the NCC and SN counter, the target base station security algorithm identifier, security policy information, and the target base station or target candidate cell identifier.
[0262] FIG10 is a schematic diagram of the structure of a terminal according to an embodiment of the present application, including:
[0263] The first communication unit 1001 is used to receive a layer 1 L1 / layer 2 L2 switching command from a source access network device, wherein the L1 / L2 switching command carries indication information and a message check code, the indication information is used for the terminal to switch to the target access network device, and the message check code is used to verify the integrity of the L1 / L2 switching command.
[0264] The first communication unit is configured to send an L1 / L2 measurement report to the source access network device.
[0265] As shown in FIG10 , the terminal further includes:
[0266] The first processing unit 1002 is configured to calculate a verification code based on the integrity protection key shared with the source access network device and the first portion of plaintext information; and verify the integrity of the L1 / L2 switching command based on the verification code and the message check code.
[0267] The indication information includes a first portion of plain text information.
[0268] The indication information includes ciphertext information, and the first processing unit is used to calculate a second portion of plaintext information based on a confidentiality key shared with the source access network device and the ciphertext information, wherein the second portion of plaintext information is different from the first portion of plaintext information.
[0269] The first processing unit is configured to calculate the verification code based on the integrity protection key shared with the source access network device, the first portion of plaintext information, and one of the following information: the second portion of plaintext information, the ciphertext information.
[0270] The first processing unit is configured to calculate a verification code based on the integrity protection key and ciphertext information shared with the source access network device; and verify the integrity of the handover command based on the verification code and the message check code.
[0271] The indication information includes ciphertext information, and the first processing unit is configured to calculate a first portion of plaintext information based on a confidentiality key shared with the source access network device and the ciphertext information.
[0272] The integrity protection key is one of the following: a first key, wherein the first key includes one of the following: a control plane integrity check key, a security base key, a user plane integrity check key, a physical layer key; and is calculated based on the first key.
[0273] The confidentiality key is one of the following: a second key, wherein the second key includes one of the following: a control plane confidentiality key, a security base key, a user plane confidentiality key, a physical layer key; and is calculated based on the second key.
[0274] The indication information is used to indicate at least one of the following: identification information, security parameters, and security activation information related to the target access network device.
[0275] FIG11 is a schematic diagram of the structure of a source access network device according to an embodiment of the present application, including:
[0276] The second communication unit 1101 is used to send a layer 1 L1 / layer 2 L2 switching command to the terminal, wherein the L1 / L2 switching command carries indication information and a message check code, the indication information is used for the terminal to switch to the target access network device, and the message check code is used to verify the integrity of the L1 / L2 switching command.
[0277] The second communication unit is configured to receive an L1 / L2 measurement report from the terminal.
[0278] The message check code is calculated based on the integrity protection key shared with the terminal and the first part of plaintext information.
[0279] The indication information includes a first portion of plain text information.
[0280] The indication information includes ciphertext information, where the ciphertext information is calculated based on a confidentiality key shared with the terminal and a second portion of plaintext information, wherein the second portion of plaintext information is different from the first portion of plaintext information.
[0281] The message check code is calculated based on the integrity protection key shared with the terminal, the first part of plaintext information and one of the following information: the second part of plaintext information and the ciphertext information.
[0282] The message check code is calculated based on the integrity protection key and ciphertext information shared with the terminal.
[0283] The indication information includes ciphertext information, where the ciphertext information is calculated based on a confidentiality key shared with the terminal and the first portion of plaintext information.
[0284] The integrity protection key is one of the following: a first key, wherein the first key includes one of the following: a control plane integrity check key, a security base key, a user plane integrity check key, a physical layer key; and is calculated based on the first key.
[0285] The confidentiality key is one of the following: a second key, wherein the second key includes one of the following: a control plane confidentiality key, a security base key, a user plane confidentiality key, a physical layer key; and is calculated based on the second key.
[0286] The indication information is used to indicate at least one of the following: identification information, security parameters, and security activation information related to the target access network device.
[0287] The device of the embodiment of the present application can realize the corresponding functions of each device in the aforementioned communication method embodiment. The processes, functions, implementation methods and beneficial effects corresponding to each module (sub-module, unit or component, etc.) in the terminal or source access network device can be found in the corresponding description in the above method embodiment, which will not be repeated here. It should be noted that the functions described in the various modules (sub-module, unit or component, etc.) in the device of the application embodiment can be implemented by different modules (sub-module, unit or component, etc.) or by the same module (sub-module, unit or component, etc.).
[0288] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0289] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0290] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included within the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A communication method executed by a terminal, comprising: Receiving a layer 1 (L1) / layer 2 (L2) handover command from a source access network device, wherein the L1 / L2 handover command carries indication information and a message check code, the indication information is used for the terminal to handover to a target access network device, and the message check code is used to verify the integrity of the L1 / L2 handover command.
2. The method according to claim 1, wherein, The method further comprises: Sending an L1 / L2 measurement report to the source access network device.
3. The method according to claim 1 or 2, wherein The method further comprises: Calculating a verification code based on an integrity protection key shared with the source access network device and a first part of plaintext information; Verifying the integrity of the L1 / L2 handover command based on the verification code and the message check code.
4. The method according to claim 3, wherein, The indication information includes a first part of plaintext information.
5. The method according to claim 4, wherein, The indication information includes ciphertext information, and the method further comprises: Calculating a second part of plaintext information based on a confidentiality key shared with the source access network device and the ciphertext information, wherein the second part of plaintext information is different from the first part of plaintext information.
6. The method according to claim 5, wherein, The calculating a verification code based on an integrity protection key shared with the source access network device and a first part of plaintext information includes: Calculating the verification code based on the integrity protection key shared with the source access network device, the first part of plaintext information, and one of the following information: the second part of plaintext information, the ciphertext information.
7. The method according to claim 1 or 2, wherein, The method further comprises: Calculating a verification code based on an integrity protection key shared with the source access network device and the ciphertext information; Verifying the integrity of the handover command based on the verification code and the message check code.
8. The method according to claim 3 or 7, wherein The indication information includes ciphertext information, and the method further comprises: Calculating a first part of plaintext information based on a confidentiality key shared with the source access network device and the ciphertext information.
9. The method according to any one of claims 3-8, wherein, The integrity protection key is one of the following: A first key, wherein the first key includes one of the following: a control plane integrity check key, a security base key, a user plane integrity check key, a physical layer key; Calculated based on the first key.
10. The method according to any one of claims 5, 6, and 8, wherein, The confidentiality key is one of the following: A second key, wherein the second key includes one of the following: a control plane confidentiality key, a security base key, a user plane confidentiality key, a physical layer key; Calculated based on the second key.
11. According to the method according to any one of claims 1-10, wherein, The indication information is used to indicate at least one of the following: identification information related to the target access network device, security parameters, security activation information.
12. A communication method executed by a source access network device, comprising: Sending an L1 / L2 handover command to a terminal, wherein the L1 / L2 handover command carries indication information and a message check code, the indication information is used for the terminal to handover to a target access network device, and the message check code is used to verify the integrity of the L1 / L2 handover command.
13. The method according to claim 12, wherein, The method further comprises: Receiving an L1 / L2 measurement report from the terminal.
14. The method according to claim 12 or 13, wherein, The message check code is calculated based on an integrity protection key shared with the terminal and a first part of plaintext information.
15. The method according to claim 14, wherein, The indication information includes a first part of plaintext information.
16. The method according to claim 15, wherein, The indication information includes ciphertext information, which is calculated based on a confidentiality key shared with the terminal and a second part of plaintext information, where the second part of plaintext information is different from the first part of plaintext information.
17. The method according to claim 16, wherein, The message authentication code is calculated based on an integrity protection key shared with the terminal, the first part of plaintext information, and one of the following information: the second part of plaintext information, the ciphertext information.
18. The method according to claim 12 or 13, wherein, The message authentication code is calculated based on an integrity protection key shared with the terminal and the ciphertext information.
19. The method according to claim 14 or 18, wherein The indication information includes ciphertext information, which is calculated based on a confidentiality key shared with the terminal and the first part of plaintext information.
20. The method according to any one of claims 14-19, wherein, The integrity protection key is one of the following: The first key, where the first key includes one of the following: a control plane integrity check key, a security base key, a user plane integrity check key, a physical layer key; Calculated based on the first key.
21. The method according to any one of claims 16, 17, and 19, wherein, The confidentiality key is one of the following: The second key, where the second key includes one of the following: a control plane confidentiality key, a security base key, a user plane confidentiality key, a physical layer key; Calculated based on the second key.
22. The method according to any one of claims 12-21, wherein, The indication information is used to indicate at least one of the following: identification information related to the target access network device, security parameters, security activation information.
23. A terminal, comprising: A first communication unit, configured to receive a layer 1 (L1) / layer 2 (L2) handover command from a source access network device, where the L1 / L2 handover command carries indication information and a message authentication code, the indication information is used for the terminal to hand over to a target access network device, and the message authentication code is used to verify the integrity of the L1 / L2 handover command.
24. The terminal according to claim 23, wherein, The first communication unit is configured to send an L1 / L2 measurement report to the source access network device.
25. The terminal according to claim 23 or 24, wherein, The terminal further comprises: A first processing unit, configured to calculate an authentication code based on an integrity protection key shared with the source access network device and a first part of plaintext information; and verify the integrity of the L1 / L2 handover command based on the authentication code and the message authentication code.
26. The terminal according to claim 25, wherein, The indication information includes a first part of plaintext information.
27. The terminal according to claim 26, wherein, The indication information includes ciphertext information, and the first processing unit is configured to calculate a second part of plaintext information based on a confidentiality key shared with the source access network device and the ciphertext information, where the second part of plaintext information is different from the first part of plaintext information.
28. The terminal according to claim 27, wherein, The first processing unit is configured to calculate the authentication code based on an integrity protection key shared with the source access network device, the first part of plaintext information, and one of the following information: the second part of plaintext information, the ciphertext information.
29. The terminal according to claim 23 or 24, wherein, The first processing unit is configured to calculate an authentication code based on an integrity protection key shared with the source access network device and the ciphertext information; and verify the integrity of the handover command based on the authentication code and the message authentication code.
30. The terminal according to claim 25 or 29, wherein, The indication information includes ciphertext information, and the first processing unit is configured to calculate a first part of plaintext information based on a confidentiality key shared with the source access network device and the ciphertext information.
31. The terminal according to any one of claims 25 - 30, wherein, The integrity protection key is one of the following: a first key, where the first key includes one of the following: a control plane integrity verification key, a security basic key, a user plane integrity verification key, a physical layer key; calculated based on the first key.
32. The terminal according to any one of claims 27, 28, and 30, wherein, The confidentiality key is one of the following: a second key, where the second key includes one of the following: a control plane confidentiality key, a security basic key, a user plane confidentiality key, a physical layer key; calculated based on the second key.
33. The terminal according to any one of claims 23-32, wherein, The indication information is used to indicate at least one of the following: identification information related to the target access network device, security parameters, security activation information.
34. A source access network device, comprising: A second communication unit, configured to send a layer 1 (L1) / layer 2 (L2) handover command to a terminal, where the L1 / L2 handover command carries indication information and a message check code, the indication information is used for the terminal to hand over to a target access network device, and the message check code is used to verify the integrity of the L1 / L2 handover command.
35. The source access network device according to claim 34, wherein The second communication unit is configured to receive an L1 / L2 measurement report from the terminal.
36. The source access network device according to claim 34 or 35, wherein The message check code is calculated based on an integrity protection key shared with the terminal and a first part of plaintext information.
37. The source access network device according to claim 36, wherein, The indication information includes a first part of plaintext information.
38. The source access network device according to claim 37, wherein The indication information includes ciphertext information, the ciphertext information is calculated based on a confidentiality key shared with the terminal and a second part of plaintext information, where the second part of plaintext information is different from the first part of plaintext information.
39. The source access network device according to claim 38, wherein, The message check code is calculated based on an integrity protection key shared with the terminal, the first part of plaintext information, and one of the following information: the second part of plaintext information, the ciphertext information.
40. The source access network device according to claim 34 or 35, wherein, The message check code is calculated based on an integrity protection key shared with the terminal and ciphertext information.
41. The source access network device according to claim 36 or 40, wherein, The indication information includes ciphertext information, the ciphertext information is calculated based on a confidentiality key shared with the terminal and a first part of plaintext information.
42. The source access network device according to any one of claims 36-41, wherein, The integrity protection key is one of the following: a first key, where the first key includes one of the following: a control plane integrity verification key, a security basic key, a user plane integrity verification key, a physical layer key; calculated based on the first key.
43. The source access network device according to any one of claims 38, 39, and 41, wherein, The confidentiality key is one of the following: a second key, where the second key includes one of the following: a control plane confidentiality key, a security basic key, a user plane confidentiality key, a physical layer key; calculated based on the second key.
44. The source access network device according to any one of claims 34-43, wherein, The indication information is used to indicate at least one of the following: identification information related to the target access network device, security parameters, security activation information.
Citation Information
Patent Citations
Key generating method, key generating device, mobile management entity and user equipment
CN101552983A
Message integrity protection and verification method and related device
CN116709333A
Method and apparatus for mobility procedure in a wireless communication system
US20220046510A1
Method, apparatus and system for cell access
WO2021018069A1
Method and apparatus for secure lower layer mobility
WO2023237172A1